State of M&A Data Rooms — Q2 2026 Read the report →

SaaS Financial Due Diligence Checklist: What PE Firms Actually Request

M&A advisory at Peony. Former investment banker at Moelis & Company, where I worked on cross-border M&A across healthcare, industrials, and consumer. I write about how deals actually get diligenced and closed.

Last updated: August 2026

I'm Chris Chen. Before joining Peony, I worked in M&A at Moelis & Company across cross-border, healthcare, industrials, and consumer transactions. When a private equity firm signs an LOI on a SaaS company, one of the first things the deal team sends the target is a document: a financial diligence request list — the exact evidence it wants, in the exact form it wants it, before it will stand behind the price it named. This post is that list. Not an explainer of what ARR or NRR mean, and not the methodology a quality-of-earnings firm uses to verify them — those are covered elsewhere and I'll point to them. This is the request artifact itself: what a PE deal team actually asks a $10M–$50M ARR SaaS target for, why each item is on the list, and the specific red flag each one is screening.

I've written it for both sides of the table. If you're the PE associate assembling the list, this is the SaaS-specific request set that a generic financial diligence checklist misses — the month-by-customer ARR schedule, the cohort files, the deferred-revenue roll-forward. If you're the founder or CFO who just received one, this tells you what is normal, what each item is really screening for, and how to stage the evidence so diligence verifies an organized package instead of stalling on a scavenger hunt.

Here's the honest framing before we start. A SaaS financial diligence list is close to standardized, and it is not adversarial — it exists because the buyer underwrites a number the seller constructed, and it has to check that number against the systems underneath it. The items below are practitioner-standard; the value is in knowing the form each should arrive in and the screen each one runs. And the through-line, which I'll come back to at the end, is that everything on the list is a document you index — which means the request list and the seller's data room are the same artifact viewed from two sides.

The condensed checklist. SaaS financial diligence runs across six evidence blocks. (1) Revenue & ARR — MRR/ARR schedule by month by customer, contract-to-invoice-to-cash tie-out samples, billing-system export, revenue-recognition policy. (2) Retention & cohorts — cohort files by start month, logo-vs-dollar churn definitions in writing, expansion/downgrade detail. (3) Customers & contracts — top-20 customer schedule, assignment/change-of-control clauses, non-standard-terms log. (4) Cost & margin — hosting/COGS breakdown, capitalized-development policy, headcount by function. (5) Cash & working capital — 13-week cash flow, deferred-revenue balance and roll-forward, net-working-capital peg inputs, debt-like items. (6) The metrics inputs buyers rebuild — NRR, gross margin, Rule of 40 components (requested as raw data, never taken from the deck). Each item has a required form and a specific red flag it screens. The full consolidated table is at the end of this post.

For what those metrics mean once verified — the ARR-to-GAAP bridge, the 12-metric verification stack, the NRR/cohort methodology, the tech/security/AI routing — see the companion SaaS due diligence guide. That post owns the how you verify; this one owns the what gets requested. And for the quality-of-earnings mechanics that sit behind the financial block — add-backs, proof of cash, the re-trade — see quality of earnings. I'll route to both rather than restate them.


What does a SaaS financial diligence request list actually contain?

A SaaS financial diligence request list is the buyer's evidence-request artifact — the specific documents it wants in specific forms, organized into six financial blocks, each item chosen to screen a specific way the headline number can be overstated. It differs from a generic financial due diligence list in one structural way: the target's headline metric, ARR, is not a GAAP number, so the request set is built to reconcile a management-constructed metric down to defensible, GAAP-recognized revenue. A widget business gets asked for a P&L built on delivered goods; a SaaS business gets asked for the machinery underneath a forward-looking annualization.

One sentence of market context, because it explains the tone of the list. Per Software Equity Group's 2026 Annual SaaS Report, there were 2,698 SaaS M&A transactions in 2025, up 28% from 2024 and the highest annual count on record — and per PitchBook's 2025 Annual US PE Breakdown, add-on transactions were 72.9% of all US PE buyouts by deal count in full-year 2025. What that means for a founder receiving a list: these requests arrive at program cadence. A mid-market PE fund runs this exact diligence several times a quarter, the associate assembling your list has sent it before, and the request set is close to standardized. It is not personal, and it is not a sign the buyer distrusts you specifically — it is the check every buyer runs on every SaaS target.

Here is the map of the six blocks, before we work through each one:

#Evidence blockWhat the buyer is really testingThe anchor document
1Revenue & ARRDoes reported ARR reconcile to billings and to cash?MRR/ARR schedule by month by customer + billing export
2Retention & cohortsDoes the base retain, or is churn hidden under expansion?Cohort files by start month, from the billing system
3Customers & contractsDoes the acquired revenue survive the change of ownership?Top-20 schedule + change-of-control clause review
4Cost & marginIs gross margin real, or propped by costs parked below the line?Hosting/COGS breakdown + capitalized-dev policy
5Cash & working capitalWhat does the business owe, and what's the peg at close?13-week cash + deferred-revenue roll-forward + peg inputs
6Metrics inputs (rebuild)Do the headline metrics hold when rebuilt from raw data?Raw inputs for NRR, gross margin, Rule of 40 — never the deck

Two notes on that table. First, the order is roughly the order the work runs — revenue first, because a target whose ARR won't reconcile is a target the buyer stops diligencing, and there is no point pricing contracts on a deal that just died on the ARR schedule. Second, look at the right-hand column: it is a document request list. That is not a coincidence. Everything the buyer verifies is a file — a schedule, an export, a contract, a policy memo — which is why the checklist you work through and the data room the seller organizes are the same artifact. We come back to that at the end.


What revenue and ARR evidence gets requested?

The revenue block is the core of the list, and it is built to walk reported ARR down to committed, defensible revenue — so it asks for the schedule, the billing export, the tie-out samples, and the recognition policy, each in a form the buyer can reconcile. This is where a padded number falls apart, and it is where the buyer spends most of its time.

Here is the request set, each item with the form it should arrive in and the red flag it screens:

ItemForm it should arrive inRed flag it screens
MRR/ARR schedule by month by customerSpreadsheet/CSV, one row per customer × one column per month, ≥24 months, with term + status flagsPilots annualized pre-conversion; month-to-month counted as permanent; churned logos not removed
Contract-to-invoice-to-cash tie-out samplesA sample of customers traced from signed order form → invoice → cash in bankRevenue in the deck that never landed in the bank
Billing-system exportRaw export from Stripe / Chargebee / Zuora / the system of recordA hand-built schedule that can't be reconciled to the system of record
Revenue-recognition policyWritten memo describing ASC 606 treatment, in prosePoint-in-time recognition of subscriptions; services bundled as subscription

The month-by-customer ARR schedule is the single most important document on the entire list, and its form matters as much as its content. It should be a machine-readable file — not a PDF screenshot of a chart — with one row per customer and one column per month across at least the trailing 24 months, plus columns flagging contract term (annual, multi-year, month-to-month), start date, and status (active, churned, downgraded). A buyer that receives a static image of a hockey-stick ARR line has learned something before reading a single number: the schedule was built for the pitch, not maintained as a system of record. That, by itself, raises the burden of proof on everything downstream.

The contract-to-invoice-to-cash tie-out is the buyer's cheapest, sharpest test. It picks a sample of customers and traces each one from the signed order form, to the invoice raised, to the cash actually collected in the bank statement. It is hard to fake all three legs at once — aggressive recognition and phantom revenue tend to break somewhere in the chain — which is exactly why the buyer asks for it. A seller who has run this tie-out on itself, pre-market, walks into diligence with the answer already built.

The billing-system export is the ground truth the schedule reconciles to. And the revenue-recognition policy — a written memo, not a verbal explanation — lets the buyer test whether subscriptions are recognized ratably under ASC 606 or point-in-time, and whether professional services have been bundled into the subscription line where they don't belong.

The buyer's quality-of-earnings team takes these inputs and rebuilds revenue under ASC 606 — the ARR-to-GAAP bridge that removes pilots, month-to-month annualizations, usage overages, terminated-but-counted logos, and bundled services, walking reported ARR down to the number the multiple is actually applied to. I'm deliberately not restating that methodology here; the full bridge, the adjustment classes, and a worked haircut example live in the SaaS due diligence guide. The checklist's job is to make sure the inputs to that bridge are in the room and in the right form, so the re-derivation starts on day one instead of after a week of file-wrangling.


What retention and cohort evidence gets requested?

The retention block asks for the raw material to rebuild net revenue retention from scratch — cohort files by start month, written churn definitions, and expansion/downgrade detail — because the buyer never accepts a summary retention chart. Retention is the second-heaviest block after revenue, and the reason it needs raw files is that a summary NRR number is trivially inflated.

The request set:

ItemForm it should arrive inRed flag it screens
Cohort files by start monthCustomers grouped by the month/quarter they started, recurring revenue rolled forward monthly, from the billing systemAggregate retention masking heavy churn in newer cohorts
Logo-churn and dollar-churn definitionsA written definitions memo — how each metric is calculated, on what denominatorDefinitions quietly re-based to flatter the number
Expansion/downgrade detailExpansion decomposed into seats, modules, and usage; downgrades itemizedOne-time upsells counted as recurring expansion

The cohort files are the heart of it. The buyer wants customers grouped by the month or quarter they started, with each cohort's recurring revenue held at a fixed starting denominator and rolled forward month by month — pulled from the billing or subscription-management system, not hand-assembled. That structure is what lets the buyer see whether newer cohorts retain worse than older ones (a deteriorating acquisition mix hidden inside a stable-looking aggregate) and whether a high headline NRR is really a handful of large expansions masking heavy small-account churn.

The written churn definitions matter more than founders expect. Logo churn (count-based) and dollar churn (revenue-based) can each be calculated several defensible ways, and the buyer wants your definitions in writing so it can check they weren't re-based between the deck and the data room. Getting the definitions in writing, in one memo, is a small preparation task that removes an entire category of follow-up questions.

The verification methodology — how the buyer rebuilds the cohort matrix, the denominator-integrity check, GRR as the honesty check on NRR, the cohort-vintage trend — is not something I'll restate here, because it is the core of the SaaS due diligence guide's retention section. On this list, the job is narrower and comes first: get the cohort files, in the right shape, out of the system of record, so the buyer's rebuild has something real to run on.


What customer and contract evidence gets requested?

The customer-and-contract block asks for the evidence that determines whether the acquired revenue survives the change of ownership — the top-20 customer schedule, the assignment and change-of-control clauses, and a log of every non-standard term. A dollar of ARR under a consent-required, month-to-month contract is worth far less than a dollar under a committed multi-year one, and this block is how the buyer weights the difference.

The request set:

ItemForm it should arrive inRed flag it screens
Top-20 customer scheduleTable: customer, ARR contribution, % of total, start date, renewal date, termConcentration — an anchor customer whose loss resets the thesis
Assignment / change-of-control clausesThe actual clauses extracted from the MSAs/ToS, tied to each customer's ARRRevenue that walks or renegotiates on a change of ownership
Non-standard-terms logA schedule of MFN, price-protection, cap, custom-SLA, and unusual-renewal termsHidden constraints on post-close pricing and margin

The top-20 customer schedule is the concentration probe. The buyer wants each top customer's ARR contribution and share of total, plus start date, renewal date, and contract term, so it can size the risk that one departure resets the whole investment case. Concentration isn't automatically fatal — but it is a repricing or earnout conversation, and the buyer would rather find it in a clean schedule than discover it later.

The change-of-control and assignment clause review is the durability probe. The buyer reads the master subscription agreements and terms of service for provisions that let customers walk, renegotiate, or withhold consent when the company changes hands. Revenue sitting under consent-required or terminate-on-change-of-control terms is partly at risk on close, and the buyer prices that consent risk directly.

The non-standard-terms log catches the constraints that don't show up in the ARR number but bind the buyer's post-close levers: most-favored-nation clauses, price-protection and cap provisions, unusual renewal mechanics, custom SLAs. If the investment thesis includes a pricing reset, these are the terms that can neutralize it.

A staging note for sellers, because this is the most competitively sensitive block: in a multi-bidder SaaS process the bidder pool often includes strategic acquirers who compete with the target, so named-customer contracts should sit behind a post-LOI gate — the buyer sees that the contracts exist and can review clause terms in the abstract, but customer identities stay dark until a bidder is serious. The clause-level mechanics of how consent risk is priced, and the DPA-chain and auto-renewal detail, are in the SaaS due diligence contract section; here the point is which documents get requested and why.


What cost structure and margin evidence gets requested?

The cost block asks for the evidence to test whether gross margin is real — a hosting and COGS breakdown, the capitalized-development policy, and headcount by function — because SaaS gross margin is easy to inflate by parking delivery costs below the line. This is where the buyer confirms the profitability half of the story, and where the consensus screens buyers apply come into play.

The request set:

ItemForm it should arrive inRed flag it screens
Hosting / COGS breakdownCost-of-delivery detail: cloud/infrastructure, support, customer success, third-party API and model costsDelivery costs classified as opex to inflate the subscription-gross-margin line
Capitalized-development policyWritten policy on what R&D is capitalized vs expensed, with the amountsAggressive capitalization flattering both margin and cash flow
Headcount by functionRoster mapped to function (R&D, S&M, G&A, customer success), fully loaded costCosts mis-classified across functions to flatter unit economics

The hosting/COGS breakdown is the main event. The buyer wants cost of delivery itemized — cloud and infrastructure, customer support, customer success, and increasingly third-party API and foundation-model costs — because the most common gross-margin overstatement is to classify those as operating expense so the subscription-gross-margin line looks better than it is. The buyer re-maps the general-ledger cost centers to a standard SaaS COGS definition and recomputes margin from there.

On the screens buyers apply: it is fair to say that buyers screen for high subscription gross margin and treat costs parked below the line as a finding, and that a target clearing the Rule of 40 commands a premium (I'll quantify that in the metrics section). What I won't do — and what you should distrust when you see it — is attach an invented threshold-as-statistic, the "X% of buyers require Y% gross margin" style of claim. Those numbers circulate in advisory content without a primary source. The honest version is directional: buyers screen for margin quality, they rebuild the number rather than trust it, and where a specific benchmark can't be sourced to a named publisher, the right move is to describe the screen and omit the fake precision.

The capitalized-development policy screens for aggressive capitalization of R&D, which flatters both margin and cash flow, and the headcount-by-function roster lets the buyer confirm that costs are sitting in the right functional buckets before it recomputes CAC, CAC payback, and the Rule of 40 components. The verification methodology for margin and the unit-economics stack is in the SaaS due diligence guide; the checklist supplies the raw cost detail those computations need.


What cash, working capital, and debt-like items get requested?

The cash block asks for the near-term liquidity picture, the deferred-revenue balance, and the net-working-capital peg inputs — because deferred revenue makes SaaS working capital its own negotiation, and the peg is where a lot of the price actually gets set. This block is smaller than the revenue block but disproportionately contentious.

The request set:

ItemForm it should arrive inRed flag / what it sets
13-week cash flowA rolling 13-week direct cash-flow modelNear-term liquidity — does the business fund itself through close?
Deferred-revenue balance + roll-forwardThe balance plus a roll-forward tying billings → deferred revenue → recognized revenueThe balance-sheet anchor the ARR schedule must reconcile to
Net-working-capital peg inputsTrailing monthly working-capital components (AR, prepaids, accruals, deferred-rev treatment)Sets the 'normal' working-capital level delivered at close
Debt and debt-like items scheduleCapital leases, deferred payments, earnouts, anything behaving like debtUndisclosed obligations that reduce equity value

The 13-week cash flow shows the near-term runway. Even a profitable SaaS target gets asked for it, because the buyer wants to confirm the business funds itself through to close without a surprise.

The deferred-revenue balance and roll-forward is where SaaS diverges from a widget deal. A customer who prepaid an annual contract sits in deferred revenue as a real obligation the buyer inherits — and deferred revenue is also the balance-sheet anchor that the ARR schedule has to tie to. The buyer reconciles billings to the change in deferred revenue to recognized revenue, and any leg that doesn't tie is a finding.

The net-working-capital peg inputs are the trailing monthly working-capital components that set the "normal" level of working capital the buyer expects to be delivered at close. Here is the part that gets contentious: in SaaS, deferred revenue can be argued as an ordinary working-capital item or as a debt-like item, and the classification moves the purchase price. That is a genuine negotiation, not a checklist item, and I won't relitigate it here — the peg fight, and how a well-prepared seller pegs working capital on real trailing-twelve-month data to defend it, is covered in the sell-side due diligence playbook. The proof-of-cash test the buyer runs to confirm that reported earnings actually landed in the bank — reconciling the income statement to bank statements — is a quality-of-earnings procedure covered in quality of earnings. On this list, the point is which documents to have ready: near-term cash, the deferred-revenue roll-forward, the peg inputs, and a clean debt-like-items schedule.


Which SaaS numbers do buyers rebuild themselves?

Buyers never take the headline SaaS metrics from the pitch deck — they request the raw data and rebuild NRR, gross margin, and the Rule of 40 inputs from scratch, because those three numbers move the multiple enough that no buyer will underwrite the seller's version. This is worth calling out as its own section, because the most common founder misconception is that the metrics slide is the diligence deliverable. It isn't. It's the hypothesis the buyer sets out to disprove.

The three the buyer always rebuilds:

  • Net revenue retention. Rebuilt from the cohort matrix (block 2) with a fixed denominator. A summary NRR chart is inflated by re-basing the cohort or folding new logos into the existing-customer base, so the buyer computes it from the raw cohort files.
  • Gross margin. Rebuilt by re-mapping the GL cost centers (block 4) to a standard SaaS COGS definition. Delivery costs parked in opex get moved back below the line, and margin gets recomputed on the corrected classification.
  • Rule of 40 inputs. Growth rate plus profit margin, recomputed on consistent GAAP inputs rather than the "adjusted" figures a deck tends to lead with.

Why buyers spend the effort here rather than trusting the slide: the quality premium is real and it is quantified. Per Aventis Advisors' Rule of 40 in SaaS: 2026 Data, public SaaS companies that clear the Rule of 40 on a free-cash-flow basis trade at a median 4.8x EV/Revenue versus 2.7x for those that fail — a 74% premium, and each 10-point improvement in the Rule of 40 is associated with roughly +1.1x EV/Revenue. When a single metric is worth that much of the multiple, a buyer that accepted the seller's self-reported version would be underwriting the seller's marketing. (That premium is a public-market observation; private transaction multiples run their own band — SEG's private SaaS M&A median was 4.0x EV/TTM-revenue in 2Q26 — and the valuation mechanics live in our SaaS valuation multiples guide. Here the R40 premium matters only as the reason buyers rebuild the number.)

The full verification stack — the twelve metrics, where each gets overstated, and the procedure to catch it — is the SaaS due diligence guide. On this list, the operational point is simpler: request the inputs for these three (the cohort files, the GL cost-center detail, the growth and margin build), not the seller's computed outputs, so the rebuild can happen inside the room.


The full SaaS financial diligence checklist

This is the printable artifact the post exists for — the consolidated request list across all six blocks, marked essential (send in the first wave) or later-stage (post-LOI or on request), with the form each item should arrive in and the red flag it screens. A founder can read it top to bottom as a preparation list; an associate can lift it into a request memo. Essential items are the ones a buyer needs before it can underwrite the number at all; later-stage items deepen the review or gate sensitive material behind the LOI.

BlockItemFormWhat it screensPriority
1 · Revenue & ARRMRR/ARR schedule by month by customerSpreadsheet/CSV, row-per-customer × month, ≥24 mo, term + status flagsPilots/M2M/churned logos inflating ARREssential
Contract-to-invoice-to-cash tie-out samplesSample traced order form → invoice → cashDeck revenue that never hit the bankEssential
Billing-system exportRaw export from the system of recordHand-built schedule that won't reconcileEssential
Revenue-recognition policyWritten ASC 606 memoPoint-in-time recognition; bundled servicesEssential
Invoiced vs recognized vs collected reconciliationMonthly reconciliation tableTiming gaps between billings and revenueLater-stage
2 · Retention & cohortsCohort files by start monthBilling-system cohort matrix, fixed denominatorAggregate masking newer-cohort decayEssential
Logo-churn & dollar-churn definitionsWritten definitions memoDefinitions re-based to flatter retentionEssential
Expansion/downgrade detailDecomposed into seats, modules, usageOne-time upsells counted as recurringLater-stage
Renewals & bookings pipelineForward renewal schedule with datesRenewal cliff hidden in a trailing numberLater-stage
3 · Customers & contractsTop-20 customer scheduleTable: ARR, % of total, start, renewal, termConcentration resetting the thesisEssential
Assignment / change-of-control clausesClauses extracted, tied to ARRRevenue that walks on change of ownershipEssential (clauses); identities post-LOI
Non-standard-terms logMFN, price-protection, cap, SLA scheduleHidden constraints on post-close pricingLater-stage
Signed order forms / MSAs (named)The contracts themselvesUn-papered or verbal commitmentsLater-stage (post-LOI gate)
4 · Cost & marginHosting / COGS breakdownCloud, support, success, API/model cost detailDelivery costs parked in opexEssential
Capitalized-development policyWritten policy + amounts capitalizedAggressive capitalization flattering margin/cashEssential
Headcount by functionRoster mapped to function, fully loadedCosts mis-classified across functionsEssential
S&M ledger detail (for CAC rebuild)Raw sales-and-marketing spend by periodBlended/understated CACLater-stage
5 · Cash & working capital13-week cash flowRolling direct cash-flow modelNear-term liquidity through closeEssential
Deferred-revenue balance + roll-forwardBalance + billings→deferred→recognized tieARR that won't tie to the balance sheetEssential
Net-working-capital peg inputsTrailing monthly WC componentsSets the working-capital level at closeEssential
Debt & debt-like items scheduleLeases, deferred payments, earnoutsUndisclosed obligations reducing equity valueEssential
6 · Metrics inputs (rebuild)NRR raw inputsThe cohort files from block 2NRR taken from the deckEssential
Gross-margin raw inputsThe GL cost-center detail from block 4Margin taken from the deckEssential
Rule of 40 inputsGrowth + GAAP margin buildR40 computed on adjusted figuresEssential

The pattern across the whole table is the one I opened with: every item pairs a form with a screen. The form is what makes the evidence usable on day one instead of after a week of back-and-forth; the screen is why the item is on the list at all. Nothing here is box-ticking — each row is a specific probe for a specific overstatement, which is exactly why a seller who prepares the whole table pre-market walks into diligence with the repricing levers already removed.


How should sellers stage this evidence?

Sellers should stage the evidence as a data room index that mirrors this checklist one-to-one — six top-level folders, one per block, each requested document dropped into its slot in the form the buyer asked for — and sequence the first wave before the later-stage material. Build the room before you go to market, and diligence becomes a verification of an organized package instead of a scramble that drags on the price.

The prep sequence I'd run, in order:

  1. Build the ARR schedule as a system of record first. It's the anchor of the whole list and the thing most likely to be caught mid-assembly. Reconcile it to the billing export and to the change in deferred revenue yourself, before a buyer does, so you find and fix the breaks while you still control the narrative.
  2. Run your own contract-to-invoice-to-cash tie-out. Pick the sample the buyer would pick and trace it. If a leg doesn't tie, you want to know before diligence, not during it.
  3. Get the cohort files and churn definitions out of the billing system, in writing. These are the second thing a buyer rebuilds; having them in the right shape removes a whole round of follow-ups.
  4. Assemble the six-folder tree and gate the sensitive blocks. Revenue, retention, cost, and cash go in the first wave; named-customer contracts and the S&M ledger sit behind a post-LOI gate so competitor-affiliated bidders don't see identities or acquisition economics pre-signing.
  5. Watermark and track. Stamp every sensitive page with the viewer's identity, and use analytics to see which bidder is actually building a model.

Two companion guides carry the parts I'm not going to restate. For the seller-side deal arc — valuation, the buyer landscape, how the process actually runs — see how to sell a SaaS company. For the room's readiness ladder and the SaaS-specific folder taxonomy in depth, see SaaS M&A data room 2026. And one strategic note for founders selling into a PE roll-up: if the acquirer is a platform buying add-ons, the diligence is run by a team that does this repeatedly and expects the evidence in exactly this shape — the add-on acquisition strategy guide covers why that buyer moves fast and what it optimizes for. A clean, checklist-shaped room is the single biggest thing you control to keep that process moving.

This is the natural home for Peony, the data room I work at, used by 6,800+ customers across M&A, fundraising, and diligence. The Data Room plan at $52 per admin per month billed annually ($75 monthly) gives unlimited rooms and storage, Advanced NDA with countersigning, and per-viewer dynamic watermarking that stamps each page with the viewer's identity — so a leaked ARR schedule or top-customer list traces to the exact bidder. Page-level analytics — on every tier, including Free — show which reviewer spent forty minutes on the cohort matrix versus a five-minute drive-by, which is the clearest signal of who is doing real diligence. The Business plan at $30 per admin per month ($44 monthly) covers a lighter process with Simple NDA gating, and the free tier ($0, up to 50 documents) is enough to assemble the package before you commit. Viewers are always free, so inviting the buyer's QofE team, counsel, and the deal partners costs the seller nothing extra.


The bottom line

A SaaS financial diligence request list is not an interrogation — it's a standardized evidence request, run at program cadence by buyers who send it several times a quarter, built to reconcile a management-constructed metric (ARR) down to the defensible, GAAP-recognized revenue the multiple actually gets applied to. Every item on it pairs a required form with a specific screen, and once you see that structure the list stops being intimidating: the month-by-customer ARR schedule screens for inflated recurring revenue, the cohort files screen for hidden churn, the top-20 schedule screens for concentration, the change-of-control review screens for revenue that walks, the COGS breakdown screens for propped-up margin, and the deferred-revenue roll-forward keeps the whole ARR narrative tied to the balance sheet.

For the buyer, the discipline is to request raw inputs and rebuild the numbers — NRR, gross margin, Rule of 40 — rather than accept the deck, because those metrics move the multiple too much to underwrite on trust. For the seller, the entire list is a preparation checklist you can work in reverse: build the ARR schedule as a system of record, run your own tie-out, get the cohort files out in the right shape, and stage it all in a room that mirrors the six blocks. The seller who does that keeps control of the narrative; the seller who discovers a break across the table has already handed the buyer a repricing lever. Everything on the list is a document you index — which is why, in the end, the request list and the data room are the same artifact, and used by 6,800+ customers, Peony is built to hold exactly that.


Frequently asked questions

A PE firm just sent us a financial diligence request list: what's actually on a SaaS one?

A SaaS financial diligence request list is the buyer's evidence-request artifact: the specific documents the deal team wants, in specific forms, before it will underwrite the price. On a $10M–$50M ARR target it runs across six financial blocks. Revenue and ARR evidence: an MRR/ARR schedule by month by customer, contract-to-invoice-to-cash tie-out samples, the raw billing-system export, and the written revenue-recognition policy. Retention and cohort evidence: cohort files by start month, logo-churn and dollar-churn definitions in writing, and expansion/downgrade detail. Customer and contract evidence: a top-20 customer schedule, assignment and change-of-control clauses, and a non-standard-terms log. Cost and margin evidence: a hosting/COGS breakdown, the capitalized-development policy, and headcount by function. Cash and working-capital evidence: a 13-week cash flow, the deferred-revenue balance and roll-forward, and the net-working-capital peg inputs. And the metrics inputs the buyer will rebuild itself: NRR, gross margin, and the Rule of 40 components. Each item arrives in a defined form and screens a specific red flag. The list is not hostile — with 2,698 SaaS M&A transactions in 2025 and add-ons at 72.9% of US PE buyouts, these lists arrive at program cadence, and the request is close to standardized. What the metrics mean once verified is a separate topic; this checklist is the document-request layer. The full consolidated table is in the post above.

What form should the ARR schedule be in for PE diligence, and how do they tie it out?

The ARR schedule should arrive as a machine-readable file — a spreadsheet or CSV, not a PDF picture of a chart — with one row per customer and one column per month, showing recurring revenue over at least the trailing 24 months, plus columns flagging contract term (annual, multi-year, or month-to-month), start date, and status (active, churned, downgraded). The buyer ties it out three ways. First, it reconciles the schedule total to the billing-system export, so every dollar of claimed ARR maps to a billing record. Second, it runs a contract-to-invoice-to-cash tie-out on a sample: pick a set of customers, trace each from the signed order form to the invoice raised to the cash actually collected in the bank. Third, it reconciles the ARR movement to the change in deferred revenue and to GAAP-recognized revenue. The point of the exercise is to separate reported ARR from committed, defensible ARR — the buyer's quality-of-earnings team rebuilds the number under ASC 606, and the mechanics of that ARR-to-GAAP bridge live in our SaaS due diligence guide. A schedule that arrives as a static image, or that can't be reconciled to billings, is itself a finding: it tells the buyer the number was assembled for the deck rather than maintained as a system of record.

What is each item on the SaaS diligence list actually screening for?

Every item on a SaaS financial diligence list screens a specific way the headline number can be overstated. The month-by-customer ARR schedule screens for pilots annualized before conversion, month-to-month contracts counted as if permanent, and churned logos never removed. The contract-to-invoice-to-cash tie-out screens for revenue that exists in the deck but never landed in the bank. The billing-system export screens for a hand-built schedule that can't be reconciled to the system of record. The cohort files screen for retention that only looks healthy in aggregate because a few large expansions mask heavy small-account churn. The top-20 customer schedule screens for concentration — a single anchor customer that, if it leaves, resets the whole thesis. The change-of-control clause review screens for revenue that walks or renegotiates on a change of ownership. The hosting/COGS breakdown screens for infrastructure and support costs parked below the line to inflate gross margin. The capitalized-development policy screens for aggressive capitalization that flatters both margin and cash. The deferred-revenue roll-forward screens for an ARR narrative that doesn't tie to the balance sheet. In every case the item is not bureaucratic box-ticking; it is a specific probe for a specific overstatement, and the honest seller welcomes it because a clean answer removes a repricing lever.

Why did the buyer ask for change-of-control clauses and my top-20 customers?

Because both go to whether the acquired revenue survives the deal — which is exactly what the buyer is paying for. The top-20 customer schedule (name, ARR contribution, start date, renewal date, contract term) lets the buyer measure concentration. If one customer is a large share of ARR, its loss resets the whole investment case, so concentration is priced directly — not necessarily fatal, but a haircut or an earnout conversation. The change-of-control and assignment clause review answers a related question: can customers walk, renegotiate, or withhold consent when the company changes hands? A book of revenue sitting under consent-required or terminate-on-change-of-control contracts is worth less than the same ARR under committed multi-year terms, because some of it is at risk on close. The buyer usually asks for these behind a post-LOI gate, and a seller in a competitive process should stage named-customer contracts so competitor-affiliated bidders don't see customer identities before signing. The clause-level detail — assignment, DPA chains, auto-renewal, MFN — is contract diligence, and the mechanics of pricing consent risk are in our SaaS due diligence guide; here the point is that the request is standard and screens for revenue durability, not a fishing expedition.

What cash and working-capital items do PE firms request in a SaaS deal?

A SaaS buyer requests four cash and working-capital items. First, a 13-week cash flow — the near-term liquidity runway, which matters even for a profitable target because it shows whether the business funds itself through close. Second, the deferred-revenue balance and its roll-forward — in SaaS this is both a cash item and the balance-sheet anchor that the ARR schedule has to reconcile to; a customer who prepaid an annual contract sits in deferred revenue and is a real obligation the buyer inherits. Third, the net-working-capital peg inputs: the trailing monthly working-capital components (receivables, prepaids, accrued expenses, and the deferred-revenue treatment) that set the "normal" level of working capital the buyer expects to be delivered at close. Fourth, a debt and debt-like-items schedule — capital leases, deferred payments, and anything that behaves like debt. The peg is where a lot of SaaS deals get contentious, because deferred revenue can be argued as working capital or as a debt-like item, and the classification moves the price; that fight is covered in our sell-side due diligence playbook, and the proof-of-cash test the buyer runs against your bank statements is in our quality of earnings guide. The request itself, though, is routine: near-term cash, deferred revenue, the peg inputs, and debt-like items.

Which SaaS numbers do buyers rebuild themselves instead of taking from the deck?

Buyers never take the headline SaaS metrics from the pitch deck — they request the underlying data and rebuild the numbers from scratch. The three they always recompute are net revenue retention, gross margin, and the Rule of 40 inputs. NRR gets rebuilt from a cohort matrix out of the billing system with a fixed denominator, because a summary NRR chart is trivially inflated by re-basing the cohort or folding in new logos. Gross margin gets rebuilt by re-mapping the general-ledger cost centers to a standard SaaS COGS definition, because hosting, support, and customer-success costs are often parked in operating expense to flatter the subscription-gross-margin line. The Rule of 40 (growth rate plus profit margin) gets recomputed on consistent GAAP inputs rather than the adjusted figures a deck tends to use. The reason buyers spend the effort is that the quality premium is real and quantified: per Aventis Advisors' 2026 data, public SaaS companies clearing the Rule of 40 on a free-cash-flow basis trade at a median 4.8x EV/Revenue versus 2.7x for those that fail — a 74% premium. When a metric moves the multiple that much, no buyer underwrites the seller's version of it. The verification methodology for each of these lives in our SaaS due diligence guide; the checklist's job is to make sure the raw inputs are in the room so the rebuild can happen on day one.

How should I stage the request list in a data room so diligence doesn't stall?

Stage it as a data room index that mirrors the request list one-to-one, so the buyer's list and your folder tree are the same artifact. Build one top-level folder per financial block — revenue and ARR, retention and cohorts, customers and contracts, cost and margin, cash and working capital — and drop each requested document into its slot, in the form the buyer asked for. That turns diligence into a verification of an organized package instead of a scavenger hunt, which is the single biggest lever on speed. This is a natural fit for Peony, the data room I work at, used by 6,800+ customers. Peony's Data Room plan at $52 per admin per month billed annually ($75 monthly) gives unlimited rooms and storage, Advanced NDA with countersigning, and per-viewer dynamic watermarking that stamps each page with the viewer's identity — so a leaked ARR schedule or customer list traces to the exact bidder. Named-customer contracts stage behind a post-LOI gate so competitor-affiliated bidders never see identities pre-signing. And page-level analytics — on every tier, including Free — show which reviewer spent forty minutes on the cohort matrix versus a five-minute drive-by, which tells you which bidder is building a model and which is taking the meeting. The Business plan at $30 per admin per month ($44 monthly) covers a lighter process, and the free tier lets you assemble the package before you commit.

What happens if my ARR schedule doesn't tie to billings and cash?

If your ARR schedule doesn't reconcile to the billing system and to cash collected, the buyer treats the gap as a finding and walks the number down until it does — and that walk comes straight off the price. The mechanic is simple and unforgiving: the multiple is applied to defensible ARR, not reported ARR, so a 15% or 20% gap between the two is a 15% or 20% cut to enterprise value before any change in the multiple itself. A schedule that can't be tied out also does something worse than cost a few points — it costs trust. Once the buyer catches one number that doesn't reconcile, it re-scrutinizes every other number you gave it, follow-up cycles multiply, and the diligence window stretches. The fix is entirely in your control and it happens before you go to market: build the ARR schedule as a maintained system of record, reconcile it yourself to billings and to the change in deferred revenue and to GAAP revenue, and fix the breaks while you still control the story. Sellers who build that reconciliation pre-market keep the narrative; sellers who discover the gap across the table have already lost it. The re-derivation logic the buyer uses is in our quality of earnings guide, and the ARR-to-GAAP bridge specifically is in our SaaS due diligence guide.


About the author: Chris Chen works at Peony, the data room platform used by 6,800+ customers across M&A, fundraising, and diligence workflows. Before Peony, Chris worked in M&A at Moelis & Company across cross-border, healthcare, industrials, and consumer transactions.

  • SaaS Due Diligence — the verification companion: the ARR-to-GAAP bridge, the 12-metric stack, and the NRR/cohort methodology this checklist supplies the inputs for
  • Quality of Earnings — add-backs, proof of cash, and the re-trade defense behind the financial block
  • Sell-Side Due Diligence — the pre-market VDD program and the working-capital peg fight the seller prepares for
  • SaaS M&A Data Room 2026 — the seller-side readiness ladder and SaaS folder taxonomy that stages this list
  • How to Sell a SaaS Company — the full sell-side deal arc: valuation, buyer landscape, and process mechanics
  • SaaS Valuation Multiples — the private-vs-public multiple bands and the Rule of 40 premium that set the price the checklist defends
  • Add-On Acquisition Strategy — why a platform buyer running roll-ups moves fast and expects the evidence in exactly this shape