So, You Got a Term Sheet? Don't Panic, Get Prepared.
That feeling is electric, isn't it? An investor wants to give you money. You celebrate, you call your mum, and then the email lands. It's from their lawyer, and it has a subject line like “Diligence Request List”.
Suddenly, the excitement cools into a low-grade panic. What are they looking for? Is my company a house of cards? Usually, no. But due diligence has a way of making even tidy founders feel like they've left wet paint on every wall.
It helps to reframe it. This isn't an exam where someone tries to catch you out for sport. It's verification. It's the part where your story gets matched against the paperwork, the bank records, the contracts, the registers, and the reality of how your business runs.
That's why a good startup due diligence checklist matters long before money is on the table. It gives you a way to clean up the obvious stuff, spot the ugly stuff, and explain the awkward stuff before an investor's counsel does it for you. That changes the whole tone of the deal.
And yes, there's overlap with sale prep too. If you're still shaping the early deal docs, it's worth understanding drafting a strong LOI, because a vague letter of intent can create as much friction as a messy data room.
For NZ and AU founders, the local wrinkles matter. Companies Office checks, ASIC searches, FMA issues, Privacy Act questions, KiwiSaver or super mistakes, IP that still sits with a contractor, founder-led sales that haven't been systemised. That's the actual terrain.
So let's get to it. Not the glossy VC version. The one that helps you survive the process.
The first real crack in a deal often shows up in the numbers. A founder says revenue is growing, margins are improving, and cash is under control. Then diligence starts, and the bank statements tell a messier story. That gap is what investors focus on.
For NZ and AU founders, the standard is straightforward. Put your financial statements, tax filings, GST or BAS records, bank statements, and management accounts in one place and make sure they reconcile. If revenue is booked before an invoice went out, label it clearly. If founders paid suppliers personally in the early days, show the reimbursement trail and board approval if relevant. If there are one-off add-backs, explain why they exist and why they should survive scrutiny. Many do not.
Early-stage companies often have thin finance functions. That is fine. Sloppy explanations are not. Investors can live with imperfect systems much more easily than they can live with numbers that keep changing.
The cap table is usually the second pressure point.
I see the same problems repeatedly. Shares issued without clean board consent. Advisor equity promised in email but never documented. A former co-founder who still appears to own more than everyone remembers. SAFEs or convertible notes sitting in folders, ignored because they have not converted yet. If you are still operating through the wrong setup from your earliest days, fix that too. This guide on sole trader vs company structures in New Zealand is a useful refresher if the entity history is messy.
Use a single cap table that shows each holder, instrument type, issue date, price, vesting terms, and current fully diluted position. Then match it against your share register, board minutes, subscription documents, and any side letters. For New Zealand companies, check what appears on the Companies Register. For Australian companies, run the same basic sanity check through ASIC. Admin sloppiness does not always kill a deal, but it usually slows one down and gives investors a reason to retrade.
Practical rule: Pull statements directly from the bank for the full review period. Do not rely on founder-saved PDFs from old email threads.
A few areas deserve a hard look before anyone else gets there first:
If the story in the deck sounds smooth but cash movements look erratic, trust the cash first. Founders win diligence here by being precise, not polished.
Plenty of early startups behave like companies before they're properly set up like companies. That's manageable at the coffee-and-Figma stage. It's not manageable when someone is wiring money.
You need to confirm the entity exists, the ownership records are current, and the IP sits where it should. In New Zealand, investors should search the Companies Office register for the constitution, shareholder register, and director appointments because those records define ownership and governance. Missing or stale records can create serious problems at investment time, as noted in this NZ due diligence guide.
Here's the visual version of the issue:

This sounds blunt because it is. If a founder built the MVP while employed elsewhere, or a contractor shipped core code without a signed assignment, ownership can be cloudy. Investors hate cloudy.
Search the company name and product name on IP Australia and IPONZ. Check your domain registration too. A founder owning the domain personally isn't always fatal, but it's amateur-hour paperwork and should be fixed.
If you're still deciding whether your structure even makes sense, the practical trade-offs in sole trader vs company in NZ are worth understanding before diligence forces the issue.
A short hit list helps here:
People often obsess over trademarks and forget code ownership. In reality, code ownership usually matters more.
Friday afternoon term sheet. Monday morning diligence request. By Tuesday, the investor wants the top ten customer contracts, invoice history, churn data, and proof the cash hit the bank. That is usually the point where a tidy revenue slide meets reality.
For NZ and AU founders, this step is less about storytelling and more about evidence. Buyers and investors want to see what is contracted, what is month-to-month, what can be cancelled easily, and whether the revenue sits with one customer, one founder relationship, or one channel partner. If the company sells into regulated customers, expect extra scrutiny on procurement terms, privacy clauses, and service levels too.
Revenue quality matters more than headline revenue.
Ask for the underlying documents, not just the dashboard. Signed MSAs, order forms, SOWs, reseller agreements, renewal notices, invoices, Stripe or payment processor exports, and bank statement matching should all line up. If they do not, the problem is rarely the spreadsheet. It is usually the process behind it.
A few checks expose the truth quickly:

The local wrinkle in NZ and AU is that small markets create hidden concentration faster than founders expect. A startup can have 40 customers and still be exposed because three enterprise logos represent most of the ARR, or because one government or bank procurement cycle delays half the year's cash receipts. I have also seen businesses call revenue "sticky" when the actual reason customers stay is the founder personally fixes every issue.
Read the contracts like an operator, not just a lawyer. Check whether pricing matches the invoice history. Check whether discounts were approved or just promised in email. Check whether any customer has unusual MFN treatment, broad indemnities, uncapped liability, or IP ownership language tucked into procurement paper. In Australia, larger customers often push their own terms. In New Zealand, startups sometimes accept them without real review because they want the logo. That decision can come back hard in diligence.
If the product handles personal information, the customer contract should also line up with the company's privacy position. In New Zealand that means checking consistency with the Privacy Act 2020 and any data handling commitments made to customers. In Australia, the same issue often gets tested against the Privacy Act 1988 and customer security schedules. A sales contract that promises more than the product or internal controls can deliver is not a sales win. It is a future dispute.
A short customer call beats a polished pipeline report. Ten minutes with an active buyer will usually tell you whether the product is embedded, tolerated, or already halfway out the door.
One practical rule. Treat trial users, unpaid pilots, signed LOIs, and procurement-stage opportunities as pipeline, not revenue. Founders blur these categories all the time, especially in early SaaS and B2B services. Diligence should separate contracted revenue, billed revenue, collected revenue, and likely renewals. Once those buckets are clean, the revenue story gets much easier to defend.
Startups don't fail only because the product breaks. Sometimes the contracts break first.
A serious startup due diligence checklist has to inspect the people side with the same care as the numbers. In New Zealand, due diligence frameworks also look at workplace compliance, including employee entitlements and environmental obligations, through the lens of legal and operational risk in government due diligence guidance.
That sounds formal. In practice, it means checking whether your team is properly employed, paid correctly, documented properly, and not sitting on a future dispute.
There's another issue in NZ and AU that gets missed. Founder dependence. Small local teams often run on undocumented founder knowledge, founder relationships, and founder heroics. One NZ diligence checklist treats an owner-dependence audit as essential, mapping what the founder does every day and what breaks if they leave, because revenue can fall apart very quickly when the owner's know-how isn't written down, as explained in this NZ due diligence checklist.
Ask uncomfortable questions:
If the answer to all four is “the founder”, that's a risk.
A note from the trenches: Investors can forgive a lean team. They rarely forgive a business that only works when one exhausted person keeps all the wires connected.
Also review employment agreements, vesting records, contractor arrangements, super in Australia, KiwiSaver handling in NZ, and any disputes or settlements. Messy people files don't always kill a deal. They do drain trust.
This one sounds repetitive next to revenue verification, but it isn't. Revenue tells you what happened. Market validation tells you whether it's likely to keep happening.
A lot of startups can generate early sales through hustle, founder networks, or novelty. That's not the same as product-market fit. In the ANZ market, especially, founders can mistake a tight founder network for a repeatable market.
For NZ startup diligence, market size claims should come from credible third-party research, and Serviceable Addressable Market should reflect real geographic and segment limits in New Zealand and Australia rather than a global fantasy map, as outlined in this startup due diligence article. If your TAM slide starts in the billions but your true reachable buyer pool is much narrower, investors will notice.
That's the market side. On the customer side, I'd want to know whether users stick, expand, complain, refer, and build habits around the product. Tools like Mixpanel, Amplitude, HubSpot, Intercom, and Stripe are handy here because they show behaviour, not just opinion.
A practical set of checks looks like this:
If you're still pressure-testing whether the problem is real, how to validate a startup idea gives a more grounded starting point than vanity metrics ever will.
Notion is a useful reference point here. Its adoption story made sense because users kept pulling other users in. Compare that with products that get plenty of signups but low repeat use. Those are very different beasts, even when the dashboards look cheerful for a month or two.
A deal can feel close to done until someone asks a plain question: are you allowed to sell this product, in this market, with this data setup? If the answer is fuzzy, diligence gets tense fast.
This area gets underestimated by NZ and AU founders because the business can look healthy long before the compliance file catches up. Revenue is coming in. Customers are happy. The product works. None of that fixes a missing licence, a sloppy privacy process, or a regulated activity that was never properly identified.
Start with the boring checks. They are often the ones that save a round.
For fintech, payments, lending, insurance, and investment products, confirm exactly which entity is operating and whether it appears on the relevant registers. In Australia, that often means checking ASIC records. In New Zealand, it may mean reviewing Financial Markets Authority obligations, the Financial Service Providers Register, or both. If the company says a licence application is underway, ask what can legally be sold before approval and what must wait. Founders regularly blur that line.
Privacy comes up in almost every software deal now, especially for B2B SaaS selling into enterprise, health, education, or government-adjacent buyers. Under the New Zealand Privacy Act 2020, investors and customers will want a straight answer on what personal information you collect, where it is stored, which vendors can access it, and whether any offshore disclosure rules are triggered. Australian buyers ask the same questions under their own privacy regime, even if the startup is incorporated in NZ.
Data residency is not a theoretical issue in this market. If customer data sits in the US, say so. If backups replicate across regions, say so. If you use subprocessors, produce the list. I have seen otherwise solid companies lose momentum in diligence because the founder said “NZ-hosted” and the architecture diagram told a different story.
A practical review usually covers:
Sector specifics matter here. A medtech startup may need to address product classification and advertising limits. A fintech may need to show how it avoids giving unlicensed financial advice. An AI company selling to enterprise buyers should be ready for questions on training data, model outputs, human review, and whether customer inputs are reused.
IP and compliance also overlap more than founders expect. If your brand is registered through IPONZ but your privacy terms still name an old entity, or your customer contracts are signed by a different company than the one on the register, investors will assume other loose ends are hiding nearby.
Big companies can absorb compliance mistakes for a while. Startups usually cannot. The cost is not only fines or regulator attention. It is procurement delays, redlined contracts, and investors pricing risk into the round.
Founders often say, “We've got no debt,” and then mention a founder loan, a director advance, two SAFEs, a note with a cap, and unpaid vendor invoices five minutes later. That's debt enough to matter.
This part isn't glamorous, but it can alter the economics of the whole round. An investor may like the business and still hate the stack sitting above or beside them. Especially if the paperwork is vague.
Request a schedule of all liabilities. That means bank debt, founder loans, unpaid tax, leases, supplier arrears, notes, and SAFEs. Then read the actual documents.
A few recurring traps:
I've seen founders quote their ownership as if none of the paper will convert. Nice idea. Investors won't model it that way.
If there's family money in the business, don't shrug it off as informal. Informal money is still money. And “we'll sort that out later” is exactly how rounds get delayed.
A startup can look independent and still be dangerously dependent. One supplier, one channel partner, one API, one enterprise partner, one government contract. Pull any one of those bricks out and the wall starts wobbling.
This is why your startup due diligence checklist should go beyond customer contracts. You need the broader commercial web around the business. Some dependencies are healthy. Some are handcuffs.
Founders love naming big partners. Fair enough. But the essential question is what the contract says. Can the partner terminate on short notice? Are there exclusivity clauses? Revenue shares? Liability riders? Restrictions on territory or resale?
For NZ and AU startups, this is especially important when selling into banks, telcos, and government channels. Those relationships can look prestigious and still be one-sided.
Check these carefully:
Xero's ecosystem is a good example of both opportunity and risk. Integration partners can build meaningful businesses around it. They can also become too reliant on rules they don't control.
A flashy partnership announcement is not the same thing as durable commercial leverage.
Look for asymmetry. If the startup needs the partner far more than the partner needs the startup, factor that into your risk view.
A polished demo can hide a mess underneath. Sometimes that's acceptable. Early products often carry rough edges. But investors still need to know whether the software is a shed with fairy lights or something the team can build on.
That means asking awkward technical questions in plain English. What's the stack? Why was it chosen? Where are the fragile points? What's held together by one engineer's memory and a prayer?
Here's the image I'd keep in mind:

Ask for a high-level architecture diagram. Have the founder or CTO explain it without jargon soup. Then review the code repository history, deployment process, cloud setup, logging, and incident response habits. GitHub, GitLab, Jira, Linear, AWS, Azure, and GCP usually tell a pretty honest story.
A few useful prompts:
There's a broader commercial angle too. If a company could meet the same customer need with packaged tools rather than custom engineering, that says something about margins, complexity, and moats. The trade-offs in custom software vs off-the-shelf in NZ are relevant here because buyers and investors will ask whether the tech is a real asset or just expensive plumbing.
Stripe is a handy example. Its technical credibility came from maintainable systems and clear developer experience, not just speed. On the flip side, plenty of small SaaS tools build themselves into corners with hardcoded workflows and brittle architecture long before revenue catches up.
A startup can be good and still be a bad investment if the market story is fuzzy. That's the uncomfortable truth.
Founders often pitch the market in broad, flattering strokes. Big category. Huge demand. Fragmented competitors. Plenty of room. Maybe. But when you map actual alternatives, the picture usually gets messier. US and European products spill into ANZ quickly, and local founders often underestimate how fast that pressure arrives.
Start with the basics. Ask the founder to name the top competitors and say, clearly, what each one does better and worse. If the answer is “we don't really have competitors”, that's almost always nonsense. The competitor may be Xero, MYOB, QuickBooks, a spreadsheet, a service firm, or the status quo.
Then test the claimed edge:
Xero is the obvious regional case study because the differentiation was real. It entered a market with established accounting software players and still won loyalty through product and fit for SMB users. That's very different from an app that mostly competes on being slightly cheaper or slightly prettier.
One final reality check. Market sizing should be grounded, not theatrical. If your TAM starts with the whole planet and your current go-to-market only works in Auckland, Sydney, and a founder's personal network, investors will discount the slide heavily. Fairly, too.
| Area | 🔄 Implementation Complexity | ⚡ Resource Requirements | 📊 Expected Outcomes | 💡 Ideal Use Cases | ⭐ Key Advantages |
|---|---|---|---|---|---|
| Financial Statements and Cap Table | High, detailed reconciliations and cap table parsing | Moderate, accounting expertise, bank & cap table access | Clear view of solvency, burn rate, dilution risks | Pre-investment verification, valuation adjustments | High, exposes liabilities, validates founder financial competence |
| Legal Structure, Registrations, and IP Ownership | Moderate, registry checks and assignment reviews | Moderate, legal counsel, trademark/patent searches | Legal title and IP clarity; reduced ownership risk | IP-heavy startups, incorporation checks, M&A prep | High, secures ownership, prevents third‑party claims |
| Customer Contracts and Revenue Verification | High, contract review and payment tracing | Moderate–High, finance, customer confirmations, processor access | Validated revenue, CAC/LTV insight, concentration risk identified | SaaS MRR validation, revenue-driven term sheets | High, confirms real traction and unit economics |
| Team and Employment Records | Moderate, contracts, background checks, employment law review | Moderate, HR/legal review, reference checks | People risk assessment, retention and compliance status | Assess key-person risk, ESOP validation, regulated hires | Medium, reveals talent stability and legal compliance |
| Customer Due Diligence and Market Validation | Moderate, analytics + qualitative research | Low–Moderate, product analytics, customer interviews | Product‑market fit signals, retention and engagement metrics | Early product validation, GTM strategy refinement | High, indicates sustainable demand beyond vanity metrics |
| Regulatory Compliance and Industry Licenses | High, jurisdictional regulatory assessments | High, specialist legal/regulatory advisors, audits | Operating clearance, compliance gaps and enforcement risk | Fintech, healthtech, data-sensitive startups | High, prevents regulatory shutdowns and major fines |
| Debt and Liabilities (Convertible Notes/SAFEs) | High, complex instrument and dilution modelling | Moderate, legal review, cap table modelling | True capitalization, conversion impacts, hidden obligations | Pre-round negotiations, SAFE/note-heavy cap tables | Medium–High, clarifies economic exposure and negotiation leverage |
| Contracts and Key Business Relationships | Moderate, commercial contract and dependency review | Moderate, legal/commercial analysis of MSAs and suppliers | Partner concentration, supplier stability, termination risk | Channel- or supplier-dependent businesses | Medium, secures operational continuity and potential moats |
| Product Roadmap, Tech Stack, and Technical Debt | High, architecture review and codebase audit | High, engineering expertise, repo access, technical audits | Scalability assessment, technical debt and rework needs | Tech-heavy startups, scaling assessments, infra planning | High, reveals scalability potential and future cost drivers |
| Competitive Landscape and Market Position | Moderate, market research and competitor mapping | Low–Moderate, analyst reports, competitive intelligence | Realistic TAM, market-share outlook, moat identification | Market-entry strategy, fundraising narrative validation | Medium, clarifies positioning and strategic risks |
Okay, that was a lot. But the useful part is simpler than the list makes it seem.
You do not need to wait for an investor to force this process on you. The strongest founders I've dealt with run their own internal diligence regularly. Not because they enjoy admin, obviously. Because it keeps small problems from becoming financing problems.
Start with a data room. It doesn't need to be fancy. A well-organised Google Drive, Dropbox, Notion hub, or DocSend room is fine if the folders are clean, the files are dated, and the naming makes sense to someone who wasn't in the company when the files were created. If counsel or an investor opens the room and immediately sees chaos, they assume chaos elsewhere too. That may be unfair. It still happens.
I'd structure it around the same categories above. Financials. Corporate records. Cap table. IP. Material contracts. Team docs. Product and tech. Compliance. Customer information. Keep a short note in each folder that says what's there, what's missing, and what's being fixed. That little touch does two things. It shows maturity, and it stops people guessing.
There's also a useful mental shift here. Due diligence is not just a fundraising exercise. It's company maintenance. A founder who knows where the contracts are, who owns the IP, which customers drive revenue, what obligations sit in old SAFEs, and where data is stored is usually running a healthier business. You can feel it in the conversations. The answers are cleaner. The stress level is lower. The negotiation posture is stronger.
And yes, some contradictions are real. You can have a messy cap table and still have a brilliant product. You can have founder dependence and still be growing fast. You can have technical debt and still be a very good investment. None of those issues automatically kill a deal.
What hurts is surprise.
That's why I'd treat every red flag in one of three buckets. Fix now. Disclose clearly. Or explain why it's acceptable for the stage you're at. Missing IP assignments? Fix now. A customer concentration issue you can't unwind this quarter? Disclose clearly. A rough deployment process in a young product with a small user base? Explain it transparently and show the plan.
For NZ and AU founders, there's another layer. Keep local compliance in view from the beginning. Check the Companies Office records. Keep ASIC filings tidy if you're on the Australian side. Understand FMA and AML/CFT issues if your model touches regulated activity. Don't treat Privacy Act questions as something you can tidy up after the round. Larger buyers and more careful investors are asking earlier, especially around data location and AI tools.
The founders who handle diligence best are rarely the founders with zero problems. They're the ones who know what the problems are, have the paperwork ready, and don't get cute when the hard questions arrive.
That's the point of a startup due diligence checklist. It doesn't just help you pass scrutiny. It helps you build a company that deserves confidence.
If you're building, evaluating, or marketing a SaaS, AI, app, or tech business in New Zealand or Australia, NZ Apps is worth keeping on your radar. It covers the regional tech scene with founder-focused guides, market analysis, and company visibility opportunities that make sense for ANZ operators, especially if you need local credibility, a relevant .co.nz presence, or a sharper read on the market you're selling into.
Add your NZ or Australian app or tech company to the NZ Apps directory and get discovered by founders and operators across the region.
Get ListedReach tech decision-makers across New Zealand and Australia. Sponsored and dofollow editorial links, permanent featured listings, and sponsored articles on a DA30+ .co.nz domain.
See Options