• Curved glass façades of two office blocks against a blue sky
Insight

Due diligence for corporate acquisitions

Types of due diligence, the data room process, typical red flags and protecting the buyer’s interests.

| Reading time 12 min. | Author: Johannes Egelhof LL.M.

Due diligence involves a structured review of the target company before signing the contract. During this process, documents relating to the company's legal, financial, tax and operational matters are analysed in the data room, and key risks are prioritised. This is necessary because, in a share deal, the statutory warranty under Section 453 of the German Civil Code (BGB) usually only covers the shares, not the underlying company. The four main areas of review are legal, financial, tax and commercial due diligence. Depending on the sector, technical, environmental or IT reviews may also be included. As the buyer has no rights regarding known defects under Section 442 of the German Civil Code (BGB), any identified risks must be mitigated through warranties, specific indemnities or a reduction in the purchase price.

What is due diligence in a corporate acquisition?

The term originates from Anglo-American law and refers to the standard of care required in commercial transactions, whereby a buyer examines the target company. Applied to a corporate acquisition, due diligence is the structured review by which a buyer determines, prior to signing, the legal, financial and tax status of the target company. It does not replace any warranty given by the seller, but rather provides the buyer with the information needed to assess which warranties they require in the first place.

Legally, the structure of the corporate acquisition itself compels the buyer to do this. In a share deal, the buyer acquires shares in the company. Section 453 of the German Civil Code (BGB) applies the provisions governing the sale of goods only by analogy to this purchase of rights; consequently, the statutory warranty generally extends only to the shares, not to the underlying company with its contracts, liabilities and risks.

Only when the buyer acquires all or virtually all of the shares does the Federal Court of Justice (BGH) treat the purchase, in economic terms, as a corporate acquisition and, as an exception, extend liability for defects in goods to the company itself.

A buyer who would otherwise rely on the law is left virtually empty-handed in the case of a struggling company. They must identify the risks themselves and protect themselves against them contractually. This is precisely what due diligence achieves: it is the prerequisite for the buyer to demand the correct warranties and indemnities in the purchase agreement, and it provides the arguments on which the buyer bases the purchase price.

What types of due diligence are there?

Due diligence is divided into several strands of review, covering different specialist disciplines and running in parallel. The four main strands are legal, financial, tax and commercial due diligence. In smaller transactions, these are combined; in larger ones, they are supplemented by further reviews.

Legal due diligence forms the core of the legal work. It examines the corporate structure and the clear ownership of shares, key contracts with customers, suppliers and banks, the portfolio of land, licences and intellectual property rights, the employment law situation, and any ongoing or potential legal disputes.

Financial due diligence examines the figures: the quality of the reported earnings – that is, determining which profits are sustainable and which are one-off – as well as the actual net debt and working capital requirements.

Tax due diligence reviews the company’s tax history, examines open tax assessment periods, assesses the risk arising from an ongoing or forthcoming tax audit, and identifies any potential hidden profit distributions. Commercial due diligence looks externally at the market, competition and customer structure, and determines whether the business model is viable and to what extent the company is dependent on individual customers or suppliers.

Depending on the sector, further assessments may be required. Technical due diligence assesses plant and production facilities; environmental due diligence examines contaminated sites and environmental risks; and IT due diligence evaluates systems and data protection compliance. Which areas require scrutiny depends on the company. A manufacturing business on an old industrial site requires a different approach to a software company whose core value lies in source code and licences.

How does the due diligence process work?

It all starts with confidentiality. Before the seller discloses sensitive documents, the parties sign a confidentiality agreement. On the basis of an initial declaration of intent – often a letter of intent – the buyer draws up a list of requirements specifying exactly which documents they wish to inspect. The seller uploads these documents to a data room.

Nowadays, the data room is usually a virtual data room – a secure online platform where the documents are stored in a structured manner and to which only authorised reviewers have access. There, the advisers work their way through the contracts, balance sheets, tax files and licences. Any questions arising from the documents are channelled to the seller via a controlled question-and-answer process. The process culminates in a due diligence report. Often, a ‘red flag’ report is chosen, which focuses on the risks critical to the purchase decision rather than documenting every single detail. Its findings feed directly into the negotiations on the purchase agreement.

Due diligence therefore takes place between the letter of intent and the signing of the contract and lasts for several weeks. This phase also reveals whether the transaction requires regulatory approvals that will determine the timetable leading up to completion, such as clearance under merger control law or an investment review under foreign trade law. The overall process from the letter of intent to closing is the subject of a separate article. This article focuses on the due diligence process itself and what it brings to light.

What are the most common red flags?

Any finding that significantly reduces the value of the company, calls the purchase into question or requires specific contractual safeguards is considered a red flag. The same patterns recur time and again during legal due diligence. Change-of-control clauses in key contracts grant the contracting party a right of termination as soon as there is a change in shareholding, and can render a key customer or supplier contract worthless following the acquisition.

Unclear ownership of trade marks, patents or source code affects the buyer at the very heart of the company’s value. Missing or expiring public-law licences can jeopardise operations. Ongoing or impending legal proceedings and identifiable compliance breaches – for example, in competition law, data protection law or supply chain law – give rise to continued liability that can catch up with the buyer years after the acquisition.

Tax and financial due diligence brings its own warning signs to light. An ongoing tax audit, hidden profit distributions or questionable transfer pricing can trigger substantial additional tax claims. In the figures, inflated earnings, concentration risks relating to a small number of major customers or underestimated net debt are typical findings that put pressure on the purchase price.

Regulatory red flags form a category of their own, which can delay or block the completion of the transaction. If the companies involved reach the turnover thresholds set by German merger control, the merger must be notified to the Federal Cartel Office. These thresholds are a total worldwide turnover of more than 500 million euros, as well as domestic turnover of more than 50 million euros for one of the companies involved and more than 17.5 million euros for the other (§ 35(1) GWB). A prohibition on implementation applies until clearance is granted. A transaction implemented prematurely is, in principle, invalid (Section 41(1) of the German Act against Restraints of Competition (GWB)).

If the acquirer is from outside the EU and EFTA, an investment review under foreign trade law may also apply. In the cross-sectoral assessment under Sections 55 and 55a of the Foreign Investment Act (AWV), an acquisition of 25 per cent or more of the voting rights is subject to review; in the case of security-related activities, this threshold is as low as 10 or 20 per cent. Only in these specific cases is the acquirer subject to a notification obligation (Section 55a(4) of the AWV). A straightforward 25 per cent acquisition is subject to review, but can only be initiated ex officio. Anyone who only discovers such authorisation requirements shortly before signing the agreement will lose weeks.

How does the due diligence process differ between a share deal and an asset deal?

The structure of the transaction determines where the risks lie and what the due diligence process focuses on. In a share deal, the purchaser acquires the shares and thus the legal entity as a whole. They inherit everything that forms part of that legal entity, including liabilities and hidden liabilities that do not appear in the accounts. For this reason, legal and tax due diligence must be particularly comprehensive in such cases, as any hidden liabilities are also transferred. As the statutory warranty under Section 453 of the German Civil Code (BGB) generally covers only the shares, the buyer’s protection depends entirely on the contractual warranty provisions, which the due diligence process is designed to define in detail.

In an asset deal, the purchaser acquires individual assets and can, in principle, choose what to take on and what to leave behind. This apparent freedom has limits imposed by law, which the due diligence process must bring to light.

If the purchaser continues the trading business under the previous company name, they are liable for the previous business liabilities under Section 25 of the German Commercial Code (HGB). This liability can only be excluded by an agreement entered in the commercial register and made public, or by a notice to the creditors.

With regard to business taxes, the transferee is liable under Section 75 of the German Fiscal Code (AO), limited to the value of the assets taken over and to taxes that have arisen since the start of the last calendar year prior to the transfer of ownership. Furthermore, under Section 613a of the German Civil Code (BGB), employment contracts are transferred by operation of law to the acquirer as soon as a business or part of a business is transferred. They cannot be excluded from the sale. An asset deal therefore does not automatically free the buyer from the past, and due diligence determines whether these pitfalls are identified and mitigated in the contract.

Why does due diligence determine liability under the warranty?

Due diligence plays a key role in determining what, if anything, the seller will subsequently remain liable for. Under Section 442(1) of the German Civil Code (BGB), the buyer’s rights in respect of a defect are excluded if they were aware of the defect at the time the contract was concluded. In cases of ignorance due to gross negligence, the buyer retains rights only if the seller has fraudulently concealed the defect or has given a guarantee. For a corporate acquisition, this means that the buyer cannot subsequently claim as a defect anything of which they were already aware.

This principle shapes the negotiation of the sale contract. Sellers typically place large volumes of documentation in the data room and agree that everything disclosed is deemed to be known to the buyer. Such disclosure via the data room qualifies the warranties: anything contained in the data room is deemed to have been disclosed, and the seller is no longer liable for disclosed circumstances. A comprehensive data room is therefore not merely a service to the buyer, but also a means of limiting liability. A thorough review is the only way to identify the critical issues within this vast volume of information before they tacitly work to the buyer’s disadvantage.

The findings of the due diligence process thus translate directly into contractual safeguards. As statutory warranties offer little protection in corporate acquisitions, the purchase agreement relies on independent, no-fault warranty undertakings based on the freedom of contract under Section 311(1) of the German Civil Code (BGB).

For general circumstances, a list of such guarantees is sufficient. For a specifically identified risk, such as an impending additional tax assessment arising from an ongoing tax audit, a guarantee is not sufficient because the circumstance has already been disclosed and is therefore known. In such cases, the buyer requires either a specific indemnity whereby the seller assumes precisely this risk, or a corresponding reduction in the purchase price. Without due diligence, the buyer has no way of knowing what such an indemnity would need to cover.

How are due diligence and W&I insurance linked?

W&I insurance – Warranty and Indemnity insurance – covers claims arising from a breach of the warranties given in the purchase agreement and tax indemnity. It has established itself as a useful tool because it enables the seller to exit the transaction cleanly without ongoing liability and provides the buyer with a solvent point of contact should a warranty later prove to be incorrect. It is closely linked to due diligence in two respects.

On the one hand, the due diligence review forms the basis on which the insurer underwrites the policy in the first place. The underwriter and their lawyers review the buyer’s due diligence reports and the data room, and will only insure matters that have been adequately examined. An incomplete review leads to gaps in cover or exclusions.

Secondly, W&I insurance only covers unknown risks. Anything specifically uncovered by due diligence or disclosed in the data room is known and is generally excluded from the insurance cover. For such identified risks, the seller must either provide a separate indemnity or the purchase price must be adjusted. W&I insurance therefore does not replace due diligence; it is a prerequisite for it. We provide an in-depth overview of the structure and limits of the cover in a separate article.

How much does due diligence cost and how long does it take?

The cost and duration of due diligence depend on the size and nature of the transaction. Key factors include the number of audit tracks, the scope of the data room, the complexity of the company, and whether a full audit or a ‘red flag’ approach focusing on key risks is chosen. In the case of a Mittelstand transaction, the actual review usually takes a few weeks between the letter of intent and the signing of the agreement.

The costs are generally borne by the buyer, as it is in their interest to commission the review. They are money well spent when measured against what is at stake. A single overlooked risk, a hidden tax liability or a key contract subject to termination can amount to many times the cost of the due diligence. Cutting corners on due diligence means cutting costs at the very point where the company’s valuation and future security are determined.

About the author

Johannes Egelhof
Johannes Egelhof LL.M.
Partner · M&A & Restructuring
Get in touch

Johannes Egelhof, LL.M., advises companies on company law and supports them through corporate acquisitions and disposals, from due diligence through to completion, including in cross-border transactions.

A cable-stayed bridge with a white pylon and a red deck, seen from below against a clear evening sky

Planning for a corporate acquisition?

Due diligence is one component — we support the structuring, due diligence, purchase agreement and completion as part of the overall process.

View Company Law & M&A

Frequently Asked Questions about due diligence

Due diligence is the structured examination of the target company by the buyer prior to signing the purchase agreement. Legal, financial and tax documents are reviewed in a data room in order to identify risks and assess the value of the company. It is necessary because the statutory warranty offers little protection in a corporate acquisition, and the buyer must identify the risks themselves and safeguard against them contractually.

Legal due diligence examines the legal circumstances, namely corporate structure, contracts, licences, intellectual property rights and legal disputes. Financial due diligence assesses the figures, distinguishing between recurring and one-off revenues, and identifies net debt and working capital. Commercial due diligence examines the market, competition and customer base, and assesses whether the business model is viable. These three strands address different issues and run in parallel.

Red flags are issues that reduce the value of the company or require special safeguards. Typical examples include change-of-control clauses in key contracts, unclear ownership of trademarks or source code, missing approvals, ongoing legal proceedings and compliance breaches, as well as outstanding tax audits, hidden profit distributions and concentration risks relating to a small number of major customers. This also includes necessary approvals, such as an antitrust notification or an investment review, which delay the completion of the transaction.

A data room is an organised collection of documents that the seller makes available to the buyer for review. Nowadays, this is generally a virtual data room – a secure online platform with structured filing and controlled access. The contents of the data room are generally regarded as having been disclosed and are therefore deemed to be known to the buyer, which, under Section 442 of the German Civil Code (BGB), may preclude any subsequent claims arising from these circumstances.

No. W&I insurance covers claims arising from breaches of warranties and tax indemnities, but only covers unknown risks. Any specific issues uncovered during due diligence or disclosed in the data room are known and are generally excluded from the scope of the insurance cover. For such identified risks, the buyer requires a separate indemnity or a purchase price adjustment. At the same time, a thorough due diligence review forms the basis on which the insurer grants cover in the first place.

The costs depend on the size and structure of the transaction, in particular on the number of audit tracks, the scope of the data room and the choice between a full audit and a ‘red flag’ approach focused on key risks. These costs are generally borne by the buyer. Given the potential consequences of a single overlooked tax liability or a key contract that can be terminated, they are usually money well spent.

More articles on this topic

Show all 31 articles Show less

Contact

Get in touch

Send us a message. We will get back to you within one working day.

Maxfeld.legal

Rechtsanwaltsgesellschaft mbH
Leipziger Platz 21
90491 Nuremberg

Brochure

Request brochure

Enter your contact details. We will send you the brochure by email right away.