Resources Guide

How to set up a data room for due diligence

A practical guide to structuring, permissioning, and running a due-diligence data room for M&A or fundraising — and the mistakes that slow deals down.

A data room is where a deal gets real. The moment a buyer, investor, or auditor starts asking for documents, the way you share them starts shaping the process: a well-structured room keeps momentum and signals competence; a chaotic one generates duplicate requests, version confusion, and doubt.

This guide covers the mechanics that matter — structure, permissions, gating, Q&A, and analytics — whether you're selling a company, raising a round, or standing up diligence infrastructure for clients.

Start with the index, not the files

Resist the urge to upload first and organize later. Build the folder structure before anything goes in, because the structure is the buyer's map of your business. A typical top-level index:

  1. Corporate & governance — formation documents, cap table, board minutes, shareholder agreements
  2. Financials & tax — statements, management accounts, budgets, tax filings
  3. Legal & contracts — material agreements, licenses, litigation, insurance
  4. Intellectual property — patents, trademarks, assignments, open-source posture
  5. HR & organization — org chart, key employment agreements, equity plans
  6. Commercial — customer contracts, pipeline, pricing, key metrics
  7. Compliance & regulatory — certifications, audits, data-protection posture
  8. Assets & facilities — property, equipment, leases

If you've received a request list from the counterparty, mirror it — reviewers find documents where they expect them, and you can track completion against the list folder by folder.

Set permissions before inviting anyone

Permissions are easiest to get right when the room is empty and hardest to fix after the wrong person has seen the wrong file. Three practices cover most situations:

  • Permission per group, per folder. Give each bidder or investor group its own track. Advisors see their scope, not the whole room.
  • Stage disclosure. Not everything belongs in the room on day one. Commercially sensitive material — customer names, pricing detail, key-person terms — can sit in restricted folders that open to finalists only.
  • Default to view-only with watermarks for anything you wouldn't want forwarded. Dynamic watermarking ties every viewed page to the viewer, which changes forwarding behavior all by itself.

Gate the door

Every reviewer should pass through an NDA and identity verification before seeing a single document. Doing this inside the room — NDA gating on entry, verified onboarding per user — beats chasing signatures over email and leaves a record of exactly who agreed to what, when.

Keep Q&A inside the room

Diligence questions asked over email fork into parallel threads, lose their context, and get answered twice with different answers. Scoped Q&A — where each question attaches to the document or folder it's about — keeps one channel, one answer, and a record of both. It also lets you route questions to the right owner internally without exposing your org chart to the counterparty.

Read the analytics

Reviewer activity is negotiating intelligence. Engagement analytics and heat maps show which bidders are deep in the financials versus skimming, which documents keep getting re-read (often a signal a follow-up question is coming), and who has gone quiet. Sell-side teams use this to gauge seriousness before management calls and to prepare for the questions the reading pattern predicts.

Common mistakes

  • Uploading unstructured piles. A dump of files with cryptic names reads as disorganization — the exact impression diligence exists to test.
  • Over-sharing early. Full disclosure to every early-stage tire-kicker maximizes leak surface for no process benefit.
  • Running diligence on a general-purpose drive. Consumer and collaboration tools lack the gating, per-reviewer watermarking, and audit evidence diligence needs — see our comparison of data rooms and file-sharing tools.
  • Letting the room die at closing. Earn-outs, staged closings, and post-close disputes all reach back for the record. Use a room with no forced expiration so the history survives the deal.
  • No single owner. One person should own index completeness, permission changes, and Q&A routing. Committees leak and stall.
Checklist: index built before upload · permissions per group and folder · staged disclosure for sensitive material · NDA gating and verified onboarding · watermarked view-only for anything forwardable · Q&A scoped to documents · analytics reviewed weekly · one named owner · room retained post-close.

Frequently asked questions

What is a data room?

A data room (or virtual data room) is a controlled online workspace where a company shares confidential documents with outside parties during due diligence — typically for M&A, fundraising, or audits. Unlike a shared drive, access is gated, permissioned per user and folder, watermarked, and fully logged.

What should a due-diligence data room include?

A typical index covers corporate and governance records, financials and tax, legal and contracts, intellectual property, HR and organization, commercial information, compliance and regulatory matters, and assets and facilities — organized to mirror the buyer's or investor's request list.

When should I set up the data room?

Before you need it. Sellers and founders who assemble the room while preparing for a process surface gaps early, answer faster once diligence starts, and signal preparedness — all of which sustain deal momentum.

Contact One business day

Structure your next deal in an OVI data room

Hierarchical structures, per-folder permissions, NDA gating, scoped Q&A, and reviewer analytics — with no forced expiration.