Due diligence on an AI sales and marketing automation business
Due diligence on an AI sales and marketing automation business verifies how customer data has been used to train scoring and personalization models, whether outbound messaging defaults comply with Canada’s anti-spam law, how dependent the product is on a single foundation-model vendor, and whether every contractor who built the model actually assigned its IP.
By the time a buyer is under a signed letter of intent on a martech platform, the financial statements have usually already told a reasonable story. What diligence in this sub-sector is really testing is whether the AI capability behind that story is what it was represented to be, and whether the customer data feeding it has been handled in a way that does not become the buyer’s liability the day the deal closes.
The document list specific to this sub-sector
- Data-processing agreements and any consent language covering how prospect and customer data may be used, including for model training
- Signed IP assignments from every contractor, freelancer or agency who built or contributed to the scoring, sequencing or personalization models
- A history of anti-spam complaints, platform-policy actions or deliverability penalties tied to the sending infrastructure
- CRM and marketing-platform integration and partner agreements, and whether they survive a change of ownership
- The contract with the underlying foundation-model provider, including pricing terms and assignability on a sale
What a CASL complaint in the file actually means
Canada’s Anti-Spam Legislation applies to commercial electronic messages regardless of whether AI generated them, and a documented history of complaints or enforcement attention is not automatically disqualifying — but it is a signal worth taking seriously, because it usually reflects something about the product’s default messaging behaviour, not just one customer’s misuse of it. Ask specifically whether the issue traces back to a default the platform ships with, since a default problem affects every customer using the tool, not just the one who triggered a complaint.
Testing the cross-customer data claim
Ask the technical team to walk through, concretely, whether and how one customer’s prospect data ever contributes to outcomes for another customer’s model — a general assurance that “data is kept separate” is not the same as a documented architecture that actually enforces it. Where cross-customer signal genuinely does improve outcomes across the platform, confirm whether that use was disclosed to and consented to by customers, since undisclosed use here is one of the more serious findings a buyer can uncover in this category.
Foundation-model dependency: what to ask for
Request the actual contract with the foundation-model provider, not a summary of it, and review pricing terms, rate limits, and what happens if the provider changes its terms of service or discontinues the specific model the product relies on. A business built entirely around one model version from one provider, with no tested fallback, carries a concentration risk that a buyer should price into the deal rather than discover after closing when a provider changes course.
Deliverability and sending-infrastructure checks
Review bounce rates, spam-complaint rates and domain reputation history for the sending infrastructure the platform uses on behalf of its customers, since this asset is both real value and a real risk depending on its condition. A platform with a clean, well-documented sending history is handing over something durable; one with an undocumented or troubled history may be handing over a liability dressed up as an asset.
IP assignment gaps: the single most common finding
The most frequent gap uncovered in this sub-sector is a missing or informal IP assignment from an early contractor who built part of the scoring engine before the company thought to formalize the relationship. This does not always kill a deal, but it needs to be identified and, where possible, resolved before closing rather than left as an open question a buyer inherits along with the code.
What the trademark and domain registrations actually show
It is common in an earlier-stage martech business for the trademark the product is marketed under, or the domain it runs on, to have been registered by a founder personally rather than by the company — often simply because the brand existed before the company was incorporated and nobody circled back to fix it. Confirm who is the actual registrant of record for both, and where either sits outside the company, treat getting it formally assigned as a condition of closing rather than a detail to chase afterward, since a buyer who discovers post-closing that the seller does not control the name the business trades under has a real problem, not a paperwork inconvenience.
Registry searches worth running before you sign
Beyond the document list above, run a personal property registry search — the PPSA registry in most provinces — against the corporation to check whether a lender or another creditor holds a registered security interest that could reach the scoring models, source code or other intangible assets, not only whatever physical equipment the business happens to have. Pair that with a standard corporate good-standing search and a check for outstanding tax debts attached to the entity, since any of the three turning up unexpectedly after closing shifts from being the seller’s problem to being the buyer’s.
Financial diligence alongside the technical review
None of the checks above replace ordinary financial diligence — normalized financial statements over several years, reconciled to actual bank and payment-processor records, with revenue broken down between recurring subscription revenue and one-time implementation or services fees. Confirm what has been added back to reported profit and whether each add-back would genuinely not recur under new ownership, and specifically check whether inference cost has been presented as a fixed line item when it actually scales with lead or message volume, since that recharacterization can materially change what the business’s true margin looks like at higher scale.
Customer contract terms diligence teams often skip
A customer list with logos and revenue figures tells a buyer far less than the actual contracts behind it, so pull a sample of the real customer agreements rather than accepting a summary. Look specifically for termination-for-convenience clauses that let a customer exit with minimal notice, auto-renewal terms that may not be as durable as they first appear once a customer actually wants out, and change-of-control provisions that give a customer the right to renegotiate or terminate the moment ownership of the business changes hands. A concentration of major customers holding a change-of-control termination right is a real risk to the revenue a buyer is paying for, and it is common enough in software agreements that it needs to be checked contract by contract, not assumed away because the relationship looks stable today.
Sources
Every requirement and figure referenced in this guide traces to a primary source. Links were last confirmed on the dates shown.
- 01Treadstone LawLegal commentaryCybersecurity and Data Privacy Due Diligence When Buying a Business in Ontario
- 02Treadstone LawLegal commentaryHow Long Does Due Diligence Take When Buying a Business in Ontario?
- 03Office of the Privacy Commissioner of CanadaGovernmentThe Personal Information Protection and Electronic Documents Act (PIPEDA)
- 04Canadian Radio-television and Telecommunications CommissionGovernmentSpam and malware
- 05Treadstone AssociatesAdvisoryAI-Assisted Due Diligence
Deavo is an advertising and listings platform, not a brokerage, law firm or valuation firm. This page is general information, not legal, tax, accounting or valuation advice, and rules differ by province. Confirm anything you rely on with a qualified professional before you act on it.