Rodan · Resources · PE

PE Data Room Checklist

Data and technology prep for exit clocks and 100-day plans. Start 12–18 months before exit, not 12 weeks.

What is inside

  • Systems register and source-of-truth requirements
  • Metric dictionary and EBITDA / adjustment lineage
  • Privacy pack: DPAs, Article 30, breach history
  • Access control: named users, MFA, leavers
  • Key-person map, vendor posture and reporting latency evidence

Email unlocks the full printable checklist. Free to access, we just ask for an email.

How to use

  • Mark each item Done / In progress / Gap. Attach an owner and a date.
  • Put working files in a controlled folder now. Promote to the formal data room when the process opens.
  • CFO owns the portco checklist. IT supplies evidence, not ownership.

1. Systems register

  • Inventory of applications holding material operational or financial data
  • Include shadow systems: analyst master spreadsheets, shared drives, WhatsApp groups used for decisions
  • Business owner, vendor / hosting location, criticality, personal data flag for each row
  • Register reviewed in the last six months, with a named custodian

2. Source of truth and metric dictionary

  • Board metrics map to a single authoritative system each
  • Written definitions for revenue, margin, cash, cohort / recurring metrics as used in IC papers
  • Lineage documented: source system → transform → report
  • Known conflicts between systems listed with a resolution owner

3. EBITDA and adjustment lineage

  • Adjustment schedule reproducible by a third party from source extracts
  • Each material add-back has evidence, owner and recurrence note
  • Bridge from management EBITDA to statutory / locked books is documented
  • One-off vs run-rate treatment is explicit

4. Privacy and processors

  • DPAs signed with every processor that touches personal data
  • Article 30 record of processing exists and matches the systems register
  • Cross-border transfers logged with a valid transfer mechanism
  • Lawful basis recorded per material processing purpose
  • Breach history for the last 24 months disclosed (or clean attestation dated)
  • Data subject request process can meet 30-day timing with evidence

5. Access control and MFA

  • Named users on critical systems (no shared admin logins)
  • MFA enforced on finance, CRM, warehouse, identity and production admin paths
  • Leavers process removes access within a defined SLA
  • Privileged access list reviewed quarterly

6. Key-person and operating resilience

  • Map of who alone can run reporting, integrations or critical systems
  • Documented handover for month-end and board pack
  • Backup and restore evidence for systems that would stop trading or reporting in 48 hours
  • Incident contacts and escalation path written down

7. Vendor, licence and security hygiene

  • Material SaaS contracts and renewal dates listed
  • Open-source copyleft exposure noted where relevant to product
  • Secrets handling and recent security findings summarised
  • Insurance / cyber cover note available if required by process

8. Reporting latency evidence

  • Measured time from period close to usable board pack (last three cycles)
  • List of manual bridges that slow the pack
  • Plan items that would cut latency without rewriting the whole stack

Timing guide

  • T−18 to T−12 months: register, dictionary, DPA / Article 30 hygiene
  • T−12 to T−6 months: MFA, key-person, EBITDA lineage, restore tests
  • T−6 to T−3 months: pack rehearsal for buyer Q&A, close open gaps
  • Process open: freeze definitions, version the room, track Q&A separately