Financial Due Diligence Checklist: Why the Risk Lives Between the Categories, Not Inside Them
Every financial due diligence checklist covers the same six categories: historical financials, earnings quality (quality of earnings), working capital and cash flow, debt and liabilities, tax compliance, and operations and projections. That list is genuinely comprehensive, and none of it is wrong. It's also not where a diligence process actually fails.
The categories aren't independent. A finding in one changes how much you should trust a number in another — and a checklist, by its nature, treats each category as a box to check, not a set of numbers that need to be reconciled against each other. That's the real gap, and it's structural, not a matter of working harder through the same list.
Why the Financial Due Diligence Checklist Format Is Borrowed From the Wrong Domain
Here's the opinionated version, because it's the part almost nobody says out loud: the checklist is not a neutral container. It's a tool with a design bias, and the bias is wrong for this job.
Checklists earned their reputation in aviation and surgery — pre-flight checks, the surgical safety checklist. In those settings the format works brilliantly, and it works because the items are independent failure points. Whether the flaps are set has nothing to do with whether the fuel is loaded; each item is a separate switch, and the only failure mode is forgetting one. The checklist's entire job is completeness — did we touch every switch. That is exactly what it optimizes for, and it's genuinely the right instrument for a world of independent checks.
Financial diligence is not that world. The findings are not independent switches. They are a correlated system, where the value of one number is conditional on another. A checkbox can hold "done" or "not done." It cannot hold "this revenue figure is only trustworthy if the concentration number holds" — there is no field on a checklist for a dependency between two findings, because the format was built for a domain where those dependencies don't exist. Import the tool built for independent failure points into a domain of correlated risk and you get a category error dressed up as rigor: a document that proves you looked at everything and quietly says nothing about whether the things you found agree with each other.
Completeness is not coherence. A checklist measures the first and is silent on the second. The unit a checklist works in is the item; the unit a deal lives or dies on is the interaction between items. That mismatch is the whole problem, and no amount of adding more line items fixes it — a longer checklist is just more independent boxes, never the connection between them.
The Number That Ties the Categories Together
Revenue Quality Score measures the percentage of trailing-twelve-month revenue that's recurring, contracted, or high-confidence repeat business, as opposed to one-time, project-based, or genuinely at risk of not repeating.
| Industry | Top Quartile | Average | Bottom Quartile |
|---|---|---|---|
| SaaS | 95% | 82% | 65% |
| Fintech | 88% | 72% | 50% |
| Distribution | 72% | 56% | 38% |
| Healthcare Provider | 72% | 55% | 35% |
| Professional Services | 65% | 45% | 25% |
| Manufacturing | 60% | 42% | 22% |
| Consulting | 55% | 38% | 20% |
| Retail | 42% | 26% | 10% |
A target sitting at bottom-quartile revenue quality has a revenue base that has to be re-won every period — real execution risk that a category-by-category checklist will record as "customer schedule reviewed, complete" without ever asking what that number should do to your confidence in the numbers next to it on the list.
Interaction One: Customer Concentration Should Discount Revenue Quality — and EBITDA Confidence
A financial DD checklist has a line item for customer concentration (what percentage of revenue comes from the top 1, 3, or 10 customers) and a separate line item for revenue quality. Run them independently and you can end up with a target that reports 80% "recurring" revenue while 45% of total revenue sits with three customers, each with an unremarkable renewal history and no real switching cost.
That's not 80% quality revenue. It's revenue that's contractually recurring today and structurally exposed to a small number of relationships that could each walk without much friction. The checklist format doesn't force that reconciliation — it has a box for concentration and a box for quality, and a diligence process that treats them as separate line items instead of two inputs to the same underlying risk will report a clean checklist on a target that's genuinely more fragile than the individual boxes suggest.
Interaction Two: An Existing QoE Report Isn't a Substitute for Checking It
Almost every financial DD checklist has a line for "quality of earnings report — obtained: yes/no." That's the wrong question. The right one is whether the QoE report's add-backs and adjustments reconcile against management's own normalized EBITDA bridge — the two are frequently built by different people at different times, and they don't always agree.
When they diverge, the gap is real information: either the QoE team found something management's own bridge missed, or management's bridge is optimistic in a way the QoE report didn't fully challenge. A checklist that just confirms the document exists never surfaces that divergence — the box gets checked the moment the PDF lands in the data room, whether or not the two numbers inside it actually agree with each other.
What This Looks Like When It All Checks Out and Still Isn't Right
Picture a composite target assembled from the pattern that recurs across mid-market deals in distribution and light manufacturing — not any one company, but the shape these deals tend to take. It comes to market at 78% "recurring" revenue and a clean, third-party QoE report. Every box on the financial checklist gets a tick.
Now look at the connections the ticks don't capture. That 78% "recurring" figure rests on standing purchase orders from three accounts that happen to reorder most months — no contracts, no switching cost, just years of habit. The QoE add-backs restore, say, $1.4M of "one-time" freight spikes and owner compensation to EBITDA; management's own normalized bridge only restores about $1.0M of it. And working capital looks pristine — fast collections, low DSO — precisely because those same three habitual accounts pay quickly.
Read category by category, this target passes cleanly: concentration noted, revenue quality high, QoE obtained, working capital healthy. Read as a connected system, it's a different business. The revenue quality, the concentration, the collections, and the $0.4M EBITDA disagreement are not four findings — they're four views of a single question: what happens to this company when one of three habitual buyers meets a new owner's first post-close price increase? A checklist has no row for that question, because the question lives between the rows. That's the pattern worth internalizing: the deals that surprise buyers rarely fail an item on the list — they fail the arithmetic between items that nobody was asked to do.
Why Running the Categories in Parallel, Not in Isolation, Is the Real Fix
Neither of these interactions requires new information — every number involved is already sitting in the standard checklist. What's missing is the discipline to run commercial, financial, and the rest of the workstreams as one connected read of the same business, with each new finding checked against the others as it comes in, instead of five separate teams each producing their own tidy, internally-consistent, and individually incomplete section of the same data room package.
A diligence process that surfaces a customer concentration number without asking what it does to revenue quality, or accepts a QoE report without reconciling it to management's bridge, will still produce a checklist that looks complete. It just won't tell you the thing you actually needed to know before you signed.
The same interaction logic applies beyond the deal itself — a target's working capital position and its revenue quality aren't independent either: a business collecting fast from a concentrated customer base can look like it has clean working capital metrics right up until one of those customers renegotiates terms. And any GAAP conversion sitting inside the target's financials carries the same cross-checking requirement — an unreconciled restatement is exactly the kind of thing a category-by-category review can miss entirely.
Performis's PE Due Diligence work runs all five workstreams — commercial, financial, management, market, and risk — in parallel rather than sequentially, with findings in one workstream explicitly checked against the others as they surface: a concentration finding adjusts the revenue quality read, a QoE report gets reconciled against management's own bridge before either number is trusted, producing an IC-memo-ready recommendation instead of five clean-looking sections that were never actually checked against each other.
If you're evaluating a target and want the categories checked against each other, not just checked off, start a PE Due Diligence engagement before you're relying on a data room nobody's reconciled.