top of page

Business Due-Diligence

Our Due-Diligence (DD) service gives boards, investors, and programme sponsors an independent, evidence-based view of a company’s digital readiness—before you commit capital or kick off a transformation. We assess technology, data, cyber security, operating model, and value creation levers, then translate findings into costs, risks, and a 100-day plan you can execute.

When to use this service

Considering a major investment, merger, carve-out, or platform upgrade (e.g., move to SAP S/4HANA or a new data platform).
Launching a multi-year digital programme and want hard numbers on feasibility, spend, and ROI.
A board or audit committee requires an independent health check of delivery risk and benefit realisation.

What we assess (scope)

1) Strategy & Value Case -
Clarity of the transformation thesis, OKRs, and alignment to P&L.
Benefit logic (revenue, cost-to-serve, risk reduction) and baselines.

2) Technology & Architecture
Current estate mapping (ERP/CRM/e-commerce, data platform, integrations).
Cloud posture, scalability, resilience, technical debt, vendor lock-in.

3) Data & AI Readiness
Data model, ownership, lineage, quality, privacy and retention.
Analytics & AI capabilities, MLOps, and measurable business impact.

4) Cyber Security & Compliance
Control effectiveness (mapped to NIST/ISO), identity & access, DR/BCP.
Regulatory exposure (GDPR and sectoral), third-party risk.

5) Operating Model & Delivery
Product vs. project setup, governance, decision rights, and funding model.
Talent mix, partner dependence, delivery metrics (DORA), and ways of working.

6) Customer & Digital Growth
Journey performance (conversion, churn), performance/UX, experimentation velocity.
Channel economics (CAC/LTV), SEO/ASO defensibility and content ops.

Our approach (three phases)
Phase 1 — Rapid Diagnostic (2–3 weeks)
Artefact review, leadership interviews, KPI baselining, risk heatmap.
Hypotheses on value levers and cost ranges (capex/opex).
Output: Executive read-out, red/amber/green heatmap, initial business case.

Phase 2 — Deep-Dive Due-Diligence (3–6 weeks)
Code/architecture sampling, dependency mapping, cost-to-serve analysis.
Data quality profiling, security control testing, operating model assessment.
Output: Detailed DD report with quantified risks, investment required, critical path, and sensitivity analyses.

Phase 3 — Board-Ready 100-Day Plan
Prioritised roadmap with owners, milestones, and measurable benefits.
Governance design (product councils, architecture guardrails), value tracking.
Output: Implementation plan and benefits register tied to the P&L.

What you receive (deliverables)
Digital Risk & Opportunity Heatmap across six domains.
Investment envelope with low/likely/high scenarios and cashflow timing.
Value creation model (revenue uplift, cost reduction, risk avoidance).
Readiness score benchmarked to peers and best practice.
100-day plan + 12–18 month roadmap, with KPIs and OKRs.
Vendor & contract review highlighting lock-in, exit costs, and renegotiation opportunities.

bottom of page