Buying an SEO company, whether you are selecting a long-term provider or evaluating a business for acquisition, is a due diligence exercise. The decision should not rest on polished rankings, recognizable logos, or a small collection of successful case studies.
Those materials may be relevant, but they are selected by the seller and rarely show how the company behaves when a plan underperforms, a team member leaves, a site migration goes wrong, or a search change invalidates an assumption.
The asset you are evaluating is the operating system behind the work. That system includes discovery, technical review, content planning, approvals, implementation, quality assurance, reporting, escalation, and adaptation.
It also includes the people who own each stage, the accounts and code controlled by the client, and the evidence retained when decisions are made. A useful starting point is the agency's documented system for navigating volatility, not a promise that any specific result will occur.
The inputs for a sound decision are historical artifacts, team interviews, client references, retention data, technical samples, compliance controls, account ownership records, and a draft contract. The decision criteria are consistency, transparency, specialist fit, implementation quality, dependency risk, accountability, and alignment with your business model.
The buyer should appoint one owner for the evaluation and involve technical, content, legal, finance, and business stakeholders where their judgment is needed.
The sequence in this guide moves from evidence to risk and then to contract design. First, inspect historical work. Next, test how the agency handles current search features and entity clarity without relying on vague AI language.
Then review regulated-content controls, technical debt, client retention, and ownership. Finally, convert the findings into explicit deliverables, responsibilities, access rights, and exit terms.
The output should be a written buying memo that records what was verified, what remains uncertain, which risks are accepted, which conditions must be resolved, and why the selected company is suitable for the work. Results cannot be guaranteed. Process quality, ownership, and reviewability can be assessed before signing.
Key Takeaways
- 1Request real, anonymized work from 18 months ago so you can compare the stated process with the process that was actually used.
- 2Test whether the agency can explain how it maintains visibility within AI Overviews and LLM responses without promising inclusion or inventing a special markup requirement.
- 3Map every critical dependency, including people, tools, publishing access, approvals, and the method used for how to measure search results.
- 4Apply a separate regulatory review when legal, healthcare, or financial content requires subject matter approval and documented controls.
- 5Contract for named artifacts, decisions, owners, and review points instead of guaranteed rankings or traffic.
- 6Inspect technical debt, account ownership, code changes, migration practices, and vendor lock-in before accepting the delivery model.
- 7Review retention, departures, and post-mortems as operating evidence rather than treating client logos as proof.
- 8Require every material claim in the buying process to connect to a document, workflow, owner, or independently reviewable record.
1How Do You Verify That the Delivery Process Is Real?
Start with ordinary delivery records rather than a sales demonstration. Request anonymized material from a client engagement that has been active for at least 18 months, subject to confidentiality limits, and ask the agency to explain how each record was used.
Useful evidence includes discovery notes, technical findings, implementation tickets, content briefs, source lists, approval records, quality checks, reporting commentary, and records of changes in direction.
Choose a representative recommendation and reconstruct its full path. Identify who found the issue, which evidence supported the recommendation, who approved the work, who implemented it, how the change was tested, and what the team did after observing the result. This reveals whether the agency has a repeatable decision process or merely a collection of polished documents.
Compare work from two years ago with recent work while allowing for legitimate changes in search guidance, client needs, and service scope. The question is not whether the documents look identical. It is whether the agency applies consistent standards for evidence, ownership, review, and follow-through.
Large unexplained differences between account teams may indicate that delivery quality depends on individual memory rather than shared controls.
Ask delivery leaders to walk through a project that underperformed. A useful post-mortem identifies the original assumption, the contrary evidence, the decision owner, the corrective action, the client communication, and the change made to prevent recurrence. The buyer should be able to distinguish a mature learning process from retrospective storytelling.
Finish with an evidence table that links every material sales claim to a historical artifact, an accountable person, and a verified example. Where confidentiality prevents document sharing, request redacted structures, screen-shared walkthroughs, and process evidence that can be examined without exposing client data.
2Can the Agency Discuss AI Search Without Making Unsupported Promises?
Evaluate AI search capability through a real client example, not through a vocabulary test alone. Ask the agency to show how it establishes consistent names, ownership, authorship, services, sources, and relationships across the site and relevant public records.
The team should explain how those facts are made understandable to users and search systems without claiming that a schema type or content pattern guarantees inclusion in Google AI Overviews.
Request the research record for a topic where the client sought visibility. Review the questions selected, the sources used, the claims that required primary evidence, and the additions that made the page more useful than a generic summary.
Structured data may describe visible facts, but it should not be presented as a mechanism that forces an AI feature to cite the page.
Ask how the agency samples AI feature visibility. A sound method records the query, market, device or interface context, date, observed source or recommendation classification, and known limitations.
It separates an observed citation from a commercial outcome and never converts a recorded recommendation into a claim that a user chose the client.
The team should also explain how traditional results and AI features are reviewed together. The old top 10 blue-link view is no longer the only presentation a buyer may care about, but it remains part of search visibility and should not be dismissed.
Look for measurement that distinguishes branded appearance, cited-source appearance, organic landing-page performance, and qualified business actions.
The final output should be a written readiness assessment containing the agency's assumptions, evidence rules, monitoring method, owners, and limits. Clear uncertainty is a positive signal. Claims that the agency can make a client the preferred answer should be treated as sales language unless supported by a precise, reviewable method.
3What Controls Are Required for a Regulated Engagement?
A regulated engagement adds risks that a generic content workflow may not control. The buyer should identify the applicable professional, advertising, privacy, data, and recordkeeping requirements before evaluating the agency.
The SEO company does not replace legal, medical, financial, or compliance counsel, and it should be willing to work inside the review structure defined by the client.
Inspect the approval path for a representative page. Who drafts the content? Which sources are permitted? How are claims checked? Who verifies credentials? Which client subject matter expert or compliance reviewer approves publication? Where is that approval recorded? What happens when a regulation, service, author, or disclosure changes?
Ask for the process used to handle sensitive information. A healthcare workflow may need controls related to HIPAA, but the exact requirements depend on the data, systems, and role of each party. A legal workflow may need jurisdiction-specific review under bar association rules.
A financial workflow may involve SEC-related considerations or other applicable oversight. The agency should describe its operational boundaries and defer legal conclusions to qualified reviewers.
Review author and editorial records. Anonymous production is not automatically prohibited, but the public page should accurately represent authorship, review, and responsibility. The agency should not invent credentials or imply specialist approval that did not occur. It should retain source notes and revision history sufficient for the client to review material claims.
Check how citations and links are selected. High-trust content should use relevant, accurate sources and avoid treating a third-party statistic as verified when the supporting source is absent. If a previously published number cannot be reconciled, the workflow should flag it for correction or qualified framing rather than silently repeating it as fact.
The output is a compliance responsibility matrix covering drafting, fact checking, specialist review, legal approval, technical publication, privacy, and retention. The contract should identify which party owns each decision and what happens when approval is delayed or denied.
4Which Technical Liabilities and Dependencies Will You Inherit?
Technical due diligence should determine whether the agency leaves clients with maintainable assets or with systems that only the agency can operate. Current rankings and visually polished reports do not reveal undocumented redirects, fragile plugins, personal-account access, manual deployment steps, abandoned integrations, or unresolved indexation problems.
Request a walkthrough of technical records from established client work, subject to permission and anonymization. Review issue inventories, prioritization notes, implementation tickets, release checks, incident records, migration plans, monitoring alerts, and accepted risks.
For each material recommendation, ask what the agency controlled, what depended on the client, and how completion was verified.
Map ownership across domains, hosting, analytics, Search Console, tag management, repositories, content systems, licenses, dashboards, and automation. Proprietary software can be appropriate, but the buyer needs clear export rights, data access, replacement cost, continuity arrangements, and a list of functions that stop after termination.
Inspect the agency's approach to information architecture, internal linking, status codes, canonicals, indexation controls, structured data, site performance, and migrations. For large sites, require evidence showing how crawl behavior is diagnosed rather than accepting a generic statement that crawl budget is optimized.
For migrations, review ownership of redirect mapping, pre-launch testing, launch approval, rollback planning, and post-launch validation.
The output is a dependency register showing every critical asset, current owner, access level, documentation status, replacement risk, and handover requirement. Unresolved ownership or access issues should become contract conditions rather than assumptions.
5How Should Retention and Churn Influence the Buying Decision?
Retention is useful evidence only after the buyer understands how it is calculated. Ask the agency to define an active client, a completed project, a pause, an expansion, and a departure. If average tenure is less than 12 months, investigate the service mix, onboarding quality, fit, delivery capacity, and reasons for exit rather than assuming one cause.
Long relationships can indicate continuing value, but duration alone is not proof. The company may have clients retained for 3, 5, or 10 years, yet the buyer still needs to verify that the work remains active, relevant, and appropriately staffed. Contract length, switching cost, account concentration, and limited alternatives can also influence tenure.
Request cohort analysis by service, market, client size, account lead, and start period. Reconcile the headline figures with CRM or invoicing records where appropriate, and apply the same inclusion rules throughout.
Then review why the most recent departing clients left. Distinguish agency error, strategic mismatch, client constraints, budget changes, completed scope, and external events.
A useful post-mortem records the departure reason, supporting evidence, client communication, internal owner, corrective action, and recurrence check. An agency that blames every exit on the client or search changes is not demonstrating accountability. An agency that accepts every departure as its fault is not necessarily being accurate either.
Speak with a long-tenured client, a recently onboarded client, and, where possible, a former client. Compare their descriptions of staffing continuity, communication, implementation, reporting, and problem handling.
The output should be a retention memo that states the definitions used, cohort differences, concentration risk, departure findings, and operating changes.
6What Must the Agreement Specify Before Work Begins?
The agreement should convert due diligence findings into responsibilities that both parties can inspect. Broad promises about optimization, outreach, strategy, or Page 1 performance do not explain what will be delivered, who will approve it, where it will be implemented, or how quality will be judged.
List the required artifacts for the actual scope. These may include technical findings, implementation specifications, content briefs, reviewed drafts, source records, release checks, measurement notes, and decision logs.
For every artifact, define the owner, required client input, due condition, acceptance standard, revision process, and storage location. Avoid selecting quantities merely because they are easy to count.
Separate controlled work from externally influenced outcomes. The agency can control research, recommendations, production, implementation within its access, quality checks, and reporting. It cannot guarantee rankings, traffic, Google AI Overview citations, leads, or revenue. The scorecard can monitor outcomes, but the contract should state the dependencies and limits clearly.
Define ownership of content, code, data, accounts, research, creative assets, reports, technical configurations, and custom tools. State how credentials are managed, which systems remain client-accessible, which licenses are transferable, and what must be exported at termination.
Add service levels for communication, approval requests, incidents, and escalation. Strategy changes should require documented evidence, impact assessment, an accountable decision, and a scope update when necessary.
The exit schedule should cover handover records, open work, repositories, source files, account access, redirects, historical data, and transition support.
The final contract attachment should let a new stakeholder understand what is being purchased, how it will be reviewed, which dependencies belong to the client, and what the client retains after the relationship ends.
7What Most Guides Get Wrong
A weak buying process treats an agency's position for a broad query as decisive proof. Ranking #1 for a generic SEO phrase may reflect the seller's own marketing choices, but it does not show that the delivery team can work inside your market, technical stack, approval process, or risk tolerance.
The opposite is also true: a capable legal or healthcare specialist may generate most of its demand through referrals, partnerships, or narrow commercial queries rather than a public contest for a broad agency term.
The more useful test is operational. Ask how research becomes a recommendation, how implementation is approved, how subject matter review is recorded, how technical changes are validated, and how the team responds when evidence contradicts the plan.
Headcount and proprietary software deserve the same caution. A large writing team can produce uneven work, and a custom platform can create dependency without improving decisions. Buyers should assess whether people, data, content, technical execution, reporting, and ownership operate as one reviewable system.
8What I Wish I Knew Earlier
Early buying decisions are easy to distort with novelty. A proprietary dashboard, an impressive ranking, or a confident founder can feel more valuable than a routine operating record. Over time, the more dependable signal is whether the company can explain and document how work moves from evidence to decision, implementation, review, and correction.
The strongest service businesses are often operationally unremarkable in the best sense. They keep versioned records, assign owners, disclose uncertainty, preserve client access, review failures, and improve the system without pretending that every change was predictable. Their quality does not depend entirely on one charismatic person remembering what to do.
When buying an SEO company, I now place more weight on calm operating maturity than on claims of a secret advantage. The question is not whether the team has ever produced an exceptional result. It is whether the buyer can verify what the team does repeatedly, understand the limits, and retain the assets needed to continue if the relationship changes.
9A 30-Day Buyer Due Diligence Schedule
Evidence review: Days 1-5
Collect real historical records from at least three engagements and trace representative decisions from discovery through validation.
Outcome: An evidence table showing which claimed capabilities are supported by routine delivery records and which remain unverified.
Search-feature review: Days 6-10
Examine how the agency researches, samples, classifies, and reports Google AI Overviews and other LLM visibility.
Outcome: A documented assessment of AI search capability, measurement limits, evidence standards, and accountable owners.
Team interviews: Days 11-15
Interview the technical and content leaders who will own delivery, then compare their explanations with the reviewed records.
Outcome: A clear map of the people, responsibilities, review controls, and key-person dependencies behind the proposed service.
Technical review: Days 16-20
Inspect maintenance history, ownership, access, migration controls, proprietary dependencies, and unresolved technical risk.
Outcome: A dependency register showing asset ownership, technical liabilities, continuity requirements, and conditions for handover.
Retention review: Days 21-25
Reconcile churn definitions and cohorts, interview references, and review a redacted departure post-mortem.
Outcome: A retention memo that explains tenure, departures, capacity, accountability, and operating changes without relying on a headline rate.
Contract design: Days 26-30
Convert the findings into named artifacts, owners, acceptance rules, access rights, change controls, and exit obligations.
Outcome: A contract schedule that makes delivery, measurement, dependencies, ownership, and termination reviewable.