Let’s talk about your firm · A free 15-minute discovery call. No commitment.Prepare for my call

Fundraising and Financing5 min read

Legal due diligence: preparing your startup for an investor audit

Everything a founder should prepare for successful legal due diligence in 2026: corporate matters, contracts, IP, GDPR, employment/tax, data room, timetable and remediation.

Legal due diligence is the audit investors conduct to check your startup’s soundness and compliance before committing funds. In practice, it covers corporate matters, contracts, intellectual property (IP), employment, tax and regulatory compliance. For founders, the general pre-contractual duty to inform requires fair disclosure of decisive information (Code civil, art. 1112-1).

Practical objectives: identify and address priority risks, accelerate the process and avoid last-minute renegotiations. Market best practice is widely documented, notably by France Invest and practical industry guides (definition and procedure).

What investors check first

1) Corporate matters and governance

  • Legal existence and history: Kbis, up-to-date articles, payment of capital, registers (share movements, decisions), beneficial owners (RBE) — see Service Public Pro — register of beneficial owners.
  • Cap table and instruments: previous round(s), BSPCE, BSA, convertible bonds, preference/liquidation rights. To anticipate discussions, revisit key points on liquidation preferences.
  • Governance documents: shareholders’ agreement, delegations of authority, regulated related-party agreements and intra-group agreements.

2) Contracts and revenue

  • Key customers/suppliers: term, renewal, exit clauses, SLAs, penalties, assignments/assignability, change of control and compliance of terms of sale.
  • Distribution/partnerships: exclusivity, territories, quotas, commission rebates; anti-corruption policy (Sapin 2 Act).
  • Evidence of recurring revenue: order schedules, BAFOs, credit notes; consistency of invoicing/VAT.

3) Intellectual property and technology

  • Chain of title: assignments by founders and contractors, employee invention clauses.
  • Protected assets: trademark/design/patent filings, monitoring and oppositions — guides and procedures from INPI.
  • Code and licences: evidence of originality, open-source policies and control of critical dependencies. To structure initial contributions, see assignment of intellectual property by founders.

4) Employment, GDPR and compliance

  • Employment relations: standard contracts, variable pay, remote work, contractors/freelancers and reclassification risk; mandatory registers; elections/representative bodies.
  • Data protection: record of processing activities, legal basis, DPIAs, SCCs, DPO — reference framework and guides from CNIL.
  • Anti-corruption and ethics: risk mapping, whistleblowing procedures, gifts and conflicts of interest (Sapin 2 Act).
  • Duty of vigilance: applies to large groups (Act no. 2017-399, Legifrance), but investors often request a proportionate value-chain assessment.

5) ESG and reporting

  • CSRD: non-financial reporting requirements for companies in scope (Directive (EU) 2022/2464 — EUR-Lex).
  • CS3D: forthcoming European directive on sustainability due diligence, with the framework being finalised (EUR-Lex).

Beyond legal matters, investors also challenge the business model and governance. The Bpifrance framework and investor best practices help you calibrate your approach.

Building an investor-grade data room

A clear data room saves weeks and immediately reassures investors. Structure it by topic (Corporate, Contracts, IP/Tech, Employment, Tax, Compliance, Litigation) and maintain a timestamped index. For a step-by-step method, see our legal data room guide.

Minimum contents by section

  • Corporate: Kbis, articles, shareholders’ agreements, securities/decision registers, RBE, cap table and delegations.
  • Contracts: top 20 customers/suppliers, signed templates, NDAs, partners/distribution.
  • IP/Tech: founder/contractor assignments, INPI filings, software inventory and open-source policy.
  • Employment: employee/contract list, variable pay and BSPCE, remote-work agreements/policy, contractors.
  • Tax/Accounting: tax returns, VAT, tax credits (CIR/CII), ongoing disputes/inspections.
  • Compliance: GDPR (records, DPIAs, DPAs), anti-corruption (mapping, code, reporting), KYC/KYB.
  • Litigation: threats/claims, settlements, decisions — verifiable through advisers and, if needed, useful information available on Justice.fr.

Good practice: standardised naming, frozen versions, signed documents, proof of enforceability (acceptance emails, acknowledgements of receipt) and a Q&A log.

Operational due diligence checklist (startup SAS)

  • Corporate: incorporation and capital-increase minutes, full payment of capital, RBE, regulated related-party agreements, funding-round history and confirmations of no pledges/security interests.
  • Cap table & instruments: complete table (shares, BSPCE, BSA, convertible bonds), board consents, grant plans, exercise prices, vesting/acceleration and standard terms to include in the term sheet.
  • Contracts: commitment thresholds, change of control, exclusivity, non-solicitation/non-compete clauses and audit of terms of sale.
  • IP: signed and dated assignments, evidence of creation (filings, timestamps), INPI oppositions and third-party licences.
  • Tech: security policy, secrets/access management, disaster recovery/business continuity plans and open-source compliance (SBOM inventory).
  • Employment: pre-employment declarations (DPAE), single personnel register, working time, variable pay, independent contractors (framework agreements and indicators of dependence), employment tribunal disputes.
  • GDPR: record, DPIAs, DPAs/processing arrangements, transfers outside the EU (SCCs), breach procedure (CNIL obligations and practical guides on cnil.fr).
  • Tax: returns for 3 financial years, VAT/OSS, transfer pricing for groups, CIR/CII, inspections or adjustments.
  • Litigation: exhaustive list, provisions, prospects of success; representations and lawyers’ letters.

Managing common red flags and fixing them quickly

  • IP not assigned by a founder or contractor: immediately obtain signed assignments and amendments; consolidate evidence of priority (filings, timestamps) — procedural resources from INPI.
  • Inaccurate cap table: reconcile the share movement register, minutes and capitalisation table; prepare a securities compliance certificate.
  • Freelancers resembling employees: review the working arrangements and secure them through framework agreements, or regularise employment; guides to employer obligations on Service Public Pro.
  • GDPR gaps: update records, DPAs and notices; for risky processing, conduct a DPIA; refer to guides from CNIL.
  • Sensitive customer clauses: renegotiate liability caps, punitive SLAs, change of control and excessive exclusivity before signing the round.

Process and timetable: from term sheet to closing

  1. Pre-term sheet: data room 80% ready, risk mapping and remediation plan.
  2. Term-sheet signing: audit scope and timetable; alignment on financial clauses (liquidation preference, anti-dilution). To prepare, revisit our term-sheet analysis and the effects of liquidation preferences.
  3. Audit and Q&A: 2–6 weeks depending on readiness; respond quickly, document everything and respect the duty of fair disclosure (art. 1112-1 C. civ.).
  4. Remediation and conditions precedent: finalise IP assignments, customer amendments and GDPR corrections.
  5. Signing/Closing: corporate approvals, RCS filing, RBE update and legal notices. For an overview, see the legal steps in a seed round.

Expectations differ depending on the round type (shares, BSA-AIR/convertible bonds); AMF mainly regulates public offers, but its publications help structure clear financial information (amf-france.org).

Tools and AI to accelerate the audit

  • Clause extraction and anomaly detection in contracts (SLAs, liability, change of control).
  • Version comparisons and traceability of commitments.
  • Building an SBOM and auditing open-source licences.
  • Centralised progress dashboards and Q&A.

These tools do not remove the need for qualified human review. They complement the method but replace neither judgement nor strategy.

Useful industry resources

To structure your approach: the due diligence framework from France Invest, practical guidance from Bpifrance and operational guides (e.g. complete guide).

Prepare early, document everything and fix issues quickly: this is the best way to ensure a smooth audit and calm negotiations.

For more on the stages of a round, also see our guide to fundraising steps and our article on preparing the data room.

Further reading

Related resources

Frequently asked questions

FAQ

What is legal due diligence in fundraising?

A comprehensive audit of corporate matters, contracts, IP, employment, tax and compliance to identify risks and validate the investment.

Which documents should go in the data room?

Kbis, articles, shareholders’ agreements, cap table, key contracts, INPI filings, IP assignments, GDPR records, employment documents, tax returns and all litigation.

Which French and European legislation should be reviewed first?

Code civil Art. 1112-1, the Sapin 2 Act, Act 2017-399, GDPR (through CNIL), CSRD and CS3D work on sustainability.

How much time should be allowed for the investor audit?

On average, 2 to 6 weeks, depending on document volume, data-room quality and required remediation.

How should unassigned IP be addressed as a red flag?

Sign dated assignments/amendments with evidence of priority and update the data room before signing.

References

Sources used

Training · Audit · Support

Put what you read into practice

Initial helps law firms define AI usage, train teams, deploy the right tools and oversee adoption.

Explore the auditBook an introductory call
← Back to all articles