PE Data Room Checklist
Rodan · Exit and hold-period prep · guides.rodan.io
Rodan · Resources · PE
PE Data Room Checklist
Data and technology prep for exit clocks and 100-day plans. Start 12–18 months before exit, not 12 weeks.
How to use
- Mark each item Done / In progress / Gap. Attach an owner and a date.
- Put working files in a controlled folder now. Promote to the formal data room when the process opens.
- CFO owns the portco checklist. IT supplies evidence, not ownership.
1. Systems register
- Inventory of applications holding material operational or financial data
- Include shadow systems: analyst master spreadsheets, shared drives, WhatsApp groups used for decisions
- Business owner, vendor / hosting location, criticality, personal data flag for each row
- Register reviewed in the last six months, with a named custodian
2. Source of truth and metric dictionary
- Board metrics map to a single authoritative system each
- Written definitions for revenue, margin, cash, cohort / recurring metrics as used in IC papers
- Lineage documented: source system → transform → report
- Known conflicts between systems listed with a resolution owner
3. EBITDA and adjustment lineage
- Adjustment schedule reproducible by a third party from source extracts
- Each material add-back has evidence, owner and recurrence note
- Bridge from management EBITDA to statutory / locked books is documented
- One-off vs run-rate treatment is explicit
4. Privacy and processors
- DPAs signed with every processor that touches personal data
- Article 30 record of processing exists and matches the systems register
- Cross-border transfers logged with a valid transfer mechanism
- Lawful basis recorded per material processing purpose
- Breach history for the last 24 months disclosed (or clean attestation dated)
- Data subject request process can meet 30-day timing with evidence
5. Access control and MFA
- Named users on critical systems (no shared admin logins)
- MFA enforced on finance, CRM, warehouse, identity and production admin paths
- Leavers process removes access within a defined SLA
- Privileged access list reviewed quarterly
6. Key-person and operating resilience
- Map of who alone can run reporting, integrations or critical systems
- Documented handover for month-end and board pack
- Backup and restore evidence for systems that would stop trading or reporting in 48 hours
- Incident contacts and escalation path written down
7. Vendor, licence and security hygiene
- Material SaaS contracts and renewal dates listed
- Open-source copyleft exposure noted where relevant to product
- Secrets handling and recent security findings summarised
- Insurance / cyber cover note available if required by process
8. Reporting latency evidence
- Measured time from period close to usable board pack (last three cycles)
- List of manual bridges that slow the pack
- Plan items that would cut latency without rewriting the whole stack
Timing guide
- T−18 to T−12 months: register, dictionary, DPA / Article 30 hygiene
- T−12 to T−6 months: MFA, key-person, EBITDA lineage, restore tests
- T−6 to T−3 months: pack rehearsal for buyer Q&A, close open gaps
- Process open: freeze definitions, version the room, track Q&A separately

