AI Diligence

AI Due Diligence for Private Equity

Every target claims AI. Some have it in production. Some have it on a slide deck. Some have data-provenance exposure that will show up in the buyer’s next round of diligence, not this one. Independent AI due diligence separates the three — before the deal team writes the thesis.

Timeline 2–3 weeks standard
Fee Fixed project fee
Deliverable AI risk memo + governance gap analysis
Structure Standalone or DD add-on

Why AI Needs Its Own Diligence Track

AI diligence is not a bolt-on to standard technology diligence. It has its own risk vocabulary, its own governance failure modes, and its own class of vendor lock-in exposure. Deal teams that treat it as a footnote in the technology memo miss the parts most likely to become material after close.

Three patterns show up repeatedly in AI-forward targets:

  • Capability claims that outrun the code. The pitch describes AI-driven features that either do not exist in production or run on an unstable pipeline the target does not fully understand. The revenue attributed to those features may or may not survive scrutiny.
  • Data-rights exposure with a long tail. Models trained on customer data without clear license terms. Fine-tuning done against data the target does not have unrestricted rights to. Data-provenance documentation that would not survive a customer audit or a regulator inquiry.
  • Vendor and platform lock-in disguised as an AI moat. The AI capability is thin API integration to a third-party foundation model. If the underlying vendor changes pricing, changes API terms, or is acquired, the moat evaporates. Nothing in the CIM discloses the dependency.

The engagement gives the deal team an independent read on all three before the LOI or before final IC approval.

What the Engagement Covers

1. AI and ML Model Inventory

Complete inventory of what the target actually has in production, what is in development, and what is claimed but not built. Model type (traditional ML, deep learning, foundation-model API, RAG pipeline, agent framework). Training data sources. Model owner. Production status. Business use case tied to revenue or margin. The inventory is the foundation for every other assessment.

2. Data Rights and Provenance

Data used to train, fine-tune, or ground models. Ownership, licensing, and consent posture. Customer-data usage rights. Public-scrape or third-party dataset dependencies. Regulatory exposure by data class (health, financial, biometric, minors, EU personal data). This is often where the largest hidden liability sits.

3. Governance and Controls

How models are tested before deployment, monitored in production, versioned, retired. Model risk management framework if any. Bias and fairness testing where relevant. Model incident history and postmortem discipline. Documentation adequate to answer a customer audit or regulator inquiry.

4. Vendor and Platform Lock-In

Dependency map on external LLM providers, cloud AI platforms, model APIs, embedding services, vector databases, and ML tooling vendors. Contractual protection against price change, API change, or provider acquisition. Cost sensitivity of the target’s AI-related revenue to a 2x, 5x, or 10x increase in underlying inference cost. Substitutability of each vendor.

5. AI Thesis Validation

Independent review of any AI-related claim in the deal thesis: AI-driven revenue growth, AI-driven margin expansion, AI-enabled productivity gains, product-differentiation moat from AI capability, or defensibility of an AI-based product against competitor entry. Each claim tested against the model inventory, the data rights posture, and the vendor lock-in exposure.

The pattern to watch for

The most reliable early indicator of AI diligence exposure is not the sophistication of the technology — it is the gap between the pitch and the org chart. Targets where the AI story is being told by the CEO and the CFO, without a corresponding technical owner who can defend it in an unscripted conversation, are the ones where the model inventory almost never matches the pitch. That gap belongs in the deal thesis.

Timeline & Process

A standard 2–3 week engagement runs as follows:

  • Week 1 — Intake, information request, and model inventory. Scoping call with the deal team. Information request to the target through the deal team or banker. Model inventory drafted from data-room materials, technical documentation, and initial management calls.
  • Week 2 — Deep-dive on data rights, governance, and vendor lock-in. Focused calls with the target’s technical leadership, data or ML lead, and where possible the individual model owners. Data-provenance documentation reviewed. Vendor contracts and API terms reviewed. Governance controls tested against what is claimed.
  • Week 3 — Thesis validation and memo delivery. AI-related deal-thesis claims tested against findings. Cost sensitivity modeled. Final AI risk memo delivered with governance gap analysis. Deal-team walk-through.

Compressed 2-week engagements are workable for smaller targets or add-on engagements to a buy-side diligence already in flight. AI-heavy targets or deals requiring joint scope with a specialist ML practitioner run longer and are scoped individually.

Deliverables

  • AI risk memo (15–25 pages). Model inventory, data rights posture, governance gap analysis, vendor lock-in assessment, AI thesis validation, and remediation recommendations sequenced for the first 100 days post-close.
  • Model inventory register. Every AI and ML system with owner, use case, training data, vendor dependencies, and production status. Reusable as the post-close model governance baseline.
  • Data-provenance register. Every training and fine-tuning dataset with source, licensing basis, consent posture, and regulatory exposure.
  • Vendor and platform lock-in map. External AI dependencies with contractual protection, cost sensitivity, and substitutability.
  • Deal-team briefing. Verbal walk-through of the memo with the deal partner and any associates staffing the deal.

Add-on structure

When engaged as an add-on to a Vertex CIO buy-side technology due diligence, the AI diligence runs in parallel with the standard seven-area work, shares information collection where possible, and delivers a single combined memo with the AI findings integrated into the deal-team briefing. Reduced pricing applies. Read the AI diligence framework insight →

Scope Exclusions

AI due diligence is not:

  • Academic model evaluation or novel machine-learning research. The engagement assesses AI systems from a technology-leadership and deal-risk perspective. Deals requiring deep-model performance benchmarking or research-grade evaluation are scoped jointly with a specialist ML practitioner.
  • Financial or legal diligence. Financial modeling of AI-related unit economics, legal review of AI-related IP or contracts, and formal regulatory opinions remain with the deal team’s existing advisors.
  • Post-close AI implementation. The engagement produces the memo and recommendations. Post-close model governance stand-up, model risk management framework implementation, and AI-related remediation are engaged separately — typically through a Fractional CIO engagement.

Fees and When to Engage

Fixed project fees, known upfront. Typical range $8,000–$25,000 for a 2–3 week engagement. Reduced pricing when engaged as an add-on to a Vertex CIO buy-side technology due diligence. AI-heavy targets and deals requiring joint scope with a specialist ML practitioner are scoped individually. No hourly billing. No contingent or success fees tied to close.

See our full pricing philosophy → — the reasoning behind fixed fees, and how AI diligence fits alongside standard buy-side and sell-side engagements.

The best time to engage is alongside buy-side technology due diligence, or immediately before final investment-committee approval on a deal where AI is central to the thesis. For pre-LOI screening on an AI-forward target, the pre-LOI technology quick look can absorb a focused AI red-flag pass.

Frequently Asked Questions

What is AI due diligence for private equity?

AI due diligence is an independent pre-close assessment of the AI and machine learning systems in an acquisition target, or of an AI-driven acquisition thesis. The engagement inventories what the target actually has, evaluates data rights and provenance, assesses model governance and controls, tests vendor and platform lock-in exposure, and pressure-tests any AI-related revenue or margin claim in the deal thesis. Available standalone or as an add-on to buy-side technology diligence.

When does a deal need AI due diligence separate from standard technology diligence?

Standalone AI due diligence is warranted in three situations: when the acquisition thesis depends on the target’s AI capability or AI-driven revenue, when the target has material AI or ML systems in production and the deal team wants an independent view of them, or when the target’s product roadmap depends on generative-AI features whose economics and technical assumptions need independent validation. For deals where AI is peripheral, an AI-focused module of the standard buy-side diligence is usually the right structure.

What does the AI diligence actually cover?

The engagement covers five areas: AI and ML model inventory (what is in production, what is in development, what is claimed but not built), data rights and provenance (what data the target owns, licenses, or has been trained on without clear rights), governance and controls (how models are tested, monitored, versioned, retired), vendor and platform lock-in (dependency on external LLM providers, cloud AI platforms, or third-party model APIs), and AI thesis validation (whether the AI-related revenue and margin assumptions in the deal thesis are defensible).

How is Vertex CIO qualified to conduct AI due diligence?

Vertex CIO conducts AI diligence from a technology leadership perspective — the same seven-area framework used in buy-side diligence, extended into the AI-specific questions of data rights, model governance, and vendor lock-in. The engagement does not perform academic model evaluation or produce novel machine-learning research. For deals requiring deep-model performance benchmarking or research-grade evaluation, Vertex CIO scopes the engagement jointly with a specialist ML practitioner.

How much does the AI due diligence cost?

Fixed project fees, typical range $8,000 to $25,000 for a 2 to 3 week engagement. Reduced pricing when engaged as an add-on to a Vertex CIO buy-side technology due diligence. AI-heavy targets and deals requiring joint engagement with a specialist ML practitioner are scoped individually. No hourly billing, no contingent fees tied to close.

Diligencing an AI-forward target?

30-minute call to walk through the target’s AI story, the thesis, and what an independent AI diligence would test. If the thesis holds up on the call, we’ll say so.