Operational Due Diligence

Understand operational risk and integration effort before completion.

Operational due diligence surfaces governance gaps, control exposure, key-person risk and integration effort — early, with evidence.

Used alongside financial and legal due diligence in mid-market acquisitions.

93 Assessment Questions7 Workstreams13 Walkthroughs5 Management Interviews
← Back to Finance Transformation
The Gap

What traditional due diligence covers — and what buyers still inherit

Financial and legal due diligence are essential — but they’re not designed to test whether the business can operate effectively after completion. Operational due diligence focuses on the risks inherited on Day 1: governance, control integrity, process reliability, key-person dependency, and integration readiness. These issues rarely appear in the financial model — but they drive cost, disruption and delay immediately after completion.

Financial Performance

Historical earnings, normalisation adjustments, working capital, net debt. Reviewed as part of financial due diligence.

Tax Compliance

Income tax, activity statements, payroll tax, fringe benefits tax, stamp duty. Reviewed as part of tax due diligence.

Legal & Contracts

Material contracts, litigation, intellectual property, employment agreements. Reviewed as part of legal due diligence.

Property & Assets

Title, valuations, environmental. Reviewed by specialist advisors.

Governance & Accountability

Decision rights, delegations, and approval boundaries — whether they’re documented, followed, and enforceable in practice.

Process Maturity

Whether core processes are documented, repeatable, and scalable — or dependent on workarounds and tribal knowledge.

Key Person & Knowledge Risk

Single points of failure across finance, payroll, operations, customer delivery, and critical supplier relationships — plus the depth of cross-training and documentation.

Systems & Integration Readiness

System landscape and reporting capability, data quality, change-of-control constraints, and the practical path to integration.

Internal Controls & Fraud Risk

Segregation of duties, payment controls, supplier master controls, and the exposure to internal and external fraud scenarios.

Financial Reporting Discipline

Close speed, reconciliation discipline, evidence retention, and audit-readiness under buyer reporting expectations.

The Approach

How operational due diligence works

The engagement runs alongside financial and legal due diligence and is scaled to the size and complexity of the transaction. The goal is simple: provide a clear, evidence-based view of operating risk and integration effort before completion.

1

Scoping & Data Room Request

Confirm transaction context, tailor document requests, and identify the relevant workstreams and interview sessions.

2

Desktop Review

Review data room documentation against structured assessment questions and log preliminary findings.

3

Management Interviews & Walkthroughs

Structured sessions with key roles and live walkthroughs of critical finance and operational processes.

4

Control & Maturity Assessment

Assess governance, internal controls, process maturity and operating discipline across seven workstreams.

5

Findings & Deal Support

Deliver findings register, risk ratings, deal protections and Day-1 integration priorities.

7
Operational workstreams
93
Assessment questions
13
Process walkthroughs
5
Management interviews
Scope of Review

What the review covers

Structured for transactions — not compliance. Each workstream focuses on post-completion realities: integration effort, control gaps, and dependencies that affect continuity and reporting discipline.

The output is a practical, evidence-based view of what works, what doesn’t, and what must be addressed before and after completion — with findings mapped into deal protections, Day-1 priorities, and integration planning.

Integrated Operational Assessment

A consolidated view of operating maturity, cross-workstream risks and integration effort. The seven workstreams combine into a single, evidence-based assessment of how the business actually runs — highlighting the risks that affect continuity, governance and post-completion performance.

A

Governance & Accountability

Decision rights, delegations, oversight, risk ownership, succession planning, and operating cadence.

10 questions
B

Process Maturity & Documentation

Core process coverage, walkthroughs, workarounds, standard operating procedure discipline, and repeatability at scale.

20 questions4 walkthroughs
C

Key Person & Knowledge Risk

Single points of failure, cross-training depth, retention exposure, and relationship concentration.

7 questions
D

Systems, Data & Integration Readiness

System landscape, reporting reliability, data quality, licence constraints, cyber resilience, integration path.

12 questions2 walkthroughs
E

Internal Controls & Fraud Risk

Payment controls, supplier master controls, segregation of duties, contracting discipline, fraud indicators.

16 questions4 walkthroughs
F

Financial Reporting Discipline

Close speed, reconciliation discipline, journal controls, evidence retention, audit readiness, asset controls.

14 questions3 walkthroughs
G

Compliance & Regulatory Readiness

Obligations register, monitoring discipline, workplace health and safety, payroll compliance, insurance, environmental and climate posture.

14 questions
Governance & Control Maturity

Operating maturity and integration effort

A four-level maturity view gives the buyer a concise read on operating risk and integration effort. Informal or Ad Hoc isn’t a deal-breaker — but it must be understood, costed, and planned for.

Ad Hoc

No formal governance. The owner makes every decision, nothing is delegated, and nothing is documented. The business cannot function without them.

Heavy integration

Informal

Some structure exists but it relies on individuals rather than systems. Key-person dependencies are high. Processes work but are not written down or consistently followed.

Significant integration

Defined

Roles are clear, processes are documented, and controls exist. The business can operate with management changes, though some gaps remain. Integration is manageable.

Moderate integration

Managed

Continuous improvement culture with performance monitoring, robust controls, and audit-ready reporting. The business is largely self-sustaining and integration effort is minimal.

Minimal integration
Sample Deliverable

Structured findings, not just opinions

Every finding is logged in a formal register with the evidence source, an estimated impact where possible, a risk rating based on a consistent methodology, a recommended deal protection, and a clear flag for Day-1 integration priorities. This register becomes the single source of truth that connects the due diligence to the Share Purchase Agreement negotiations and the integration plan.

Ref Workstream Finding Rating Quantum Deal Protection Day-1
F-001 Internal Controls No dual approval on banking platform Critical Unquantifiable Condition precedent
F-002 Internal Controls Bank detail changes unverified High $50K–$500K Specific indemnity
F-003 Process Maturity 18-day close, no checklist High Integration delay Financial Controller retention + Day-30 milestone
F-004 Key Person Risk Financial Controller is sole person for close, payroll, system Critical Operational shutdown Retention agreement + knowledge transfer
F-005 Systems & Data 340+ duplicate supplier records High $40K–$80K Price adjustment or escrow
F-006 Process Maturity No purchase order discipline — 85% of spend Medium $80K–$200K/yr Day-1 integration requirement
Engagement Outputs

Decision-ready outputs for the deal team

The engagement produces a structured set of outputs designed for Share Purchase Agreement negotiations, completion planning and post-deal integration.

Due Diligence Report

A comprehensive report on the target business presenting findings by workstream, governance and control maturity assessment, risk ratings, estimated impacts, recommended deal protections, and integration priorities. This is the document that goes to the board, the deal team, and the buyer’s legal advisors.

Due Diligence Findings Register

Every finding with evidence, risk rating, estimated impact where possible, and deal protection recommendation. The working register behind the report.

Consents & Approvals Register

Change-of-control clauses across contracts, leases, licences, and banking facilities — with counterparties, lead times, and risk if consent is not obtained.

Inherited Obligations Register

Liabilities the buyer will inherit: leases, warranties, employee entitlements, environmental obligations — with exposure ranges and provision adequacy.

Control Self-Assessment

93-question assessment of the target’s control environment with maturity ratings and remediation notes across all seven workstreams.

Deal Protections Schedule

Price adjustments, indemnities, escrows, conditions precedent — mapped to specific findings and ready for legal review.

Integration Recommendations

Day-1 priorities, 30/60/90-day plan, governance maturity assessment, estimated integration effort, and resource requirements.

Free Resource

Pre-Acquisition Operational Readiness Checklist

25 operational questions that financial and legal due diligence won’t answer. A practical checklist for M&A teams assessing operational risk before Day 1.

Discuss an upcoming acquisition

A short discovery call can confirm scope, timing and whether an operational due diligence review is appropriate for the transaction.

Book a Discovery Call →