Live: Tesla PDF 3s (DI-1F0059F32F) - median 15s across 4 real orders - code DI20-WELCOME - $49 to $39.20 - Order now →
Home / Regulatory DD / Compliance Due Diligence

Compliance Due Diligence: Program, Controls & Management Systems

A practical guide to compliance due diligence for PE, corp dev, and deal teams — how to test whether the target has working compliance machinery (AML, export controls, sanctions screening, data protection, training, monitoring) before you inherit liability and remediation cost.

Risk / compliance workstream
6
Compliance pillars
50
Checklist items
$150K+
Specialist deep dive
$49
First-pass pack

Buyers price the business and forget the compliance apparatus underneath it. Compliance due diligence asks whether the target's internal controls actually work — or whether they exist only in a binder that no one follows. It is not the same as regulatory diligence (licenses, permits, and enforcement actions), FCPA diligence (anti-bribery specifically), sanctions diligence (OFAC and restricted-party screening), or data privacy diligence (GDPR/CCPA program). Compliance diligence confirms the management system that is supposed to connect and run all of them.

Compliance vs regulatory vs FCPA vs sanctions vs legal diligence

WorkstreamPrimary questionTypical output
Compliance DDDoes the internal program work?Program assessment, control testing, gap/remediation plan
Regulatory DDAre licenses and permits in order?License register, renewal calendar, enforcement history
FCPA / anti-bribery DDIs bribery risk controlled?Gift/travel logs, third-party diligence, intermediaries
Sanctions DDIs restricted-party screening live?Screening evidence, hits, false-positive rate
Data privacy DDIs personal data handled lawfully?ROPA, DPIAs, consent records, breach history
Legal / corporate DDAre formalities and contracts clean?Charter, minutes, material contracts, litigation

Six pillars of compliance diligence

1. Program design, governance & tone from the top

Assess whether compliance is a real function or a title. Is there a designated compliance officer with authority, budget, and a direct line to the board or audit committee? Does a written code of conduct exist, is it current, and is it actually distributed and acknowledged? Look for a risk assessment that drives the program design — not a generic off-the-shelf policy library. Connect program gaps to board diligence when oversight is absent and to management diligence when no one owns the function.

2. AML / CTF & financial-crime controls

For any target touching payments, lending, remittances, crypto, or high-risk jurisdictions, test the anti-money-laundering and counter-terrorism-financing program: customer due diligence (CDD/KYC) standards, enhanced due diligence on high-risk customers, transaction monitoring rules and alert handling, suspicious activity reporting (SAR/STR) history, and beneficial-ownership identification. A paper KYC process that never files a SAR is a regulator magnet. Link findings to financial diligence when unusual cash flows appear.

3. Export controls, trade compliance & customs

For targets in technology, defense, dual-use goods, aerospace, semiconductors, or cross-border manufacturing, assess export-control posture: classification of products and technology (ECCN/USML), license requirements and authorizations, deemed-export rules for foreign nationals, re-export and end-use controls, and customs compliance (valuation, origin, classification, FTAs). Undisclosed export violations can trigger criminal exposure and block deal clearances. Connect to technology diligence and IP diligence when controlled technology is a value driver.

4. Sanctions screening & third-party diligence program

Test whether restricted-party screening is automated, current, and covers customers, suppliers, intermediaries, and counterparties across all jurisdictions. Ask for screening evidence: hit logs, false-positive rates, escalation records, and what happened when a true match was found. Assess the third-party diligence program: due diligence tiers, onboarding controls, ongoing monitoring, and termination triggers. A sanctions program that screens at onboarding but never re-screens is a gap. Link to sanctions diligence and supply-chain diligence.

5. Data protection, privacy & records management

Confirm the privacy program is operational, not just documented: records of processing activity (ROPA), data-subject-access and deletion response capability, data-protection-impact assessments for high-risk processing, cross-border transfer mechanisms (SCCs, adequacy, binding corporate rules), breach notification readiness, and retention/destruction schedules. For targets in healthcare, fintech, adtech, or AI, privacy compliance gaps can trigger regulatory action and require expensive remediation. Connect to data privacy diligence, healthcare diligence, and AI diligence.

6. Training, monitoring, whistleblower & remediation

A compliance program is judged by how it detects and fixes problems. Assess training coverage and frequency (not just a one-time click-through), monitoring and internal audit of high-risk processes, testing of transaction-monitoring and screening rules, and the whistleblower channel: is it confidential, anti-retaliation protected, and actually used? Look for remediation evidence — when problems were found, were they fixed, documented, and escalated? Connect to cybersecurity diligence for incident-response maturity and to insurance diligence for D&O and management-liability coverage of compliance failures.

Cost reality: specialist compliance program reviews for middle-market and cross-border deals often run $25K–$150K+ once program documentation, transaction testing, regulator correspondence, and remediation planning are in scope. A structured public first-pass pack is $49 (or $39.20 with code DI20-WELCOME) — useful for triage, not a substitute for counsel-led review.
Order first-pass PDF → View sample report

Stage sequencing (IOI to close)

StageCompliance focusBuyer action
Pre-LOI / IOIPublic enforcement records, sector risk, jurisdictional exposurePrice only theses that survive compliance reality
LOI / exclusivityProgram documentation, policies, org chart, training recordsData request; compliance specialist scope
Confirmatory DDControl testing, screening evidence, SAR/STR history, whistleblower logRed/amber/green; remediation plan; kill criteria
SPA / financingReps on compliance, investigations, escrow, special indemnitiesDocument successor-liability protections
Close / Day-1Program integration, reporting lines, remediation ownersNo orphaned compliance gaps in first two quarters

Red flags

SignalSeverityWhy it matters
No functioning AML program where money flowsDeal-KillerRegulator action, fines, licence loss post-close
Willful or repeated export-control violationsDeal-KillerCriminal exposure; deal-clearance block
Sanctions exposure via subsidiaries or intermediariesDeal-KillerSuccessor liability; asset freezes; reputational
Compliance program on paper with no monitoringHighProgram exists but does not detect problems
Ongoing government investigation undisclosedHighSuccessor liability; SPA breach; deal-break risk
Whistleblower channel absent or retaliated againstHighProblems fester; regulator treats as aggravating
No third-party diligence on intermediariesWatchBribery and sanctions risk through agents
Training is a one-time click-through with no testingWatchWeak culture; weak evidence of effectiveness

Cost & timeline (traditional vs first-pass)

ApproachTypical costTimelineBest use
Full compliance program review + transaction testing$50K–$150K+3–8 weeksCross-border, regulated, known gaps
Focused program assessment + key-control testing$25K–$75K2–4 weeksMid-market with moderate compliance risk
Public first-pass risk pack$49Minutes to hoursTriage before LOI / shortlist

50-point compliance diligence checklist

  • Compliance officer designated with authority, budget, and reporting line
  • Written code of conduct current, distributed, and acknowledged
  • Risk assessment drives program design (not generic policy library)
  • Board or audit committee oversight of compliance documented
  • Compliance budget and headcount adequate for risk profile
  • AML/CDD/KYC standards documented and risk-tiered
  • Enhanced due diligence on high-risk customers performed
  • Transaction-monitoring rules documented and tuned
  • SAR/STR filing history and rationale reviewed
  • Beneficial-ownership identification process in place
  • PEP and adverse-media screening on relevant customers
  • Export-control product/technology classification (ECCN/USML)
  • Export licenses and authorizations tracked and current
  • Deemed-export controls for foreign-national access
  • Re-export and end-use controls documented
  • Customs compliance: valuation, origin, classification, FTAs
  • Restricted-party screening automated and current
  • Screening covers customers, suppliers, intermediaries, counterparties
  • Screening hit logs, false-positive rates, escalation records
  • Re-screening cadence (not only at onboarding)
  • Third-party diligence tiers and onboarding controls
  • Ongoing monitoring and termination triggers for third parties
  • Records of processing activity (ROPA) maintained
  • Data-subject-access and deletion response capability
  • Data-protection-impact assessments for high-risk processing
  • Cross-border transfer mechanisms (SCCs, adequacy, BCRs)
  • Breach notification readiness and prior breach history
  • Retention and destruction schedules enforced
  • Training coverage, frequency, and completion tracked
  • Training includes role-specific content (not only general)
  • Internal audit or monitoring of high-risk processes
  • Transaction-monitoring and screening rule testing
  • Whistleblower channel confidential and anti-retaliation protected
  • Whistleblower reports logged, investigated, and resolved
  • Remediation evidence for prior compliance findings
  • Regulator correspondence and examination history
  • Enforcement actions, settlements, or consent orders
  • Ongoing or threatened government investigations disclosed
  • Self-disclosure history and voluntary-refund evidence
  • Compliance-related litigation or regulatory claims
  • Insurance coverage for compliance fines and investigation costs
  • Successor-liability analysis for pre-close violations
  • SPA reps and warranties on compliance and investigations
  • Escrow or special indemnity for known compliance gaps
  • Remediation plan and budget for identified gaps
  • Post-close compliance integration plan and owners
  • Data-room request: policies, training logs, screening evidence, SARs
  • Kill criteria: no AML program, willful export violations, sanctions exposure
  • Link findings to regulatory, FCPA, sanctions, privacy, cyber, legal
  • IC narrative distinguishes licensed-and-compliant from licensed-but-broken

How deal teams use a first-pass pack

Before LOI, buyers use structured public research to pressure-test compliance theses: enforcement records, litigation themes, regulatory filings, disclosed remediation actions, leadership departures following compliance events, and jurisdictional exposure maps. After LOI, the same hypotheses drive the data-room and counsel plan — program documentation, transaction testing, screening evidence, SAR/STR history, and regulator correspondence — so specialists do not spend weeks confirming what public records already signaled. The pack is screening research, not a substitute for counsel-led compliance program assessment, transaction testing, or remediation planning.

Inherit a business, not its compliance liability

⇧ Already delivered: Tesla (TSLA) · Alphabet (GOOGL) · Palantir (PLTR) — real orders, real SEC data, every claim source-cited.

Get a structured first-pass diligence pack on your target — useful input for compliance program / control / successor-liability hypotheses, not a substitute for counsel-led review.

Order report $39.20 → Free brief Sample PDF