Maine Street Partners

[ MSP.DD ] For investors and founders · Updated

What's in a technical due diligence report?

Short answer

A good report gives a verdict per area (red, amber or green), the evidence behind each verdict, and the issues to raise in negotiation. For an AI company the areas are: what's built versus rented, code safety including AI-written code, cost to run, regulation, and team. A partner should be able to read the summary in fifteen minutes.

Why it matters

A report that lists tool output without a verdict pushes the work back to the investor. The value is in the judgement and the evidence behind it.

The sections

  1. 01Summary: one verdict per area and the three findings that matter most.
  2. 02Built or rented: architecture, model dependencies and the rebuild test.
  3. 03Code safety: AI-written share, vulnerabilities, secrets, licences and tests.
  4. 04Cost to run: cost per customer today and at 10× usage.
  5. 05Regulation: EU AI Act classification, dates and gaps.
  6. 06Team: key-person risk and delivery capacity.
  7. 07Issues to raise in negotiation, and an evidence appendix.

Red flags

  • No verdicts, only tool output.
  • Findings without evidence.

Good signs

  • Every finding links to evidence.
  • Clear separation between facts and judgement.

The numbers

  • A typical technical review runs on read access to the git repository plus three to five interviews with the CTO and team, under NDA. [1]

Sources

  1. Kolonell, Technical due diligence cost in London (2026)