Evidence comes from four independent sources: documents, interviews, direct observation, and external measurement. Collected separately, they rarely agree in full — and the disagreements are where the findings are.
Financial quality of earnings establishes that the earnings were real. Legal diligence establishes that the entity is clean. Neither answers the question that matters most to a buyer holding ten-year acquisition debt: will these earnings still exist at maturity.
That is a technology question now, and it is not being asked.
This page describes how the assessment is conducted — what evidence gets collected, where it comes from, and how conflicting evidence is resolved. The method is deliberately transparent. Diligence that can't explain itself isn't diligence.
Documents alone produce a flattering picture. Interviews alone produce the picture management believes. Neither is sufficient, and the discrepancy between them is frequently the most valuable output of the engagement.
Documents. Software and vendor agreements, license terms, renewal and assignment provisions, custom development and its ownership, account and domain control, data ownership and portability, security posture, insurance attestations. Most of this is absent from a standard data room because the standard request list was written for financial and legal review. Supplying that request list is the first deliverable of the engagement.
Interviews. Structured conversations with the owner, the operations lead, and whoever administers the systems. The operations lead is consistently the most informative and the least prepared for — they know which system everyone quietly stopped using, which report takes three exports to produce, and what piles up when they take a week off.
Observation. A live walkthrough of the business's own systems, using real records rather than a prepared demonstration. A job traced from inbound inquiry through quote, schedule, delivery, invoice, and payment. This is the single highest-signal hour in the engagement and it is almost never requested. Watching the work reveals the spreadsheet sitting between two systems that are described as integrated.
External measurement. The business is evaluated the way a customer encounters it — inbound responsiveness, after-hours handling, quote and follow-up behavior, review solicitation patterns, public technical footprint. This source requires no cooperation from anyone, which is precisely what makes it useful. It can be run before an LOI is signed, and it cannot be curated.
The four sources are collected independently and then compared. Agreement across all four is a confirmed fact. Disagreement is a finding, and findings are what the engagement is for.
The pattern recurs in a recognizable form. A capability is described in the offering memorandum. Management confirms it in conversation. The documents contain no supporting contract, and external measurement shows no evidence of it operating. The finding is not that a feature is missing. The finding is that a revenue projection depends on a capability that does not exist — and that every adjacent claim now requires independent verification rather than acceptance.
The inverse occurs as often and is more interesting. A business is described as having no meaningful systems. Observation shows disciplined manual process, complete records, and a workforce doing accurately by hand what software would do faster. That is not a risk. That is a documented improvement thesis with a known cost and a known payback, and it belongs in the valuation conversation rather than the risk register.
Neither conclusion is reachable from any single source.
Revenue defensibility. An assessment by revenue line rather than by business, covering the share of billed work that is task-substitutable, the portion requiring physical presence or credentialed delivery, intermediation exposure where the business sits between two parties who could transact directly, and displacement risk affecting the customer base rather than the business itself. Reported as a band with the mechanism named. Lenders and investment committees need a stated cause, not a score.
Capability verification. Every automation or AI claim made during the sale process, traced to its supporting contract and its observable behavior. Whether it transfers at close. Whether it is licensed to the entity or to the owner personally. Whether it constitutes a differentiator or a category standard being charged for as one.
Transfer and continuity risk. Account and domain control, data ownership and extractability, custom development and whether it was ever assigned, vendor concentration, and change-of-control provisions in the operating stack. Assignment clauses in operational software are reviewed by no one in a conventional diligence process, and they reprice.
Remediation cost. What the first twelve months require to bring the environment to the state the acquisition thesis already assumes. Priced, sequenced, and separated into what must happen before close and what can follow.
Buyers and sellers are asking one question from opposite sides.
For a buyer, an operational gap is risk to be priced or a thesis to be underwritten. For an owner preparing to exit, the identical gap is a discount that a future buyer will discover and apply — and a finite, addressable list of things to fix while there is still time to fix them.
The evidence collection is the same. The interpretation inverts. An owner who has seen the buy-side version of this assessment understands exactly what the other side of the table will find, which is a materially different position than learning it during exclusivity.
This is not a financial quality of earnings review. Earnings verification, add-back substantiation, and working capital analysis are performed by a CPA. Where that work is needed and not already underway, an introduction is available.
Findings are bounded by access. Requests that go unanswered are reported as unanswered, with the specific risk that could not be assessed and a recommendation on whether it belongs in closing conditions. Gaps are not filled by inference. An unanswered technology request under exclusivity is itself informative — it generally means either that no one knows the answer or that someone does.
Forward-looking assessment is not prediction. Displacement risk is evaluated against observable mechanisms — what is substitutable, what is protected by licensure or physical presence, what depends on intermediation that is becoming cheap. Where the evidence supports a range rather than a conclusion, a range is what appears in the report.
Below a certain deal size the method changes shape. Businesses without a data room shift the weight onto interviews and observation, and the absence of documentation becomes a scored finding in its own right rather than an obstacle to scoring.
Assessments are scoped to fit inside a standard exclusivity period. A preliminary external read requires no seller cooperation and can be completed before an LOI is signed.