Cash flow due diligence is the process of calculating and verifying a target company's cash-generating metrics, checking that its reported earnings hold up under scrutiny, and identifying the specific red flags that signal the numbers aren't as clean as they look. This guide covers the actual metrics, methods, and warning signs, the mechanical side of the process, as a follow-up to our companion piece on how cash flow affects business valuation, which covers the theory behind why cash flow drives price.
Key takeaways
- Operating Cash Flow, Free Cash Flow, and Adjusted EBITDA each answer a different question. Calculate all three before you rely on any single number.
- Net Working Capital shows up in two distinct places: a general current-ratio health check, and a specific purchase-price peg trued up 60 to 120 days after closing. Buyers commonly conflate the two.
- Quality of Earnings and proof of cash are different, complementary checks. QoE asks whether earnings are sustainable; proof of cash asks whether the reported numbers are even accurate.
- A tolerable variance in a proof-of-cash reconciliation is roughly 3% or less. Wider gaps need a specific explanation, not a shrug.
- Monthly (not annual) trailing 12 to 36 month trend data reveals seasonality, manipulation, and decline patterns that a single year-end snapshot hides.
The Core Cash Flow Metrics to Calculate
Three metrics answer three different questions, and a full picture requires all of them, not just whichever one the seller's broker leads with.
Operating Cash Flow (OCF) measures cash generated by day-to-day operations: net income adjusted for non-cash items (depreciation, amortization) and changes in working capital. It answers whether the core business, before any capital spending decisions, actually generates cash.
Free Cash Flow (FCF) takes OCF and subtracts capital expenditures, showing what's left over after the business reinvests in itself. FCF is the more relevant number for a buyer thinking about what cash will actually be available to service acquisition debt or take as distributions.
EBITDA and Adjusted EBITDA standardize operating performance by adding back interest, taxes, depreciation, and amortization, then further adjusting for owner-specific and non-recurring items. A worked example: a target reports $180,000 in net income. Add back $40,000 in interest and taxes and $30,000 in depreciation to get $250,000 EBITDA. From there, add back a documented $60,000 above-market owner salary and a one-time $15,000 legal settlement, arriving at $325,000 in Adjusted EBITDA, the figure most buy-side multiples in the $1M to $25M range are actually applied against. Every add-back in that bridge should have a receipt behind it, not just a line item on a spreadsheet.
Net Working Capital: Health Check vs. Purchase-Price Peg
Net Working Capital shows up in two genuinely different contexts, and conflating them is a common mistake.
As a health check, the current ratio (current assets divided by current liabilities) tells you whether a business can cover its short-term obligations. A ratio below 1.0 is a liquidity red flag. Beyond that, "healthy" varies by industry: retail businesses commonly run 1.5 to 2.0, construction runs higher at 2.0 to 3.0 given project-cycle cash needs, and professional services typically sit around 1.2 to 2.5. There's no single universal number, so compare a target against its own industry norm, not a blanket rule.
As a purchase-price mechanism, Net Working Capital works completely differently. The buyer and seller agree on an NWC target, commonly called the peg, usually set as the trailing-twelve-month average of normalized working capital, which smooths out seasonal distortion that any single month-end snapshot would introduce. At closing, actual NWC is measured against that peg: if actual NWC comes in below the peg, the purchase price is reduced dollar-for-dollar; if it comes in above, the buyer typically pays the excess. This gets trued up 60 to 120 days after closing once final numbers are confirmed, not settled on day one.
Quality of Earnings and Proof of Cash
These two methods work together but answer different questions, and knowing which one you're looking at matters.
Quality of Earnings (QoE) evaluates whether reported earnings are sustainable and properly normalized, adjusting EBITDA for add-backs, one-time items, and accounting quirks to show what the business would actually generate under new ownership. It's a judgment-driven analysis of whether the numbers, once cleaned up, represent real, repeatable earning power.
Proof of cash is more mechanical: a three-part reconciliation matching net income to bank deposits, sales to bank deposits, and expenses to actual disbursements. Practitioners commonly treat a variance of roughly 3% or less as tolerable; anything wider in any of the three legs needs a specific, documented explanation before you trust the underlying numbers at all. Where QoE asks whether the earnings are good, proof of cash asks whether the reported numbers are even real.
A full QoE engagement from an outside firm typically runs several thousand dollars and one to three weeks, which is worth it for most deals above roughly $2M to $3M in enterprise value. Below that, a buyer can run a scaled-down version of the same logic themselves: pull the add-back schedule, request bank statements for the trailing 12 months, and personally walk through the three-part reconciliation before deciding whether a professional QoE is worth the added cost and time on a smaller deal.
Scenario-Based Forecasting
Build three cash flow projections rather than one: a best case assuming current trends continue, a worst case stress-testing a key customer loss or a seasonal downturn worse than history, and a likely case blending the two. This matters most for financing: if the worst-case scenario still covers debt service on your acquisition loan, you have real margin for error. If only the best case clears that bar, you're underwriting the deal on optimism rather than evidence.
A worked version: a target generates $400,000 in Adjusted EBITDA with one customer representing 22% of revenue. Your likely case assumes flat performance and produces a 1.4x debt service coverage ratio against your proposed SBA loan payment, comfortably above the 1.15x to 1.25x most lenders require. Your worst case models that single customer leaving entirely, which drops EBITDA to roughly $290,000 and coverage to 1.0x, uncomfortably tight. That gap between likely and worst case is exactly the kind of concentration risk that should shape your offer, your financing structure, or a request for a customer contract with real term length, not just something to note and move past.
Historical Trend Analysis: Why Monthly Beats Annual
Pull trailing 12, 24, and ideally 36 months of monthly, not just annual, cash flow statements. Horizontal analysis (comparing the same line item across periods) and vertical analysis (comparing line items as a percentage of revenue within a period) surface patterns an annual summary smooths away entirely: a steady quarter-over-quarter decline that nets out to a flat annual number, a seasonal pattern that needs 24 to 36 months to confirm as consistent rather than a one-off swing, or a spike in a single month that turns out to be a customer prepayment rather than a genuine trend.
Two examples of what this catches in practice. First, a business showing flat $500,000 annual EBITDA for three straight years can still be masking a real problem: if year one ran $450,000 in the first half and $50,000 in the second, year two ran $400,000 and $100,000, and year three ran $350,000 and $150,000, the annual total never moves, but the business's core operations are declining every single half while a shrinking second-half recovery is propping up the total. Second, cost-side vertical analysis (each expense line as a percentage of revenue) catches margin compression that a raw dollar comparison misses entirely, since rising costs can track revenue growth closely enough that the dollar trend looks fine while the percentage tells a different story. Neither pattern shows up if you only look at annual totals.
Red Flags and How to Spot Each One
Inconsistent or declining operating cash flow. A downward trend across multiple periods, even a modest one, is worth investigating for a root cause (customer loss, margin compression, rising costs) rather than dismissing as noise.
Non-recurring items inflating metrics. A "one-time" gain or expense that shows up more than once across your trailing trend data isn't one-time. Check whether add-backs the seller claims as non-recurring actually recur. A useful test: pull the add-back schedule and cross-reference each item against your 36-month trend data. If a "one-time equipment repair" appears in the add-back list for three consecutive years, it's not one-time, it's a normal cost of operating the equipment, and it belongs back in the earnings, not adjusted out of them.
Revenue recognition gaps. Compare reported revenue against actual bank deposits for the same period. A persistent, unexplained gap often points to revenue booked before cash was collected, deferred revenue that isn't being tracked and released properly, or activity concentrated suspiciously near period-end. A one-off gap tied to a known invoicing delay is normal. A recurring pattern is not.
Run this as a direct test rather than a general impression: for each of the trailing 12 months, list reported revenue on one side and actual deposits on the other. Most SMBs on cash or modified-cash accounting should show these numbers tracking closely, generally within a few percentage points, month to month, since there's little formal deferred-revenue mechanism at play. A business on accrual accounting with real deferred revenue (annual service contracts billed upfront, for instance) will show a structural gap that's explainable and consistent. What you're hunting for is the gap that has no consistent explanation, that widens unpredictably, or that concentrates suspiciously around fiscal year-end when a seller has the most incentive to make a number look better than it is.
For the full document-level version of this process, our due diligence checklist covers everything else to request alongside the cash flow analysis, and our guide on financial red flags goes deeper on the discrepancies most likely to change your offer.
A Due Diligence Cash Flow Checklist
| Step | What to do | What it tells you |
|---|---|---|
| Calculate OCF, FCF, Adjusted EBITDA | Build the bridge from net income with documented add-backs | Whether the business generates real, sustainable cash |
| Separate NWC health check from NWC peg | Compare current ratio to industry norm; confirm the peg calculation methodology | Solvency today vs. purchase-price impact at close |
| Run a proof of cash reconciliation | Match net income, sales, and expenses to bank activity | Whether the reported numbers are accurate at all |
| Build 3 cash flow scenarios | Best, worst, and likely case against your financing needs | Whether the deal survives a bad year, not just an average one |
| Review 12 to 36 months monthly | Horizontal and vertical trend analysis | Real patterns an annual number would hide |
| Test revenue recognition | Compare booked revenue to bank deposits period by period | Whether revenue is being reported honestly and on time |
How Clef Fits In
If you're running this process across more than one deal at a time, which is common once you're a few weeks into an active search, keeping each target's cash flow findings, documents, and open questions straight matters as much as the analysis itself. Clef's deal pipeline organizes every acquisition under LOI in one place, alongside an aggregated feed of more than 120,000 business-for-sale listings and an AI assistant to help you screen the next one while you're still working through this one.
Frequently asked questions
What is the difference between Quality of Earnings and Proof of Cash in due diligence?
Quality of Earnings (QoE) evaluates whether a target's reported earnings are sustainable and normalized, adjusting for add-backs and non-recurring items to show what the business would actually generate going forward. Proof of cash is a separate, more mechanical check that confirms the numbers on the P&L actually reconcile to what moved through the bank account. QoE asks whether the earnings are real and repeatable; proof of cash asks whether the reported numbers are even accurate to begin with.
What is a tolerable variance in a proof of cash reconciliation?
Practitioners commonly use a rule of thumb of around 3% or less as a tolerable variance between reported figures and bank-reconciled cash movement. Anything wider than that in any of the three reconciliation legs (net income to deposits, sales to deposits, expenses to disbursements) warrants a specific explanation from the seller before you rely on the reported numbers.
How is the Net Working Capital target or peg calculated in an acquisition?
The NWC target (often called the peg) is typically set as the trailing-twelve-month average of the target's normalized working capital, which smooths out seasonal swings that a single month-end snapshot would distort. At closing, actual NWC is compared to the peg, and the difference becomes a dollar-for-dollar adjustment to the purchase price, trued up 60 to 120 days after closing once final numbers are confirmed.
How do you spot inflated EBITDA add-backs during due diligence?
Request documentation for every add-back rather than accepting the seller's summary schedule. Legitimate add-backs (owner's above-market salary, one-time legal fees, a single non-recurring asset sale) should have a clear paper trail and a plausible explanation for why they won't recur. Add-backs that are vague, recurring in disguise (a 'one-time' repair that shows up three years running), or unverifiable against actual invoices and bank records are the ones that should worry you.
What revenue recognition red flags should a buyer check for in due diligence?
Compare reported revenue on the P&L against actual cash deposits in the bank statements for the same period. A persistent, unexplained gap between the two often points to timing manipulation (recognizing revenue before cash is collected), channel-stuffing near period-end, or deferred revenue that isn't being tracked and released correctly. A one-time gap tied to a known invoicing delay is normal; a recurring pattern is not.