For GPs raising and reporting to institutional capital

Your team is using AI. Your DDQ answers assume someone has looked.

Operational due diligence asks how your firm actually runs — controls, data handling, business continuity — and AI governance is now inside those questions. Your answers are written representations to the people deciding whether to commit capital. If AI is in the firm and nobody has mapped it, you’re either guessing or overstating. We fix that by mapping your AI usage and giving you a defensible register within 30 days (max), before your next DDQ.

Book a 20-minute callFixed price · Delivered before your next DDQ or close

The pressure you’re already under

You don’t need an AI-specific question for AI to be a diligence problem.

Some allocators have added explicit AI questions. Many haven’t yet. It makes less difference than GPs assume, because the operational sections that already exist — compliance, cybersecurity, data handling, business continuity — now expect AI to be governed inside them. And the bar has moved: in a 2026 Altss survey of 1,200 institutional investors, 72% had deepened their operational due diligence in the past twelve months.

The answers are representations, not marketing

A DDQ response is a written statement an allocator relies on. Describe an AI oversight process you don't run and you've misrepresented your operations to the people funding you — with fundraising and reputational consequences, and, for FCA-authorised managers, a fair-clear-not-misleading problem on top.

Written representation to the LP

AI is the thing nobody registered

It arrives inside the tools the firm already uses — the research stack, the DDQ software itself, the copilots analysts switch on. Nobody logged it, nobody approved it, in the worst case nobody has asked. It's exactly what an operational reviewer is now trained to probe.

Shadow AI

And the window has compressed

The average private-markets DDQ now runs 23 sections and 280+ questions, and the response window has shrunk from fourteen days to five. You cannot map your AI estate for the first time inside a five-day turnaround. The work has to already be done.

Private-markets diligence benchmarks, 2026

What you’re already answering

The questions are on the DDQ today. AI is what makes them hard to answer.

These are the operational and technology questions already landing from allocators — and every one gets harder once you accept that AI is in the firm and nobody has mapped where.

AI use across the firm

Describe the firm's use of AI and the controls governing it.

Can you answer without guessing — for the whole firm, not just the tools you happen to remember?

Data handling

What data may be input into AI tools, and how is confidential and portfolio information protected?

Including the deal memo or LP data pasted into a public model at nine in the evening?

Accountability

Who is responsible for AI-related risk, and how is it overseen?

Named? Evidenced? Or a gap you'd rather the reviewer didn't find?

Investment process

What is the firm's policy on AI-assisted research and IC materials?

Does a policy exist — and does it match what the deal team actually does under deadline?

Cyber & information security

Describe third-party AI tools in use and how their data handling is assessed.

The model inside your research platform is a third party. Have you assessed it as one?

Business continuity & operational resilience

Describe resilience for AI-dependent processes.

If a vendor model sits in a process you rely on, is it anywhere in your BCP — or invisible until it fails?

Phase one

AI Exposure Review

The diligence work, done before the diligence lands. Know exactly where AI lives in the firm, what’s yours to govern, where the gaps are, and what closing them will involve. Two to four weeks. Fixed price. You keep the artefacts whether or not you go further — and you can hand them straight into the next DDQ.

AI footprint map

The answer, evidenced

One map per function — deal team, research, operations, investor relations — consolidated into a single firm-wide view: where AI is used, in which processes, by whom, against which data and which portfolio companies. Including the tools nobody flagged.

AI systems register

Your single source of truth

The operational inventory of every AI system in the firm, with a named owner against each. The document your COO points to, and the source your DDQ answers are drawn from rather than improvised.

Gap list against allocator and regulatory expectations

What's missing, and what it exposes

Where the firm falls short on documented oversight, data handling, third-party assessment and continuity — the exact areas an operational reviewer probes — prioritised, with the exposure named plainly.

Costed plan for closing the gaps

Makes the next decision concrete

A fixed-price, evidence-based scope for the governance build, so the bigger decision is a known quantity rather than open-ended fees.

Duration
Two to four weeks
Price
Fixed, scaled to firm size and AUM
Guarantee
Artefacts delivered before your next DDQ or close, or you don’t pay
If you proceed
Fee credited against the build

Phase two · optional

Then: the build, and the training.

Phase one tells you what’s actually there. Phase two puts the governance in place — aligned with ISO/IEC 42001, without the weight or cost of a certification programme — so the DDQ answer is backed by something real.

AI Governance Build

The policies, controls, records and evidence that let your COO answer an operational reviewer — and let you stand behind the representations you make to LPs.

  • AI policy and authorised-tools list
  • Integrated risk register (AI × confidentiality × data protection)
  • Documented human-oversight and review controls, with a named owner
  • Third-party AI assessment fit for the cyber and BCP sections of any DDQ
  • A DDQ-ready evidence pack, mapped to the standard operational questions

Deal-team and operations training

Practical and role-level, not a compliance lecture — because the risk is an analyst pasting a confidential memo into a public model under deadline.

  • What the approved tools are, and how to use them
  • Confidentiality, MNPI and what never leaves the firm
  • AI-assisted research and diligence — where judgement stays human
  • Attendance records you can evidence to an allocator

Honest fit

Who this is for — and who it isn’t.

A good fit if

  • You’re a private-fund manager — hedge, PE or venture — roughly up to 50 staff
  • You have no in-house risk or operational-diligence function doing this actively
  • Your team is using AI — with or without a policy
  • You raise from or report to institutional LPs
  • A DDQ, a re-up or an annual ODD review is coming

Not a good fit if

  • You have a mature operations and compliance function already running this
  • You’ve already mapped and registered your AI use
  • You want full ISO 42001 certification now — different engagement
  • You want a policy document with nothing behind it

Who you’d be working with

We don’t sell paperwork.

A policy that claims a control you don’t run is worse than none. In a DDQ that isn’t a documentation problem — it’s a representation you can be held to. Everything we build is real, evidenced, and defensible.

Certified ISO/IEC 42001

Standards

Committee member, BSI & ISO technical committees

Delivery

Regulated, sensitive-data environments

Questions

What GPs ask us.

There's no AI question on the DDQs we're getting.

There may not be one yet — some allocators have added them, many haven't. But the operational sections already ask how you handle confidential data, assess third parties and maintain continuity, and AI now sits inside all three. It doesn't need its own question to make those answers harder to stand behind.

We're not raising right now. Why now?

Because the work can't be done inside a five-day response window, and re-ups and annual ODD reviews arrive without a raise. Doing it cold, under deadline, is where answers get overstated — and an overstated operational representation is the kind of thing that surfaces later, at the worst time.

We already have an AI policy.

Then you're ahead of most firms. The harder question is whether it matches what the deal team actually does under deadline. A policy that doesn't reflect real usage is a written statement you can be measured against — and it doesn't stand in for having mapped your actual estate.

We handle this in-house.

Plenty of firms can, and if your COO's function is actively doing it, you don't need us. Where we earn our place is doing the initial mapping and build quickly, in the form allocators expect, so your people stay on deals and investor relations.

Does this make us ISO 42001 certified?

No. This is a lightweight, ISO/IEC 42001-aligned governance baseline without the weight or cost of a certification programme. It's the right foundation if you certify later — but the point is to let you answer allocators now.

Will this slow the deal team down?

The opposite is the intention. Most firms are stuck between a blanket ban nobody follows and a free-for-all nobody can evidence. Approved tools, clear rules and an oversight trail are what let people use AI properly rather than quietly.

Before the next DDQ lands

Could you answer the AI questions today — accurately?

A 20-minute call. We’ll walk the operational questions your allocators are already asking, and you’ll leave knowing whether you could evidence your answers. Whether or not you work with us.

Book a 20-minute call