Key takeaways
- Scope the work to post-close continuity evidence. Qualified advisers own legal, financial, tax, employment, security and transaction diligence.
- Inventory recurring events, owners, source systems, open exceptions and reporting definitions without copying unnecessary sensitive data.
- Ask for counts, samples and control descriptions before bulk exports. Preserve source ownership and access conditions.
- Convert findings into a Day 1 continuity register and post-close observation backlog, not a false readiness score.
Write the exclusions before requesting data
Operational due diligence is used broadly across transaction work. The International Bar Association's guidelines place operational review beside separate legal, financial, tax, HR, IT and other work. This page takes one narrow slice: evidence needed to keep recurring work visible and owned after close.
Use the parties' authorization, confidentiality controls and adviser instructions. Start with descriptions and aggregate counts. Request samples only when the process question cannot be answered another way.
| In scope | Record | Out of scope |
|---|---|---|
| Recurring event | Trigger, frequency, owner and finish | Revenue quality or valuation conclusion |
| Source dependency | System, record, access owner and fallback | Cybersecurity assessment |
| Open exception | Count, age, route and accountable owner | Legal exposure conclusion |
| Reporting definition | Term, source field, period and local variant | Accounting opinion |
| Relationship handoff | Role, commitment record and consented introduction | Contract interpretation |
Capture six continuity facts for each material process
- 01Name the business eventTriggerUse an observable start such as “job marked complete” or “weekly reporting cut-off.”
- 02Name current and fallback ownersHuman approvalRecord responsibility and escalation. Do not infer authority from job title alone.
- 03Map approved source recordsCodeList system of record, identifiers, freshness, retention and access owner. Do not put secrets in the map.
- 04Count and sample exceptionsHuman approvalRecord classes, age and destinations. Use redacted samples under the authorized protocol.
- 05Reconcile definitionsAI judgmentCompare labels such as active, completed or urgent with the field and rule that actually produce them.
- 06Write the Day 1 fallbackHuman approvalIf access or knowledge does not transfer on time, name the manual route, decision owner and recovery evidence.
Prefer a request ladder to a data-room vacuum
| Level | Request | Control |
|---|---|---|
| 1. Description | Process card, owner and system list | Approved channel; no personal data |
| 2. Aggregate | Volumes, exception counts and age bands | Minimum fields and defined period |
| 3. Redacted sample | Normal and imperfect cases | Purpose, masking and access log |
| 4. Controlled observation | Authorized live demonstration | Named participants and no secret capture |
| 5. Post-close test | Successor-run case in the approved environment | Rollback, reconciliation and accountable owner |
NIST's data-integrity work treats honest mistakes as well as malicious events as threats to records. Preserve a source snapshot, validation counts and rollback path before cleanup or migration changes anything.
A definition mismatch becomes a Day 1 task, not a diligence verdict
Northline's weekly report shows completed jobs by branch. One branch counts a job after technician closeout; another waits for customer sign-off. The diligence record captures both definitions, source fields, current owners and three redacted exception shapes.
The record does not decide which definition is financially correct or change the source systems. It creates a Day 1 continuity task: preserve both fields, publish the mismatch and assign an accountable owner to reconcile the reporting rule after close.
Turn the evidence into two bounded outputs
- Day 1 continuity register: essential event, owner, source, open exception, fallback and escalation.
- Post-close observation backlog: process, next live case, definition gap, seller dependency and successor test.
After close and under the appropriate access controls, move the second output into the acquisition process inventory. Its score prioritizes observation; it is not diligence or approval.
Limitations and when not to use this
- This page is not legal, financial, tax, accounting, employment, privacy, cybersecurity, regulatory, investment, valuation or transaction advice or diligence.
- Only collect information the parties have authorized for a defined purpose. Apply the actual confidentiality, privacy, access and retention requirements.
- The record describes operating dependencies; it does not determine whether to buy a business or whether a control is adequate.
- Northline is simulated. No transaction, customer, system or outcome is represented.
Sources
- Corporate and M&A Legal Due Diligence Guidelines — International Bar Association Accessed 9 August 2026
- Contingency Planning Guide for Federal Information Systems — NIST Accessed 9 August 2026
- Data Integrity: Detecting and Responding to Destructive Events — NIST Accessed 9 August 2026
Build the process inventory
Rank authorized process observations after the operating evidence is collected.
Build the process inventoryUli Prantz
Builds and operates all-agents
Uli Prantz builds all-agents, the process-automation platform this site documents. He writes about the operational side of automating recurring business work: where deterministic code beats model judgment, where it does not, and where a human still has to approve.