Insights

How to Use Legal AI to Produce Red Flag Reports For Due Diligence

A red flag report surfaces the legal risks that could reshape an M&A deal. Learn what belongs in one and how AI reviews the full data room for hidden risk.

by Harvey TeamSep 9, 2026

A live data room holds thousands of documents, the deadline is measured in days, and a partner or a general counsel weighing an acquisition needs to know one thing quickly. What in this target could change the price, reshape the structure, or turn a likely yes into a no?

Every reviewer on the matter feels the same pull. Move fast enough to keep the deal on schedule, and miss nothing that a court, a regulator, or a board would later say should have been caught. Read every page and you blow the timeline. Sample the set and you gamble on what you skipped. That tension has defined diligence review for as long as data rooms have existed.

What has changed is the economics of review. For the first time, reading the entire data room is affordable, and that single shift is quietly redefining what a red flag report can be. This guide explains what the deliverable is, how full-coverage AI review changes it, how verification keeps it trustworthy, and how to tie every flag to your organization's own view of risk.

Understanding the Due Diligence Red Flag Report

A red flag report is a due diligence deliverable that flags only the material legal risks found in a target's documents, such as change of control provisions, litigation exposure, or missing consents. It gives deal teams a prioritized view of what could affect valuation, deal structure, or the decision to proceed.

A long-form diligence report is a different document. It records what the documents say across every category a buyer asked about, from corporate records to employment to intellectual property. A red flag report does less on purpose. It elevates only the findings that could change the deal, and it leaves the exhaustive record to the longer report and any deal summary prepared alongside it.

Experienced reviewers know the usual suspects. They include change of control provisions that let a counterparty walk when ownership shifts, assignment restrictions that block the transfer of a key contract, and litigation that could outlast the closing. Missing consents or signatures, non-compete and exclusivity terms, and data protection gaps round out the list. A red flag report surfaces these and ranks them so the deal team can act on the ones that matter.

Rethinking Red Flag Review With AI

The red flag report was never really a preference. It was a triage response to a problem no one could solve. Reading every document in a large data room, consistently and under deadline, cost more time and money than most deals could justify. So deal teams sampled and prioritized, and the red flag report became the elegant output of that compromise.

AI for due diligence changes the input to that equation. A tool that reads the full set can extract terms and surface risk signals across every document, so prioritization no longer depends on which files a reviewer had time to open. The report can now rest on complete coverage while still reading like the same focused deliverable.

This is the capability at the center of the shift. Harvey extracts terms and insights across a large volume of documents and identifies and summarizes the potential risks or issues a reviewer needs to weigh. The reviewer still decides what matters, and the raw work of finding candidate issues no longer scales with headcount and hours.

The pattern already shows up in practice. Emerging Trends for the Evolving Business of Law documents a diligence workflow that uses Harvey to classify documents, apply prompts by document category, and produce summaries. The same workflow flags missing information, rates risk, and suggests next steps such as an information request, a warranty, or a closing condition. It produces a preliminary risk assessment and a draft report for the team to review, with reported time savings of 15% to 20% on structured diligence and up to 75% on unstructured data rooms.

One caution belongs up front. The AI's risk output is only a first draft, and a qualified lawyer decides what it means for the deal. Every flagged issue needs review and confirmation before your organization relies on it, and no summary or risk rating should stand as a legal conclusion on its own.

What makes the approach useful is that the tool reads legal meaning inside the documents. It recognizes that a clause is a change of control provision, weighs whether a required consent is missing, and produces a risk view the reviewer can act on. The output is analysis a lawyer can check, expressed in the categories diligence already uses.

Full Document Review Across Thousands of Contracts

The red flag that sinks a deal is rarely the obvious one. The obvious risks get found early, when attention is fresh and the important agreements sit at the top of the pile. The dangerous flag is the assignment clause in agreement four thousand, or the indemnity buried in a schedule to a minor contract, found late if it is found at all.

Manual review degrades across a large, heterogeneous set. Consistency can slip after a reviewer is a few hundred documents in, standards drift between reviewers, and a sampled read can miss precisely what a full read would have caught. The limit is arithmetic. A person reading under deadline can hold only so much.

Full-coverage extraction is what closes the gap, and the results show up in real deals. According to RSGI's report The Accelerating Impact of AI, Flex uses Harvey for M&A due diligence across 15,000 supplier contracts that once required manual review. Since adopting it, the average cost of a deal has fallen by roughly 30%. The saving is the smaller story. What matters is that the team can work through a set that large with more certainty and fewer hallucinations.

Coverage is the protection. When Harvey identifies and summarizes potential risks across the full document set, nothing material sits unread because a reviewer ran out of hours. The reviewer's judgment then applies to a complete set of candidate issues, with the whole data room behind it.

The data room itself does not move. It stays where diligence already keeps it, such as a document management platform, and Harvey reads and analyzes what is there. The coverage comes from how thoroughly the set is read, while the documents stay in place.

Verifying Every Flag Against the Source Document

A flag is only as good as the reviewer's ability to check it. A risk rating with no path back to the clause that triggered it is an assertion, and assertions do not survive the scrutiny of a counterparty, a regulator, or your own deal committee. Verification is what turns a surfaced issue into a finding a team can stand behind.

This is a governance point as much as a technical one. The Legal AI Governance Imperative in Practice frames accuracy and output integrity as a matter of taking responsibility for the outputs a team reviews and relies on. A team should be able to answer questions about its work with evidence and a clear audit trail, and a red flag report is exactly the kind of work that invites those questions.

Citation grounding is what makes that trail practical. Each flagged issue links back to the exact clause and document it came from, so a reviewer can open the source and confirm the call in seconds. The report becomes a set of claims a lawyer can check, one flag at a time, each one anchored to the text that produced it.

The habit is already visible in how skilled practitioners work. Perspectives on Legal AI's Power Users describes the most capable users interrogating large document sets iteratively, pushing on the output until they reach the essentials, and treating each answer as a draft to check. Experienced lawyers assume the output will not be right every time, and they build that assumption into how they use it.

That assumption reflects a basic professional responsibility. A lawyer who relies on a tool is expected to understand what it does well, where it falls short, and how to check its work. AI-generated output supports the reviewer's judgment and never stands in for it, and the lawyer who signs the report owns every flag in it.

Setting Materiality Thresholds in Due Diligence

Not every red flag is red in every deal. A change of control provision that sinks a carve-out acquisition can be immaterial in an asset purchase, depending on the thesis, the sector, and the representations and warranties at issue. Materiality is a function of the deal, and a fixed due diligence checklist will over-flag some risks and under-weight others.

This is where a general-purpose tool and a legal one part ways. A generic model applies generic notions of what matters, drawn from the internet at large. The value for a deal team comes from a tool that applies your organization's own precedent, your prior deal standards, and your definitions of what rises to a flag. The same clause reads one way for a buyer with a history of earn-out disputes and another way for a buyer without that experience.

In practice, a reviewer sets the risk categories and materiality thresholds for the matter before the review runs. The same document then surfaces different flags depending on the criteria applied. A data protection gap might be a headline risk in one deal and a footnote in another, close to what a policy gap analysis does when it measures a company's policies against a standard.

Harvey applies the criteria and precedent your team defines when it reviews and analyzes the set. Reusable prompt workflows, available as Harvey Playbooks, let a team codify how it wants a category reviewed so the same standard runs across matters. The judgment about what counts stays with your organization, encoded in the criteria the tool applies.

Building a Reliable Red Flag Report Process

A red flag report holds up when the process behind it is repeatable and reviewable. A one-off review that lives in one associate's head is hard to defend and harder to reproduce. A defined process, run the same way each time, is what lets a team stand behind the output and improve it deal over deal.

A dependable workflow runs in five stages.

  1. Scope the matter: Set the risk categories and materiality thresholds for this deal before any review begins, so the criteria are explicit and agreed.
  2. Run extraction across the full set: Read every document in the data room and pull the terms and risk signals that matter.
  3. Cluster and rank: Group the issues by type and rank them by severity, so the most consequential flags rise to the top.
  4. Tie each flag to its source and a next step: Link every issue to the exact clause and document it came from, and attach a recommended action, such as an information request, a warranty, or a closing condition.
  5. Route for human sign-off: Send the draft to a qualified lawyer to review and confirm every flag before the report reaches the deal team.

Diligence is multi-stakeholder work, and it lives in the tools a team already uses, such as Word, email, a document management platform, and legal document comparison software. A workflow that stays inside those tools reduces friction, because reviewers keep working in the places they already know without exporting files between them.

Across these stages, Harvey handles the extraction, risk identification, and summarization, while the reviewer keeps judgment and sign-off. The tool does the reading at scale, and the lawyer does the deciding, which is the division of labor a defensible process needs.

The Future of AI in Due Diligence

Full-coverage, source-linked risk review is on its way to becoming the baseline expectation for diligence. As tools make it practical to read an entire data room, sampling starts to look less like prudent triage and more like an accepted gap. A buyer, a board, or a regulator will increasingly assume that every material issue has surfaced and that each one can be traced to its source.

Once coverage is a given, the edge moves to judgment. When every team can read the whole set, the difference is in the quality of the questions asked. It also lives in the materiality thresholds set for the deal and the reading a seasoned lawyer applies to what the review surfaces. The scarce skill shifts from finding the issues to knowing which ones change the deal.

This is where Harvey fits. It delivers the full-coverage extraction, risk identification, and summarization this article has described, and it grounds every flag in its source so a reviewer can verify it fast. That combination is what legal AI makes possible, letting your organization give complete coverage and keep judgment where it belongs, with the lawyer. See how Harvey works on your diligence documents in a live demo.

Frequently Asked Questions About Red Flag Reports

How is a red flag report different from a long-form due diligence report?

A red flag report elevates only the material risks that could change the deal, so the deal team can act on the important issues quickly. A long-form diligence report documents findings across every category a buyer reviewed, whether or not each one affects the decision.

Who prepares a red flag report?

Outside deal counsel usually prepares it, or an in-house legal or corporate development team working from the target's data room. Whoever prepares it, a qualified lawyer reviews and signs off on the flags before the deal team relies on them.

Can AI write a red flag report?

AI can draft the preliminary risk assessment and surface candidate flags across the full document set, which is where it saves the most time. A qualified lawyer must review and confirm every flag before anyone relies on it, and AI output should be treated as a draft to check, with the reviewing lawyer responsible for the final report.

What belongs in a red flag report?

Each material issue belongs, along with its severity, the source document it came from, and a recommended next step, such as an information request, a warranty, or a closing condition. The goal is a prioritized, verifiable view of the risks that could affect valuation, structure, or the decision to proceed.