A due diligence review of a Bangalore SaaS company checks different things than one on a Delhi manufacturer. Source code ownership instead of factory registers. ESOP grants instead of fixed deposits. A data-protection trail that barely existed as a category five years ago. Sapient Services runs due diligence services in Bangalore for acquirers, investors, banks, and NBFCs evaluating SaaS companies, IT services firms, GCCs, and life-sciences startups headquartered in the city. Financial, legal, tax, technical, and operational review run as one coordinated engagement, handled by a multidisciplinary team of Chartered Accountants and IBBI-registered valuers rather than five separate hand-offs.
Bengaluru’s business base leans heavily on software, biotech, and GCC operations. That changes what a diligence team checks first. When the asset under review is a codebase, a customer contract, or a cap table rather than a factory floor, a report built around inventory counts and land titles misses most of what actually matters.
For technology companies specifically, a few questions come up repeatedly. Does the company actually own the code its engineers wrote, or did an early contractor retain rights? Is the ESOP pool documented properly, or does the cap table exist mostly on paper? These aren’t edge cases for a SaaS or IT services target — they’re close to the default checklist.
Historical revenue, cash flow, working capital, and — for subscription businesses — recurring versus one-time revenue, net revenue retention, and customer concentration. A SaaS company needs a different financial lens than a manufacturer; applying the same checklist to both understates real risk.
Corporate structure, contracts, litigation history, and IP ownership. For technology companies, this includes checking whether IP created by contract developers was formally assigned to the company — a gap worth reviewing as its own line item rather than folding it into a general contracts check.
GST compliance, past assessments, transfer-pricing exposure for group entities, and pending litigation, reviewed against the company’s filings. Tax periods after 1 April 2026 fall under the Income-tax Act, 2025 rather than the 1961 Act it replaced — the section numbering has changed in places relevant to transaction work, so a report citing the old section numbers for a post-2026 period is citing the wrong law. Earlier tax years and pending proceedings continue under the 1961 Act’s transitional provisions.
Market position, customer concentration, and competitive dynamics tested against the specific market the business competes in, not a national average. For an early-stage SaaS company, this usually matters more than the financial review, since most of the company’s value sits in growth assumptions rather than historical earnings.
Code quality, architecture, scalability, infrastructure, and how dependent the company is on any single engineer. This sits separately from IP ownership review — a technical reviewer can tell you whether the architecture will scale; whether the company legally owns what it built is a legal question, checked separately.
ESOP documentation, key-employee retention risk, and vendor contracts. For GCCs, this extends to whatever state-level incentives, registrations, or contractual conditions apply to that specific operation.
The Digital Personal Data Protection Rules, 2025 were notified in November 2025 with a staggered commencement — different provisions take effect at different stages through 2027. A diligence review checks a target’s current data-handling practices and its readiness for the provisions that apply later, rather than treating the Act as either fully binding today or irrelevant until some future date.
For M&A specifically: a deal above ₹2,000 crore can trigger CCI notification requirements where the target has substantial business operations in India, even if standard turnover or asset thresholds aren’t met. Worth checking early rather than at signing.
A single-entity financial review with clean records can close in around three weeks. A multi-workstream engagement with scattered documentation runs longer, sometimes past eight weeks. Those are directional, not a quote; actual scope needs a conversation.
| Factor | How It Affects Cost |
| Scope (single vs multi-workstream) | A financial-only review costs less than a combined financial, legal, and technical engagement |
| Entity count | Group structures and subsidiaries add document volume and review time |
| Data-room readiness | An organised data room shortens the timeline; missing documentation adds follow-up rounds |
| Specialist input needed | SaaS/IP-heavy and life-sciences reviews often need technical or sector specialists beyond standard financial and legal checks |
We give a written, scope-specific quote after an initial call rather than a fixed online price. Two engagements both labelled “financial due diligence” can differ substantially in actual scope.
| Mistake | Better Approach |
| Reviewing a SaaS company’s finances the same way as a manufacturer’s | Weight retention metrics — recurring revenue, NRR, churn — over raw topline numbers |
| Skipping IP-assignment checks for early-stage companies | Verify whether contract developers signed work-for-hire agreements assigning IP to the company |
| Leaving ESOP documentation until late in the process | Review the cap table and option grants early — gaps here can delay signing, not just diligence |
| Treating DPDP compliance as either fully binding or irrelevant | Assess readiness against the actual staggered commencement dates |
| Using one generalist reviewer for a multidisciplinary risk | Run financial, legal, and technical review together — these risks tend to compound, not sit in isolation |
A: Financial, legal, and tax review at minimum, with commercial, technical, and operational review added depending on the target and transaction. Scope depends on what the buyer or investor needs verified.
A: Scope-dependent. A focused, single-discipline review with clean records can close in a few weeks. A multi-workstream engagement with several entities or scattered documentation takes longer.
A: Driven by scope, entity count, and data-room readiness rather than a fixed rate. We quote after a scoping call.
A: Yes. The DPDP Rules, 2025 commence in stages through 2027, so we check current data-handling practices and readiness for provisions that apply later, rather than assuming either full compliance or no obligation yet.
A: Findings are reported as they surface, risk-rated, and tied to what they mean for the deal — price, structure, an indemnity, or further investigation.
A: Yes. We review the Indian entity’s financial, operational, and compliance position — FEMA and FDI considerations included — working alongside the client’s own international counsel rather than duplicating their scope.
A: Financial statements and GST filings, cap table and ESOP documentation, IP assignment agreements, material contracts, litigation records, and — for tech companies — code repository access and architecture documentation.
A: An audit gives assurance on historical financial statements. Due diligence investigates the facts and risks specific to a transaction and is scoped around the deal, not a fixed annual requirement.
A due diligence review doesn’t certify that a deal is safe. It identifies findings and what they mean for the transaction — a price adjustment, a changed structure, a condition, or a case for walking away. For Bangalore transactions, that usually means IP ownership, ESOP documentation, and data-protection readiness sitting alongside the standard financial and legal review.
Sapient Services Pvt. Ltd. runs due diligence engagements in Bangalore for investors, acquirers, and founders. Call +91 9540162888 or email valuation@sapientservices.com to scope a review.
Please take a moment to fill out the form.
