A founder can be brilliant, the product can be real, and the deck can look airtight. Then one Companies House check, one missing PSC link, or one contract held by a related party blows the deal open three weeks before completion. That's when startup due diligence stops being a polite formality and starts doing what it should have done from day one, protecting capital, control and reputation.
In UK deals, the pain is rarely exotic. It's the mundane stuff, weak records, sloppy ownership reporting, filings that don't reconcile, controls that haven't kept pace with growth, and answers that sound neat until you ask for the underlying evidence. The point of this guide is simple, it's the practitioner view from the forensic side of the table, where the question isn't whether the story is exciting, but whether the numbers, ownership chain and operating controls will survive scrutiny.
If you need a practical starting point for supporting documents and templates, it's also worth taking a look at browse R&D resources from ClaimKit, especially if the target says its growth story depends on technical development, product iteration or claims about innovation.
The Deal That Looked Perfect Until Diligence Found the Truth
A London investor once came into a process convinced the round was close. The founder had clean slides, an energetic sales narrative and a tidy spreadsheet, and the timetable looked manageable. Then the diligence pack started to land, and the story stopped lining up with the records.
The first problem was the register. The founder's explanation of control didn't match what Companies House showed, and the PSC register raised questions that had never appeared in the pitch meetings. Under the Economic Crime and Corporate Transparency Act 2023, Companies House now has stronger powers to check and challenge company information, which matters because the register is huge, with more than 5 million registered companies and around 8 million corporate officers on the books (Companies House's register scale and ECCTA context). In practice, that means a loose story about control is no longer something you can leave for later.
The second problem was a supplier contract. It sat with a related party the seller had never clearly disclosed, so the margin story depended on a relationship that nobody had framed properly. That doesn't just affect valuation, it affects completion mechanics, warranties and remedies if the deal falls over after signing.
Practical rule: if the ownership chain or contract chain is fuzzy, assume the rest of the diligence needs a harder look, not a softer one.
This is why startup due diligence in the UK can't be reduced to a pitch deck review. The significant losses usually come from ordinary gaps in records, control, and disclosure, not from cinematic fraud. When those gaps sit inside a company that claims to be scaling fast, the risk multiplies because weak controls don't stay weak for long, they start breaking at the point of growth.
The useful mindset is forensic, even if the deal is friendly. Ask what must be true for the story to hold, then ask for the evidence that proves it.
Scoping, Timing and the Three-Stage Workflow
Good diligence starts with scope, not paperwork. A seed investor, a growth fund and a strategic buyer should not run the same process, because the commercial risk is different, the document load is different, and the consequence of a miss is different. The practical question is which workstreams are essential, and which can wait until the first pass tells you where the risk sits.
The standard structure is preparation, investigation and final decision (stage-based workflow description). In preparation, define the decision you're trying to make, the red flags that would change it, and the specialists you need in the room. In investigation, collect the documents, test them against filings and interviews, and push back when the evidence is thin. In final decision, turn the findings into a yes, a renegotiation, a condition precedent or a no.
How to scope without wasting money
A phased approach works better than a single all-encompassing exercise, especially where the company has cross-border operations, IP-heavy assets or regulated revenue streams. That's not just an opinion, it follows from the fact that due diligence costs vary widely, with seed-stage reviews around $10,000, mid-market deals commonly $75,000 to $250,000, and large M&A investigations exceeding $2 million (market cost bands). Those numbers don't tell you what to spend, but they do explain why scope discipline matters.
Use the deal stage to set the depth. Early-stage raises need a sharper read on ownership, controls, burn, tax and IP. Growth rounds need deeper testing of revenue quality, counterparty concentration, covenant exposure and operating resilience. If the company's data room is thin, don't pretend the answer is to “just keep going”. Tighten the scope and focus on the risks that could kill the transaction.
For a UK buyer's-eye checklist, the due diligence checklist for buyers from Chern & Co is useful as a document reminder, even if you tailor it to your own sector and structure. It works best when used as a starting map, not as a substitute for judgement.
Set deadlines around the transaction, not around the data room. If legal signing is fixed, diligence has to give the deal team enough time to react, not just enough time to read.

The Document and Data Checklist That Actually Matters
The best checklists are organised by risk, not by filing cabinet logic. A founder can send you fifty documents and still hide the one thing that changes the deal. What matters is whether each workstream gives you enough evidence to trust the story, or enough contradiction to pause it.
Financials, ownership and contracts
Start with the financial spine. Ask for management accounts, bank statements, debtor ageing, VAT and PAYE evidence, then reconcile those to the company's filings and internal explanations. If the bank credits don't reconcile to reported revenue, or the VAT position looks messy without a clear reason, you don't have a small admin issue, you have an earnings quality issue.
For ownership, insist on the full cap table, all ordinary and preference shares, all SAFEs and convertible notes, option pool size, side letters and any vesting changes in the last 24 months. UK due diligence checklists are explicit that investors should verify ownership, option-pool size and every SAFE or note, because these items drive dilution, control and completion risk (checklist areas investors are told to verify). If the answer arrives as a polished summary without source documents, treat it as a red flag, not a finished answer.
For contracts, request customer MSAs, supplier agreements, employment and contractor agreements, and any threatened or actual litigation. The weak answer here is usually vague ownership, missing signatures, or the classic “we've always done it this way” response. That rarely survives a serious legal review.
IP and compliance
IP needs invention assignments, registered and unregistered rights, and the full licence chain for anything used but not owned. Compliance should cover GDPR records, sector-specific obligations and any outstanding HMRC issues. A company with tidy product claims but untidy tax, payroll or processing records usually creates more work later, not less.
If a founder can't produce the source document, the summary usually doesn't count.
The most efficient approach is to ask for these in one organised drop, then mark each item as evidence, partial evidence or missing. That gives the deal team a clean way to separate noise from genuine gaps.
If you want a practical financial lens for this part of the process, the ten-step financial due diligence checklist is worth keeping open while you review the pack. It's most useful when you use it to interrogate cash, working capital and controls rather than just to tick boxes.

Forensic Accounting Checks and Red Flags Founders Hope You Miss
Management accounts often look clean because someone has made them clean. The forensic job is to see whether the clean-up is presentation, or whether the underlying controls support the numbers. That means reading the accounts against the bank, the VAT returns, the payroll trail and the way the business operates.
What to test first
Reconcile reported revenue to bank credits. Then test debtor ageing for old balances that keep rolling forward without proper recovery action. After that, look at VAT returns and PAYE positions, because UK SMEs often expose control weaknesses there before they show up anywhere else.
Unusual related-party transactions deserve special attention. They can hide diverted value, inflated costs or arrangements that keep margin in the group while pushing risk elsewhere. Round-tripping can be even harder to spot because the cash appears to move, cycle and return in a way that flatters the numbers but doesn't create real value.
What breaks when a company scales
The controllership-scaling question matters more than most guides admit. The issue isn't only whether the forecast looks plausible, it's what breaks first when headcount, revenue or cross-border activity grows. UK government fraud guidance has repeatedly treated weak internal controls and poor verification as enablers of financial loss, and the ICAEW has stressed that SMEs often lack the control environment needed for reliable reporting and fraud detection (control weakness and SME environment context).
That's why I look closely at whether finance can handle VAT, PAYE, Companies House filings, payroll and related-party transactions without improvisation. If the company needs one heroic person to bridge all those gaps, the business is already carrying hidden risk.
Decision rule: pause the deal if you find unexplained cash movement, mismatched ownership information, or repeated revenue and bank inconsistencies. Negotiate if the issue is real but curable. Walk away if the answers keep changing.
You won't catch every issue on day one, but you can tell very quickly whether the finance function has the discipline to scale. That's the difference between a temporary clean-up and a structural weakness.
AI, Open Source and Data Governance Risks Most Guides Skip
A lot of startup diligence still treats technology as a single line item, which is too blunt for how modern products are built. A company can own the brand, the front end and the sales motion, yet still have unresolved exposure in the codebase, the training data, or the way customer data gets processed.
What to ask for
Ask how much of the product is owned, licensed or exposed to change. For open-source software, request a software bill of materials and the licence obligations that come with it. For AI features, ask for a model card, details of training-data provenance, and evidence of who approved the use case internally. For data governance, request a data-protection impact assessment and a record of processing activities.
That matters in the UK because the ICO continues to emphasise data minimisation, lawful processing and governance over personal data, and deal teams can't assume those issues are solved just because the product is commercially promising. If the company uses generative AI, you also need to know whether the workflow depends on third-party data, what retention rules apply, and whether the output creates compliance or customer-contract risk.
Why this changes valuation
The valuation risk is simple. A product can look defensible in a demo and still carry unresolved licensing or privacy exposure that affects how a buyer prices the asset. This is especially true where the team talks a lot about code quality but not enough about ownership boundaries, data retention or downstream obligations.
For a sharper cyber and technology lens, the cybersecurity due diligence resource from Lighthouse Consultants is useful if the target relies on cloud tools, customer data or AI-assisted workflows. Keep the focus on evidence, not optimism.
If the company can't show where its data came from, how it's used, and who approved it, assume the diligence file is incomplete.
The best technology diligence doesn't ask whether the product is clever. It asks whether the product is defensible under scrutiny, whether the obligations are known, and whether the operating model can withstand a regulator, a buyer or a post-close integration team.
Risk Scoring, Valuation Adjustments and Reporting Templates
Diligence reports often fail because they list findings without helping the deal team decide what to do next. A useful report needs a simple risk view, a clear link to valuation or structure, and enough detail that legal and commercial teams can act on it quickly. I prefer four bands, low, medium, high and blocker, across financial, legal, commercial and technology workstreams.
How to turn findings into action
Low risk usually means accept and monitor. Medium risk means negotiate warranties, covenants or a tighter disclosure schedule. High risk often justifies a price chip, escrow or a condition precedent. A blocker means the issue is too fundamental to ignore, and the team should be ready to walk away.
A practical example helps. If the target has customer concentration and the PSC position is not properly verified, those issues together can justify a narrower warranty package and a price adjustment. The customer issue affects earnings resilience, and the ownership issue affects trust in the control chain. Neither one needs to be fatal on its own, but together they change the shape of the deal.
What the report should contain
Keep the structure tight.
- Executive summary: one page that states whether the deal looks clean, constrained or dangerous.
- Workstream findings: financial, legal, commercial and technical issues, each in plain English.
- Quantified exposures: where a number can be supported, show it. Where it can't, say so clearly.
- Recommended adjustments: price, structure, warranties, indemnities or conditions precedent.
- Outstanding questions: the items that must be resolved before approval.
If the deal also needs a working capital adjustment, keep it separate and evidence-led. The working capital adjustment resource is useful if you need to align close mechanics with the actual cash profile of the business.
A good diligence report doesn't try to impress. It helps someone decide.
That's the standard I use. If the findings don't point to a clear commercial action, the report is too soft.
When to Escalate and How Lighthouse Consultants Can Help
Some deals need more than a standard diligence review. Escalate when you see suspected fraud, cross-border complexity, IP disputes, regulator interest, or unexplained gaps in the financial record. Those are the moments when a generalist approach stops helping and specialist forensic or legal support starts saving time.
| Red Flag | What It Signals | Specialist to Escalate To |
|---|---|---|
| Unexplained cash movements | Possible misstatement, diversion or hidden liabilities | Forensic accountant |
| PSC or ownership inconsistencies | Control, disclosure or fraud risk | Forensic accountant, corporate lawyer |
| IP assignment gaps | Title uncertainty and enforceability risk | IP lawyer, forensic accountant |
| Regulator correspondence | Compliance exposure and timing pressure | Specialist adviser, legal counsel |
| Cross-border records with weak support | Translation, tax and evidence risk | Forensic accountant, tax adviser |
The common objections are predictable. Cost, delay and fear of “spooking” the founder. In reality, a targeted escalation is usually cheaper than discovering the same problem after signing, and a short, focused review often saves more time than a broad, optimistic one. Good diligence doesn't derail a deal, it stops the wrong deal from taking up everyone's calendar.
Lighthouse Consultants fits where the question is not just “is this business growing?”, but “can the records, controls and evidence stand up in a transaction, dispute or challenge?” The firm's forensic accounting, internal audit and due diligence work can help when the numbers don't reconcile, the ownership chain is unclear, or the control environment needs independent testing.
If you're facing a startup acquisition, investment round or a diligence issue that isn't lining up, speak to Lighthouse Consultants and ask for a scoped review. Their team can test the records, quantify the risks and give you a clear action plan before you commit capital. Visit Lighthouse Consultants to start the conversation.



