Operational due diligence, and what they check first
Five questions. See whether you would pass a diligence check tomorrow.
Would you pass one tomorrow?
Five areas. Answer for what you could produce tomorrow, without a scramble.
1. Entity and authority
Good standing in every state you operate in, and who can sign what.
2. Delivery risk
What happens if your key person is unavailable, and who does the work.
3. Money and cover
Insurance certificates, invoicing terms, and financials you could hand over.
4. Data and access
Who can see a customer system, and what happens the day somebody leaves.
5. Records
Signed contracts, change control, and being able to show who did what and when.
Producible tomorrow, without a scramble
0 of 5
Answer the five to see where you stand.
The read
Do this next
Show the reasoning
A second opinion
Have one landing on your desk right now?
We reply within one business day.
Diligence readiness is one of six areas in the broader business health check, which is the better starting point if a sale or a raise is not the immediate reason you are here.
What this usually leads to
See alsoBusiness documents legal operations invoice faster or chase harder
Saved in this browser, nowhere else. See all your answers together · All twenty-five tools
The questionnaire arrives after you have won the work, and somebody in procurement or risk has to sign off by asking questions nobody at your company owns. The delay is rarely bad answers. It is answers living in six places and three heads, assembled under time pressure.
What you get
Who you are
Entity in good standing wherever you operate, ownership clear.
Whether you can deliver
Concentration risk, subcontractors, and real capacity.
Money and cover
Certificates that are current and name the right entity, invoicing that runs on a rhythm.
Data and access
Who can see a customer system, and what happens the day somebody leaves.
They are not testing whether you are good
This almost never arrives as a diligence process with a name. It arrives as a spreadsheet from somebody in procurement, or a list of attachments a bank needs, or a founder asking what happens if you get hit by a bus. It lands after you have already won on merit, which is what makes it so frustrating: the hard part is done and the delay is administrative.
And the delay is the real cost, not the outcome. Most competent companies would eventually pass. What they lose is three weeks assembling answers under time pressure while the other side watches, and watching a company assemble basic facts about itself is itself information. It suggests the same thing would happen if something went wrong mid-contract.
A buyer asks who releases payments. This is the answer worth being able to give. One of the documents they ask for now. How to write an AI policy. If the diligence in question is a funding round, preparing for a raise covers what breaks first.
The thirteen questions, and what each one is really for
Almost none of these is asking what it appears to ask. The good standing question is not about the filing, it is about whether anybody owns the calendar. The key person question is not curiosity, it is the risk they are most often burned by. Answering the surface question well and missing the real one is how competent companies still fail these.
| What they ask | What they are testing | What a weak answer tells them |
|---|---|---|
| Is the entity in good standing everywhere you operate? | Whether anybody owns the compliance calendar. It is the cheapest possible signal of whether the rest is looked after. | That an administrative failure went unnoticed. They now assume others have too. |
| Who is authorized to sign this? | Whether authority is defined or improvised. Also whether the person negotiating can commit. | That a contract might later be disputed as unauthorized, which is their risk, not yours. |
| What happens if your key person is unavailable for a month? | Concentration risk. This is the question most often asked politely and weighted heavily. | That they are buying one person rather than a company, and that person is not on their payroll. |
| Employees or subcontractors, and who exactly? | Whether their work will be done by people they have not vetted, and whether classification is clean. | That there is a compliance exposure attached to their contract that they did not agree to. |
| What is your capacity right now? | Whether you will take the work and then discover you cannot staff it. They have been burned before. | That the answer is being calculated for the first time in the meeting. |
| Do you carry the insurance the contract requires? | Whether the certificate exists today, names the right entity, and has not lapsed. | A scramble here reads as a company that renews things when reminded. |
| How fast do you invoice, and what are your terms? | Whether your cash cycle is stable enough that you will still be here in eighteen months. | Erratic invoicing suggests the finance function is somebody doing it when they get time. |
| Who at your company can see our data? | Whether access is granted deliberately or accumulated. The follow-up is always about removal. | That the list cannot be produced, which means it is longer than anybody thinks. |
| What happens to access when somebody leaves? | The single most predictive security question for a company this size, and the one most often unanswered. | That former staff probably still have access, and nobody would know. |
| Have you had an incident, and what happened? | Honesty, and whether there is a process. A well-handled incident is a better answer than none. | A flat no with no detection capability behind it reads as not having noticed. |
| Where are the signed contracts? | Whether records survive the person who made them. | That the relationship depends on goodwill and memory rather than documents. |
| How do you handle a change of scope? | Whether there is a change process or whether extra work is absorbed and later argued about. | That disputes are likely, and that they will be resolved by whoever is more stubborn. |
| Can you show who did what, and when? | Whether an audit trail exists at all. In regulated buyers this one is disqualifying. | That nothing can be reconstructed after the fact, including in your own defense. |
Notice how many are about whether something is written down rather than whether it is good. That is the whole pattern. They are not auditing your judgment, they are testing whether the company works when the person in the room is not there.
The order to fix them in, and roughly what each takes
Do not start with the hardest. Start with the ones that are cheap, fast, and most visible to somebody forming a first impression, because those buy you the benefit of the doubt on the slower ones.
- Good standing and the compliance calendar, a few daysCheck every state you operate in, fix what has lapsed.
- The access list, about a weekWrite down who can see what, across every system.
- Offboarding, a day to write, ongoing to holdA checklist that runs every time somebody leaves, with a name against it.
- Insurance and the certificate, a dayConfirm the coverage matches what your largest contracts require.
- Signing authority, a dayWrite down who can commit the company to what, and up to what value.
- Contract storage, about a weekOne place, searchable, with the executed version rather than the draft.
- Key person cover, several weeksThe slow one, because it means documenting what only one person knows.
- Change control, a fortnightA written path for scope changes, including who approves and how it is recorded.
Questions we get
We are not raising or selling. Does this still apply?
More than if you were. The commonest version of this is a large customer sending a vendor questionnaire, and that happens to companies with no intention of ever raising anything.
How long does it take?
Two to four weeks for most of it, and days for the parts that matter most on first impression. Good standing, the access list, insurance and signing authority are the fast ones.
What if we fail on something?
A known gap with a plan is treated very differently from a gap discovered during the process. Procurement and lenders deal with imperfect companies constantly. What they cannot price is surprise.
Who should own this internally?
One person, named, and not necessarily senior. Most of it is assembly and maintenance rather than judgment, and it fails when it belongs to everybody.
More in the guides and every answer in one place.
Shaheer leads the work, with engineers, writers, filers and analysts behind him. C-suite operations for a San Francisco AI company, Six Sigma on the process side, Anthropic certified on the Model Context Protocol, ten years across eight industries. See what we have built
Read next
The four areas this breaks into, and where each one is covered properly.