A marketing agency pitch arrives as a deck: case studies, a team slide, a fee page. Marketing agency due diligence is the work of turning that deck back into the records that produced it and checking whether they hold. The reason to bother is the same one buyers of whole companies face. Bain's 2026 Global Private Equity Report frames current deal economics with the phrase "12 is the new 5", meaning returns now depend on faster EBITDA growth earned operationally rather than on cheap leverage. If your growth plan routes through an outside agency, that agency is part of the engine being inspected. This checklist covers what to request, how to verify it, and how to grade what comes back. If you are still building the shortlist rather than diligencing it, start with how to choose a growth marketing agency.
GPI's view is that an agency pitch should be treated as an asset under diligence, with the burden of proof on the seller. Judge every claim on three things: the evidence behind it, the method that produced it, and the limitations the agency is willing to write down. Ask for data to settle one concrete decision, whether to commit a retainer of a given size and term, rather than to build a file. When an agency links its creative and media work to revenue, treat that link as an attribution output until a holdout or incrementality test says otherwise. An agency that welcomes this scrutiny is showing you how it will report to you after signature.
What marketing agency due diligence means, and why the buy-side lens fits
Marketing agency due diligence is the verification of an agency's operational capability, performance claims and data practices using primary records rather than pitch material. The decision it serves is narrow: sign a retainer of a stated size and term, sign with remediation clauses, or walk away.
Commercial due diligence sizes the market; marketing due diligence inspects the engine
Commercial due diligence, as set out in general M&A checklists such as Bloomberg Law's, asks whether the market, competitive position and revenue plan are credible. Marketing due diligence asks how demand is actually generated, measured and reported, and whether the people and systems doing it will keep working under your ownership. Checklists from advisory firms such as Dealroom and fusepoint apply this lens to acquisition targets; this article applies it to the agency you would hire to run part of that engine.
| Question | Commercial due diligence answers | Marketing agency due diligence answers |
|---|---|---|
| Is there a market? | Size, growth, competitive intensity | Not addressed |
| Where does demand come from? | Channel mix at summary level | Which platforms, audiences and assets produce it, from raw exports |
| Are the metrics real? | Revenue reconciles to financials | CAC, LTV and ROAS rebuild from spend, invoices and customer records |
| Who owns the data? | Rarely examined | Ad accounts, pixels, consent records and their provenance |
| Will it scale? | Plan versus market headroom | Agency capacity, process repeatability, measurement durability |
The distinction matters because a commercial diligence provider or a generic agency scorecard will usually leave the right-hand column empty.
Why the burden of proof sits with the agency
The macro reason buyers are tightening scrutiny is that growth has to be earned rather than financed. McKinsey's private markets report cites a StepStone analysis of deals done between 2010 and 2022 in which leverage and multiple expansion made up 59 percent of returns, with the remaining 41 percent from revenue growth and margin. That window is historical and benefited from near-zero rates; it does not describe today's mix. It does explain why the operational share of growth, including outsourced demand generation, now gets inspected harder. Bain's data-backed edge framing is the same argument from the other side.
Where this checklist starts and stops
This checklist covers the commercial and marketing operations of the agency and the accounts it would run. Product roadmap, technical architecture and IP diligence are separate workstreams and are out of scope. Before sending requests, write a one-paragraph mandate that names the retainer size and term under consideration, the records that will be requested, and which person on your side signs off on each area.


The marketing agency due diligence checklist, field by field
Copy the eight-field table below into your procurement tracker, assign one owner per field, and send the full document request list to every shortlisted agency on the same day. Refuse to score any field without a file reference.
| Field | What to request | Acceptable evidence | Verification method | Pass signal | Red flag |
|---|---|---|---|---|---|
| 1. Ownership and stability | Ownership structure, two years of management financials, key-person list | Filed accounts or accountant-prepared statements, org chart | Reconcile revenue to client roster; identify dependence on named individuals | Profitable or funded, no single person on every account | Refusal to share any financials, one principal across all delivery |
| 2. Client roster | Client list with start dates, end dates, spend band | Spreadsheet export, three references you choose | Compute tenure and churn; call references not on the reference slide | Median tenure supports the term you want | One client dominating revenue, references all under a year |
| 3. Team | Named staff for your account, seniority, hours per month | Org chart, role descriptions, LinkedIn cross-check | Compare pitch team to delivery team; ask who leaves if a bigger client signs | Named delivery team in the contract | Senior faces in the pitch, unnamed juniors in delivery |
| 4. Methodology | Written measurement approach, attribution model, test protocol | Internal document, sample monthly report | Check whether incrementality is tested or assumed | Documented method with stated limitations | Method described only verbally or as proprietary |
| 5. Performance claims | Raw exports behind each case study | Platform spend exports, invoices, customer records for the same window | Rebuild CAC, LTV and ROAS (see the verification section) | Claim reproduces within tolerance | Summaries only, windows that do not match |
| 6. Technology and data | Martech inventory with account owner per asset | Admin screenshots, access matrix | Confirm client owns ad accounts, analytics, tag containers | Client ownership in writing | Agency-owned accounts you cannot export from |
| 7. Privacy and consent | Consent record format, tag inventory, platform policy history | Sample consent log, tag audit output | Live tag audit with consent declined (see the martech section) | Provenance for every audience and tag | No consent records, undisclosed policy strikes |
| 8. Commercial terms | Redlined standard contract, fee schedule, media markup disclosure | Contract draft, sample invoice | Trace fees from invoice to platform spend; check exit and data return clauses | Transparent fees, defined exit with data handover | Undisclosed markups, long lock-in, no data return |
The table is a template; pass signals and red flags are GPI's proposed standards, not an industry norm.
Field 1: Ownership, financial stability and key-person exposure
Ask for enough financial information to know the agency will exist for the length of your term and is not dependent on one founder's relationships. For a small project retainer this field can be lightened; for a multi-year commitment it cannot.
Field 2: Client roster, concentration and churn
A roster export with dates does more than a logo wall. Tenure and churn are computable; concentration is visible. Choose your own reference calls from the list rather than accepting the agency's selection.
Field 3: Team, seniority and who actually works the account
The question is who does the work on Tuesday, not who presented on pitch day. Get names into the contract and ask what happens to your staffing if the agency wins two more accounts your size.
Field 4: Methodology and measurement approach
Request the written method behind the reports you would receive: attribution model, test protocol, how disputes on numbers are resolved. A method that lists its own limitations is worth more than one that claims none.
Field 5: Performance claims and case study evidence
Request source exports rather than slides. The rebuild method is covered in full in the next section; here the point is only that the request goes out with every other field.
Field 6: Technology stack, access and data ownership
Inventory every account, property and container the agency would operate, with an owner beside each. You should be able to remove the agency's access and keep everything.
Field 7: Privacy, consent and platform policy compliance
Ask for the format of consent records and any history of platform policy enforcement. The evidence standard is in the martech section.
Field 8: Commercial terms, fees, media markups and exit provisions
A redlined contract reveals more than a fee page. Trace a sample invoice to platform spend, confirm any markup is disclosed, and read the exit clause for data return and notice period. Weight this field heavily at every retainer size.
Running the request list in a shared data room
A labeled, indexed data room shortens the review. Guidance from a data room provider notes that complete, clearly labeled documents reduce advisor hunting time and allow parallel review across workstreams. That is vendor guidance, so treat it as a mechanism rather than a quantified saving, but the mechanism holds: specify file names and formats up front so reviewers can work fields simultaneously.
- Send the full request list with a folder structure and file naming convention.
- Log the receipt date for each document.
- Assign one reviewer per field.
- Record pass or fail with the evidence file name beside it.
- Escalate open items in writing before the final pitch, and treat items still open at signature as contract conditions.
For how to split ownership of these fields between marketing and procurement, see who owns which decisions in agency selection.
Verifying CAC, LTV and ROI claims in agency case studies
For each case study the agency presents, request spend exports, invoices and customer records for the same window, recompute CAC and LTV yourself, and grade the result before allowing the case study to influence scoring. Acquisition economics are the claims worth this effort because, as Bain's 2026 report argues, deals now require faster EBITDA growth and a data-backed edge; reach and engagement figures do not carry that weight.
Rebuild the claimed CAC from source data, not the slide
Agency CAC claims get distorted in three recurring ways: omitted costs (agency fees, creative production, tooling), mismatched windows between spend and conversions, and platform-attributed conversions counted as customers.
- Request the raw platform spend export for the exact case study period.
- Request agency invoices covering the same months.
- Request CRM or order data showing new customers in that window, with acquisition source if available.
- Compute paid CAC (platform spend divided by new customers attributed to paid) and blended CAC (platform spend plus agency fees plus creative and tooling, divided by all new customers).
- Compare both to the slide and note which definition the agency used.
A hypothetical illustration, with placeholder values only and no relation to any agency: a slide claims a $40 CAC. The export shows $100,000 of platform spend and the CRM shows 2,000 new customers, so paid CAC is $50. Adding $30,000 of agency fees and creative gives a blended CAC of $65. The claim was not fabricated; it excluded costs and used platform conversions rather than customers. That distinction is what the grade should record.
Test the LTV assumptions: retention window, margin and discounting
Ask four questions of any LTV figure. Which retention period does it use, and is that period observed or projected? Is value measured on revenue, gross margin or contribution margin? Is churn cohort-based or a single average? Does the LTV to CAC ratio depend on a projected lifetime that no cohort has yet lived? An LTV built on a projected five-year life for a product with eighteen months of data is a forecast, and should be graded as one.
Distinguish platform-reported ROAS from incremental contribution
Platform ROAS is an attribution output. It reports revenue the platform claims credit for under its own rules, which does not establish that the revenue would have been absent without the spend. Request holdout or geo test results where they exist. Where they do not, request a written statement of what was not tested. An agency that can say plainly which results are attributed and which are proven incremental is easier to trust than one that presents a single number.
Time windows, seasonality and survivorship in case study selection
Check when each case study starts and stops. A window that begins after a product launch or ends before a peak season fades will flatter the result. Ask how many clients the agency worked with in the period the case studies cover, and how the featured ones were chosen. Case studies are selected for success; that is normal, but the selection ratio tells you something about repeatability.
| Claim type | Source data required | Recalculation check | Common distortion | Outcome grade |
|---|---|---|---|---|
| Paid CAC | Platform spend export, customer records | Spend divided by new customers | Conversions counted as customers | Verified, caveated, unverifiable or contradicted |
| Blended CAC | Spend, invoices, creative and tooling costs | All acquisition cost divided by all new customers | Agency fees omitted | Same rubric |
| LTV | Cohort retention, margin data | Recompute on observed cohorts at contribution margin | Projected lifetime, revenue instead of margin | Same rubric |
| LTV to CAC | Both of the above | Ratio on matched windows and definitions | Numerator and denominator on different bases | Same rubric |
| ROAS | Platform report, test results | Compare attributed to incremental where tested | Attribution presented as causation | Same rubric |
The rubric in the final column is GPI's framework for this checklist rather than a published standard; the underlying method of rebuilding from primary records is the same one advisory checklists such as Dealroom's recommend for acquisition targets.
How to evaluate the result of your verification
Grade each claim on four levels. Verified within tolerance: the rebuild lands close to the claim on the same definition; the case study can count. Verified with disclosed caveats: the numbers hold but the agency used a narrower definition and says so; count it at reduced weight. Unverifiable due to missing data: the field is open, not failed; decide whether it is disqualifying for your retainer size. Contradicted by source data: the claim does not reproduce from the agency's own records; treat this as disqualifying unless the agency can explain the gap in writing. Record the grade and the file reference, and let the graded evidence rather than the polish of the deck decide.

Auditing the martech stack, consent records and AI workflows you would inherit
Before the final pitch, run a live tag audit on a sample landing page with consent declined, request the agency's consent record format for one prior campaign, and require written confirmation that all ad and analytics accounts will be owned by your company. This section supplies the evidence standard behind Fields 6 and 7 of the checklist.
Who owns the accounts, pixels and data
Inventory everything the agency would operate on your behalf: ad accounts, analytics properties, CDP or CRM connectors, tag containers, creative libraries and any audience lists. For each, confirm that ownership and admin rights sit with you and that the agency holds delegated access you can revoke. If an asset was created under the agency's own business manager, ask for a migration plan before signing. General M&A privacy checklists from bodies such as the IMAA Institute treat data ownership and access control as core diligence items; the same applies to a retainer.
Consent records and the proof burden under CASL, GDPR and CCPA
The operating principle comes from guidance on privacy diligence for agencies: buyers know the proof burden sits with the sender, so thin consent records read as latent liability even when nobody has complained. That guidance is written around Canada's anti-spam legislation, CASL, and the rules under GDPR and US state laws differ in detail; the principle that provenance must be demonstrable transfers without the specifics. Apply it to any list, audience or pixel the agency proposes to use or has used for prior clients. Practical consent evidence means timestamped opt-in records, the source of each consent, working unsubscribe handling, and a documented lawful basis per jurisdiction. An agency that built audiences it cannot show provenance for is offering you a liability alongside a capability, and only the capability is on the slide.
Pixel, tag and server-side tracking hygiene
Run the check on one page the agency would manage. Match the tag inventory to a documented purpose for each tag. Confirm consent-mode configuration and data retention settings. Then load the page with consent declined and record what fires. Anything that fires before consent is a finding, and the agency's response to it tells you how it will handle the same issue on your properties.
Auditing AI-assisted workflows: claimed productivity versus documented process
Where an agency describes AI-assisted production, request the documented process, the tool list, the human review points and any before-and-after time or output records. Ask where client data enters the tools and under what terms. Treat undocumented productivity claims as unverified rather than false; the grade is the same as a missing spend export.
| Asset or workflow | Ownership check | Compliance evidence to request | Test to run | Failure signal |
|---|---|---|---|---|
| Ad accounts | Client is admin, agency has delegated access | Access matrix | Revoke and restore agency access in a sandbox | Agency-owned account with no migration plan |
| Analytics and tag containers | Client owns property and container | Tag inventory with purpose per tag | Load page with consent declined | Tags fire before consent |
| Audiences and lists | Source documented per record | Consent log format, lawful basis note | Sample ten records for provenance | No timestamps or source fields |
| Server-side tracking | Endpoint under client control | Data flow diagram, retention settings | Inspect payloads sent post-consent | Undocumented fields forwarded |
| AI-assisted workflows | Client data handling terms | Process document, review points, tool list | Walk one deliverable from brief to output | Productivity claim with no records |
Failure signals in the table are GPI's proposed thresholds for this checklist; the proof-burden standard behind them is drawn from the Privacy Horizon guidance cited above.
Red flags that surface in the data room, and how to weigh them
Score every shortlisted agency against the five flags below using only documents received, assign a severity to each hit, and write the remediation clause into the contract draft before negotiation begins. The severity scale is a conceptual framework for this checklist, not an industry standard, and the point of each flag is how it appears in the data room rather than in conversation. Advisory work on diligence makes a similar point: some risks only surface through primary research rather than management presentations.
Vanity metrics in place of financial outcomes
The sample monthly report leads with impressions, engagement rate and follower growth, and revenue or pipeline appears late or not at all. Ask which metric in the report your CFO would recognize, and where it comes from.
Channel and client concentration
One platform accounts for most claimed results across all case studies, or one client accounts for most of the agency's revenue in the roster export. The first means your results depend on a single algorithm; the second means your account competes for attention with the client that keeps the lights on. Ask what the agency's plan is if that platform or that client changes.
Rented demand versus owned demand
Rented demand is results that exist only while paid spend or a platform's algorithm keeps delivering. Owned demand is supported by first-party audiences, content assets, retention improvements or brand search that persists. The durability test is whether any case study shows what happened after spend paused or fell. If every story stops when the budget stops, ask directly what the agency has built for a client that outlasted the contract.
Founder or single-person dependence
The same senior name appears on every account in the org chart and in every reference conversation. Ask who would run your account if that person left, and whether that person's name can be written into the contract.
Thin, late or reformatted records
Documents arrive late, incomplete, or as reformatted summaries where source exports were requested. The proof-burden principle from privacy diligence, that thin records read as latent liability even absent complaints, generalizes to the whole data room. An agency that sends summaries instead of exports during a pitch has already answered the question of how it reports under pressure. Ask for the original export and note the response time.
| Red flag | How it appears in documents | Question to ask | Severity | Remediation if proceeding |
|---|---|---|---|---|
| Vanity metrics | Reports lead with reach and engagement | Which line would finance recognize? | Remediate before signing | Contractual reporting template with revenue or pipeline first |
| Concentration | One platform or one client dominates | What is the plan if it changes? | Monitor in contract | Diversification milestones, continuity clause |
| Rented demand | Every case study stops with spend | What outlasted the contract? | Remediate before signing | Owned-asset deliverables in scope |
| Single-person dependence | Same name on every account | Who runs it if they leave? | Monitor in contract | Named team and substitution clause |
| Thin or late records | Summaries instead of exports | Can you send the original? | Disqualifying if unresolved | None; resolve before signature |
Severity levels in the table are GPI's suggested framework and should be adjusted to your retainer size and risk tolerance.
Integration and scalability: will the agency's model survive your growth plan?
Ask each finalist for a written capacity statement covering the named team, hours per month and onboarding milestones, plus a measurement plan that works without third-party cookies, then compare both against your twelve-month budget plan. This section looks forward at fit; the martech section already covers consent and tag checks, and the red flags section covers concentration.
Capacity: headcount, utilization and onboarding runway
Test whether the agency can absorb your planned spend and scope. Request staffing ratios per account, the current utilization of the team proposed for you, and a documented onboarding plan with dates. Then ask in writing: what happens to your team if the agency wins two more clients your size in the next quarter? A credible answer names hiring plans or a cap on new business.
Fit with your stack, reporting cadence and decision rights
Define the integration checks before signing. Where does campaign and cost data flow into your finance and CRM systems, and in what format? How often do reports arrive and who reads them? Who approves budget shifts between channels and who approves creative? How are disagreements about measurement resolved, and who arbitrates? Write the answers into the statement of work, not a side email.
Durability in a privacy-constrained, cookieless environment
Ask whether the agency's past results depended on tracking conditions that no longer hold for your properties. Request its approach to server-side measurement, its first-party data strategy, and evidence that it can design and read an incrementality test. The StepStone analysis cited by McKinsey found that for 2010 to 2022 deals, 59 percent of returns came from leverage and multiple expansion; that was a near-zero-rate window and says nothing about today's split. The shift Bain describes toward a data-backed edge means an agency's repeatable, measurable process now matters more than one strong period in a case study.
Does the checklist change for B2B SaaS versus consumer brands?
The request list is the same; the pass thresholds differ. B2B SaaS buyers weight pipeline contribution, sales cycle length and retention cohorts, because acquisition economics only resolve months after the campaign. Consumer brands weight contribution margin, repeat purchase and creative velocity, because the unit economics close quickly and creative fatigue is the binding constraint.
| Dimension | B2B SaaS emphasis | Consumer brand emphasis | Evidence to request |
|---|---|---|---|
| Primary outcome | Qualified pipeline and closed revenue | Contribution margin per order | CRM or order export matched to spend |
| Time horizon | Full sales cycle, cohort retention | First purchase and repeat rate | Cohort tables by acquisition month |
| Creative | Message and offer testing | Volume and refresh cadence | Test log with results |
| Measurement | Multi-touch reconciled to CRM | Incrementality via holdout or geo tests | Written test protocol |
| Capacity risk | Strategist depth | Production throughput | Staffing plan by role |
Emphases in the table are GPI's framing of where each buyer type should set stricter pass thresholds; the underlying documents requested do not change.
How GPI's methodology supports marketing agency due diligence
What documented evidence looks like in a directory profile
GPI's published methodology explains how directory profiles weigh documented evidence, stated method and disclosed limitations rather than an agency's self-description. That is the same standard this checklist asks you to apply: a claim counts when its records, its method and its caveats are visible.
Using the checklist alongside GPI criteria
Use the directory criteria as a pre-screen to build a shortlist of agencies whose claims are already documented, then run the eight-field checklist as the post-shortlist diligence layer. GPI evaluates evidence; it does not run client campaigns or audit specific agencies for articles like this one, so the field-level work and the graded decision remain yours.
The decision this checklist is meant to settle
The checklist resolves to one of three outcomes: sign, sign with remediation clauses written into the contract, or walk away. Each rests on graded evidence with file references rather than on how the pitch felt. Bain's framing that today's growth requires a clearer, data-backed edge applies to agency selection as much as to the deals it describes. An agency that meets the standard has shown you, before signature, how it will report to you after it.
FAQ
How long should marketing agency due diligence take?
Long enough to receive and grade every field before the final pitch, which is usually set by your own request format rather than by the agency. Complete, clearly labeled documents let reviewers work in parallel, as data room guidance describes; a vague request list is the most common cause of delay.
What if the agency refuses to share raw platform exports?
Treat the affected claims as unverifiable rather than false, and record them that way. Then decide whether an unverified performance field is disqualifying for the retainer size you are considering; for a large or long commitment it usually is.
Can we rely on the agency's own attribution reports?
They are useful for direction and diagnosis, and they are not proof of incremental revenue. Ask what was tested with a holdout or geo design and what was assumed, and weight the reports accordingly.
Do we need consent records for audiences the agency built for other clients?
Yes, for any audience or list the agency proposes to reuse on your behalf. The proof burden sits with the sender, and thin records are a latent liability regardless of whether complaints exist; if provenance cannot be shown, do not use the audience.
How much diligence is proportionate for a small retainer?
Scale the field set to risk. A small project can lighten financial stability and roster analysis, but data ownership, consent provenance and exit terms should never be skipped, because those are the fields that cost most to unwind.
Who should own the final sign-off on an agency selection?
Marketing owns the judgment on capability and fit; procurement owns commercial terms and compliance sign-off; both record their grades against the same file references. GPI's guidance on the split between marketing and procurement in agency selection sets out that division in more detail.

