Mergers and Acquisitions Compliance: The Regulatory Checklist I Run Before Every Deal

Mergers and Acquisitions Compliance: The Regulatory Checklist I Run Before Every Deal

April 27, 2026

Mergers and Acquisitions Compliance: The Regulatory Checklist I Run Before Every Deal

Mergers and acquisitions compliance is the process of verifying that a target business — and the transaction itself — satisfies every applicable federal, state, local, and industry-specific law before, during, and after close. It covers antitrust filings (HSR), securities and tax rules, licensing and permits, employment and benefits law, data privacy, environmental regulations, and industry-specific oversight (healthcare, financial services, defense, food). Skip it and you inherit fines, rescinded licenses, personal liability, and lawsuits the day the wire clears.

Look, I’ve done 300+ deals over 30 years. Compliance isn’t the sexy part of dealmaking, but it’s the part that will unwind your transaction, empty your bank account, or land you in front of a regulator if you skip it. I’ve watched buyers close in 60 days flat and then spend two years cleaning up a mess they inherited because nobody pulled the license file.

Here is the exact way I approach regulatory compliance on every acquisition, and the way we teach it inside Dealmaker Academy. One caveat before we start: I’m a dealmaker, not your attorney and not your CPA. Every point below is a starting checklist. You hire your own counsel and tax advisor to sign off on the actual filings.

Why M&A Compliance Is a Deal-Killer If You Ignore It

Regulatory non-compliance is one of the top three reasons acquisitions blow up after signing — right alongside financial misrepresentation and customer concentration. Fines transfer with the entity in a stock deal. Licenses can be non-transferable. And personal liability can attach to officers and directors if they knew or should have known about a violation.

The buyer inherits the sins. Price that in or paper around it — don’t pretend it isn’t there.

The Six Compliance Categories Every Acquirer Must Assess

Every business acquisition triggers compliance obligations across six distinct regulatory categories, and each one can independently kill a deal or trigger post-close liability. Work through all six on every target, even if your gut says the industry is “clean.”

  1. Antitrust and competition law. Sherman Act, Clayton Act, and the Hart-Scott-Rodino (HSR) pre-merger notification thresholds enforced by the FTC and DOJ. If your deal clears the HSR size test, you file and wait through the review period before you can close.
  2. Securities and tax law. Asset vs. stock structure changes the tax profile, the liability profile, and what has to be filed. Get your CPA and securities counsel in the room before the LOI is signed, not after.
  3. Licensing and permits. Contractor licenses, liquor licenses, professional licenses, DOT authority, franchise agreements. Some transfer automatically. Many don’t. Confirm every single one in writing.
  4. Employment, benefits, and labor. ERISA, COBRA, WARN Act notices, immigration I-9s, worker classification (1099 vs. W-2), collective bargaining agreements, and unfunded pension exposure.
  5. Data privacy and cybersecurity. GDPR, CCPA, HIPAA, PCI-DSS, state breach-notification laws. Any prior breach the seller failed to disclose becomes your problem the moment you close.
  6. Industry-specific rules. Healthcare (Stark, Anti-Kickback, HIPAA), financial services (FINRA, SEC, state banking), defense (ITAR, CFIUS), food (FDA), environmental (EPA, state DEQ). Every regulated industry has its own layer on top of the general ones above.

The Compliance Audit: What I Actually Look At

A compliance audit is a systematic review of the target’s regulatory posture — filings, licenses, disclosures, past enforcement actions, and internal policies — designed to surface every liability that will follow the business into your ownership. Your attorney runs the legal review. You and your CPA run the operational and financial review. Nobody skips a category.

Here is the seven-part audit I run alongside legal counsel on every target:

  • License and permit inventory. Pull every active license, permit, and certification. Confirm expiration dates, renewal requirements, and — critically — transferability at change of control.
  • Regulatory filings history. Last 5 years of tax filings, sales tax returns, payroll filings, industry-specific filings. Missing filings are unpaid liability with interest and penalties compounding.
  • Enforcement history and pending actions. Any prior investigations, consent decrees, fines, or open matters with any regulator. Ask directly. Get it in the disclosure schedule.
  • Contracts with change-of-control clauses. Customer contracts, supplier contracts, leases, and franchise agreements often terminate or require consent on transfer. That’s a valuation issue if 40% of revenue walks the day you close.
  • Employee and benefits compliance. I-9 audits, worker classification, wage-and-hour compliance, benefits plan documents, and unfunded pension liabilities.
  • Environmental exposure. Phase I environmental site assessment on any real estate. Phase II if Phase I flags anything. Environmental liability is CERCLA joint-and-several — you can inherit it even in an asset deal.
  • Data and cyber posture. Prior breaches, current cybersecurity controls, GDPR/CCPA readiness, and whether the business holds any regulated data (PHI, PCI, PII).

HSR and Antitrust: When You Have to File

The Hart-Scott-Rodino Act requires pre-merger notification to the FTC and DOJ whenever a transaction crosses the current “size of transaction” threshold, which is adjusted annually. If you’re in that range, you file, you pay the filing fee, and you wait out the statutory review period before closing.

Four things to know before you assume HSR doesn’t apply:

  • Thresholds change every year. The dollar figures reset each February. Confirm the current number with your antitrust counsel — do not rely on a blog post, including this one.
  • The “size of person” test matters too. Below the top threshold, HSR may still apply if the buyer or seller entity is large enough. This trips up private buyers acquiring small targets under a large holding company.
  • Structure affects filing. Some asset deals, minority investments, and intra-family transfers are exempt. Some aren’t. Counsel tells you which bucket you’re in.
  • Gun-jumping is real. You cannot integrate operations, share competitively sensitive data, or coordinate pricing until after clearance. Violations carry per-day fines.

Most Main Street deals I coach through don’t hit HSR. Middle-market and up frequently do. Never assume.

Structuring the Deal for Compliance Protection

Deal structure is your first line of defense against inherited compliance risk — the choice between asset purchase and stock purchase, plus the reps, warranties, indemnities, holdbacks, and escrows in the purchase agreement, determines who wears the liability if a violation surfaces after close.

Five structural tools I use on every deal with regulatory exposure:

  • Asset purchase over stock purchase when possible. An asset deal typically lets you leave successor liability behind (with important exceptions for environmental, tax, employment, and product liability — your attorney maps them out for your industry).
  • Robust reps and warranties on compliance. The seller represents in writing that the business is compliant with all applicable laws. That rep survives close for a defined period and is backed by indemnification.
  • Disclosure schedule. Every known exception to the reps gets listed. What isn’t disclosed is on the seller if it surfaces later.
  • Escrow or holdback. A portion of the purchase price sits in escrow for 12 to 24 months to fund indemnity claims. Non-negotiable when I see any regulatory smoke.
  • Reps and warranties insurance. On larger deals, a third-party policy backs the indemnification obligations. Useful when the seller is retiring and won’t be collectable in three years.

Post-Close Compliance Integration

The 90 days after closing is when most compliance failures actually happen — filings that get missed, licenses that don’t get transferred, employees who fall out of I-9 compliance, and disclosures that don’t reach regulators on time.

Your first 90 days need a written compliance integration plan covering:

  • License and permit transfers or reapplications. Filed within the deadlines dictated by each regulator.
  • Change-of-control notices. To customers, suppliers, landlords, franchisors, and lenders as required by each contract.
  • Employee documentation refresh. New I-9s where required, benefits enrollment, updated handbook acknowledgments.
  • Tax registrations. Federal EIN, state sales tax, payroll, and unemployment accounts in the acquiring entity’s name.
  • Data and IT cutover. Access controls, breach-response plan, and privacy notices updated to reflect the new ownership.

Run this like a project. Assign owners, set dates, hold a weekly stand-up until every line is closed.

When to Walk Away for Compliance Reasons

Some compliance findings are fixable at a price you can negotiate into the deal. Others mean you throw the red flag and move on. Knowing the difference is what separates buyers who build wealth from buyers who fund lawyers.

Four categories that are usually walk-away situations, not negotiation situations:

  • Active criminal investigations of the seller or the business. Not something you paper around.
  • Systematic tax evasion. Unreported cash sales, off-book payroll, phantom deductions. The IRS follows the entity and often the owners.
  • Undisclosed environmental contamination. Remediation costs routinely exceed the purchase price on smaller deals.
  • Non-transferable core license the business depends on. If the license is the business and it won’t transfer, there is no deal.

A great business with a fatal compliance issue is still a fatal deal.

Compliance Is a Team Sport — Who You Need in the Room

No serious M&A transaction gets done without a compliance team, and the smaller the deal, the more the buyer tries to skip this and pays for it later. At minimum you need M&A counsel, a CPA experienced in transaction tax, and — for regulated industries — a specialist in that specific regulatory scheme.

  • M&A attorney. Drafts and negotiates the purchase agreement, runs legal due diligence, and coordinates specialist counsel.
  • Transaction CPA. Structures the deal for tax efficiency, runs quality-of-earnings analysis, and reviews the target’s tax posture.
  • Industry specialist. Healthcare attorney, environmental consultant, cybersecurity assessor — whoever matches the target’s regulatory surface area.
  • Insurance broker. Reviews existing coverage, prices reps-and-warranties insurance if applicable, and lines up the day-one policies you need as the new owner.

If a seller pushes you to skip counsel or cut the diligence period, that is the diligence finding.

Frequently Asked Questions

What is mergers and acquisitions compliance?

Mergers and acquisitions compliance is the discipline of confirming that a target business — and the transaction itself — satisfies every applicable federal, state, local, and industry-specific regulation before, during, and after close. It covers antitrust filings, securities and tax rules, licensing, employment law, data privacy, environmental regulations, and any industry-specific oversight. The goal is to prevent inherited fines, rescinded licenses, canceled contracts, and personal liability from becoming the buyer’s problem after the wire clears.

What regulations govern mergers and acquisitions in the United States?

The core U.S. regulations include the Sherman Act and Clayton Act (antitrust), the Hart-Scott-Rodino Act (pre-merger notification to the FTC and DOJ), federal and state securities laws for equity transactions, tax code provisions governing asset versus stock treatment, ERISA and COBRA for employee benefits, and CFIUS for deals involving foreign buyers. Industry-specific rules — HIPAA and Stark in healthcare, FINRA and SEC in financial services, ITAR in defense, FDA in food and pharma, EPA in environmental — layer on top of the general regime.

Do I have to file an HSR notification for my acquisition?

You must file a Hart-Scott-Rodino pre-merger notification if the transaction crosses the current “size of transaction” threshold, which the FTC updates annually each February. Some deals below that threshold still require filing under the “size of person” test if the buyer or seller entity is large enough. Confirm the current thresholds and your specific filing obligation with qualified antitrust counsel before signing an LOI, because gun-jumping violations carry per-day fines and can unwind the transaction.

What is a compliance audit in an acquisition?

A compliance audit is a systematic pre-close review of the target’s regulatory posture — licenses and permits, tax and regulatory filings, past enforcement actions, contracts with change-of-control clauses, employee and benefits compliance, environmental exposure, and cybersecurity posture. Your attorney handles the legal review and your CPA handles financial and tax compliance. The output is a written record of every risk that will follow the business into your ownership, priced into the deal or paper-protected through the purchase agreement.

Should I do an asset purchase or a stock purchase for compliance protection?

Asset purchases generally offer stronger protection from inherited liability because you buy specific assets and assume specific liabilities rather than acquiring the entity itself. Important exceptions apply — environmental, tax, employment, product liability, and successor liability doctrines can still reach an asset buyer in many states. Stock purchases are simpler for license transfers and existing contracts but carry the entity’s full history. The right structure depends on the target’s regulatory profile, tax situation, and jurisdiction. Your M&A attorney and transaction CPA make the call together.

What are reps and warranties in an M&A compliance context?

Reps and warranties are the seller’s written statements in the purchase agreement about the condition of the business — including that it is compliant with all applicable laws, holds all required licenses, has filed all required returns, and has not been the subject of undisclosed enforcement actions. These representations survive closing for a defined period and are backed by an indemnification obligation, often supported by an escrow or holdback of a portion of the purchase price. On larger deals, reps and warranties insurance can back the seller’s obligations.

What compliance issues should make me walk away from a deal?

Walk away when you find active criminal investigations of the seller or business, systematic tax evasion (off-book payroll, unreported cash, phantom deductions), undisclosed environmental contamination on owned real estate, or a core operating license that legally cannot transfer to a new owner. These aren’t discounts to negotiate — they are structural defects. A great business with a fatal compliance defect is still a fatal deal, and remediation or defense costs routinely exceed the purchase price on smaller acquisitions.

What compliance work happens after close?

The first 90 days after close is when most compliance failures actually occur. You must file license and permit transfers within regulator-specific deadlines, send change-of-control notices to customers, suppliers, landlords, franchisors, and lenders, refresh employee documentation including I-9s and benefits enrollments, update tax registrations to the acquiring entity, and cut over IT access and privacy notices. Run it as a formal project with named owners, deadlines, and weekly check-ins until every line is closed.

Where can I learn how to run compliance diligence on a live deal?

Dealmaker Academy walks compliance diligence on real acquisition targets with Carl Allen and the coaching team, including sample checklists, LOI language, and disclosure schedules. The Protégé Community is where active dealmakers share what surfaced on their own deals and how they papered it. For a deal you’re working on right now, book a coaching call to walk through the specific target with the team, then hire your own attorney and CPA to execute.


Next move: pull your target’s license list, last five years of regulatory filings, and enforcement history this week. Take what you find to your M&A attorney and CPA before you sign the LOI. See the rest of our due diligence playbooks, or book a coaching call to pressure-test a live deal with the team.

Disclaimer: This article is educational, not legal, tax, or financial advice. Regulatory compliance in mergers and acquisitions is highly fact-specific and jurisdiction-dependent. Always retain qualified M&A counsel, a transaction CPA, and industry-specific specialists before signing any letter of intent or purchase agreement.

Learn From REAL Dealmakers

We do deals everyday.
And we’re here to give you all the secrets.

FEATURED TRAINING

The Creative Dealmaker

14 episodes

FEATURED TRAINING

Become an Equity Partner

11 episodes

FEATURED TRAINING

9-Figures
in 24 Months

1 training

Learn the art of creative deal structuring.

Learn the art of creative deal structuring.

Reserve Your Copy Today

A Creative Business Buying Fable