Deal killers in due diligence, and the records problems behind them

The most common deal killers in due diligence are earnings that do not hold up, customer concentration or churn, undisclosed liabilities, owner dependence, and records problems: unclear code or IP ownership, missing contracts, deleted archives and privacy consent gaps. The records problems matter twice, because they also decide whether a company can ever license its data.

What kills deals in due diligence?

Most deals that die in diligence die because something the buyer relied on turns out to be untrue or unprovable. Earnings shrink under a quality-of-earnings review, revenue is more concentrated or less recurring than presented, a liability nobody mentioned appears, the business turns out to run on the owner, or the records cannot support the story. Sellers underestimate the last group most: unclear ownership of code and content, missing contracts, deleted archives and privacy consent gaps.

Records problems hurt twice. They give a buyer grounds to reprice or walk, and they decide whether the company could ever license its operational data to AI labs and data buyers.

The common deal killers

Deal killerHow it surfacesTypical consequence
Earnings do not hold upQuality-of-earnings work rejects add-backs or finds revenue timing issuesPrice cut or walk
Customer concentration or churnCustomer-level revenue and cohort analysisEarnout, holdback or lower multiple
Working capital shortfallNormalized working capital below the seller's assumptionA purchase price adjustment fight
Undisclosed liabilitiesLitigation searches, tax review, employee claimsSpecific indemnity, escrow or walk
Owner dependenceInterviews show the owner holds clients and know-howLonger transition, earnout
Tax exposureSales tax nexus, worker classificationEscrow or a change of structure
Security incidentsIncident history, insurance, penetration testsSpecific indemnity or delay
IP and code ownership gapsMissing assignments from founders and contractorsClosing condition or walk
Missing or unassignable contractsChange-of-control clauses, unsigned versionsConsents needed before closing
Deleted or incomplete recordsRequests nobody can answerLost buyer confidence
Privacy and consent gapsPrivacy promises that do not match data practiceIndemnity, remediation or walk

Many of these do not kill the deal outright. They trigger a retrade after the letter of intent, when the buyer has exclusivity and the seller has the least leverage.

Which deal killers are really records problems?

Five of them come down to whether the company created, kept and can prove its records.

Records problemWhat buyers findAlso blocks a data license?Fix before marketing
Code or content written by contractors without an assignmentThe company may not own what it sellsYes: a company cannot license what it does not ownCollect signed assignments now
Contracts missing, unsigned or restricting data useRevenue that cannot be verified; consents neededYes, where client contracts forbid use of the recordsBuild a signed-contract index and read the data-use clauses
Archives deleted or tools cancelled without exportThe history behind the numbers is goneYes: deleted archives are a licensing red flagFreeze retention changes and export before cancelling
Privacy promises that conflict with actual useRegulatory exposureYes: mainly consumer personal data with no licensing basis is out of scopeCompare policies with practice
Records that belong to clients, as at outsourcers and agenciesA smaller proprietary asset than presentedYes, unless the clients consentSeparate company records from client records

Ownership is where to start. The Copyright Act's definition of a work made for hire covers what employees create as part of their jobs, plus commissioned work in nine listed categories backed by a signed written agreement (17 U.S.C. 101). Standalone software is not among those categories, so code written by an outside contractor usually needs a written assignment before it belongs to the company. The CTO due diligence interview questions and the guide to AI-generated code in due diligence show how buyers probe it.

Privacy comes next. FTC staff have stated that promises not to use customer data for undisclosed purposes, such as training AI models, are enforceable wherever they were made, including privacy policies, terms of service and marketing (FTC staff post, January 2024); that is staff guidance, not a rule. In California, the CCPA gives consumers rights that include opting out of the sale or sharing of their personal information, as the California Attorney General's CCPA overview explains. This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting.

The records pre-diligence check

Run it before the CIM is drafted. The company's own team answers each item; nobody outside the company needs to open a confidential file.

Ownership

  • Signed invention and IP assignment agreements for every founder, employee and contractor who wrote code or core content
  • A list of open-source and third-party components in the product
  • A clear split between company records and records that belong to clients under service contracts

Contracts

  • An index of customer, vendor and partner contracts with the signed version located
  • Change-of-control and assignment clauses flagged
  • Data-use, confidentiality and AI clauses in client contracts flagged

Retention

  • Every business system listed with how far back its history goes
  • Auto-delete and retention settings documented and frozen until the deal is done
  • Exports taken before any tool is cancelled or migrated

Privacy

  • Current and past privacy policies collected and compared with actual data practice
  • Call recording notices and consents documented
  • Consumer and patient personal data identified and kept separate

How to use the results

ResultWhat it meansNext action
All clearRecords support the story and ownership is cleanGo to market; the company may also be a licensing candidate
Fixable gapsMissing assignments, unsigned contracts, open retention settingsFix before the CIM and disclose what cannot be fixed
Records owned by clientsThe proprietary asset is narrower than it looksPresent it accurately; only company-owned records could be licensed
History deletedDiligence answers will be thinRebuild from backups where possible and set expectations early
Privacy conflictPossible regulatory exposureBring in privacy counsel before launch

Why the same records decide whether a company can license its data

AI labs and data buyers look for what a careful acquirer looks for: records the company created, kept and has the right to license. SourceX's red flags line up closely with the records deal killers, among them data that belongs to someone else, mainly consumer personal data with no licensing basis, deleted archives and nobody able to export the data. A company that clears the pre-diligence check may also be a licensing candidate if it meets the baseline on who qualifies: 50+ full-time employees at peak (contractors excluded), several years of records showing how the business ran, the right to license them and an authorized executive to sponsor it.

A failed sale does not close that door. Companies still operating, acquired or wound down can all qualify if the data still exists. Brokers who build a records slide into their pitch, as in the business broker listing presentation template, catch these problems before a buyer does, and serial acquirers meet the same questions in acquired companies' archives, as the guide to programmatic M&A explains.

For advisors: making the introduction

  1. Share the pre-diligence findings with the owner alone and ask whether a license is worth exploring.
  2. Use the company fit checker with the owner as a first, non-binding screen.
  3. Submit the company through the referral form, or hand the owner your referral link so the application is credited to you.
  4. SourceX qualifies the business; the company inventories its systems and agrees price and terms before any buyer review.
  5. The advisor's job ends with the introduction; exports, uploads and descriptions of records stay with the company.

Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company. The reward becomes payable only after the buyer pays and SourceX receives its fee, it is never taken from the company's payment, and no reward is guaranteed.

Next step

Run the records check on your next mandate before the CIM goes out. If the company passes, register as a partner and introduce it; sell-side advisors will find the program details on the M&A advisor partner page.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

What share of deals fail in due diligence?

No reliable single figure applies across deal sizes and sectors, so be wary of precise percentages quoted without a source. What advisors see consistently is that problems found after a letter of intent tend to lead to repricing rather than outright collapse, and that problems found before marketing are far cheaper to fix.

Can a records problem be fixed after the letter of intent?

Some can. Missing contractor assignments can often be signed late, and lost contracts can sometimes be located or re-executed. Deleted archives usually cannot be restored. Every fix after a letter of intent happens under buyer scrutiny, with the clock running and the buyer holding exclusivity, which is why a check before marketing pays off.

Does a failed sale stop a company from licensing its data?

No. Whether the company is still operating, has been acquired or has wound down, it can qualify for a license if the data still exists, the company has the rights to license it and an authorized sponsor can sign. The same records issues that stalled the sale, such as missing ownership or deleted archives, would need resolving first.

Who should run a pre-diligence records review?

The company's own finance, IT and operations leads, coordinated by the sell-side advisor and checked by deal counsel for contracts, IP and privacy. Advisors and referral partners should ask questions and review summaries, not open confidential files. The goal is to know the answers before a buyer asks the questions.

Is contractor-written code always a deal killer?

No, but it is a common source of closing conditions and delays. If contractors signed agreements assigning their work to the company, ownership is usually clean. If not, the fix is to obtain written assignments, which is easiest while relationships are good and before a buyer makes it a condition. Deal counsel should confirm what is needed.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment