After a due diligence review, most teams move straight to deal structuring or a go/no-go recommendation. The step they skip is testing whether the review's findings rest on verified evidence or on assumptions the process never examined.

A due diligence review is a structured investigation of a target's financial, legal, and operational position, conducted before a transaction or commitment is finalised.

The standard next step after a due diligence review

The standard move is to synthesise findings into a recommendation. Each workstream reports: financial due diligence confirms the numbers, legal review flags undisclosed liabilities and pending claims, commercial review tests the target's market position, operational review examines systems and headcount. The workstream leads produce a findings memo, typically colour-coded. Green items are verified. Amber items carry residual questions. Red items are material concerns requiring negotiation or price adjustment.

The memo goes to the investment committee or the board. How much due diligence is enough is treated as a question about coverage: were all the categories checked, were all the documents requested, did external counsel confirm the agreed scope was completed. If no red items remain and the amber items have proposed mitigations, the committee moves to deal structuring. Price adjustments, indemnity provisions, and warranty schedules absorb whatever the review surfaced.

What to do after a due diligence review: test the assumptions beneath the findings before committing
The due diligence review verifies facts. The decision turns on what those facts are taken to prove.Click to expand

The process is organised around verification. The request list tells the target what to produce. Advisers read what arrives. Discrepancies get flagged. Harvey and Lusch (1995) described due diligence as expanding beyond financial audit into the strategic, operational, and cultural dimensions of the target. In practice, most reviews still organise around documents rather than around the beliefs the decision rests on.

From this point forward, every planning decision treats the review's outputs as established facts, not as claims tested within the boundaries the review happened to cover.

What that step adds

The review adds genuine protection. Without it, the buyer operates on whatever the seller chose to present. A due diligence review replaces the target's marketing narrative with independently verified data. Contract terms are confirmed. Financial statements are tested against supporting records. Pending litigation is surfaced. Regulatory exposure is identified. These are real contributions, and skipping them would be reckless.

The process also creates a defensible record. If the deal produces losses, the board can demonstrate that it followed an established process, engaged qualified advisers, and reviewed material categories before committing. In regulated industries, this procedural defence is often the difference between a bad outcome and a governance failure. Evidence-based decision-making relies on exactly this discipline: substituting verified data for assertion.

There is also a coordination benefit. A due diligence review forces multiple disciplines to examine the same target within the same timeframe. Legal, financial, commercial, and operational teams each bring a different lens. Cross-referencing across workstreams catches inconsistencies that a single reviewer would miss. A contract portfolio that looks clean to the legal team may reveal concentration risk to the commercial team.

The limitation is not in what the review does. It is in what the review's outputs are taken to mean once the committee receives them. A finding that customer retention has been 92% for three consecutive years is a verified fact. The inference that retention will remain at 92% after the acquisition is an assumption. The review produced the first. The committee acted on the second. Nothing in the process distinguishes between them.

Rewrite the finding your deal decision depends on most as a claim about post-close conditions and test it before the price adjustment substitutes for verification. Start the Walk →

Where the standard playbook breaks down

The playbook breaks down at the boundary between verified data and the inferences built on top of it. Every due diligence finding carries an implicit claim about what it proves, and that claim is rarely written down. A reviewed financial statement proves the numbers were accurately recorded. It does not prove the business model that produced those numbers will continue to function under new ownership, in a different market, or under different regulatory conditions.

What the due diligence producedWhat it assumedGap to test
Loan portfolio sampled and reviewedStated underwriting standards reflect actual origination practicesWhether loan files match the guidelines the lender claims to follow
Financial statements audited and confirmedRevenue growth can be sustained under the acquirer's operating modelWhether growth depended on practices the acquirer will not continue
No material litigation disclosedAbsence of filed claims means absence of exposureWhether regulatory inquiries or pre-litigation disputes exist outside the data room
Management interviews completedManagement's representations are consistent with operating realityWhether internal communications contradict the narrative presented to the buyer

Bank of America's acquisition of Countrywide Financial in 2008 demonstrated what happens when those gaps go untested. Bank of America agreed to acquire Countrywide for approximately $4.1 billion in January 2008. Countrywide was the largest mortgage originator in the United States. Due diligence covered the standard categories: loan portfolio, financial statements, legal exposure, operations.

The review verified what was in the data room. It did not test the assumption that Countrywide's stated underwriting standards reflected how loans were actually originated. The Financial Crisis Inquiry Commission (2011) later documented that Countrywide had systematically departed from its own guidelines. Internal quality control reports had flagged defect rates in loan origination. An internal programme that employees referred to as "the Hustle" removed quality checkpoints from the origination process to increase volume. The due diligence had examined loan files. It had not tested whether those files represented the norm or the exception.

The costs exceeded $40 billion. In August 2014, the Department of Justice announced a $16.65 billion settlement covering fraud in the origination, packaging, and sale of mortgage-backed securities, much of it originating from Countrywide's operations before the acquisition.

The due diligence was not careless. It verified the documents it was given. The failure was in what the verified documents were taken to prove. A sampled loan file that met stated guidelines was treated as evidence that the portfolio was sound. That inference required an assumption: that stated guidelines governed actual origination practice. Nobody wrote that assumption down, tested it against Countrywide's own internal reports, or assigned it a confidence level proportionate to the $4.1 billion it was holding up. Decisions made with uncertainty need exactly that discipline, and the standard due diligence process does not supply it.

The step to take first

The due diligence review is not the problem. Building on its outputs without testing the assumptions they carry is. Before the findings memo enters the decision, each material finding needs a second column: what is this being taken to prove, and how confident is the evidence?

Due diligence complete. Findings memo delivered.
Two paths forward
Standard path
Proceed to deal structuring. Negotiate price based on reviewed materials. Commit.
Assumes: verified documents prove the investment thesis
With assumption testing
List the beliefs the deal depends on. Test each against evidence independent of the data room. Set monitoring triggers before close.
Tests: whether the deal's value rests on conditions the review never examined

The five-step structure in the Sufficient Certainty method places assumption recognition before any commitment. Frame the decision: what exactly is being decided, and what outcome would make this commitment worthwhile. Identify the tentative elements: the factors, conditions, and relationships the decision depends on. Surface the assumptions embedded in the due diligence findings: which conclusions rest on verified evidence and which rest on inferences the review did not test. Determine whether the evidence behind each critical assumption is proportionate to how much that assumption is holding up. Then implement with monitoring in place.

An assumption that carries the deal and rests on a management interview is not a finding. It is an input that needs independent verification before the commitment is made.

The value of a situation analysis in any form depends on what happens to its outputs. A due diligence review produces verified facts. Those facts support inferences. Those inferences carry assumptions. The step that separates a defensible process from a defensible decision is testing those assumptions before the committee treats them as settled. A situation analysis that actually serves the decision does not stop at describing what was found. It identifies what the findings are being taken to prove, tests that claim, and records the result.

You could close this tab and carry that decision into another week.

Work through your decision

No sign-up. Just pick your decision and start.


Grant Purdy is the co-author, with Roger Estall, of Deciding (2020), and the architect of the Universal Decision-Making Method.