[ MSP.DD ] For investors and founders · Updated
What's in a technical due diligence report?
Short answer
A good report gives a verdict per area (red, amber or green), the evidence behind each verdict, and the issues to raise in negotiation. For an AI company the areas are: what's built versus rented, code safety including AI-written code, cost to run, regulation, and team. A partner should be able to read the summary in fifteen minutes.
Why it matters
A report that lists tool output without a verdict pushes the work back to the investor. The value is in the judgement and the evidence behind it.
The sections
- 01Summary: one verdict per area and the three findings that matter most.
- 02Built or rented: architecture, model dependencies and the rebuild test.
- 03Code safety: AI-written share, vulnerabilities, secrets, licences and tests.
- 04Cost to run: cost per customer today and at 10× usage.
- 05Regulation: EU AI Act classification, dates and gaps.
- 06Team: key-person risk and delivery capacity.
- 07Issues to raise in negotiation, and an evidence appendix.
Red flags
- No verdicts, only tool output.
- Findings without evidence.
Good signs
- Every finding links to evidence.
- Clear separation between facts and judgement.
The numbers
- A typical technical review runs on read access to the git repository plus three to five interviews with the CTO and team, under NDA. [1]