Due diligence is two problems wearing one name. The first is coverage: thousands of documents in the room, a deal clock measured in weeks, and a review budget that forces sampling. The second is judgment: deciding which findings actually matter to this client, on this deal, at this price. Teams have always traded one against the other, sampling the contract population so that senior lawyers have time to think about what the sample turned up.
AI changes the economics of coverage. A properly instrumented review reads every document in the room rather than a sample, and applies the same issue lens to the five hundredth supply agreement as to the first. What it does not change is judgment. No model knows the client's risk appetite, the price sensitivity, or the board dynamics behind the deal thesis. The checklist below assumes both halves: machines for coverage, the deal team for judgment, and a verification discipline connecting them.
One framing note before the phases. Treat machine output the way you treat a first-year's: useful, fast, and unverified until checked. Every step below pairs an automation with the human act that makes it reliable.
Before the data room opens
- Define the issue taxonomy for this deal. Change of control and anti-assignment provisions, exclusivity, most favored nation commitments, termination rights, IP ownership chains, data privacy exposure. Write the list down. The taxonomy is the instruction set for extraction, and a vague taxonomy produces confident answers to the wrong questions.
- Map the taxonomy to the deal thesis. A buyer paying for recurring revenue cares most about customer termination rights and pricing commitments. A buyer paying for technology cares about the IP assignment chain from every founder, employee, and contractor. The thesis decides where deep review happens.
- Set materiality thresholds with the client. Agree in writing on what does not get escalated: contract value floors, expired agreements, jurisdictions out of scope. Thresholds set early prevent both noise and the awkward late discovery that the client expected to see everything.
- Agree on the verification protocol. Who checks machine output, at what sampling rate, and what happens when a check fails. Decide this before the first document is processed, because nobody improvises verification discipline in week three of a four-week sprint.
- Calibrate on a known set. Before relying on extraction across the room, run it on a handful of agreements the team already knows well and compare the output against what a senior associate finds. Ten documents of calibration buys justified confidence, or a justified change of approach.
First pass: classification and inventory
- Classify everything on arrival. Document type, parties, effective and expiration dates, governing law, language. This pass turns a folder tree into an inventory, and it should take hours, not weeks.
- Flag completeness gaps against the disclosure schedules. Amendments referenced but never uploaded, exhibits that do not appear, the master agreement implied by a statement of work. The gap list becomes a supplemental document request the same day.
- Resolve entities across the room. The same counterparty appears under five names: the abbreviation on an invoice, the full legal name in the master, the predecessor entity in an assignment. Entity resolution turns a pile of contracts into a map of relationships, and it is graph work more than search work, the kind of structure Reframe's Context Graph exists to hold.
- Order the queue by risk, not by folder. Once classified, sequence review by materiality and thesis relevance rather than alphabetically, so the team reads the most consequential paper first and the client hears about problems in week one, not week four.
Second pass: issue extraction
- Clause-level flags with citations. Every flagged provision links to the exact passage it came from, so a reviewer confirms or dismisses it in seconds. A flag without a citation is a rumor. The mechanics are the subject of our piece on contract review inside your tenant.
- Consent and notice registers. Which contracts require counterparty consent to close, which require only notice, addressed to whom, in what form, by when. This register drives the closing workstream, so it gets built during review, not reconstructed afterward.
- Cross-document dependencies. Side letters modifying master agreements, amendment chains that reverse an earlier position, schedules that override body text. Single-document review misses these by construction; the extraction layer has to connect documents to each other.
- Aggregate exposure by issue. How many contracts carry uncapped indemnities, how much revenue sits under agreements terminable on thirty days' convenience. Counts and totals give the client scale, and every number must trace back to the list of documents behind it.
Human review tiers
Machine coverage does not flatten the review pyramid. It changes what each tier does. Junior review confirms extractions and clears routine flags against the playbook. Senior review takes the judgment calls: the ambiguous change of control trigger, the consent that might actually be withheld. Partner attention goes to red flags that touch the deal thesis, framed against the client's tolerance.
Two rules keep the pyramid honest. Every red flag is verified against the source passage before it reaches the memo; nothing goes to the client on the model's word alone. And green-rated documents get sampled: pull a random slice of what the machine cleared and re-review it by hand. The sample rate can fall as calibration improves, but it never reaches zero, because sampling is how you learn the tool's blind spots on this room's document quality rather than on a vendor's benchmark.
Specialists slot into the same structure. Tax, benefits, environmental, and regulatory reviewers should receive their slice of the room already classified and flagged, with citations, rather than a folder link and a deadline. The specialist's hour goes to assessing the exposure, not to finding it.
Output: a memo and a register that outlive the deal
The diligence memo should be grounded end to end. Every material statement carries a citation to the underlying document, so a specialist or the client can open the source without asking an associate to find it. Grounding is not decoration; it is what makes the memo auditable when a finding is challenged after signing.
Format follows the audience. The board wants the six findings that affect price or certainty. The client's deal lead wants the full issue list with owners and status. The post-closing team wants the register. One grounded dataset should produce all three views without a weekend of reformatting.
The second deliverable matters longer. Every consent, notice obligation, and post-closing covenant identified during review flows into an obligations register that survives closing and feeds post-closing tracking, which we cover in its own piece. On Reframe, the sequence runs as a governed workflow in the Harness: extraction rules, review tiers, and citation requirements configured once, enforced on every run, with an audit trail of who verified what.
What goes wrong
Garbage rooms are the norm, not the exception. Scanned faxes, sideways pages, files named final_v2_OLD, folders labeled Miscellaneous. Budget real time for OCR and triage before extraction begins, and report data quality to the client early; it is their seller to push.
Version traps are quieter. The room holds three drafts and one executed copy, and only the executed set counts. Review keyed to the wrong version produces findings that are precisely wrong. Make execution-version identification part of classification, and treat unlabeled versions as gaps to chase.
The last failure is human. When the tool has been right nineteen times in a row, the twentieth flag gets waved through. The temptation to skip verification grows exactly as fast as the tool earns trust, which is why the sampling audit lives in the protocol: discipline agreed to in writing survives deal pressure far better than discipline someone meant to keep.
Run this way, AI does not make diligence judgment-free. It makes coverage complete, verification cheap, and the deal team's hours available for the questions that move price and risk. That is the trade this checklist is designed to protect.