Due Diligence Theater: How Acquirers Keep Missing the Liabilities That Destroy Deal Value
There is a particular kind of corporate optimism that takes hold once an acquisition target has been identified. Executives become advocates. Bankers become architects. And the due diligence team, consciously or not, becomes a validation exercise rather than an investigation. The result is a process that looks rigorous from the outside—hundreds of document requests, weeks of site visits, financial model iterations—but functions primarily as theater.
The consequences are well-documented and consistently underappreciated. According to research from McKinsey & Company, roughly 70 percent of acquisitions fail to deliver their anticipated value. The explanations that surface post-close tend to cluster around familiar themes: integration friction, cultural mismatch, market timing. Rarely do post-mortems acknowledge the more uncomfortable truth—that the problems were visible before the deal closed, embedded in data the acquirer already possessed.
Understanding why buyers miss what is plainly in front of them requires examining not just what due diligence teams review, but the structural incentives that govern how they interpret what they find.
The Confirmation Trap
Due diligence in most large transactions is organized around a thesis: the target is worth acquiring at approximately this price for these strategic reasons. Every workstream—financial, legal, operational, commercial—begins with that premise and proceeds to build a case around it. Analysts who surface concerns are frequently asked to contextualize them within the broader deal rationale rather than stress-test the rationale itself.
This dynamic is not the product of bad faith. It emerges naturally from deal economics. By the time a company reaches the formal due diligence phase, significant time and capital have already been deployed. Walking away carries real costs—reputational, financial, and organizational. The incentive structure quietly tilts toward completion.
The result is that second-order risks—those that require connecting multiple data points across workstreams—go unexamined. A legal team flags a pending regulatory inquiry. A financial team notes elevated customer churn in one segment. A commercial team observes that a handful of enterprise accounts represent a disproportionate share of revenue. Each finding is recorded. None are synthesized into a coherent risk narrative. The deal closes. The problems compound.
Customer Concentration: The Risk That Hides in Revenue Tables
Customer concentration is among the most commonly overlooked acquisition liabilities, in part because it appears so plainly in the financial data. A target whose top three customers account for 60 percent of annual revenue is not concealing that fact—it is right there in the revenue schedule. Yet acquirers regularly discount this exposure, particularly when those anchor customers have long tenure or appear in high-growth verticals.
The miscalculation stems from conflating historical stability with forward durability. A customer relationship that has persisted for eight years under founder-led management may not survive a change of ownership, a shift in procurement leadership, or the entry of a well-capitalized competitor. The acquirer, focused on the attractiveness of the revenue line, fails to model the scenario in which that concentration becomes a liability.
Consider the pattern that emerged across several mid-market software acquisitions in the 2018–2021 period. Buyers, attracted by strong net revenue retention metrics, repeatedly underweighted the fact that retention figures were anchored by a small number of deeply embedded accounts. When those accounts renegotiated contracts post-close—often citing the acquisition itself as justification for pricing pressure—the financial model collapsed rapidly. The revenue was real. The durability was not.
Operational Fragility and the Invisible Single Point of Failure
Operational due diligence has improved substantially over the past decade, yet it continues to underperform in one critical area: identifying single points of failure that are not visible in organizational charts or process documentation.
These vulnerabilities tend to concentrate around people and systems. A target company may have a highly capable operations function that, on closer inspection, is effectively one individual—a VP of Operations who has built institutional knowledge over fifteen years and whose departure would require eighteen months to partially replace. Similarly, a technology platform may appear robust in vendor documentation while running on infrastructure that has not been materially updated since the company's Series B.
The due diligence process struggles with these exposures because they require inference rather than documentation review. No target company will voluntarily produce a memo identifying its most fragile dependency. The acquirer must construct that picture from interviews, system audits, and organizational analysis—a synthesis that checklist-driven processes are structurally ill-equipped to perform.
Regulatory Exposure and the Incomplete Paper Trail
Regulatory risk represents perhaps the most dangerous category of overlooked liability, precisely because it sits at the intersection of legal, operational, and commercial workstreams without clearly belonging to any one of them.
Acquirers in heavily regulated industries—healthcare, financial services, energy, defense contracting—typically deploy specialized legal counsel to review compliance posture. What this review frequently misses is not the documented regulatory history, but the undocumented operational practices that have not yet attracted regulatory attention. A healthcare services company that has been billing under a gray-area coding interpretation for three years has created real exposure. The fact that no enforcement action has occurred does not eliminate the liability; it merely means the clock has not yet started.
Post-close, acquirers in these situations face a particularly difficult choice: remediate the practice and absorb the margin impact, or continue it and inherit the full regulatory exposure. Neither option was priced into the deal.
Building an Adversarial Review Framework
The antidote to confirmation-driven due diligence is not more checklists—it is a deliberate structural commitment to adversarial analysis. This means formally designating a team or external advisor whose explicit mandate is to construct the case against the deal. Not to kill it, but to surface the most credible version of the downside scenario.
Effective adversarial review operates on several principles. First, it synthesizes across workstreams rather than reviewing them in isolation. The combination of customer concentration, key-person dependency, and a pending regulatory inquiry is qualitatively different from any one of those factors in isolation. Second, it stress-tests management representations rather than accepting them as baseline assumptions. If the CEO asserts that customer relationships will transfer seamlessly post-close, the adversarial team's job is to find the specific conditions under which that assertion fails. Third, it models second-order consequences—not just what happens if a risk materializes, but what happens to the rest of the business when it does.
This framework does not make acquisitions safer by making them less frequent. It makes them safer by ensuring that when a deal closes, the buyer has genuinely understood what they are purchasing—rather than what they hoped they were purchasing.
The Strategic Cost of Willful Optimism
The organizations that consistently generate acquisition value share a common discipline: they treat the deal process as an exercise in intellectual honesty rather than transactional momentum. They build processes that reward the analyst who identifies a fatal flaw just as much as the banker who structures a creative financing arrangement. They create organizational permission to walk away.
This disposition is harder to maintain than it sounds. The pressure to execute—from boards, from shareholders, from deal teams who have invested months in a transaction—is substantial and real. But the companies that allow that pressure to compromise their analytical rigor are, in effect, paying a premium for the privilege of discovering problems they could have identified in advance.
Due diligence was never meant to be theater. Restoring its function as genuine risk discovery is not a process improvement—it is a strategic imperative.