
TL;DR
Do not ask only “What does the BPO have?” Ask:
- what is legally owned;
- what is transferable;
- what is compliant;
- what must remain in place for operations to continue;
- what liabilities follow the transaction;
- what must be changed on Day 1.
The most dangerous acquisition assumptions often concern assets that exist before closing but do not automatically transfer afterward: leases, customer contracts, bank access, software licenses, registrations, employee retention and administrator credentials.
Due diligence should therefore produce a decision and transition plan, not just a folder of documents.
Corporate identity and authority
Start by proving exactly what legal entity is being acquired and who has authority to sell it.
Obtain and reconcile:
- SEC certificate and current Articles/By-Laws;
- ownership and beneficial-ownership records;
- directors and officers;
- corporate secretary records and board approvals;
- registered address;
- material subsidiaries or affiliates;
- related-party transactions;
- liens, pledges or restrictions affecting shares/assets;
- pending disputes or claims;
- authority for the proposed sale.
Match names and registration numbers across contracts, bank records, tax filings, leases and permits. Similar trading names can hide different legal counterparties.
SBMA registration, permits and incentives
For a Subic transaction, collect every current SBMA certificate, permit and registered-activity document.
Then ask:
- What activity is actually registered?
- Is the entity in good standing?
- What renewals are pending?
- What performance or reporting commitments exist?
- Does the proposed ownership change require notice, consent or re-registration?
- Does the buyer's intended activity fit the existing registration?
- Are any incentive assumptions tied to a particular project or historical regime?
National incentives rules have changed under CREATE and CREATE MORE. Do not value an “incentive” until the current treatment is confirmed for the transaction and future activity.
Financial, tax and working-capital reality
Reconcile financial statements to underlying records rather than accepting a management summary.
Review:
- tax returns and assessments;
- general ledger and trial balance;
- bank statements;
- receivables aging;
- payables aging;
- payroll registers;
- employee advances;
- shareholder/director loans;
- deferred revenue;
- security deposits;
- vendor commitments;
- contingent liabilities;
- penalties and unresolved tax matters.
Build a normalized view of earnings and cash requirements. Remove owner-specific expenses where appropriate, but also add costs the seller currently absorbs personally and the buyer will need to replace.
For a platform with little or no recurring customer revenue, the valuation should focus more heavily on the corporation, time saved, digital assets, registrations, location value and transition cost rather than applying an operating-company multiple that the facts do not support.
Customer and revenue due diligence
Create a contract matrix for every material customer showing:
- legal counterparty;
- services and scope;
- revenue and margin;
- start/end date;
- renewal terms;
- termination rights;
- assignment/change-of-control provisions;
- service levels and credits;
- data/privacy obligations;
- security requirements;
- subcontracting restrictions;
- dispute history.
Verify customer concentration and whether the customer intends to remain after a transaction where that confirmation can appropriately be obtained.
Do not treat a customer logo, old purchase order or historical relationship as proof of transferable future revenue.
Workforce and key-person dependency
Review the people who actually make the operation function.
Collect:
- headcount by role and employment status;
- tenure;
- compensation and benefits;
- leave/accrued obligations;
- shift and attendance data;
- turnover/attrition;
- disciplinary or labor matters;
- training records;
- supervisor spans;
- key-person dependencies.
Identify roles where a single person controls customer knowledge, payroll, network administration, cloud access, source code or vendor relationships.
Where appropriate, interview critical managers and technical administrators before closing and create a retention/knowledge-transfer plan.
Property and facility
Inspect the physical operation and reconcile it with the contracts.
Review:
- lease/sublease documents;
- landlord/sublessor authority;
- expiry and renewal;
- escalation;
- deposits;
- assignment and change-of-control restrictions;
- restoration obligations;
- permitted use and operating hours;
- fit-out ownership;
- generator and UPS arrangements;
- HVAC;
- carrier contracts and entry paths;
- access control;
- fire/life-safety documentation.
Test generator, UPS and network failover where possible. “Redundant” should describe a tested architecture, not two logos on a slide.
Technology asset register
Create a register showing what is owned, leased, subscribed or personally controlled.
Include:
- endpoints and serial numbers;
- network devices;
- servers and appliances;
- domains and DNS;
- cloud tenants;
- email systems;
- telephony/contact-center systems;
- SaaS subscriptions;
- source-code repositories;
- certificates and signing keys;
- backup systems;
- software licenses;
- vendor accounts;
- administrator and billing ownership.
For each item, record transferability, renewal date, owner, cost and post-closing action.
A system may be technically operational but commercially unusable if the buyer cannot obtain the license or account ownership.
Cybersecurity and privacy
Assume that an acquired operation includes technical debt until evidence shows otherwise.
Review:
- MFA coverage;
- privileged accounts;
- dormant and shared accounts;
- endpoint management;
- patching and vulnerability status;
- firewall/network segmentation;
- logging and retention;
- backups and restoration tests;
- remote access;
- third-party access;
- security incidents;
- customer audit findings;
- data-retention practices;
- privacy notices and processing agreements.
Under the Philippine Data Privacy Act framework, accountability for outsourced processing and appropriate safeguards remain important even when data processing is delegated. If customer personal data is processed, review the contracts, documented instructions, processing locations and security obligations in detail.
Prepare a Day-1 security plan before closing: reset privileged credentials, rotate secrets, review DNS, disable unnecessary accounts, reissue access and verify backups.
For larger remediation or architecture work, WebShop.ph is a relevant technology and cybersecurity resource that can be evaluated independently.
Digital assets and web properties
Digital assets are easy to overlook because they may not appear on a traditional fixed-asset register.
Check:
- domains and registrars;
- websites and source repositories;
- analytics/Search Console accounts;
- social accounts;
- cloud infrastructure;
- email domains;
- app-store accounts;
- design/source files;
- intellectual-property ownership;
- third-party images/fonts/licenses.
Confirm that the legal seller actually controls each asset and that transfer credentials or account changes are possible.
Banking and payment transition
An existing bank account is not simply a transferable asset in the same way as a desk or domain.
Review current banking, payment processors and signatories, then confirm the bank's ownership-change, KYC and authorization requirements directly.
Plan payroll and vendor payments so the business is not operationally dependent on an old signatory after closing.
Transition dependencies
Create a closing/transition list for every item that requires consent, notice or a coordinated cutover:
- customer approval;
- lease consent;
- bank access;
- payroll control;
- insurance;
- domain transfer;
- DNS change;
- cloud ownership;
- telecom contracts;
- software licenses;
- employee communications;
- regulatory notices;
- vendor changes.
Assign an owner and latest acceptable completion date.
Maintain a red-flag register
Every unresolved issue should be visible in one place.
| Field | Purpose |
|---|---|
| Issue | What is uncertain or wrong |
| Evidence requested | What would resolve it |
| Owner | Who must obtain/assess it |
| Severity | Business impact |
| Price/structure effect | How it changes the deal |
| Closing condition | What must happen before closing |
| Remediation | What happens after closing |
| Deadline | Latest safe decision date |
This turns due diligence into a decision system instead of a document dump.
For a real Subic transaction, the BPOForSale.com opportunity can be assessed with this same framework.
Primary sources and further reading
- FIRB Laws and Issuances
Current national incentives issuances relevant to registered business enterprises. - SBMA Business Registration
Current public registration process for prospective Subic investors. - National Privacy Commission - Data Privacy Act
Official Philippine law governing processing and outsourcing of personal information. - National Privacy Commission - Implementing Rules
Outsourcing, security and accountability requirements for personal-data processing.