When we passed the threshold of 100 diligence packages processed through Undwrlyft, Sofia sat down with the output data and asked a simple question: what did we actually learn about where the risk hides in M&A documents? Not from first principles, not from theory — from the 100 actual rooms.
The answer was more consistent than expected, and more useful. The patterns that emerge when you have the full document set visible at once are not the patterns that due diligence checklists are built around. They're the things that fall through the gaps between categories.
This is what we observed — with the caveat that these are patterns from a set of mid-market deals processed through our system, not a statistical study. The patterns are real and consistent enough to be worth sharing.
The Critical Clause Is Almost Never in the Document You'd Expect
The single most consistent pattern across 100 rooms: the provision that creates the most deal-closing risk is not in the transaction document. It's in a contract that's three directories deep in the data room.
In M&A deals, the asset purchase agreement or merger agreement contains carefully negotiated representations and warranties. Those representations are what the deal is built on. But a representation that the target has no material change-of-control provisions in its customer contracts is only as good as the diligence that verified it. And the diligence on that representation typically reviews the top 10 customer contracts by revenue, not all 35.
In 14 of the 100 rooms, we identified a non-standard change-of-control trigger in a customer or supplier contract outside the top-10 set. In six of those, the contract was with a counterparty that represented less than 5% of revenue — not material by the threshold used to scope the review. In four of those, the provision had characteristics that would give the counterparty a right to terminate or impose conditions on assignment that the acquirer had not factored into the deal terms.
None of the four were caught by the diligence team's initial review. All four were in the data room, disclosed, technically within the representation. None of them broke a deal in our set — but each of them was information that should have changed the risk assessment or the deal structure, and none of them did.
IP Assignment Gaps in Vendor Agreements, Not Just Employment Agreements
The standard IP assignment diligence protocol for a software company acquisition focuses on employee and contractor assignment agreements. Has every developer assigned their work to the company? Do the assignments use present-tense language rather than a covenant to assign? Are there founder assignment gaps from the pre-incorporation period?
What we found: the IP assignment gap is as common in vendor agreements as in employment agreements, and it's less well-understood. A vendor agreement that licenses software to the target company but contains an "IP developed on customer data" provision — where the vendor retains rights to insights, models, or derivative works developed using the customer's data — creates an ownership ambiguity in the target's product that the standard IP diligence protocol misses entirely.
In roughly 20 of the 100 rooms, at least one vendor agreement contained a data-derived IP provision with implications for the target's product ownership. In most cases, the provision was standard SaaS vendor language and wouldn't survive a challenge. But "wouldn't survive a challenge" is not the same as "doesn't exist," and a rep-and-warranty policy underwriter asking about IP ownership clarity will note the ambiguity.
The Indemnification Cap Is Negotiated. The Carve-Outs Are Not.
In deal negotiations, the indemnification cap gets significant attention. Buyers want 100% of purchase price; sellers push for one times the escrow. The range where deals land in mid-market is well-documented. Both sides' deal counsel track the market.
The carve-outs to the cap — the exceptions to the aggregate cap for certain categories of claims — get less careful attention in first-pass review because they're assumed to follow the negotiated standard: carve-outs for fraud, for fundamental representations, for tax representations. That's the market standard, and it's usually what appears in the first draft.
But across 100 rooms, we found 23 instances where the indemnification cap carve-out structure deviated meaningfully from that standard. The deviations were not all in the same direction: some were seller-favorable (narrowing the carve-outs beyond market), some were buyer-favorable (expanding carve-outs to include IP representations at full purchase price), and some were ambiguous (carve-out language that was unclear about whether a specific rep was covered). In all 23 cases, the deviation was in the detailed drafting of the carve-out section, not in the headline cap figure.
The headline cap is what gets negotiated at the term sheet stage. The carve-out structure is what gets drafted in the agreement, under timeline pressure, by associates who know the standard but may not be reading the specific language carefully enough.
Termination Rights Have More Asymmetry Than Anyone Thinks
Employment agreements, key supplier agreements, and large customer agreements all contain termination provisions. In diligence, the standard review covers termination-for-cause criteria, notice periods, and severance obligations. That's the diligence protocol.
What the protocol misses: asymmetric termination rights. An agreement where the target has the right to terminate for convenience on 30 days' notice, but the counterparty can only terminate for cause or not at all, is protective. An agreement where the counterparty has a unilateral termination-for-convenience right and the target's only protection is the notice period is a different risk profile entirely.
In the rooms we've processed, the proportion of material contracts with asymmetric termination rights — where one party had materially broader termination flexibility than the other — was higher than we expected. More importantly, the asymmetry was not consistently in the target's favor. In contracts with key suppliers and platform vendors, it was frequently in the vendor's favor: the vendor could terminate on 30-60 days' notice for any reason, while the target had no corresponding right.
For a software business that depends on a data infrastructure provider or a payment processing platform, a vendor termination right that broad is a business continuity risk, not just a contract risk. It's the kind of finding that changes the risk adjustment conversation, not just the legal memo.
The Document Index Is Not a Reliable Coverage Guide
Every data room has an index. The index tells you what's in the room, at least at the folder level. It's the starting point for scoping the review and tracking coverage.
What we found: the index consistently understates coverage requirements. Across the 100 rooms, an average of 18% of the documents that were actually present in the room were not reflected in the top-level index — they were in sub-folders, uploaded as attachments to other documents, or included in bundle files without separate indexing.
This is not a deliberate omission by sellers. Data rooms populated under timeline pressure produce indexing errors. The associate uploading documents at 11pm on a Thursday does not always create a folder entry for each attachment. But the result is that a review protocol that tracks against the index has a structural gap: it doesn't know what it doesn't know is in the room.
The implication for AI-assisted review is specific: the coverage layer has to work from the actual document set, not from the index. Our flagging process ingests every document in the room regardless of index position, and the coverage report shows the full document count, not the indexed count. That 18% gap is where the non-standard IP provision, the side letter to the key customer contract, and the undisclosed amendment to the lease agreement tend to live.
What This Changes About How We Think About Diligence
The pattern across 100 rooms converges on a single observation: the risk in M&A diligence is not in the documents that are indexed and prioritized. It's in the documents that fall below the threshold for individual attention — the supplier contract that's only $200K per year, the employment agreement for a non-executive employee, the vendor DPA that nobody thought to review for IP clauses.
We're not saying that prioritization is wrong. Diligence has to be scoped, and scoping by materiality is a defensible approach. What we're saying is that "below the materiality threshold" and "not material to the deal" are not the same thing. The termination right in the $200K vendor contract may not be material in dollar terms. It may be material if the vendor provides a service the target cannot replace in 30 days.
The argument for comprehensive first-pass review — reading everything, flagging everything non-standard, then prioritizing based on the full picture rather than scoping before reading — is that the picture you need to prioritize well is only visible after you've done the read. Scoping before reading means you're deciding what matters before you know what the documents say.
That's what 100 diligence rooms taught us. The clause you need to find is rarely where the checklist says to look for it.