Operational due diligence (“ODD”) has undergone a significant transformation over the past decade. Once viewed primarily as a post-investment “check-the-box” exercise, ODD has become a central component of institutional investor due diligence, vendor oversight, and operational risk management. Today, investors are evaluating far more than investment performance.  They increasingly expect investment advisers and their critical service providers to demonstrate operational resilience, mature governance, effective cybersecurity programs, and thoughtful oversight of emerging technologies such as artificial intelligence. 

During Salus GRC’s recent Navigator Webinar, Operational Due Diligence: Building Programs for Fund Managers and Service Providers, Matt Haney and Jacob Cane of Salus GRC were joined by Joseph Hindi, Head of U.S. Fund Administration at Langham Hall, to discuss how operational due diligence expectations continue to evolve and how both investment managers and service providers can better prepare for today’s increasingly sophisticated review process. 

The discussion highlighted several themes that have become increasingly relevant for SEC-registered investment advisers and the broader private funds industry. 

Operational Due Diligence Has Become a Core Business Function 

Institutional investors no longer view operational due diligence as a secondary exercise conducted after investment analysis. Instead, ODD has become an independent assessment of whether an organization possesses the operational controls necessary to protect investor assets, maintain business continuity, and manage evolving risks. 

Importantly, this scrutiny now extends well beyond the investment manager itself. Investors increasingly recognize that advisers rely extensively on third-party service providers to support critical business functions.  These third-party service providers may include fund administrators, cybersecurity consultants, compliance consultants, law firms, cloud providers, and technology vendors. As a result, these service providers have become an extension of the adviser’s operational environment. 

This “extended enterprise” perspective means that weaknesses within a service provider’s control environment can directly affect investor confidence, fundraising efforts and ongoing business relationships. 

Cybersecurity and Vendor Oversight Continue to Drive ODD Expectations 

One of the strongest themes throughout the discussion was the increasing integration of cybersecurity into operational due diligence. 

Historically, cybersecurity questions often appeared as a separate section within due diligence questionnaires. Today, cybersecurity has become inseparable from broader operational governance. Investors increasingly evaluate how firms manage cyber risk alongside governance, business continuity, vendor oversight, and operational resilience. 

Recent regulatory developments have reinforced this trend. While institutional investors have long expected advisers to conduct meaningful oversight of service providers, recent amendments to Regulation S-P have further elevated expectations surrounding vendor oversight, particularly for vendors with access to sensitive customer information. 

The panel also noted that sophisticated investors increasingly evaluate whether advisers simply satisfy minimum regulatory requirements or instead adopt broader, fiduciary-driven best practices that exceed regulatory minimums. 

ODD Reviews Now Focus on Evidence, Not Simply Policies 

Another significant shift discussed during the webinar is the growing emphasis on evidence-based due diligence. 

Rather than simply confirming the existence of written policies and procedures, investors increasingly seek evidence that those policies operate effectively in practice. Reviewers routinely request documentation such as: 

  • Business continuity and disaster recovery plans  
  • Incident response procedures  
  • Cybersecurity policies  
  • Vendor management documentation  
  • Insurance coverage  
  • Organizational governance materials  
  • SOC reports  
  • Evidence that controls are periodically tested  

Service providers that proactively maintain organized due diligence packages can typically respond much more efficiently to investor requests than organizations that assemble documentation only after receiving a due diligence questionnaire. 

The panel emphasized that preparation itself often reflects positively on an organization’s overall governance maturity. 

SOC Reports Remain Important, but Are No Longer Sufficient 

SOC reports remain among the most frequently requested documents during operational due diligence, but the discussion emphasized that investors are becoming increasingly sophisticated in how they evaluate these reports. 

SOC 1 reports continue to provide important assurance regarding financial reporting controls, particularly for fund administrators responsible for NAV calculations, investor reporting, and financial workflows. 

SOC 2 reports remain valuable for assessing information security controls. However, the panel noted that investors increasingly recognize their limitations. A clean SOC 2 report should not automatically be interpreted as evidence of a mature cybersecurity program. 

Instead, reviewers increasingly evaluate: 

  • Scope limitations  
  • Control exceptions  
  • Complementary user entity controls  
  • Remediation efforts  
  • The reporting period covered  
  • Whether identified deficiencies have been addressed  

Simply collecting SOC reports without reviewing their contents can create a false sense of security. 

Operational Readiness Requires Continuous Preparation 

The webinar emphasized that organizations should view operational due diligence as an ongoing program rather than a periodic event. 

Successful organizations generally maintain current documentation, regularly review policies, conduct periodic testing, and continuously improve internal controls. 

The panel also discussed several practical methods for strengthening due diligence readiness, including: 

  • Developing standardized due diligence response packages  
  • Creating concise summaries of key operational controls  
  • Mapping supporting documentation to common due diligence questionnaires  
  • Regularly updating governance documents  
  • Ensuring policies accurately reflect current practices  

At the same time, organizations performing due diligence should avoid relying exclusively on materials prepared by the service provider. Effective operational due diligence frequently requires targeted follow-up questions that explore areas not addressed within standard due diligence packages. 

Common ODD Findings Continue to Center on Governance 

Although cybersecurity remains an important focus area, many operational due diligence findings continue to involve relatively basic governance weaknesses rather than sophisticated technical failures. 

Among the most common issues discussed during the webinar were: 

  • Stale or outdated policies  
  • Lack of evidence that business continuity plans have been tested  
  • Weak vendor oversight programs  
  • Poor documentation of incident response procedures  
  • Excessive user access rights  
  • Inadequate onboarding and offboarding controls  
  • Limited oversight of subcontractors and fourth-party providers  
  • Unclear allocation of responsibilities between advisers and service providers  

Importantly, the panel noted that many of these findings are readily remediated. Investors are generally less concerned about identifying isolated weaknesses than about whether organizations acknowledge those weaknesses, assign ownership, establish realistic remediation timelines, and demonstrate meaningful follow-through. 

AI Governance Is Becoming an Important Component of ODD 

Artificial intelligence represented one of the webinar’s most forward-looking topics. 

Although AI governance remains an emerging area, investors increasingly ask organizations whether they use AI tools and, more importantly, how those tools are governed. 

Current due diligence questions increasingly focus on: 

  • Whether AI tools are approved before use  
  • What data may be entered into AI platforms  
  • Whether confidential information is used to train models  
  • Data retention practices  
  • Human review of AI-generated outputs  
  • Employee training  
  • Shadow AI usage  

The panel cautioned that many organizations underestimate the operational risks associated with rapidly adopting AI-enabled tools, particularly note-taking applications and workflow automation platforms that may not provide security controls comparable to traditional enterprise software. 

Rather than attempting to prohibit AI entirely, organizations should establish practical governance frameworks that define acceptable use, require approval before implementation, educate employees, and periodically reassess emerging technologies as the market evolves. 

Key Takeaways for Investment Advisers 

As operational due diligence continues to mature, both investment advisers and their service providers should recognize that institutional expectations now extend well beyond traditional compliance documentation. Investors increasingly seek evidence of mature governance, operational resilience, thoughtful vendor oversight, and proactive cybersecurity and AI risk management. 

Several practical themes emerged from the discussion: 

  1. Operational due diligence has evolved into an ongoing governance process rather than a periodic compliance exercise.  
  1. Investors increasingly evaluate service providers as extensions of an adviser’s operational environment.  
  1. Effective ODD requires documented evidence that operational controls function in practice, not merely written policies.  
  1. SOC reports remain valuable but should be evaluated carefully rather than treated as standalone evidence of effective controls.  
  1. Strong documentation, periodic testing, and timely remediation significantly improve investor confidence during due diligence reviews.  
  1. AI governance is rapidly becoming a standard area of operational due diligence and should be incorporated into existing governance frameworks before institutional expectations become even more demanding.  

As investor expectations continue to evolve alongside regulatory developments, organizations that proactively strengthen their operational governance, vendor oversight, cybersecurity programs, and AI governance will be best positioned to demonstrate institutional-quality operational resilience during future operational due diligence reviews.