Normalizing EBITDA for a founder-owned business is, by now, a well-trodden exercise. Owner compensation above market rate, a facility leased from a related party, a personal vehicle run through the company, these get found, documented, and added back, because everyone doing diligence on a founder-owned target knows to look for them. The add-back exercise is necessary and it's covered in enough detail elsewhere that it doesn't need repeating here. What's less covered is what happens after the EBITDA bridge is clean: the category of risk that has nothing to do with the income statement and everything to do with how an operator running their own shop for a decade or more actually manages the parts of a business that never show up in adjusted earnings.
These are the red flags that surface late in a process, usually after financial diligence is already signed off, and usually because nobody thought to ask about them until legal diligence or IT diligence stumbled onto them by accident.
IP ownership and assignment gaps
A founder-owned software company that's ten or fifteen years old was very likely started before anyone involved thought carefully about intellectual property assignment. The first version of the product might have been built by a contractor paid in cash with no work-for-hire agreement, or by an early employee who's since left the company on unclear terms, or in some cases by the founder personally, moonlighting while employed somewhere else, with no documentation establishing that the code wasn't the previous employer's property.
None of this shows up in financial statements. It shows up when a buyer's counsel asks for IP assignment agreements for every person who's ever contributed code, a request founder-owned targets are disproportionately likely to fail, not from bad faith but from never having had a reason to formalize it while the company had one owner making every decision. The fix, when a gap is found, is usually workable, a retroactive assignment agreement with the relevant party, but it takes time, occasionally requires a payment to a departed contractor who now has real leverage, and it needs to be caught early enough in the process to resolve before it becomes a closing condition under time pressure.
Customer relationships that were never actually contracts
The largest customer relationship in a founder-owned business is sometimes exactly that: a relationship, built on a personal connection between the founder and a counterpart at the customer, running on a handshake or an email exchange from years ago rather than a signed, current agreement. It works fine under founder ownership, because the relationship carries the account. It's a real risk under new ownership, because the thing that was actually holding the account in place, personal trust in the founder specifically, doesn't transfer with a change-of-control clause the way a properly documented contract does, because there's no contract to have a change-of-control clause in the first place.
This is worth checking directly rather than assuming a signed master services agreement exists just because the relationship is long-standing: pull the actual current, signed contract for the top five to ten accounts by revenue, not a summary, and confirm three things: that it's current rather than expired and running informally, that it includes standard assignment language covering a change of ownership, and that pricing and terms are documented rather than understood verbally. Any account failing all three is a real retention risk in the first year of new ownership, regardless of how the switching-cost or retention analysis elsewhere in diligence reads.
Key employee agreements that don't exist
A founder-owned business often has one or two people, a technical co-founder, the first engineer, a long-tenured operations lead, whose departure would functionally gut the company's ability to operate or to keep building the product. In a business that's never raised institutional capital, it's common for none of these people to have a non-compete, non-solicit, or even a written employment agreement beyond an offer letter from years ago, because nobody outside investor ever required one.
This matters most in a majority recapitalization or acquisition where retention of that specific person is doing real work in the underwriting, and it's worth treating as its own diligence line item rather than assuming HR paperwork is in order because payroll clearly runs fine. Ask directly: does this person have a written agreement, does it include a non-compete or non-solicit enforceable in the relevant jurisdiction (enforceability varies significantly by state and by role), and has anyone confirmed they intend to stay through and after the transaction. A verbal assumption that "of course they're staying" is not a substitute for a documented retention agreement, ideally negotiated and signed before the deal closes, not after.
Related-party arrangements beyond rent and comp
The two related-party items every EBITDA bridge catches, owner compensation and facility rent, are the visible tip of a category that often runs deeper in a business one person has controlled for a long time. Common examples that don't show up in a standard add-back schedule because they don't inflate EBITDA, they just represent undisclosed related-party exposure:
- A vendor contract with a company owned by the founder's spouse, sibling, or close friend, priced at or near market rate, so it doesn't distort EBITDA, but represents an ongoing relationship a new owner may not want to continue or may not be able to easily unwind.
- Informal loans running in either direction between the business and the owner personally, sometimes undocumented, sometimes documented as a receivable or payable buried in an "other" account that doesn't get much scrutiny.
- Personal guarantees the founder has extended on business obligations, a lease, an equipment loan, a line of credit, that need to be released at close, which is a real closing mechanic that gets missed when it's not flagged early.
- Shared resources with another business the founder owns: a bookkeeper, an office manager, or equipment used across both entities without a clean cost allocation.
None of these are necessarily deal-breakers. All of them are the kind of thing that's expensive and slow to discover during a thirty-day exclusivity window and comparatively cheap to ask about directly in the first weeks of diligence.
The single-Gmail-account problem
This one has nothing to do with financials and everything to do with operational continuity, and it's specific to businesses that grew up without a dedicated IT function. In a lot of founder-run software companies, the domain registration, the AWS or hosting account, the primary business email, the code repository admin access, and half a dozen SaaS vendor accounts are all tied to the founder's personal email address, sometimes literally a personal Gmail account rather than a company-controlled one.
The risk isn't hypothetical: a founder who leaves on bad terms, becomes unreachable, or simply forgets a password to an account with no company-controlled recovery path can take down infrastructure the entire business runs on. This is worth an explicit, itemized check before close, not a general assurance that "IT is fine": list every system critical to operating the business, confirm who holds admin access to each one, and confirm that access is tied to a company-controlled identity rather than a personal account, with a plan to migrate anything that isn't before the transaction closes.
How to actually surface these, as concrete diligence requests
Each of the risks above is findable with a specific request, not a general one. A request list that goes beyond the standard financial diligence checklist to actually catch these:
- Full cap table history and IP assignment agreements for every founder, employee, and contractor who has contributed code or product design, from company inception forward.
- Signed, current contracts (not summaries) for the top ten customers by revenue, confirmed for assignment/change-of-control language.
- Employment agreements, including non-compete and non-solicit terms, for every employee whose departure would be operationally material, plus a named retention plan for each.
- A complete related-party transaction schedule, including informal loans and personal guarantees, not limited to what already appears in the EBITDA add-back schedule.
- An admin-access audit: every domain, hosting, code repository, and critical vendor account, who holds access, and whether that access is tied to a company-controlled identity.
None of this replaces the financial diligence that produces a clean, defensible EBITDA bridge, the sample bridge and IC memo published on our Firm page walk through exactly how that side of the process works. It's the second half of the same job: the risks that live outside the income statement in a business one person has run their way for a long time, and that a buyer only avoids inheriting by asking about them directly, before close, rather than discovering them afterward.
