business resources
How M&A Due Diligence Uncovers Compliance Problems No One Knew They Had
17 Sept 2026

Acquiring a company means acquiring its problems along with its assets, and some of the most expensive problems don't show up on a balance sheet at all. Regulatory compliance gaps, particularly around international trade rules, tend to surface during due diligence precisely because nobody was looking for them before the acquisition made someone look closely. That gap between what shows up in a spreadsheet and what actually creates legal risk is exactly why specialized diligence exists as its own workstream separate from the financial review.
Due Diligence Turns Up More Than Financials
A thorough acquisition review goes well past revenue and liabilities into how a target company actually operates day to day, including who it sells to, where its products ship, and what licenses or certifications its business actually requires. On a deal of this size, the coordination across several specialties at once typically falls to an m&a attorney denver companies work with, since financial diligence alone won't catch a regulatory issue buried in a shipping manifest or a customer list.
Buyers sometimes assume a clean set of financial statements means a clean acquisition, but export compliance gaps rarely show up in an income statement. They surface instead through questions a specialized reviewer knows to ask, like whether a company has ever shipped a product overseas without checking whether that product required an export license first.
Sanctions screening is part of that broader review too, and it catches a different kind of problem than export licensing does. A company doing business with an entity on a restricted party list, even unknowingly, creates exposure that has nothing to do with what product was sold and everything to do with who the buyer turned out to be. Screening customer and vendor lists against current sanctions lists is a standard part of thorough diligence for exactly this reason.
Deemed exports add a layer many companies overlook entirely. Sharing controlled technical information with a foreign national employee, even inside the company's own facility in the United States, can count as an export under certain regulations, which means a target company's workforce composition sometimes matters as much as its shipping records during diligence.
Export Control Violations Aren't Always Obvious
Here's the thing though: a lot of export control violations happen without any intent to break a rule at all. A company selling a piece of equipment or software with a dual civilian and military use can trigger licensing requirements it never realized applied, particularly if the buyer is located in a country subject to trade restrictions. On acquisitions, export control lawyers get brought in specifically because these rules apply based on the product's classification and destination, not based on whether anyone at the company understood the requirement existed.
The classification process itself trips up a lot of companies. A product might seem purely commercial on its face but still fall under export control jurisdiction because of a specific component or the software embedded inside it, and getting that classification wrong before a violation is discovered is a very different situation than getting it wrong after.
Reexport rules complicate the picture further for companies operating internationally. A product legally exported to one country can still trigger a separate violation if that country's buyer then reexports it to a restricted destination, and the original exporting company can bear responsibility for that downstream transfer under certain circumstances, even without direct involvement in the second transaction.
Not every export violation falls under the same set of rules either. Military and defense-related items generally fall under one regulatory framework, while most commercial and dual-use items fall under a separate one, and each framework carries its own licensing process and enforcement agency. Misidentifying which framework applies to a given product is itself a common source of violations, independent of whether a license was ever actually needed.
Historical Violations Don't Expire on Their Own
A violation that happened years before an acquisition doesn't disappear just because nobody caught it at the time. Regulatory agencies can pursue enforcement well after the fact, and an acquiring company that takes on a target's operations can inherit exposure for violations that occurred entirely before the deal closed, depending on how the transaction is structured. This can include obligations related to workplace safety standards, where past compliance failures may continue to create regulatory exposure. The lookback period for enforcement varies depending on the specific regulation involved, but several years isn't unusual, which means an acquisition can inherit liability tied to conduct well before the deal was ever contemplated. Successor liability rules vary by jurisdiction and by how the acquisition is structured; an asset purchase generally limits inherited liability more than a stock purchase or merger does, though export control agencies don't always apply successor liability the same way commercial creditors would. Getting the classification right the first time, before a product ships rather than after a violation is flagged, remains the most effective way to avoid this category of problem altogether.
Voluntary Disclosure Isn't Automatic, But It's Often the Right Move
Once a violation surfaces during diligence, the decision about what to do next carries real consequences either way. Disclosing a violation to the relevant agency before it's discovered independently generally results in a more favorable outcome than waiting for an investigation to find it, though disclosure isn't without its own risks and isn't the right call in every situation. Weighing this decision typically falls to a voluntary disclosure lawyer, who looks at the severity of the violation and what steps the company has already taken to fix the underlying problem before recommending which direction actually makes sense.
Penalties for export violations can be substantial on their own, calculated per violation rather than per shipment in some cases, which means a pattern of repeated violations over time can compound quickly even if any single instance seems minor in isolation.
Agencies reviewing a voluntary disclosure generally consider whether the violation was self-identified promptly and what compliance improvements followed once it was found. A disclosure paired with genuine remediation tends to land very differently than one that reads as a formality.
Timing factors into this decision heavily. A disclosure made proactively, before an agency has any reason to suspect a problem, generally carries more weight than one made after an investigation has already started, even if the underlying facts are identical in both cases.
These findings also shape how a deal actually gets negotiated once they surface. A known compliance gap can lead to a lower purchase price, an escrow holdback tied specifically to that risk, or an indemnification provision that shifts responsibility back to the seller if the issue turns into an actual penalty down the road.
Insurance can play a role here too, in the form of representation and warranty insurance that shifts some post-closing risk away from direct negotiation between the parties. That option doesn't eliminate the need for thorough diligence, but it can change how aggressively a buyer needs to negotiate specific indemnification terms once a compliance issue has already been identified and priced into the deal.
Buyers who build this kind of review into the deal timeline from the start, rather than treating it as an afterthought once financial diligence wraps up, tend to negotiate from a position of far more certainty about what they're actually acquiring.
None of this means every acquisition uncovers a compliance problem, but the ones that do tend to reward the buyers who built enough time and expertise into the diligence process to actually find the issue before closing rather than after. A thorough focus on regulation and compliance can help identify potential risks early. A problem discovered during diligence is a negotiating point; the same problem discovered afterward is just a liability.






