Operational due diligence surfaces governance gaps, control exposure, key-person risk and integration effort — early, with evidence.
Used alongside financial and legal due diligence in mid-market acquisitions.
Financial and legal due diligence are essential — but they’re not designed to test whether the business can operate effectively after completion. Operational due diligence focuses on the risks inherited on Day 1: governance, control integrity, process reliability, key-person dependency, and integration readiness. These issues rarely appear in the financial model — but they drive cost, disruption and delay immediately after completion.
Historical earnings, normalisation adjustments, working capital, net debt. Reviewed as part of financial due diligence.
Income tax, activity statements, payroll tax, fringe benefits tax, stamp duty. Reviewed as part of tax due diligence.
Material contracts, litigation, intellectual property, employment agreements. Reviewed as part of legal due diligence.
Title, valuations, environmental. Reviewed by specialist advisors.
Decision rights, delegations, and approval boundaries — whether they’re documented, followed, and enforceable in practice.
Whether core processes are documented, repeatable, and scalable — or dependent on workarounds and tribal knowledge.
Single points of failure across finance, payroll, operations, customer delivery, and critical supplier relationships — plus the depth of cross-training and documentation.
System landscape and reporting capability, data quality, change-of-control constraints, and the practical path to integration.
Segregation of duties, payment controls, supplier master controls, and the exposure to internal and external fraud scenarios.
Close speed, reconciliation discipline, evidence retention, and audit-readiness under buyer reporting expectations.
The engagement runs alongside financial and legal due diligence and is scaled to the size and complexity of the transaction. The goal is simple: provide a clear, evidence-based view of operating risk and integration effort before completion.
Confirm transaction context, tailor document requests, and identify the relevant workstreams and interview sessions.
Review data room documentation against structured assessment questions and log preliminary findings.
Structured sessions with key roles and live walkthroughs of critical finance and operational processes.
Assess governance, internal controls, process maturity and operating discipline across seven workstreams.
Deliver findings register, risk ratings, deal protections and Day-1 integration priorities.
Structured for transactions — not compliance. Each workstream focuses on post-completion realities: integration effort, control gaps, and dependencies that affect continuity and reporting discipline.
The output is a practical, evidence-based view of what works, what doesn’t, and what must be addressed before and after completion — with findings mapped into deal protections, Day-1 priorities, and integration planning.
A consolidated view of operating maturity, cross-workstream risks and integration effort. The seven workstreams combine into a single, evidence-based assessment of how the business actually runs — highlighting the risks that affect continuity, governance and post-completion performance.
Decision rights, delegations, oversight, risk ownership, succession planning, and operating cadence.
Core process coverage, walkthroughs, workarounds, standard operating procedure discipline, and repeatability at scale.
Single points of failure, cross-training depth, retention exposure, and relationship concentration.
System landscape, reporting reliability, data quality, licence constraints, cyber resilience, integration path.
Payment controls, supplier master controls, segregation of duties, contracting discipline, fraud indicators.
Close speed, reconciliation discipline, journal controls, evidence retention, audit readiness, asset controls.
Obligations register, monitoring discipline, workplace health and safety, payroll compliance, insurance, environmental and climate posture.
A four-level maturity view gives the buyer a concise read on operating risk and integration effort. Informal or Ad Hoc isn’t a deal-breaker — but it must be understood, costed, and planned for.
No formal governance. The owner makes every decision, nothing is delegated, and nothing is documented. The business cannot function without them.
Some structure exists but it relies on individuals rather than systems. Key-person dependencies are high. Processes work but are not written down or consistently followed.
Roles are clear, processes are documented, and controls exist. The business can operate with management changes, though some gaps remain. Integration is manageable.
Continuous improvement culture with performance monitoring, robust controls, and audit-ready reporting. The business is largely self-sustaining and integration effort is minimal.
Every finding is logged in a formal register with the evidence source, an estimated impact where possible, a risk rating based on a consistent methodology, a recommended deal protection, and a clear flag for Day-1 integration priorities. This register becomes the single source of truth that connects the due diligence to the Share Purchase Agreement negotiations and the integration plan.
| Ref | Workstream | Finding | Rating | Quantum | Deal Protection | Day-1 |
|---|---|---|---|---|---|---|
| F-001 | Internal Controls | No dual approval on banking platform | Critical | Unquantifiable | Condition precedent | ✓ |
| F-002 | Internal Controls | Bank detail changes unverified | High | $50K–$500K | Specific indemnity | ✓ |
| F-003 | Process Maturity | 18-day close, no checklist | High | Integration delay | Financial Controller retention + Day-30 milestone | ✓ |
| F-004 | Key Person Risk | Financial Controller is sole person for close, payroll, system | Critical | Operational shutdown | Retention agreement + knowledge transfer | ✓ |
| F-005 | Systems & Data | 340+ duplicate supplier records | High | $40K–$80K | Price adjustment or escrow | |
| F-006 | Process Maturity | No purchase order discipline — 85% of spend | Medium | $80K–$200K/yr | Day-1 integration requirement |
The engagement produces a structured set of outputs designed for Share Purchase Agreement negotiations, completion planning and post-deal integration.
A comprehensive report on the target business presenting findings by workstream, governance and control maturity assessment, risk ratings, estimated impacts, recommended deal protections, and integration priorities. This is the document that goes to the board, the deal team, and the buyer’s legal advisors.
Every finding with evidence, risk rating, estimated impact where possible, and deal protection recommendation. The working register behind the report.
Change-of-control clauses across contracts, leases, licences, and banking facilities — with counterparties, lead times, and risk if consent is not obtained.
Liabilities the buyer will inherit: leases, warranties, employee entitlements, environmental obligations — with exposure ranges and provision adequacy.
93-question assessment of the target’s control environment with maturity ratings and remediation notes across all seven workstreams.
Price adjustments, indemnities, escrows, conditions precedent — mapped to specific findings and ready for legal review.
Day-1 priorities, 30/60/90-day plan, governance maturity assessment, estimated integration effort, and resource requirements.
25 operational questions that financial and legal due diligence won’t answer. A practical checklist for M&A teams assessing operational risk before Day 1.
A short discovery call can confirm scope, timing and whether an operational due diligence review is appropriate for the transaction.