Current to July 21, 2026
Before you buy a business, you need to check it out. This is called due diligence.
- Look closely at the money, the legal paperwork, and how the business actually runs day to day.
- Check contracts, staff obligations, intellectual property, privacy compliance, lawsuits, and any claims against the assets.
- Whatever you find should change something: the price, the deal structure, a closing condition, or a protection built into the contract.
Due diligence is not a paperwork exercise. It is how you decide what to pay, what to ask for, and whether to walk away.
- Financial: work with an accountant to check if the profit numbers are real, and review debt, taxes, unpaid invoices, and inventory. Larger deals often call for a Quality of Earnings report.
- Corporate: confirm who owns the business, and that the share records and minute book are in order.
- Contracts: find the ones that need consent before they can transfer to you, and start that process early.
- Employment: review written job terms, pay, benefits, legal obligations, and any pending staff claims.
- IP and privacy: confirm the business owns what it says it owns, and handle personal information carefully.
- Liens: search for registered claims against the business assets, and get them cleared before closing.
- Operations: check how much the business depends on one customer, one supplier, or the current owner.
- Turn every real finding into something concrete: a price change, a condition, or a written protection.
Why Due Diligence Matters
Due diligence has a bad reputation. People picture a giant binder of paper that nobody actually reads.
Done properly, it is the opposite. It is how a buyer checks that the business they are paying for is the business they think it is. It shows what needs fixing before closing. It tells you which risks belong in the price, the closing conditions, the contract terms, or the insurance.
I have seen due diligence catch hidden lawsuits. I have seen it catch a lease that could not be transferred, and key staff with no written contracts. I have seen it catch a business whose revenue depended on one customer who was about to leave. Every one of those problems could be solved. But only because we found them before closing, not after.
Financial Due Diligence
This step is where you work with your accountant to confirm whether the seller's numbers are legitimate and accurate. You and your accountant review several years of financial statements, tax filings, unpaid invoices, and unpaid bills. You also check debt, inventory, and working capital, the cash a business needs to run day to day.
Sellers sometimes add expenses back into their profit figures to make the business look more profitable than it is. Look closely at these add-backs, because not all of them hold up. Your accountant can compare the seller's internal reports to their actual tax returns and bank records, and test whether the unpaid invoices will really get paid. They can also watch for expenses pushed into next year, or one-time revenue that will not repeat. Once you know the real numbers, confirm the accounting rules that will set your working capital adjustment at closing.
On many deals, especially larger ones, the buyer also asks for a Quality of Earnings report, often just called a QOE. An accountant prepares this report. It digs into the seller's profit numbers line by line, tests whether they hold up, and adjusts for one-time items and add-backs that should not count toward the real, ongoing earnings of the business. A QOE report gives you a more reliable number to negotiate from than the seller's own figures.
Legal Due Diligence
This is usually where I get involved directly.
I start with the company itself. I confirm it legally exists and is in good standing, and I review its articles, bylaws, share issuances, minute book, shareholder agreements, and the approvals needed to sell. Ontario law requires corporations to keep records like these.[1] Gaps in the paperwork can mean shares were issued incorrectly, ownership is disputed, or a required approval is missing.
Then I review the major contracts, the lease, intellectual property, lawsuits, and any letters from regulators. If you are buying the assets, some contracts may need consent before they transfer to you. If you are buying the shares instead, a contract can still be affected even though the company itself has not changed hands. I build a list of every consent we need as early as possible, and I push to make the most important approvals a condition of closing, not a promise for later.
I also search the seller's name, and any past names, under Ontario's Personal Property Security Act.[2] This search shows whether anyone has registered a claim against the business assets. A registration is a starting point, not proof of what is actually owed, so I match each one to what it secures and find out which equipment is financed or leased. From there, I get a current payout amount and make sure we get a proper discharge or agreement at closing.
I run several other searches alongside the PPSA search. A corporate profile search confirms the company is active and in good standing, and shows who its directors and officers are. A Bank Act security search shows whether a bank has registered a separate type of security interest under the Bank Act. A search against the Canada Revenue Agency shows whether there is a registered lien for unpaid taxes. A writs of execution search shows whether a court judgment has been filed against the seller, which can attach to real property. And a litigation search shows any lawsuits involving the seller, past or present, that they might not think to mention on their own. Where it matters, I also search bankruptcy filings, title records, and federal trademark or patent filings.
During legal due diligence on a retail purchase, we found a problem in the lease. It had a clause requiring the landlord's consent before this kind of sale could go ahead. The seller had not noticed it applied. We raised it early, got the landlord's consent as a condition of closing, and used the smooth process to negotiate a small reduction in future rent. Because we caught it during due diligence, it became a bargaining chip instead of a last-minute crisis.
Operational Due Diligence
An operational due diligence consultant, or an M&A advisor from an accounting or transaction-advisory firm, usually leads this review. Depending on the business, the buyer may also bring in specialists in the industry, HR, IT and cybersecurity, environmental matters, or regulatory compliance. Together, they test whether the business can run without its current owner: customer relationships, key staff, suppliers, licences, systems, cybersecurity, and how much of its value depends on one person. A business that runs on the seller's personal relationships is a riskier purchase than one with real systems and a team already in place.
On the employment side, review written job contracts, pay, vacation, benefits, bonus plans, contractors, union rules, workplace safety, and any pending claims. The rules differ depending on how the deal is structured. In an asset sale, if the buyer keeps an employee on, Ontario law generally treats their employment as continuing, so their years of service carry over.[3] Get separate advice on any other legal obligations, and on any new offers made to staff. In a share sale, the employer does not change at all, but bonuses tied to a change in ownership, and staff retention, still matter.
A buyer nearly completed the purchase of a service business on the strength of strong revenue figures alone. Then operational due diligence looked at customer concentration. Roughly sixty percent of that revenue came from one contract. It was set to expire in ninety days. There was no automatic renewal, and no sign the customer planned to stay. The buyer did not walk away. Instead, they lowered the upfront price and added an earn-out tied to keeping that customer. This shifted the risk back onto the seller.
Privacy: What Belongs in the Data Room
Privacy law does not stop you from sharing personal information during due diligence, but it does not give you a free pass either. The real question is not whether the information might be useful to a buyer. It is whether identifiable information is actually necessary to evaluate or complete the deal. Where you can, start with information that is not personal, or that has been grouped together so no one can be identified. Save identifiable records for later stages of the review.
Canada's federal privacy law, PIPEDA, lets parties to a business sale use and share personal information without asking each person's consent, but only if two conditions are met. First, the information has to be necessary to decide whether to go ahead with the deal, and to complete it if the parties do go ahead. Second, the parties need a written agreement that limits the information to deal-related purposes and requires proper safeguards. That agreement also has to require the recipient to return or destroy the information if the deal falls through.[4] This exception covers more than a typical share or asset sale. It also applies to mergers, amalgamations, financings, security interests, and certain leases or licences of business assets.[4]
- Aggregate workforce numbers, like headcount, pay ranges, and turnover, where no one can be identified.
- Customer concentration and revenue data, organized by number or category rather than by name.
- Redacted or sampled records, where the details are genuinely needed to test a liability or check a claim.
- Identifiable information, but only where it is genuinely necessary. For example, to assess key-person risk or check a restrictive covenant.
- Ordinary business contact information used only to reach someone in their professional role.
- Uploading full employee or customer databases just because it is convenient.
- Sharing Social Insurance Numbers, banking details, or medical information, where less sensitive evidence would answer the question.
- Using data room information for marketing, recruiting, or competitive intelligence.
- Letting people download, forward, or access information they do not need.
- Keeping the information after a deal falls through, without another lawful reason.
- Relying on this exception where the real point of the deal is buying or selling personal data itself.
A standard confidentiality agreement is usually not enough on its own. The agreement should say clearly what the information can be used for, what security safeguards apply, who can access it, and what happens if the deal does not close. The data room itself should back this up, with role-based access, staged disclosure, view-only permissions, no downloading, activity logs, and extra controls for the most sensitive material.
If the deal closes, a few more conditions kick in. The information you received has to stay necessary for running the business you bought. Everyone involved has to keep protecting it, limit how it is used afterward, and respect anyone who has withdrawn consent. One of the parties also has to tell the people affected, within a reasonable time, that the deal happened and their information was shared.[4]
Where the Line Gets Blurry
The hardest question is usually what counts as "necessary." It depends on the situation. Named details about a handful of senior employees might be necessary early on, while full personnel files for the whole workforce usually are not. A buyer often needs to confirm the size and value of a customer base. But it does not always need customer names or full account histories to do that.
Redacting names is not the same as making information anonymous. Job titles, locations, dates, and transaction history can still point to a specific person, especially in a small group. Even summarized data can accidentally reveal someone if the group behind it is small enough. The real risk is measured against everything the buyer already knows, not just what is on the page in front of them.[5]
PIPEDA is also not the only law that matters. Alberta, British Columbia, and Quebec each have their own private-sector privacy laws, and health, credit, and financial information can carry extra rules on top. PIPEDA's employee information provisions mostly apply to federally regulated businesses. Before anything sensitive goes into a data room, confirm which privacy law actually applies.[5]
A good rule of thumb is to disclose in layers. Start with aggregate or anonymized information. Move to redacted material once more detail is genuinely justified. Save identifiable or highly sensitive information for situations where its necessity is documented and access is tightly controlled.
Building Your Due Diligence Request List
I build the request list around this specific business, the deal structure, and the risks that matter, not around a generic form that produces paperwork nobody reads.
How I Build the List
I start by defining the transaction and understanding the business, then I narrow the list down to the risks that could actually affect this deal.
- Asset purchase or share purchase.
- Which business assets and locations are included.
- How the deal is being financed.
- The proposed closing date and conditions.
- How it earns its revenue.
- Key customers, staff, suppliers, systems, licences, and property.
- How much it depends on the current owner.
- Industry-specific regulatory and environmental risks.
From there, I focus the requests on the risks that matter. I concentrate on issues that could affect the purchase price, delay or prevent closing, or create liability after closing. I also watch for anything that needs a third party's consent, could interrupt operations, or could undermine the assumptions the buyer is relying on.
I organize what is left by priority. The first priority is the minute book, financial statements, tax records, major contracts, the lease, debt, litigation, licences, and permits. The second priority covers employees, intellectual property, insurance, privacy, cybersecurity, suppliers, and operational systems. Specialist items, like environmental, pension, union, real estate, or technical records, come in only where they are actually relevant to this deal.
Each request is specific. I name the document, the time period it covers, a materiality threshold where one makes sense, which entities it applies to, and whether I need a summary or the complete file. I avoid asking for "all documents relating to" a broad subject unless I genuinely need that much.
I also stage the requests. I start with what I need to spot the major risks. Once those are reviewed, I send targeted follow-up requests and track down anything that is missing, incomplete, or out of date. Sensitive information gets protected along the way. I redact personal information, restrict access to competitively sensitive material, and use staged disclosure or a clean-team process where it is appropriate.
Who Usually Helps
A business broker or M&A advisor usually handles the majority of the due diligence work. They coordinate the overall request list and manage the back-and-forth with the seller. My role is narrower but still important. I focus on the legal issues, and on specific searches like CRA, bankruptcy, and PPSA. When I flag a legal risk, I turn it into a price adjustment, a closing condition, a representation, an indemnity, a holdback, or another protection written into the contract.
I usually work alongside other specialists, brought in as the deal calls for them:
- Accountant or transaction-advisory professional. Financial statements, working capital, taxes, earnings quality, and debt.
- Operational due diligence consultant. Customers, suppliers, staff, systems, and owner dependence.
- Environmental consultant. Property history, hazardous materials, permits, and remediation risk.
- Employment lawyer or HR specialist. Employment terms, benefits, unions, workplace claims, and retention.
- IT and cybersecurity specialist. Systems, data security, cyber incidents, and access controls.
- Industry or regulatory specialist. Licences, permits, compliance, and approval timelines.
- Intellectual property lawyer. Ownership, registrations, licences, and transferability.
The best approach is one coordinated list, managed by the broker or M&A advisor, with each specialist, including me, contributing only the requests that belong to their own area. That cuts down on duplication and keeps the review focused on the issues that could actually change the deal.
Environmental checks are worth calling out on their own, since they should match the business and the property. Review permits, past spills, hazardous materials, compliance orders, and cleanup reports. For real estate or higher-risk businesses, consider a history search and a qualified environmental assessment. Ontario regulators can order cleanup or preventive action against people connected to a property, so how you structure the deal will not always remove this exposure.[6] Confirm that licences can transfer after a sale or a change of ownership, find out how long new applications take, and make the key approvals a condition of closing.
What to Do When Due Diligence Finds a Problem
Finding a problem is not the end of the deal. It is usually the start of a negotiation.
Depending on what you find, there are several ways to fix it. You might ask for a lower price, a specific promise from the seller, a tailored indemnity, or money held back after closing. Insurance can help too. Sometimes the best fix is a condition: the seller must fix the issue before closing. What it should not be is something you quietly accept and hope for the best.
Due diligence and the purchase agreement do different jobs. If a fact matters to the price, it should not live only in an email or a data room folder.
Write down what you relied on. Make your assumptions clear in writing. Make sure important answers show up in the contract itself, in the representations, the covenants, or the closing deliverables, not just in a conversation.
At the same time, disclosure does not automatically make the seller responsible for every problem. Wording about non-reliance, knowledge limits, time limits, cap amounts, and exclusive remedies can all narrow what you can recover later. Fraud and certain other claims are treated differently and need their own legal advice.
Five Common Mistakes
- “Using a generic request list that misses the risks unique to this business.”
- “Treating an incomplete answer as if it were a completed request.”
- “Missing a change-of-control or consent clause buried inside a contract.”
- “Sharing personal information without limiting or redacting it first.”
- “Finding a real problem and not turning it into price, conditions, or protection.”
Ontario FAQs
Start with who owns the business and the quality of its profits. Then check the major contracts, staff obligations, taxes, and regulatory compliance. Also check lawsuits, liens, and how much the business depends on people or systems that might not stay.
No. Some obligations carry over. Employment rules, environmental exposure, and other legal duties can still affect a buyer even in an asset purchase.
No. Check each contract for rules about assignment, change of control, notice, and termination. Then make the important consents a condition of closing.
They show registered claims against the assets you are buying. You should investigate each one and get a proper discharge or agreement before closing.
Use them to adjust price or structure, and to negotiate conditions, promises, indemnities, holdbacks, insurance, or the right to walk away.
Related Articles
Primary Authorities Cited
This article gives general information about Ontario and Canadian law, current to July 21, 2026. It is not legal, tax, accounting, or investment advice, and it does not replace advice about your specific situation. Reading it does not create a lawyer-client relationship. Laws and practices change. Get advice from a qualified Ontario lawyer, and your tax and financial advisors, before you rely on this article or complete a transaction.
Forgione Deal and Corporate Counsel · Burlington · Mississauga · Oakville · Vaughan · Toronto