Due Diligence Questionnaire for Buying a Small Business
Due Diligence Questionnaire for Buying a Small Business

You've found a small business that looks profitable, the seller has supplied a folder of financial statements, and the broker is asking whether you're ready to move toward a purchase agreement. Then you notice the gaps. A major customer contract is missing, the owner appears to approve every important decision, and the tax records don't reconcile cleanly with the management accounts.
That's the point at which a due diligence questionnaire becomes useful. It isn't a formality and it isn't a giant list of questions sent to the seller without context. For an acquisition entrepreneur, it's an evidence-backed workflow that connects seller representations to documents, assigns responsibility for follow-up, and turns uncertainty into a decision.
Table of Contents
- Introduction to Due Diligence Questionnaires for Small Business Buyers
- How Standardized DDQs Evolved and Why They Matter Today
- Building a Modular DDQ That Fits Owner Operated Deals
- Financial Legal and Tax Questions Every Buyer Must Verify
- Operations HR and IT Systems Due Diligence Explained
- Customers Sales and Commercial Health Checks
- From DDQ Findings to Integration and Deal Protections
- How to Prioritize and Right Size Your Questionnaire
- Quick Reference Templates Checklists and Cross References
Introduction to Due Diligence Questionnaires for Small Business Buyers
A due diligence questionnaire, or DDQ, is a structured request for information used to investigate a company before an investment, acquisition, or other material transaction. In an SMB purchase, it should help you answer three practical questions:
- What does the business own and operate?
- Which risks could affect value, financing, or post-close performance?
- What must be resolved, protected, or reflected in the purchase agreement?
A generic checklist asks whether the target has contracts, employees, insurance, systems, and financial records. A strong DDQ goes further. It asks who owns each answer, when the answer is due, what evidence supports it, and what happens if the seller can't provide that evidence.
Practical rule: Treat every material DDQ response as a claim that needs a verification path.
Suppose the seller says customer retention is strong. Your questionnaire should point to renewal records, invoices, customer-level revenue, and the commercial analysis. If the owner says there are no material legal disputes, the response should connect to litigation searches, attorney correspondence, threatened claims, and the representations in the purchase agreement. If the company relies on a single software administrator, that answer belongs in operations, technology, key-person risk, and your integration plan.
The most useful DDQ is therefore an auditable diligence map. Each workstream identifies what you need to understand, what you need to request, and what could change your decision. A modular design keeps the process manageable for an owner-operated company while preserving comparability across targets.
Use this guide as a field reference rather than a form to complete mechanically. Start with the core modules, tag each question by risk and evidence status, cross-reference findings to financial, legal, operational, and commercial reviews, then escalate only the issues that can affect price, structure, closing, or first-day control.
How Standardized DDQs Evolved and Why They Matter Today
Standardized DDQs exist because buyers repeatedly ask similar questions, while sellers repeatedly receive different formats. A common baseline makes responses easier to compare and reduces the amount of ad hoc questioning that obscures the risks.
The global history began in hedge funds and alternative investments. The Alternative Investment Management Association says it has provided DDQs for more than 20 years, and it published its first questionnaire for investors diligencing hedge fund managers in 1997 in response to requests for a standardized question set. AIMA describes those questionnaires as an industry-standard template, while later private-markets work extended the same logic into private equity and related transactions. AIMA's history of due diligence questionnaires explains that development.
Private markets later developed their own shared infrastructure. The Institutional Limited Partners Association first released its standardized DDQ in October 2013, revised it in September 2016, updated it again in 2018, and published DDQ 2.0 in November 2021. ILPA says its DDQ and Diversity Metrics Template were created to standardize key areas of inquiry used by investors when diligencing managers. Its account of the 2021 refresh also describes input from public comment, LP and GP discussions, industry bodies, working groups, and roundtables. ILPA's due diligence questionnaire resource library shows how the document became a coordinated market practice rather than a private spreadsheet.
What standardization solves
A standardized template improves coverage and comparability. It gives a buyer a repeatable bank of questions across firm background, strategy, team, track record, fund terms, governance, accounting, legal matters, technology, security, and ESG. That structure helps prevent a first-time buyer from focusing only on revenue and earnings while missing ownership, compliance, data, or continuity problems.
Standardization doesn't eliminate judgment. Institutional templates may assume multiple departments, formal policies, and extensive reporting systems. An owner-operated target may have sound practices that aren't documented in institutional language, or it may have serious weaknesses hidden behind informal processes.
The right approach is to borrow the architecture, not blindly copy the volume. Start with a common core, then add modules for the target's sector, dependencies, legal entities, data flows, and owner reliance.
Building a Modular DDQ That Fits Owner Operated Deals
A useful SMB DDQ has a core set of workstreams and optional modules. The core should apply to every target. Optional modules should activate when the business has a particular exposure, such as regulated services, inventory, outsourced fulfillment, software development, cross-border data, or heavy reliance on the seller.
Build the questionnaire around these workstreams:
- Firm and ownership: Legal entities, ownership records, organizational history, affiliates, liens, licenses, and authority to sell.
- Strategy and operations: Products, services, pricing, suppliers, facilities, workflows, quality controls, and business continuity.
- Financial and tax: Financial statements, bank records, tax filings, debt, working capital, projections, and normalization items.
- People and HR: Employees, contractors, compensation, benefits, agreements, turnover, key-person dependency, and succession.
- Technology and security: Core applications, access controls, backups, vendors, incidents, data governance, and recovery procedures.
- Commercial and ESG: Customers, pipeline, marketing channels, competitive position, environmental commitments, and relevant reporting obligations.
Each question needs four control fields: owner, deadline, response status, and evidence required. The owner might be the seller, bookkeeper, operations manager, outside counsel, or your own diligence lead. Without an assigned owner, questions sit unanswered. Without a deadline, the data room becomes an archive rather than a workflow.
Use response categories that expose uncertainty instead of hiding it. A practical set is answered, partially answered, not applicable, evidence missing, and material issue identified. A narrative answer that says “the owner handles this” should usually be marked partial until the seller identifies the process, backup person, system access, and transition plan.
Link questions to verification steps
Every important question should point to a next action. For example:
| Question | Evidence | Verification action |
|---|---|---|
| Who owns the operating entity? | Formation records, ownership ledger, purchase history | Confirm authority to sell and identify liens |
| How are sales recorded? | General ledger, invoices, bank deposits, tax filings | Reconcile revenue by period and customer |
| Who approves supplier payments? | Bank permissions, approval policy, payment reports | Test segregation of duties and access |
| What happens if the owner is unavailable? | Process documents, schedules, employee interviews | Identify transition and key-person exposure |
This format keeps the DDQ from becoming a free-text exercise. It also creates a clean handoff to advisors. Counsel can see legal questions, the accountant can see financial questions, and the buyer can retain the cross-functional risk view.
For an owner-operated target, ask fewer irrelevant questions and demand better evidence for the questions that matter. A shorter, well-owned DDQ can reveal more than an institutional questionnaire that overwhelms the seller and produces vague responses.
Financial Legal and Tax Questions Every Buyer Must Verify
Financial diligence starts with reconciliation, not the seller's summary. Request financial statements, general ledgers, bank statements, accounts receivable and payable aging, inventory reports where relevant, tax returns, debt schedules, and supporting explanations for unusual items.
Financial verification
Test whether reported revenue reaches the bank and accounting records. Compare customer-level sales to invoices, deposits, credit notes, refunds, and tax filings. Review gross margin by product or service, investigate unusual period-end entries, and separate recurring operating expenses from owner-specific or nonrecurring items.
Working capital deserves its own schedule. Identify normal levels of receivables, payables, inventory, deferred revenue, and accrued expenses, then define how the purchase agreement will calculate the working-capital peg. If the seller's reported earnings depend on underfunded maintenance, delayed payables, or owner labor that won't continue after closing, that issue belongs in both normalized earnings and the operating transition plan.
For a broader document-by-document process, use this financial due diligence checklist for acquiring a business. It complements the DDQ by organizing the records you'll need to collect and review.
Legal and ownership checks
Confirm the legal entity that owns the assets, contracts, intellectual property, permits, and customer relationships. Request formation documents, amendments, ownership records, certificates of good standing, material contracts, leases, insurance policies, litigation correspondence, settlement agreements, and security-interest searches.
Check whether the seller can transfer each important contract. A customer relationship may appear valuable in the revenue report but become fragile if assignment requires consent. The same applies to leases, licenses, software subscriptions, supplier agreements, and franchise arrangements.
Review litigation, threatened claims, regulatory notices, employment disputes, and indemnity obligations. Screen relevant parties for sanctions and AML concerns where the transaction, customer base, or jurisdiction makes that appropriate. Don't treat “none known” as the final answer. Ask what searches were performed, by whom, and when.
If the company has multiple owners or partners, examine the governing agreement, transfer restrictions, buy-sell provisions, deadlock rules, and authority requirements. A practical explanation of ownership rights and partner arrangements is available in LA Law Group APLC agreement advice, which can help frame the documents your counsel should review.
Tax and purchase agreement linkage
Request filed tax returns, notices, payment records, sales-tax or VAT filings where applicable, payroll-tax records, tax elections, and correspondence with authorities. Reconcile tax liabilities to the balance sheet and ask about audits, payment plans, unfiled returns, worker classification, nexus, and informal compensation.
Every material finding should map to a protection. Unpaid taxes may require a specific indemnity. A disputed contract may need a closing condition or consent. Uncertain working capital should influence the peg or escrow. The DDQ earns its value when the answer changes the transaction, not when the spreadsheet reaches completion.
Operations HR and IT Systems Due Diligence Explained
A profitable owner-operated business can depend on routines that exist only in the seller's memory. Ask how the work gets done, then verify the answer by observing systems, speaking with employees, and reviewing the records generated by those processes.
Operations and continuity
Document the workflow from order intake to delivery, billing, support, and renewal. Request supplier lists, terms, onboarding procedures, quality records, inventory counts, maintenance logs, insurance certificates, licenses, and business-continuity plans.
Then test dependencies. Who can place orders? Who knows the production sequence? Which supplier has no substitute? What happens if the premises, internet connection, payment processor, or primary vendor fails? A seller may describe the business as resilient while one person controls purchasing, customer service, scheduling, and system access.
Organize the data room so the evidence mirrors the operating model. Guidance on document management for small business can help buyers and sellers think through naming, access, version control, retention, and retrieval before the review becomes chaotic.
HR and key-person exposure
Request an employee roster, role descriptions, compensation records, benefits information, offer letters, employment agreements, contractor agreements, restrictive covenants, leave records, disciplinary matters, and claims. Compare payroll to the general ledger and ask which employees interact directly with customers, suppliers, regulators, or critical systems.
Pay particular attention to the owner's daily activities. List every recurring responsibility, identify the person who could assume it, and record what knowledge must transfer. If no one can run quoting, collections, scheduling, or vendor negotiations without the seller, the buyer has an integration liability even if the financial statements look clean.
Employee interviews should confirm, not replace, documentary evidence. Ask about process gaps, retention concerns, informal compensation, undocumented overtime, and operational bottlenecks. Treat inconsistent answers as a prompt for deeper review rather than an immediate accusation.
IT, cybersecurity, and data
Inventory hardware, applications, domains, cloud accounts, payment systems, customer databases, backups, integrations, and third-party administrators. Request security policies, incident records, access lists, backup logs, business-continuity documents, penetration-test reports, and relevant certifications or audit reports.
Ask who has administrator access, whether former workers remain active, how privileged access is approved, where data is stored, how long it is retained, and how vendors use or transfer it. For outsourced operations, identify subprocessors, service-level commitments, breach obligations, recovery arrangements, and data-residency requirements.
If the company uses AI-enabled tools, ask what data enters the system, whether the vendor uses that data to improve models, how outputs are tested, and how the business handles inaccurate acceptance or rejection decisions. These questions belong in technology diligence and contract review because the risk may sit with the vendor while the customer or regulator holds the target accountable.
Customers Sales and Commercial Health Checks
Revenue quality depends on customer behavior, not just the income statement. A business can show attractive historical sales while losing its strongest account, discounting heavily, or relying on a pipeline that exists only in the seller's optimism.
Start with a customer-level revenue schedule. Identify major accounts, contract dates, renewal terms, pricing changes, credits, refunds, payment history, and gross margin. Compare the schedule to invoices, bank receipts, CRM records, and the financial statements. Investigate customers whose revenue has fallen, paused, or shifted to unusual one-time purchases.
Test durability, not enthusiasm
Ask how the company wins, serves, renews, and expands accounts. Review the sales process, lead sources, conversion records, marketing spend, salesperson compensation, open opportunities, lost-deal reasons, and customer-support history.
Pipeline hygiene matters. A CRM full of old opportunities doesn't demonstrate future revenue. Request recent activity, next steps, decision dates, proposals, and documented probability assumptions. If the seller can't explain why an opportunity is active, treat it as unverified rather than forecast revenue.
Customer interviews can test whether relationships belong to the company or to the owner personally. Ask selected customers why they buy, what alternatives they considered, how they view service quality, and what could make them leave. Coordinate those conversations carefully and follow the confidentiality terms of the transaction.
Use the customer verification process for business acquisitions to structure outreach and corroborate customer identity, activity, payment behavior, and relationship durability.
Convert commercial risk into terms
Customer concentration, weak renewals, informal pricing, or owner-led selling may not kill a deal. They should, however, change the structure of your offer. Possible responses include a lower valuation, a holdback tied to retention, an earnout based on collected revenue, seller transition obligations, or specific representations about contracts and customer communications.
Cross-reference commercial findings to financial diligence. A customer with strong revenue but poor margin may not deserve the same strategic weight as a smaller, profitable account. Cross-reference them to operations as well. If service quality depends on the seller, retention risk rises after closing unless the transition plan includes customer introductions and knowledge transfer.
From DDQ Findings to Integration and Deal Protections
The DDQ should produce a decision register, not a completed questionnaire. For every material issue, record the evidence reviewed, the risk owner, the likely impact, the next verification step, and the proposed transaction response.
Triage findings by consequence
High-risk findings threaten ownership, legality, cash generation, continuity, or the ability to operate after closing. Examples include an untransferable core contract, undisclosed tax exposure, missing ownership rights, unreliable financial records, or a security incident that affects customer obligations. These issues require resolution, a credible mitigation plan, a price or structure change, or a decision not to close.
Medium-risk findings may be manageable but need contractual protection or a post-close workstream. Examples include undocumented processes, weak access controls, incomplete employee agreements, supplier dependency, or uncertain customer renewal timing.
Low-risk findings can move into monitoring and integration. A minor filing gap or outdated policy may not justify delaying the transaction, but it still needs an owner and a deadline.
The question isn't whether a target has issues. The question is whether you've priced, protected, and assigned each issue.
Use the result to negotiate specific protections. A financial uncertainty may affect price, escrow, working capital, or earnout mechanics. A legal concern may require a representation, indemnity, covenant, consent, or closing condition. An operational gap may require transition services, training, access transfer, or a seller knowledge-transfer obligation.
Carry gaps into the first operating period
Build the integration plan directly from the open DDQ items. Assign workstreams for customer communication, employee retention, system access, banking authority, vendor continuity, accounting conversion, insurance, and compliance.
A practical integration planning framework for post-acquisition challenges helps translate diligence observations into operating actions. The buyer should know which tasks must happen immediately, which require seller involvement, and which can wait until the business is stable.
The following video can add another perspective on connecting acquisition diligence to execution:
A missing process document is not merely an administrative inconvenience. It may determine whether the buyer can deliver orders, collect cash, protect customer data, or make decisions without the seller.
How to Prioritize and Right Size Your Questionnaire
More questions don't automatically produce better diligence. An oversized institutional form can exhaust an owner-operated seller, delay access to important records, and bury decision-critical issues beneath requests that have little bearing on the transaction.
Use a prioritization matrix built around deal exposure, not document volume. Consider the target's dependence on the owner, sector regulation, customer and supplier concentration, data sensitivity, operational complexity, and the time available before signing or closing.
Start with the questions that can change the deal
Ask first whether the seller owns the business, whether the financial records reconcile, whether key revenue can transfer, whether material liabilities exist, and whether the company can operate without immediate dependence on the seller. Those answers determine whether deeper diligence is worthwhile.
Defer lower-impact questions when they don't affect price, structure, closing, or continuity. Mark an item not applicable only after recording why it doesn't apply. “N/A” without reasoning is often a disguised omission.
A right-sized sequence might look like this:
- Screening core: Ownership, revenue quality, taxes, debt, major contracts, employees, customers, and critical systems.
- Risk modules: Cybersecurity, inventory, regulated activities, intellectual property, environmental exposure, or cross-border data.
- Confirmatory review: Targeted testing of anomalies, incomplete evidence, inconsistent answers, and material dependencies.
- Integration capture: Access transfer, seller transition, customer communications, employee retention, and process documentation.
The questionnaire should also accept different evidence formats. A signed policy may be appropriate for one question, a system export for another, and an interview followed by corroborating records for a third. Requiring long free-text responses everywhere encourages polished explanations instead of verifiable facts.
Recent DDQ design guidance points toward shorter, more modular questionnaires and flexible answer formats, including changes intended to remove unnecessary free-text and date controls and allow users to shorten the presentation. SmartRoom's discussion of DDQ design supports the practical lesson for SMB buyers: relevance and evidence matter more than sheer length.
Quick Reference Templates Checklists and Cross References
Keep the working DDQ in a spreadsheet, data-room index, or diligence platform with filters for workstream, owner, deadline, response status, evidence status, risk level, and purchase agreement treatment. The tool matters less than the controls.
A practical master checklist includes:
- Firm: Entity records, ownership, affiliates, permits, insurance, liens.
- Financial: Statements, ledgers, bank records, taxes, debt, working capital.
- Legal: Contracts, disputes, intellectual property, leases, privacy obligations.
- Commercial: Customers, renewals, pricing, pipeline, channels, competitors.
- Operations: Suppliers, inventory, facilities, processes, continuity.
- HR: Roster, compensation, agreements, claims, key-person exposure.
- Technology: Systems, access, backups, incidents, vendors, data flows.
- Emerging modules: AI governance, outsourcing, data residency, cybersecurity, and sustainability disclosures.
The cross-reference column is where the DDQ becomes a deal tool. Link customer concentration to revenue validation and retention planning. Link vendor concentration to continuity and working-capital risk. Link owner dependency to transition services and employment terms. Link data residency and outsourced processing to privacy representations, vendor contracts, and regulatory review.
Current guidance also highlights the expanding role of technology architecture, third-party dependencies, data residency, AI-enabled verification, and sustainability reporting. IFRS S1 and S2 are being adopted across more than 30 jurisdictions, according to Wolfia's overview of evolving DDQ coverage, so buyers should activate those modules when the target's customers, vendors, or operations create exposure.
| Workstream | Ask First When | Evidence Required | Escalation Trigger |
|---|---|---|---|
| Ownership and legal | The seller is an individual, partnership, or multi-entity group | Formation records, ownership documents, contracts, lien searches | Authority to sell or transfer is unclear |
| Financial and tax | Earnings, cash flow, or working capital drive valuation | Statements, ledgers, bank records, returns, tax notices | Records don't reconcile or liabilities remain unexplained |
| Customers and sales | Revenue depends on a few accounts or the seller's relationships | Customer schedule, invoices, renewals, CRM activity | Renewal, concentration, or customer identity can't be verified |
| Operations and suppliers | Delivery depends on informal processes or concentrated vendors | Supplier agreements, process records, continuity materials | No substitute exists or critical knowledge is undocumented |
| HR and owner dependence | The seller performs essential daily work | Roster, agreements, payroll, role and process documentation | Business can't operate without immediate seller involvement |
| IT and data | The target handles sensitive information or relies on outsourced systems | Access lists, policies, incident records, backup evidence, vendor terms | Admin access, data location, or recovery capability is unknown |
Use these rows as a starting bank, then add only the modules that reflect the target's actual risk profile. Dealmaker Wealth Society provides acquisition education, templates, checklists, and community support for buyers working through sourcing, diligence, deal structuring, and post-close execution. Its resources can sit alongside your legal, accounting, and technical advisors as you turn the questionnaire into a controlled acquisition process.
Build your next due diligence questionnaire around evidence, ownership, deadlines, and deal protections before you request another document from the seller. Visit Dealmaker Wealth Society to access acquisition training, practical checklists, and support for evaluating and executing small-business purchases.
From the Dealmaker Blog


















