IP insight
The IP Risk Register Most Boards Skip — And the 12 Rows That Prevent a Due Diligence Disaster
Hayat Amin · Updated 2026-10-06
78% of due diligence delays trace back to IP-related risks. The IP risk register is the governance document most boards skip — and the one acquirers build against you on day one.
78% of acquisition due diligence delays trace back to IP-related risks — not financials, not compliance, not cyber. Yet fewer than one in five boards maintains a formal IP risk register. Hayat Amin argues that this gap is the single most expensive governance failure in tech: "Every acquirer builds an IP risk register during due diligence. The question is whether you build yours first or they build it for you. The version they build always costs more."
According to a 2025 Ocean Tomo study, intangible assets now represent over 90% of S&P 500 market capitalisation. The document that tracks and scores the risks to those assets — the IP risk register — is the governance blind spot most boards cannot afford to leave blank.
What Is an IP Risk Register?
An IP risk register is a living governance document that catalogues, scores, and tracks every intellectual property risk that could destroy deal value, trigger litigation, or compromise competitive advantage. It sits alongside the financial risk register and the cybersecurity risk register as a board-level oversight tool — except most companies never build one.
The format is straightforward: a spreadsheet with one row per risk, scored on likelihood and impact, assigned an owner, and reviewed quarterly. What makes it valuable is not the format but the forcing function. The act of cataloguing IP risks exposes the gaps that due diligence will find anyway.
Beyond Elevation builds IP risk registers as part of every fractional Chief IP Officer engagement. The register typically surfaces three to five critical risks the board did not know existed — risks that would have appeared for the first time in an acquirer's diligence report.
Why Do Most Boards Skip the IP Risk Register?
Most boards skip the IP risk register because IP risk falls between legal and finance and is owned by neither function. The general counsel treats patents as legal filings. The CFO treats them as amortisation schedules. Nobody tracks the operational risk — the expired maintenance fee, the contractor without an assignment clause, the trade secret with no access log.
This is not a documentation problem. It is an ownership problem. Financial risk has a CFO. Cyber risk has a CISO. IP risk has nobody — until the acquirer's diligence team arrives and assigns themselves the role.
Hayat Amin's view is direct: the company that assigns IP risk ownership before due diligence controls the narrative. The company that does not assigns it to the buyer's lawyers, who will use every gap they find as a price reduction.
What Are the 12 Rows Every IP Risk Register Needs?
Every IP risk register needs a minimum of twelve risk categories to cover the territory that acquirers, investors, and litigation opponents will probe. Miss one category, and the gap becomes a negotiation lever against you. Hayat Amin's IP Risk Register Framework organises them into four blocks: ownership, protection, commercial, and compliance.
Block 1 — Ownership Risks
Row 1: IP assignment gaps. Every employee, contractor, and co-founder must have a signed IP assignment agreement that transfers ownership of work product to the company. A single missing assignment can cloud ownership of core technology. The IP assignment gap problem has killed more deals than patent disputes have.
Row 2: Co-founder IP ownership. If co-founders contributed IP before incorporation, pre-incorporation assignment agreements must exist. Without them, a departing co-founder can claim ownership of foundational technology — and the claim has legal standing in most jurisdictions.
Row 3: Third-party IP dependencies. Any technology licensed from a third party — SDKs, APIs, datasets, open-source components — creates a dependency risk. Map every dependency to its licence terms, termination triggers, and the business impact if that licence is revoked tomorrow.
Block 2 — Protection Risks
Row 4: Patent maintenance lapse. A missed maintenance fee forfeits patent rights permanently in most jurisdictions. Companies with portfolios of ten or more patents and no automated docketing system face a 15% annual probability of an accidental lapse. One lapse in a core patent can wipe out millions in portfolio value overnight.
Row 5: Trade secret exposure. Trade secrets require active protection — access controls, NDAs, documentation of reasonable security measures. A single breach without documented safeguards can void trade secret status entirely. The seven-rule trade secret policy framework Beyond Elevation deploys covers the controls courts require to prove reasonable measures.
Row 6: Open-source licence contamination. Copyleft licences such as GPL and AGPL can require disclosure of proprietary source code if compliance is mismanaged. Every codebase needs an open-source compliance audit before any transaction — and the audit needs to be repeated every six months because developers add dependencies constantly.
Block 3 — Commercial Risks
Row 7: Freedom-to-operate gaps. Selling a product without a freedom-to-operate analysis exposes the company to injunction risk. An FTO gap discovered during diligence signals either negligence or hidden litigation exposure. Neither is a message you want to send to a buyer.
Row 8: Licensing agreement exposure. Existing licence agreements may contain grant-back clauses, most-favoured-licensee provisions, or change-of-control triggers that activate during an acquisition. Each agreement needs a clause-by-clause risk score before any transaction process begins.
Row 9: Data asset ownership ambiguity. If the company collects, processes, or generates data with commercial value, ownership must be contractually clear across every source — user agreements, vendor contracts, partnership terms. Ambiguous data ownership reduces data asset valuation by 30% to 60% in diligence.
Block 4 — Compliance Risks
Row 10: Cross-border registration gaps. Patents, trademarks, and design rights are territorial. If the company generates revenue in markets where its IP is unregistered, competitors can copy freely and the company has no enforcement lever. Every revenue-generating jurisdiction needs a registration check.
Row 11: Regulatory IP compliance. The EU AI Act, export controls such as EAR and ITAR, and sector-specific regulations impose obligations that intersect with IP strategy. Non-compliance creates both a regulatory fine risk and an IP validity risk — and acquirers will flag both.
Row 12: IP insurance coverage gaps. IP litigation defence costs average $2M to $5M for a mid-cap patent case. Fewer than 8% of companies under $50M revenue carry IP insurance. The gap belongs in the register because a single infringement claim without coverage can exceed the company's entire annual operating budget.
How Should You Score Each Row?
Score each row on a 5×5 likelihood-by-impact matrix, where likelihood runs from rare (1) to almost certain (5) and impact runs from negligible (1) to catastrophic (5). Multiply the two scores. Any row scoring 15 or above is a red-level risk that requires board-level action within 30 days.
Hayat Amin says the scoring exercise reveals more than the scores themselves: "The first time a board scores its IP risk register, the conversation alone is worth the exercise. Most founders discover they have been carrying a catastrophic-likelihood risk they thought was moderate — usually an assignment gap or a trade secret with no access controls."
The matrix should be reviewed quarterly and updated whenever a material event occurs: a new patent filing, a licensing deal, a departing employee, a new market entry, or any M&A activity. The register is not a one-time document. It is a living governance tool that earns its value through consistent use.
What Happens When Acquirers Build the Register For You?
When an acquirer builds the IP risk register during due diligence, every gap becomes a price chip. A missing IP assignment worth £500 to fix becomes a £500K indemnity holdback. An undocumented trade secret becomes a 10% escrow on the purchase price. The asymmetry is structural and deliberate.
Hayat Amin reminds founders that the buyer's diligence team is incentivised to find problems: "They are paid to find problems. If you hand them a blank IP risk register, they will fill it in — and every line they write costs you money at the negotiation table."
Companies with patents are 10.2x more likely to secure early-stage funding, according to the National Bureau of Economic Research. But the patents themselves are only valuable if the risks around them are mapped and managed. An unmanaged patent portfolio is a liability dressed as an asset.
The difference between a company that presents a clean IP risk register on day one of diligence and a company that does not is typically 60 to 90 days of added deal timeline and 5% to 15% of deal value left on the table.
How to Start Building an IP Risk Register Today
Start with the twelve rows above and score each one honestly. The process takes a competent IP strategist two to three days for a company with fewer than twenty patents and a straightforward licensing portfolio. For complex portfolios the register expands, but the four-block framework stays the same.
Beyond Elevation's fractional Chief IP Officer service includes building the IP risk register as a standard deliverable in the first 30 days of engagement. The register becomes the foundation for quarterly board IP reporting and the document that travels into any future transaction data room.
Book a consultation at beyondelevation.com to start the assessment.
FAQ
How often should an IP risk register be updated?
An IP risk register should be reviewed quarterly and updated whenever a material IP event occurs — a new filing, a licensing deal, a departing key employee, or the start of any fundraising or M&A process. Stale registers are worse than no register because they create false confidence.
Who should own the IP risk register in a startup?
The IP risk register should be owned by whichever executive is responsible for IP strategy — a Chief IP Officer, a fractional CIPO, or the general counsel if no dedicated IP leader exists. The owner presents the register to the board quarterly, the same way the CFO presents the financial risk register.
Can a startup with no patents still need an IP risk register?
Yes. Trade secrets, proprietary data, source code, brand assets, and third-party IP dependencies all carry risk regardless of whether the company holds patents. A pre-patent startup often carries more unmanaged IP risk than a company with a mature portfolio, because nothing has been formally assessed or scored.
What does an IP risk register cost to build?
A standalone IP risk register engagement typically costs £5,000 to £15,000 depending on portfolio complexity. As part of a fractional Chief IP Officer engagement with Beyond Elevation, it is included in the first 30-day deliverable at no additional cost. The ROI is asymmetric: a £10,000 register can prevent a £1M+ due diligence price reduction.
Does an IP risk register replace an IP audit?
No. An IP audit is a point-in-time assessment of what IP the company owns and its current status. An IP risk register is a forward-looking governance tool that tracks threats to that IP over time. The audit feeds the register, but the register lives on as an active board document while the audit sits in a drawer.