Aug 15, 2024
Due Diligence
Most due diligence checklists circulating online cover the same ground: financials, cap table, legal structure, IP, team, market. That's the right starting point, but it's also where most checklists stop. And for a European fund, stopping there means leaving out categories that are either regulatory in nature or increasingly expected by LPs. This is a working checklist, not an exhaustive legal document; treat it as a starting structure to adapt to your fund's stage, sector focus, and jurisdiction, not a substitute for your own counsel's sign-off.
By
Rhea Colaso

Core Financial and Legal Diligence
Historical financial statements and current burn/runway
Cap table, including option pool and any outstanding convertible instruments
Corporate structure and incorporation documents, across all relevant jurisdictions
Material contracts (customer, supplier, employment, IP licensing)
IP ownership: confirming assignment from founders and any contractors
Outstanding litigation or disputes
Existing investor rights and any prior round terms that could affect this one
Team and Governance
Founder and key hire backgrounds
Cap table concentration and vesting status
Board composition and any existing governance commitments
Related-party transactions
ESG and SFDR-Aligned Review
Relevant if the fund is in scope of SFDR, wants a structured read on the founder's approach to sustainability and governance topics, or needs to report specific data to its own LPs.
Sustainability and climate risk exposure, at a category level
Business operations practices: supply chain, waste and emissions, data handling
Governance structure: management, employee relations, remuneration, tax compliance
Whether Principal Adverse Impact (PAI) data collection is required for this deal
Category detail here in ESG Due Diligence for European VC.
Dual-Use and Export Control Screening
Relevant for deep tech, defence-adjacent, semiconductor, or otherwise sensitive sectors.
Whether the product or underlying IP could fall under EU dual-use export control classification
End-user and end-use risk, particularly for cross-border sales
Existing licensing or compliance measures already in place, if any
Category detail here in Dual-Use Due Diligence for Deep Tech VCs.
Responsible AI Review
Relevant for companies building or deploying AI systems.
Likely risk classification under the EU AI Act (prohibited, high-risk, limited, minimal)
Training and validation data governance practices
Human oversight and explainability mechanisms
Documentation readiness relative to what a provider or deployer would need
Category detail here in Responsible AI Due Diligence for VCs.
KYC, KYT, and AML Screening
Relevant for every deal, though depth varies with jurisdiction and ownership complexity.
Source of funds verification
Ultimate beneficial ownership mapping
Sanctions and PEP screening
Cross-border ownership or capital flow flags
Category detail here in KYC and KYT for VC Due Diligence.
AIFMD-Aware Process Documentation
If the fund itself is regulated under AIFMD, the checklist isn't complete once the deal-level items above are done — the process used to work through them needs to be documented and repeatable in its own right.
Is the due diligence process for this deal documented in a form that could be produced on request during a supervisory review?
Is the process consistent with how the last several deals were run, or has it drifted deal to deal?
If any part of investment or risk management is delegated, is the periodic due diligence used to monitor that delegate recorded?
We go deeper on the regulatory backdrop in Due Diligence Software for European VC Funds.
Output Stage
Have financial, legal, and specialist findings been consolidated into a single report, rather than left as separate documents?
Where multiple specialist categories apply, has a risk matrix been built from the combined findings?
Is the final output in a form that could be shared with an LP if asked to demonstrate process, not just used internally?
Using This as a Living Checklist
The value of a checklist like this drops fast if it's a static document nobody updates; sectors shift, regulation changes (the EU AI Act's own timeline has moved more than once), and a checklist built for seed-stage SaaS doesn't map cleanly onto a deep-tech Series A.
Treat this as a starting structure to build into your own DDQ template, adapted by deal stage and sector, rather than a one-size list to run through unchanged on every deal.

