Series A due diligence now includes a compliance review. Institutional investors — particularly those with ESG mandates, financial services LPs, or portfolios in regulated sectors — are conducting compliance assessments as a standard part of the diligence process. Compliance gaps discovered during a fundraising process delay deals, reduce valuations, and in serious cases kill transactions.
Why Compliance Due Diligence Has Increased
Five years ago, legal due diligence in a Series A focused on corporate structure, cap table, IP ownership, and material contracts. Compliance was a minor component. The change drivers:
GDPR enforcement maturity: GDPR has been enforced for six years. Investors have seen portfolio companies receive ICO notices, face EDPB investigations, and incur significant remediation costs. Compliance due diligence reduces post-investment surprises.
AI regulation: Investors in AI companies are assessing AI Act exposure as part of diligence — particularly for high-risk AI systems that could require expensive conformity assessment or EU AI database registration.
NIS2 and DORA: Financial services and infrastructure-focused investors need to understand their portfolio companies' regulatory exposure.
ICO enforcement register: The ICO's public enforcement register is one of the first things investors check. A reprimand or monetary penalty notice on the register is a diligence finding.
Data room expectations: Series A data rooms now include a compliance section alongside financial statements, IP documentation, and customer contracts.
What Investors Check in the Compliance Data Room
GDPR
- Privacy notice: Published, current, compliant with GDPR Articles 13/14?
- Cookie consent: Correct implementation — no pre-ticked boxes, reject option equal to accept?
- Data Processing Agreements: Signed DPAs in place with all vendors accessing personal data?
- ROPA: Records of Processing Activities maintained and current?
- DSAR process: Procedure in place? Any outstanding DSARs?
- Breach history: Any reported breaches? How were they handled?
- ICO register check: Any enforcement actions, reprimands, or monetary penalties?
- International transfers: Transfer mechanism in place for non-EEA data processors?
Red flags:
- No DPA with major SaaS tools (AWS, Salesforce, Hubspot, Stripe)
- Cookie banner that does not have a reject option
- A breach that was not reported to the ICO but probably should have been
- An outstanding DSAR that is past the 30-day deadline
Security
- ISO 27001 or SOC 2: Certification status and scope?
- Penetration testing: Most recent test date and findings summary?
- MFA: Is MFA in place for all critical systems?
- Incident history: Any material security incidents? How were they handled?
Red flags:
- No certifications and no plan to achieve them (for enterprise-targeting SaaS)
- Last penetration test was more than 18 months ago
- Unpatched critical vulnerabilities discovered in due diligence
AI (for AI companies)
- AI Act classification: Has the company assessed which AI risk tier applies?
- Technical documentation: Does the company have Annex IV documentation for high-risk AI?
- EU AI database registration: Completed for high-risk systems?
- Prohibited AI check: Any AI systems that might fall under Article 5 prohibited categories?
Red flags:
- An unrecognised high-risk AI system — recruitment AI, credit scoring AI, or medical AI — with no compliance programme
- Chatbot with no Article 50 disclosure
Data and IP
- Customer data in training: Does the company use customer data to train AI models? On what legal basis?
- IP ownership of AI outputs: Clear ownership of model outputs?
- Data licences: Are training datasets properly licensed?
Building a Compliance Data Room
For a Series A fundraising process, prepare the following:
GDPR section:
- Privacy notice (link or PDF)
- Cookie consent implementation screenshot
- Standard DPA (published or PDF)
- Sub-processor list (current)
- ROPA (summary — full document on request)
- Breach history summary (confirming no material unresolved breaches)
- ICO register confirmation (no enforcement actions)
Security section:
- ISO 27001 certificate or SOC 2 report (current)
- Penetration test date confirmation and brief findings summary
- Security policy (summary)
AI section (if applicable):
- AI system inventory with risk classification
- AI Act compliance assessment summary
- Prohibited AI confirmation
Regulatory exposure summary:
- One-page summary of which regulations apply and current compliance status
- Any known compliance gaps and remediation plan
Fixing Gaps Before Fundraising
If compliance due diligence reveals gaps, investors will either:
- Require remediation before closing
- Adjust valuation to reflect compliance risk
- In serious cases, withdraw
The most common gaps that can be remediated quickly:
- Missing vendor DPAs: typically 1–4 weeks to obtain
- Outdated privacy notice: 1–5 days to update
- Cookie consent fix: 1–2 weeks developer time
- Missing ROPA: 2–5 days to complete
The most common gaps that take longer:
- Penetration test: 4–8 weeks end-to-end
- ISO 27001 certification: 6–12 months
- AI Act high-risk compliance programme: 3–6 months
Start compliance preparation at least 3 months before beginning a fundraising process.