Identify the legal and technical object
A transaction should begin with a precise description of what is being acquired. A domain, registered trade mark, copyright work, source-code repository, database, website and software licence each involve different records, rights and transfer mechanisms. Commercial shorthand can conceal important exclusions.
Confirm title and authority
The seller should demonstrate ownership or authority to transfer the relevant rights. Evidence may include registry records, assignment agreements, employee and contractor terms, licences, board authority, invoices, development records and chain-of-title documents. Use by a company does not prove that the company owns every underlying element.
Independent IP counsel should examine gaps, joint ownership, security interests, disputes and rights retained by creators or licensors.
Map the scope and restrictions
The buyer should understand territory, duration, exclusivity, permitted uses, sublicensing, assignment restrictions and termination rights. Trade marks may cover only specified goods or territories. Content may contain music, images or performances licensed on limited terms. Software may incorporate open-source or commercial components with continuing obligations.
Expose third-party and operational dependencies
Value may depend on cloud services, app-store accounts, APIs, hosting, contractors, key employees, social platforms, payment services or other contracts. Some cannot be assigned without consent; others may be terminable on a change of control or ownership. A technically complete copy may still be unusable without the surrounding environment and know-how.
Examine data and regulatory constraints
Databases and online products may contain personal data, confidential information or data sourced under restrictive terms. The buyer should examine how information was collected, the lawful basis for processing, privacy notices, consent where relevant, retention, security incidents and whether the proposed transfer is lawful. Sector-specific rules may also apply.
Access to a file, repository, account or dataset does not by itself establish the right to copy, commercialise, modify, assign or exclude others from using it.
Test security, provenance and quality
Technical diligence may cover access controls, credentials, code quality, vulnerabilities, malicious material, development history, backups, documentation and dependency maintenance. For content or AI-related assets, provenance and the rights used to create or train material may be commercially important.
Verify income, usage and valuation claims
Revenue, traffic, licence income, user numbers and cost savings should be supported by evidence and separated from the seller's wider business. The buyer should test whether the claimed benefit will continue after transfer and what additional investment or consents are required.
Plan assignment and technical transfer
The sale agreement should define the assets, rights, exclusions, price, taxes, warranties, limitations, conditions, consents, delivery requirements and remedies. Completion may require signed IP assignments, registry filings, credential changes, code and document delivery, data migration and transitional support. Each step should be linked to payment release.
Scale the review to the transaction
Diligence should be proportionate to value, intended use, complexity and risk. The objective is not to complete a generic checklist; it is to understand what the buyer will own, what it may legally do, what the asset depends on and which risks remain after completion.