A company spends six months courting a strategic partner. The pitch decks looked sharp. The revenue projections aligned. The handshake felt right. Ninety days after signing, they discover the partner is bleeding talent, fighting a wage theft claim in state court, and running a CRM that hasn’t been updated since 2019. Nobody checked. Not because they didn’t care, but because they confused financial review with actual due diligence.
That gap between what people think due diligence covers and what it should cover is where partnerships go sideways. Financial statements are table stakes. The real exposure sits in operations, litigation history, personnel stability, and reputational drag. And most organizations skip all of it.
Financial Review Is Not Due Diligence
Somewhere along the way, “due diligence” became shorthand for “send over your P&L and let our accountant glance at it.” That is a financial review. It tells you what happened on paper. What it does not tell you is whether any of it reflects how the organization actually operates.
Revenue recognition is a good example. Two companies can report the same top-line number and arrive at it through completely different methods. One books recurring SaaS revenue with 94% retention. The other front-loads annual contracts and counts implementation fees as recognized revenue on day one. Same number. Wildly different stability. The SEC’s own guidance on reading financial statements makes the point clearly: the notes and disclosures tell you more than the headline figures ever will.
Then there’s debt. Not just what’s on the balance sheet. Off-balance-sheet obligations, operating lease commitments, contingent liabilities, personal guarantees by the principals. A partner carrying $2 million in hidden exposure is not a stable foundation for a joint venture. And you will not find that number in the pitch deck.
If your pre-transaction process stops at financials, you are not doing due diligence. You are doing half of it and hoping the other half doesn’t matter. It does.
Operational Reality vs. the Presentation
Every company looks competent in a slide deck. The due diligence that matters happens when you stop looking at what they say and start examining what they do.
Internal Controls and Process Discipline
Ask to see the internal controls. Not the policy manual sitting on a shelf. The actual controls. How does money move? Who approves expenditures? What happens when a customer dispute escalates? Is there a documented chain for financial reporting, or does the founder sign off on everything from a laptop at the airport?
Weak internal controls don’t just signal disorganization. They signal susceptibility to fraud, compliance failures, and operational breakdowns that will bleed into your partnership the moment things get complicated. The SBA recommends formal cybersecurity and operational controls even for small businesses. If your potential partner hasn’t bothered with them, that tells you something about how they manage risk.
Technology and Data Security
If the partnership involves shared data, integrated systems, or customer-facing technology, their infrastructure becomes your problem. A breach on their side hits your customers, your reputation, and your liability exposure. You need to understand their stack, their security posture, their incident response plan, and whether any of it has been tested.
Asking “do you have cybersecurity insurance?” is not a substitute for understanding their actual defenses. Insurance pays after the damage. Prevention keeps the damage from happening. According to the FBI’s business fraud advisory, partner and vendor compromise is a growing attack vector. Your partner’s weak perimeter is your open door.
People
A company with 40% annual turnover is not a company with a staffing problem. It is a company with a management problem. High turnover, active labor disputes, and Glassdoor reviews that read like warning letters all point to the same conclusion: instability. And instability in a partner means missed deliverables, inconsistent quality, and leadership distracted by internal fires instead of executing on shared objectives.
Talk to the people who do the work, not just the people who present it. That is where the real operational picture lives.
Litigation, Regulatory Exposure, and Red Flags
A fable. A farmer agrees to share a well with his neighbor. The water is clean, the terms are fair, and they shake on it. What the farmer did not check was that his neighbor had been fined twice by the county for dumping chemicals near the creek bed. Six months later, the well tests positive for contamination. The farmer’s crops are dead. The neighbor’s record was public the entire time.
Litigation history is the single most underused source of intelligence in partnership vetting. Court records are public. SEC filings are searchable. State regulatory actions are accessible. And yet most organizations skip these checks entirely because they feel adversarial. They are not adversarial. They are baseline.
Look for patterns. One lawsuit is an event. Three lawsuits in the same category across five years is a pattern. A history of disputes with vendors, customers, or employees reveals how the company behaves under pressure. That behavior will not change because your partnership agreement says it should.
Regulatory Compliance
Noncompliance is not an abstract risk. It is a concrete one with a price tag. Fines, operational shutdowns, consent decrees, debarment from government contracting. If your partner operates in a regulated industry, their compliance history is your liability exposure. One regulatory action against them can freeze your joint operations, trigger contractual defaults, and put your own standing with regulators at risk.
This is corporate intelligence work, not espionage. Every piece of this information is legally obtainable through public records, regulatory databases, and professional investigation. Not checking it is a choice. A bad one.
Intellectual Property
If the partnership involves technology, creative work, or proprietary processes, verify ownership before you sign anything. Not stated ownership. Verified ownership. Patent filings, trademark registrations, assignment agreements, license terms. A partner who claims to own IP that actually belongs to a former employer or a previous co-founder is handing you a lawsuit wrapped in a term sheet.
IP disputes are expensive, slow, and capable of freezing an entire business line for years. The time to discover them is before you sign, not after you launch.
Management Assessment and Compatibility
You are not partnering with a company. You are partnering with the people who run it. If the CEO makes decisions by gut instinct at midnight, if the CFO has a track record of failed ventures nobody mentions in polite company, if the VP of Operations cannot articulate their own process flow, those are your problems now too.
Background checks on key executives are not optional in this context. They are the minimum. A background check tells you who someone is on paper. Investigative diligence tells you how they operate when things get difficult. Prior leadership roles, decision-making patterns, how they handled past disputes or downturns, whether they’ve been named personally in any litigation. All of it matters.
Cultural compatibility is harder to quantify, but just as dangerous to ignore. Two organizations with fundamentally different operating philosophies will grind against each other at every decision point. If one side moves fast and breaks things while the other requires three committees and a memo to approve a vendor, friction will eat the partnership from the inside before revenue ever materializes.
Reputation, Customer Base, and Supply Chain
Brand association is a one-way door. The moment you announce a partnership, their reputation becomes part of yours. If they carry baggage, some of it transfers to you. Recovering from reputational contamination is slower and more expensive than almost any financial loss.
Check their customer retention numbers. Not the numbers they volunteer. The real ones. A partner losing 30% of their customer base annually has a product problem, a service problem, or both. If your partnership touches their customers, those problems become your problems.
Supply chain integrity matters too, especially if the partnership involves physical products, logistics, or sourcing. A partner with an ethically compromised supply chain, labor violations in their vendor network, or sourcing from sanctioned entities exposes your organization to regulatory action and public backlash. These are not theoretical risks. They are discoverable facts that investigative consulting is designed to surface before they become your crisis.
Why This Is BD and Intelligence Working Together
Business development without intelligence is guesswork with a quota. Partnerships are supposed to create revenue, expand market access, or add capability. But a partnership built on incomplete information is a liability wearing a revenue hat.
The mandate is Build, Grow, and Defend Revenue. Building means identifying the right partners. Growing means structuring deals that actually perform. Defending means knowing what you’re walking into before you sign. Skip any of those steps and the partnership is a gamble, not a strategy.
Pre-transaction due diligence is not a box to check. It is the difference between a partnership that compounds value and one that compounds problems. The information is out there. Public records, regulatory filings, litigation databases, industry sources, sales intelligence that most BD teams never bother to gather. The question is whether you do the work before you sign, or deal with the consequences after.
If you’re evaluating a partnership and want to know what you’re actually looking at, not just what’s being presented, reach out at [email protected] or book a call at meet.brettfl.com.