Why operational due diligence matters
A sound strategy can still fail through fraud, valuation abuse, cyberattack, weak cash controls, or business disruption.
How it is applied
Evaluate whether people, governance, systems, service providers, controls, and legal structures can safeguard assets and execute the stated strategy. Review trade flow, valuation, cash movements, reconciliation, expenses, compliance, cybersecurity, business continuity, outsourcing, conflicts, and key-person dependencies. Independently verify material relationships and documents.
Portfolio example
A hedge fund reports strong returns, but operational review finds one person can initiate and approve wires, hard-to-value assets lack independent pricing, and the administrator receives position data late. Investment merit does not offset these control failures, so an allocator may require remediation or decline.
How to interpret it
Operational due diligence addresses loss from fraud, error, weak controls, disruption, or structural misunderstanding. It complements investment analysis and can affect terms, exposure, or monitoring. Strong service providers improve checks but do not transfer all responsibility or guarantee that underlying information is accurate.
Limitations and common misconceptions
Managers can stage demonstrations, references may be conflicted, and controls documented on paper may not operate consistently. Small firms face resource constraints without necessarily being unsafe. Confidentiality limits evidence, while rapidly changing cyber threats make a point-in-time review obsolete. Test samples and exceptions rather than accepting policy descriptions, and trace a transaction from order through custody and NAV. Rank findings by severity, assign remediation dates, and monitor change. Repeat review after growth, strategy expansion, staff turnover, service-provider changes, incidents, or material regulatory events. Asset verification should use independent custody or counterparty evidence where possible and reconcile it with financial statements and administrator records. Valuation review should focus on governance, inputs, overrides, and stale prices, especially when fees depend on NAV. Cyber testing covers access, backups, vendors, incident response, and payment controls rather than a policy document alone. Business continuity should be demonstrated through tests. Investors also need a plan for accessing records and assets if the manager, administrator, or key technology provider becomes unavailable. The final assessment should distinguish critical findings from ordinary improvement items. Clear severity criteria allow consistent decisions and prevent a long checklist from obscuring one unacceptable control failure.
Sources and further reading
- Investment AdvisersU.S. Securities and Exchange Commission
- Portfolio Management: An OverviewCFA Institute