Blog M&A Intelligence

Rep-and-Warranty Insurance Is Changing How Firms Scope Diligence

RWI carriers are asking harder questions about diligence depth. That's changing how acquirers scope their document review — and what AI review has to cover to satisfy underwriting.

Insurance binder and acquisition term sheet on desk

Rep-and-warranty insurance used to be a mid-market deal accessory — something private equity buyers used on larger transactions to smooth seller-side escrow negotiations. Over the past four years, RWI has moved down-market significantly. Deals in the $30M to $100M range now frequently include RWI as a structural component, not an optional add-on. The coverage costs have compressed, the underwriting timeline has shortened, and the risk transfer benefits are well understood.

What's changed with that expansion is the underwriting standard. Carriers who in 2020 would issue a policy based on a summary diligence memo and a representation schedule are now asking specific questions about what the acquirer's team actually read, when they read it, and what they did or didn't find. The RWI underwriting call is becoming a diligence quality audit.

What Carriers Are Actually Asking

The RWI underwriting questionnaire for a mid-market deal typically covers a set of standard deal terms: deal structure, purchase price mechanics, key representations, knowledge qualifier scope. What's changed is the depth of questions around specific diligence areas — particularly IP, material contracts, and compliance.

On material contracts, underwriters now routinely ask whether the acquirer's team reviewed all material contracts listed on the disclosure schedule, or a representative sample. If sample-based, what was the sampling methodology? Were any contracts flagged as having non-standard terms? What were the specific terms flagged?

This is a qualitatively different standard than "buyer confirms it has had the opportunity to conduct due diligence." The carrier wants to know the depth, not just that the diligence occurred. And where a gap is apparent — the disclosure schedule lists 40 material contracts and the diligence memo summarizes 12 — the carrier may either exclude certain contract-related representations from coverage or price the exclusion into the premium.

For IP-related representations, the questions have gotten more specific: Did the diligence cover all IP assignment agreements in the data room? Were any assignment gaps identified in agreements with founders or key employees? Was there any evidence of open-source license contamination in the product stack?

The Documentation Standard Is Rising

The practical implication for acquirer's counsel is that the diligence deliverable has to be more granular than it was five years ago. A summary memo that says "we reviewed key IP documents and found no material issues" no longer satisfies sophisticated RWI underwriting. The carrier wants to see what was reviewed, what was found, and what was determined to be non-material.

This creates a structural problem for firms doing diligence on a compressed timeline. The full coverage standard — documenting every document reviewed, every clause evaluated, every finding and its disposition — is significantly more effort than the summary-memo standard. And the timeline hasn't expanded to accommodate it; if anything, compressed deal timelines have gotten shorter.

The only way to reconcile comprehensive documentation with compressed timelines is to automate the document coverage layer. The attorney judgment layer — what does this non-standard clause mean for the deal? — still requires an attorney. The document extraction and coverage log — what was in this contract, were the key provisions standard — can be handled by systems designed to do exactly this at scale.

Specific Areas Where RWI Scrutiny Has Increased

Change-of-Control in Material Customer Contracts

Change-of-control provisions in the target's customer and supplier contracts are a standard RWI exclusion risk. If a material customer contract contains a change-of-control right that permits the customer to terminate or renegotiate on a change of control, the revenue represented in that customer relationship is contingent on the customer's post-close consent. Carriers ask specifically whether this was reviewed.

For a deal with a customer concentration issue — where two or three customers represent a significant portion of revenue — the carrier may require that the acquirer provide the specific language of the change-of-control provision in each major customer contract, not just a representation that the contracts were reviewed.

IP Assignment Coverage

As discussed in our earlier piece on IP assignment gaps in startup acquisitions, the pattern of incomplete IP assignment from founders and early employees is common enough that carriers now treat it as a base expectation. The RWI questionnaire for tech acquisitions routinely asks whether assignment agreements with all significant contributors were verified as present and complete.

What qualifies as "complete" in an assignment agreement has also tightened. An agreement that assigns inventions "created in the scope of employment" without a present-assignment clause ("hereby assigns" rather than "agrees to assign") is technically weaker, and carriers are beginning to ask about this distinction. The difference between a present assignment and a covenant to assign matters if the target needs to enforce the assignment — "agrees to assign" requires a court order to vest title; "hereby assigns" is self-executing.

Compliance Representations

Compliance reps in purchase agreements — representations that the target has complied with applicable laws and regulations — are among the broadest in any deal. Carriers routinely apply general exclusions for known compliance issues, but the emerging standard is that the acquirer must demonstrate it looked for compliance issues, not just that none were disclosed.

Data privacy and cybersecurity compliance have become specific underwriting focus areas. A target that processes personal data — which is nearly every company at this point — and whose data processing agreements don't include required CTDPA, CCPA, or GDPR processor terms is technically non-compliant with those regulatory frameworks. Carriers want to know if data processing contracts were reviewed for these requirements.

What This Means for Document Review Scope

The practical effect on diligence scope is an expansion of document coverage that doesn't come with an expansion of time or budget. The firm doing a $50M acquisition with a four-week diligence period now needs to cover not just the material contracts listed on the disclosure schedule, but also the vendor contracts and data processing agreements that weren't previously in scope because they weren't "material" from a contract value standpoint.

A vendor contract for $80,000 per year isn't material from a financial standpoint. But if it processes significant customer data and lacks adequate processor terms, it's a compliance issue that will appear on the RWI underwriting questionnaire. That contract now needs to be in scope.

We're not saying that every diligence review needs to be comprehensive — there is still legitimate scope management, and materiality thresholds still apply. What we're saying is that the scope of "what the carrier will ask about" has expanded beyond "what was material from a financial standpoint," and that expansion is driving a corresponding expansion in the document review universe.

The Flagged Brief as Underwriting Evidence

One thing we've observed in working with M&A practices that use Undwrlyft in deals with RWI is that the flagged brief doubles as underwriting documentation. A structured output showing which documents were reviewed, which clauses were extracted, which provisions were flagged as non-standard and why, and what the disposition was — that output can be provided to the carrier directly as evidence of diligence depth.

It doesn't replace the diligence memo. The memo is still necessary for the legal analysis and the conclusions. But the brief provides the coverage layer — here is every material contract, here is what the key provisions said, here is what was non-standard — that the carrier needs to evaluate the completeness of the review. That documentation didn't used to exist in a form the carrier could evaluate. It increasingly needs to.