Guides drafting of a tailored due diligence request list for a regulated data or healthcare IT target, with an executive summary of target-specific diligence themes covering regulatory risk, open-source copyleft, change-of-control revenue at risk, data licensing compliance, and time-sensitive contract expirations.
Scanned 9/11/2026
Install to Claude Code
npx -y skills add sunyifeisb-art/legalwork --skill scenario-02 --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Scenario 02?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/sunyifeisb-art-scenario-02-070f0906)More formats (shields.io, HTML) on the badges page.
---
name: draft-due-diligence-request-list-s02
task_id: corporate-ma/draft-due-diligence-request-list/scenario-02
description: Guides drafting of a tailored due diligence request list for a regulated data or healthcare IT target, with an executive summary of target-specific diligence themes covering regulatory risk, open-source copyleft, change-of-control revenue at risk, data licensing compliance, and time-sensitive contract expirations.
activates_for: [planner, solver, checker]
---
# Skill: Draft Due Diligence Request List (Scenario 02)
## 1. Subject-matter triage (only if applicable)
- Treat the target as a healthcare IT / regulated data company until the materials support a narrower view.
- Separate ordinary software diligence from diligence driven by clinical workflow, patient data, privacy, security, and product-classification risk.
- Flag any contract, renewal, consent, clearance, or data-use item that could move on the transaction timeline as time-sensitive and request it first.
## 2. Failure modes the skill is correcting
- Drafting a generic technology DDRL that misses the target’s healthcare, data licensing, and regulatory profile.
- Omitting a concise executive summary that tells the client where the real deal risk sits.
- Failing to ask for the documents needed to assess product classification, privacy compliance, open-source obligations, and revenue leakage from change-of-control rights.
- Buried urgency: not separating near-expiration customer paper, regulatory deadlines, or pending approvals from the ordinary contract population.
- Asking for descriptions of issues instead of the source materials needed to verify them.
## 3. Legal frameworks / domain conventions that apply
- Open-source copyleft in SaaS: identify copyleft-licensed components, their role in the stack, and how they are integrated; assess whether network use, distribution, attribution, notice, or source-disclosure obligations may attach under the applicable license terms.
- Change-of-control revenue risk: customer agreements may terminate, require consent, or permit repricing on a transaction; request the contract set and management’s revenue analysis for affected accounts so exposure can be assessed against closing risk.
- Data licensing and healthcare privacy: request data-use agreements, data licensing contracts, and correspondence with regulators or counterparties where health data, patient data, or other regulated data is used, shared, sold, or analyzed.
- Product classification as regulated software: where the product informs clinical decisions, analyzes patient data, or interfaces with medical devices, request the company’s classification analysis, submissions, clearances, and regulator communications to test whether oversight obligations were triggered.
- Tax and state compliance: request nexus, filing, and NOL materials sufficient to assess multi-state compliance and carryforward support.
## 4. Analytical scaffolds
- Start with a short executive summary of the diligence themes that matter most for this target.
- Cover, at minimum, regulatory/product classification, IP and open source, privacy and security, customer concentration and contract leakage, and tax/nexus.
- For each category, ask for the underlying agreements, analyses, correspondence, policies, and internal memoranda that would let counsel verify the issue rather than infer it.
- When a topic has multiple slices, enumerate them explicitly and ask for each slice separately rather than using a single umbrella request.
- Frame requests to capture both current-state documents and any drafts, redlines, or pending approvals that may change before closing.
- Keep requests document-oriented and specific to the business model; the point is to collect source material, not to write conclusions in the request list.
## 5. Vertical / structural / temporal relationships (only if applicable)
- Separate enterprise-level materials from product-level materials, because a corporate compliance posture does not resolve product-specific regulatory exposure.
- Separate legacy products, current products, and in-development products if the classification or data-use analysis differs across them.
- Separate customer agreements by term, renewal status, and control provisions so that near-term expirations and consent rights are visible at a glance.
- Separate data transfer, data processing, data licensing, and research-use arrangements, because each may carry distinct restrictions and risk.
- If the materials indicate a pending approval, renewal, audit, or regulatory inquiry, elevate that item into a time-sensitive section and request the full file.
## 6. Output structure conventions
- Produce a due diligence request list with a brief executive summary followed by numbered request categories.
- Use industry-conventional headings such as corporate/organization, capitalization, material contracts, IP/technology, data privacy and security, product/regulatory, employment, tax, litigation, and other target-specific categories.
- Include a distinct time-sensitive section for urgent items, with each request clearly tied to the relevant deadline, renewal, or transaction milestone.
- Within each category, write requests in concise, document-seeking form; ask for the agreement, policy, memo, schedule, report, or correspondence, not a narrative answer.
- Make target-specific tailoring visible in the requests themselves by calling out healthcare data, product classification, open-source integration, and change-of-control exposure.
- End with a short section for supplemental materials and a catch-all request for any item the target relies on to support compliance, commercialization, security, or disclosure positions.
- Write for immediate use in a diligence workstream; the document should be clean, client-ready, and ready to populate into the requested .docx file.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!