Skip to content

Glossary · Due diligence

Operational Due Diligence (ODD)

Also called: operational DD

Operational due diligence (ODD) is the review of whether an investment manager's non-investment set-up, including governance, control of cash and assets, valuation, service providers, compliance, reporting, technology and business continuity, can protect investor capital and produce reliable information.

Publisher: Altss LLCPublished Content modified
ALTSS-DD-003

A manager can pick good investments and still lose investors' money through a fraudulent wire, an inflated valuation, a cyber breach or a back office that cannot produce accurate statements. ODD looks for those failure modes before an investor commits. It asks who can move cash, who sets the marks, who checks the books, and what happens when something goes wrong.

Scope

AreaWhat reviewers test
Governance and ownershipWho controls the firm; key-person dependency in operations; conflicts policy
Cash controlsWho can open bank accounts and initiate, approve and release payments; dual authorisation; independent reconciliation; segregation of duties
CustodyWhere assets and cash are held; whether the custodian is independent. See custody
ValuationValuation policy, valuation committee, independence from the deal team, use of IPEV Guidelines and fair value standards, third-party valuation support
Administration and auditIndependent fund administrator and its scope; auditor identity, quality and tenure. See fund audit
Fees and expensesExpense allocation policy, fee offsets, carry calculations and whether they are audited
ComplianceChief compliance officer (CCO), policies, regulatory examinations and how deficiencies were remediated. See compliance
Technology and cyberSecurity policy and its standard, independent testing, incident history
Business continuityTested business continuity and disaster-recovery plans
InsuranceFidelity, errors and omissions, directors and officers, cyber cover

The Institutional Limited Partners Association (ILPA) asks many of these directly in its due diligence questionnaire (DDQ) 2.0: whether the fund uses an independent, unaffiliated administrator (Q15.14); whether carry payments and allocations are audited (Q15.17-15.18); whether the audit samples capital account statements, fees and expenses and the waterfall (Q15.19); whether the cyber policy follows a recognised standard such as those of the US National Institute of Standards and Technology (NIST) or ISO 27001 (Q18.1.1) and is independently audited each year (Q18.4); and what insurance the firm holds (Q13.29).

How an ODD review is done

  1. Document request: compliance manual, valuation policy, expense policy, audited financial statements, the administrator's controls report, the DDQ.
  2. Public-record cross-check. For SEC-registered advisers, Form ADV Part 1A, Schedule D Section 7.B.(1) lists for each private fund whether its financial statements are audited (Q23), its prime brokers (Q24), custodians (Q25) and administrator, including whether the administrator is a related person and sends account statements to investors (Q26), the share of fund assets valued by someone other than a related person (Q27), and marketers (Q28). Differences between Form ADV, the DDQ and the data room are a finding in themselves.
  3. Interviews and process walkthroughs with the CFO, COO, CCO and operations staff: a payment from instruction to release, a quarter-end valuation, a capital call.
  4. Service-provider confirmations: the administrator and auditor confirm their engagement and scope directly.
  5. Testing where possible: sample reconciliations, approval evidence for a wire, a capital account recalculation.
  6. Rating and conditions: pass, pass with conditions (for example, add a second signatory, appoint an independent administrator), or fail.
  7. Monitoring: periodic re-review and event-driven review after changes in staff, providers or regulatory status.

Jurisdiction and status (US)

  • Custody Rule. Rule 206(4)-2 applies to an adviser that has custody of client assets and is registered, or required to register, with the Securities and Exchange Commission (SEC); acting in a capacity, such as general partner of a limited partnership, that gives the adviser legal ownership of or access to client funds or securities counts as custody. Client assets must sit with a qualified custodian. For a limited partnership or other pooled vehicle, the adviser can satisfy the surprise-examination requirement by having the fund audited at least annually by an independent accountant registered with and inspected by the Public Company Accounting Oversight Board (PCAOB), and distributing audited financial statements prepared under generally accepted accounting principles (GAAP) to all investors within 120 days of fiscal year end and after liquidation.
  • No standalone private fund audit rule. The SEC's 2023 Private Fund Adviser Rules, which included a mandatory annual audit rule (Rule 206(4)-10), were vacated by the Fifth Circuit on 5 June 2024. For an adviser subject to the Custody Rule, an annual fund audit is one way to comply with that rule (above); otherwise an annual audit depends on the fund's own documents.
  • Anti-money laundering (AML). The Financial Crimes Enforcement Network (FinCEN) rule bringing registered and exempt reporting advisers into the AML/CFT programme regime has been postponed to 1 January 2028, so until then that rule imposes no AML/CFT programme obligation on them, and AML diligence on advisers turns on their own policies and delegated administrator procedures. See KYC/AML.

Jurisdiction and status (EU)

For an EU alternative investment fund (AIF), the manager must appoint a single depositary (AIFMD, Directive 2011/61/EU, Article 21(1); these provisions were not changed by Directive (EU) 2024/927) that monitors the fund's cash flows (Article 21(7)) and oversees subscriptions, redemptions and the calculation of unit value (Article 21(9)). Valuation must be performed by an independent external valuer or by the alternative investment fund manager (AIFM) with the valuation task functionally independent from portfolio management (Article 19(4)), and the AIFM remains responsible for proper valuation and the NAV even when it appoints an external valuer (Article 19(10)). ODD in Europe checks how these roles are filled in practice.

Operational red flags

Findings that commonly lead to conditions or a decline:

  • Self-administration with no independent check on NAV or capital accounts.
  • An auditor that is little known, recently changed without explanation, or not inspected by the relevant oversight body.
  • A related-party custodian or administrator.
  • One person able to initiate and release payments.
  • Valuations set by the deal team with no independent review or challenge.
  • No written expense-allocation policy, or expenses that move between the fund and the management company without disclosure.
  • Late audited financial statements.
  • Regulatory deficiencies that were not remediated.
  • Inconsistent answers across the DDQ, Form ADV, the data room and interviews.
  • Reluctance to let service providers speak to the investor directly.

Not the same as

  • Investment Due Diligence: Investment diligence asks whether the strategy and team can produce returns. ODD asks whether the firm can safeguard assets and report accurately.
  • Fund Audit: A financial statement audit gives an opinion on the fund's accounts for one year. ODD assesses the manager's whole operating environment, using the audit as one piece of evidence.
  • Due Diligence Questionnaire (DDQ): The DDQ supplies the manager's answers; ODD tests them through documents, walkthroughs and third-party confirmations.

Common mistakes

  • Treating a well-known administrator and auditor as proof of sound controls. They limit some risks; they do not control the manager's bank mandates or valuation judgements.
  • Reading an administrator's controls report, such as an International Standard on Assurance Engagements (ISAE) 3402 report or its US counterpart, a System and Organization Controls (SOC) 1 report, as evidence about the manager's own controls. Under ISAE 3402 the report covers controls at the service organisation, and its description can assume complementary controls that user entities are expected to run.
  • Relying on DDQ answers without testing them.
  • Assuming the 2023 SEC private fund audit rule is in force. It was vacated in June 2024.
  • Running ODD once at commitment and never again, although most operational failures follow changes in people, providers or scale.

Edge cases

  • Emerging managers often outsource the CCO role and administration; ODD then focuses on oversight of the providers.
  • Credit funds add loan administration, agency and covenant-monitoring processes; hedge funds add trade capture, prime broker and collateral controls.
  • For a fund of one or separately managed account, the investor can set the operating terms, such as its own custodian and administrator, so ODD shifts to whether the manager follows them.

Questions

Can a strong investment case override a failed ODD review?

In many institutions it cannot: operational diligence has its own sign-off and can veto a commitment. Where it does not, a failed review normally leads to conditions that must be met before closing.

Does using a big-name administrator and auditor mean ODD is satisfied?

No. They reduce some risks, but ODD still has to test cash controls, valuation governance, expense allocation, compliance and cyber, which remain the manager's responsibility.

External standards

StandardRelationNote
ILPA DDQ 2.0 (Sections 13 (governance, risk, compliance), 15 (accounting, valuation), 18 (data security, technology, third parties))related
AIMA Illustrative DDQ (2025) (Modular questionnaire for hedge fund, private credit and private equity managers)related

Sources

  1. ILPA Due Diligence Questionnaire 2.0 (and Diversity Metrics Template). Institutional Limited Partners Association, ILPA, Version 2.0, November 2021 (v1.1 dated October 2013). Status: Current (checked 2026-10-01). Q13.29 (insurance), Q15.14, Q15.17-15.19, Q18.1.1, Q18.4 — supports: Standard ODD questions on administration, carry audit, cyber standards and insurance
  2. AIMA Illustrative Questionnaire for the Due Diligence of Investment Managers (2025 edition). Alternative Investment Management Association, AIMA, 2025 edition (modular). Status: Current; full questionnaire available to AIMA members only (checked 2026-10-01). 2025 edition — supports: Industry DDQ covering hedge fund, private credit and private equity managers
  3. Form ADV Part 1A (paper version) - Uniform Application for Investment Adviser Registration and Report by Exempt Reporting Advisers. U.S. Securities and Exchange Commission, SEC 1707 (07-24). Status: in force (checked 2026-10-01). Schedule D, Sec. 7.B.(1), Questions 23-28 — supports: Form ADV disclosure of private fund auditors, prime brokers, custodians, administrators, independent valuation share and marketers
  4. 17 CFR 275.206(4)-2 - Custody of funds or securities of clients by investment advisers (Custody Rule). U.S. Securities and Exchange Commission (CFR text via LII mirror), Current text as served by LII on 2026-10-01; source line 75 FR 1484, Jan. 11, 2010. Status: in force (checked 2026-10-01). 17 CFR 275.206(4)-2(a) introductory text, (a)(1), (a)(4), (b)(4)(i)-(iii), (d)(2)(iii) — supports: Custody Rule scope, qualified custodian, surprise examination and the pooled-vehicle audit alternative (120 days, PCAOB-registered auditor)
  5. Announcement Regarding the Private Fund Advisers Rules. U.S. Securities and Exchange Commission, 2024-10-31. Status: current (checked 2026-10-01). Announcement of 2024-10-31; list of vacated rules — supports: Private fund audit rule 206(4)-10 vacated
  6. Delaying the Effective Date of the AML/CFT Program and SAR Filing Requirements for Registered Investment Advisers and Exempt Reporting Advisers (final rule), 91 FR 36. Financial Crimes Enforcement Network (Federal Register via govinfo), Effective as of 2025-12-31; published 2026-01-02. Status: in force (checked 2026-10-01). 91 FR 36 (2026-01-02), SUMMARY and DATES — supports: IA AML Rule effective date delayed from 1 January 2026 to 1 January 2028
  7. Directive 2011/61/EU on Alternative Investment Fund Managers (AIFMD). European Parliament and Council, Official Journal of the EU, L 174, 1.7.2011, Adopted 8 June 2011; transposition by 22 July 2013. Status: In force; amended by Directive (EU) 2024/927 (AIFMD II) (checked 2026-10-01). Art. 19(4), 19(10); Art. 21(1), 21(7), 21(9) — supports: Independent valuation function, AIFM responsibility for NAV, depositary appointment, cash-flow monitoring and oversight duties
  8. International Standard on Assurance Engagements (ISAE) 3402, Assurance Reports on Controls at a Service Organization. International Auditing and Assurance Standards Board (IAASB), via IFAC, Issued December 2009; extract from the 2013 IAASB Handbook; effective for service auditors' reports covering periods ending on or after 15 June 2011 (para 7). Status: Current (checked 2026-10-01). Para 1; para 9(a)-(b), (j)-(k) — supports: Scope of service-organisation controls reports; carve-out of subservice organisations; complementary user entity controls; type 1 vs type 2
  9. Directive (EU) 2024/927 amending Directives 2011/61/EU and 2009/65/EC (AIFMD II). European Parliament and Council, Official Journal of the EU, L series, 26.3.2024, Adopted 13 March 2024; Member States to adopt and apply measures by 16 April 2026 (some reporting provisions later). Status: In force; transposition deadline passed 16 April 2026; national transposition status varies by Member State (checked 2026-10-01). Art. 1 (amendments to AIFMD Art. 21 limited to new para 5a and paras 6, 11, 16; Art. 19 not amended) — supports: AIFMD Art. 19(4), 19(10), 21(1), 21(7), 21(9) unchanged by AIFMD II
7 terms
4 terms

Concept record

Concept ID
ALTSS-DD-003
Classification
Due diligence · Operational infrastructure
Topics
Due diligence
Version
2.0.0
Last reviewed
Structured data
JSON
Source check
Legal and regulatory statements checked against the cited primary sources on (how). General information, not advice.