A practical guide to compliance due diligence for PE, corp dev, and deal teams — how to test whether the target has working compliance machinery (AML, export controls, sanctions screening, data protection, training, monitoring) before you inherit liability and remediation cost.
Buyers price the business and forget the compliance apparatus underneath it. Compliance due diligence asks whether the target's internal controls actually work — or whether they exist only in a binder that no one follows. It is not the same as regulatory diligence (licenses, permits, and enforcement actions), FCPA diligence (anti-bribery specifically), sanctions diligence (OFAC and restricted-party screening), or data privacy diligence (GDPR/CCPA program). Compliance diligence confirms the management system that is supposed to connect and run all of them.
| Workstream | Primary question | Typical output |
|---|---|---|
| Compliance DD | Does the internal program work? | Program assessment, control testing, gap/remediation plan |
| Regulatory DD | Are licenses and permits in order? | License register, renewal calendar, enforcement history |
| FCPA / anti-bribery DD | Is bribery risk controlled? | Gift/travel logs, third-party diligence, intermediaries |
| Sanctions DD | Is restricted-party screening live? | Screening evidence, hits, false-positive rate |
| Data privacy DD | Is personal data handled lawfully? | ROPA, DPIAs, consent records, breach history |
| Legal / corporate DD | Are formalities and contracts clean? | Charter, minutes, material contracts, litigation |
Assess whether compliance is a real function or a title. Is there a designated compliance officer with authority, budget, and a direct line to the board or audit committee? Does a written code of conduct exist, is it current, and is it actually distributed and acknowledged? Look for a risk assessment that drives the program design — not a generic off-the-shelf policy library. Connect program gaps to board diligence when oversight is absent and to management diligence when no one owns the function.
For any target touching payments, lending, remittances, crypto, or high-risk jurisdictions, test the anti-money-laundering and counter-terrorism-financing program: customer due diligence (CDD/KYC) standards, enhanced due diligence on high-risk customers, transaction monitoring rules and alert handling, suspicious activity reporting (SAR/STR) history, and beneficial-ownership identification. A paper KYC process that never files a SAR is a regulator magnet. Link findings to financial diligence when unusual cash flows appear.
For targets in technology, defense, dual-use goods, aerospace, semiconductors, or cross-border manufacturing, assess export-control posture: classification of products and technology (ECCN/USML), license requirements and authorizations, deemed-export rules for foreign nationals, re-export and end-use controls, and customs compliance (valuation, origin, classification, FTAs). Undisclosed export violations can trigger criminal exposure and block deal clearances. Connect to technology diligence and IP diligence when controlled technology is a value driver.
Test whether restricted-party screening is automated, current, and covers customers, suppliers, intermediaries, and counterparties across all jurisdictions. Ask for screening evidence: hit logs, false-positive rates, escalation records, and what happened when a true match was found. Assess the third-party diligence program: due diligence tiers, onboarding controls, ongoing monitoring, and termination triggers. A sanctions program that screens at onboarding but never re-screens is a gap. Link to sanctions diligence and supply-chain diligence.
Confirm the privacy program is operational, not just documented: records of processing activity (ROPA), data-subject-access and deletion response capability, data-protection-impact assessments for high-risk processing, cross-border transfer mechanisms (SCCs, adequacy, binding corporate rules), breach notification readiness, and retention/destruction schedules. For targets in healthcare, fintech, adtech, or AI, privacy compliance gaps can trigger regulatory action and require expensive remediation. Connect to data privacy diligence, healthcare diligence, and AI diligence.
A compliance program is judged by how it detects and fixes problems. Assess training coverage and frequency (not just a one-time click-through), monitoring and internal audit of high-risk processes, testing of transaction-monitoring and screening rules, and the whistleblower channel: is it confidential, anti-retaliation protected, and actually used? Look for remediation evidence — when problems were found, were they fixed, documented, and escalated? Connect to cybersecurity diligence for incident-response maturity and to insurance diligence for D&O and management-liability coverage of compliance failures.
DI20-WELCOME) — useful for triage, not a substitute for counsel-led review.
| Stage | Compliance focus | Buyer action |
|---|---|---|
| Pre-LOI / IOI | Public enforcement records, sector risk, jurisdictional exposure | Price only theses that survive compliance reality |
| LOI / exclusivity | Program documentation, policies, org chart, training records | Data request; compliance specialist scope |
| Confirmatory DD | Control testing, screening evidence, SAR/STR history, whistleblower log | Red/amber/green; remediation plan; kill criteria |
| SPA / financing | Reps on compliance, investigations, escrow, special indemnities | Document successor-liability protections |
| Close / Day-1 | Program integration, reporting lines, remediation owners | No orphaned compliance gaps in first two quarters |
| Signal | Severity | Why it matters |
|---|---|---|
| No functioning AML program where money flows | Deal-Killer | Regulator action, fines, licence loss post-close |
| Willful or repeated export-control violations | Deal-Killer | Criminal exposure; deal-clearance block |
| Sanctions exposure via subsidiaries or intermediaries | Deal-Killer | Successor liability; asset freezes; reputational |
| Compliance program on paper with no monitoring | High | Program exists but does not detect problems |
| Ongoing government investigation undisclosed | High | Successor liability; SPA breach; deal-break risk |
| Whistleblower channel absent or retaliated against | High | Problems fester; regulator treats as aggravating |
| No third-party diligence on intermediaries | Watch | Bribery and sanctions risk through agents |
| Training is a one-time click-through with no testing | Watch | Weak culture; weak evidence of effectiveness |
| Approach | Typical cost | Timeline | Best use |
|---|---|---|---|
| Full compliance program review + transaction testing | $50K–$150K+ | 3–8 weeks | Cross-border, regulated, known gaps |
| Focused program assessment + key-control testing | $25K–$75K | 2–4 weeks | Mid-market with moderate compliance risk |
| Public first-pass risk pack | $49 | Minutes to hours | Triage before LOI / shortlist |
Before LOI, buyers use structured public research to pressure-test compliance theses: enforcement records, litigation themes, regulatory filings, disclosed remediation actions, leadership departures following compliance events, and jurisdictional exposure maps. After LOI, the same hypotheses drive the data-room and counsel plan — program documentation, transaction testing, screening evidence, SAR/STR history, and regulator correspondence — so specialists do not spend weeks confirming what public records already signaled. The pack is screening research, not a substitute for counsel-led compliance program assessment, transaction testing, or remediation planning.
⇧ Already delivered: Tesla (TSLA) · Alphabet (GOOGL) · Palantir (PLTR) — real orders, real SEC data, every claim source-cited.
Get a structured first-pass diligence pack on your target — useful input for compliance program / control / successor-liability hypotheses, not a substitute for counsel-led review.
Order report $39.20 → Free brief Sample PDF