Diligence guide

Assess the AI capability before you expand it.

A polished demonstration does not establish a production capability. This guide helps operating teams distinguish a useful system from a fragile dependency, before acquisition planning, additional investment, or wider rollout.

For
Operating partners and portfolio leaders
Purpose
Identify evidence gaps before committing
Prepared by
Meru AI
Last Updated
October 1, 2026

Inspect the capability, not the presentation.

Start with the systems that are actually used. A company may have a promising prototype, a production workflow, and an abandoned tool under the same “AI” label. Assess them separately.

This is an operational and technical diligence checklist for investment planning or portfolio expansion. It complements, rather than replaces, legal, financial, cybersecurity, and transaction diligence. It is not a valuation method or a certification.

For each system, record its workflow, business owner, users, production status, dependencies, data boundaries, recurring costs, and evidence gaps. Obtain authorized access and an appropriate confidentiality arrangement before requesting sensitive material.

Ask for records that can be inspected.

Evidence requests should be proportionate to the workflow and approved for disclosure.
QuestionEvidence to requestWarning sign
Is it used?A representative production period: completed work, users, exceptions, and overrides.A demo environment or license count is offered instead of operating records.
Does it perform?Baseline, evaluation examples, live quality review, and known limitations.A single accuracy figure without task definition, sample context, or error severity.
Is it integrated?System map, write permissions, failure and retry behavior, and source traceability.A person copies outputs between systems or silently repairs failed writes.
Can it be operated?Runbook, incident history, support owner, change log, and handover test.Only the original builder can explain or recover the workflow.
Can it be controlled?Access review, approved data use, retention, vendor terms, and boundary tests.Personal accounts, shared credentials, or unclear rights to source material.

Mark each item as evidenced, incomplete, or not provided, with the material reviewed and its date. A missing record is an evidence gap, not proof that a control exists or that the system has failed.

Follow a record all the way through.

With the owner, trace representative successful, failed, and unusual records from input through the business outcome. Inspect what the model generated, what a person reviewed, what was written to another system, and what happened when information was missing.

  • Does the workflow use current, authoritative source information?
  • Can a reviewer inspect why the output was produced and identify its source?
  • Are high-impact actions restricted to approved decisions and permissions?
  • What happens on an outage, a duplicate event, an invalid response, or a changed vendor interface?
  • Can the owner stop the workflow and restore a workable manual process?

A plausible answer in a demonstration does not prove reliable behavior under live demand. Agree a proportionate evaluation plan rather than choosing an arbitrary pass rate.

Understand what the system is allowed to know and do.

Map what data is sent to each provider, what is stored, who can retrieve it, and which retention rules apply. Confirm that customer commitments, licenses, vendor terms, and company policy permit the intended use. Counsel should resolve contractual interpretations.

Inspect least-privilege access, account isolation, secrets management, audit records, and the process for removing access. If the system retrieves documents or invokes tools, test whether untrusted content can redirect it into revealing information or taking unauthorized actions.

Do not assume that a portfolio mandate permits information to cross company boundaries. A wider deployment needs separate authorization for each relevant data flow.

Cost the completed workflow, including the human work.

Define one meaningful unit: a reviewed intake, a completed report, or a resolved service request. Include model usage, software, infrastructure, integration maintenance, human review, rework, and support. Use a representative period and explain fixed versus variable costs.

Where the volume and costs are measurable, calculate total workflow operating cost divided by successful completed units. Keep one-time implementation cost visible separately; do not hide it in a flattering run-rate comparison.

Compare the new workflow with the old on quality, time, cost, and adoption. Usage is not commercial value. Faster work is not realized savings unless management can show the financial consequence; projected revenue is not realized revenue.

Ask what changes at greater volume: review capacity, vendor pricing, latency, exception handling, and support. State assumptions explicitly instead of presenting a forecast as an observed result.

Check whether the capability survives a handover.

Establish who controls the accounts, code, configuration, prompts, evaluation material, documentation, and data exports. Ownership and licensing are different questions; the contracts govern what the company can retain or transfer.

Ask a second authorized operator to explain routine use, diagnose a failed run, and demonstrate the approved recovery process. Review vendor and individual dependencies, support obligations, change approvals, and the cost of replacing a provider.

For acquisition planning, identify continuity risks early without presuming that licenses, data rights, or vendor relationships automatically transfer. Assign the relevant legal or technical review to the appropriate owner.

Separate a repairable gap from a reason to pause.

The system is called proprietary, but its dependencies are undocumented.

The label conceals reliance on a vendor, contractor, or personal account.

What to do: Map the dependencies, inspect contractual rights, and test continuity before relying on the capability.

Reported quality excludes rejected or manually repaired outputs.

The measurement describes selected model responses rather than business work.

What to do: Include failures, review effort, and rework in the denominator and reassess the operating result.

A shared portfolio tool exposes another company’s information.

Convenience has displaced data boundaries and permission checks.

What to do: Restrict the affected access, investigate with the security owner, and resolve the boundary before expansion.

Turn diligence into a specific operating recommendation.

Produce an evidence register and a prioritized remediation plan. For each gap, state the consequence, action, accountable owner, dependency, and evidence needed for closure.

  • Expand: Production evidence supports the intended use, and the next environment can meet the requirements.
  • Improve first: The workflow is useful, but specific controls, integrations, measurement, or ownership need repair.
  • Defer: Material evidence is unavailable or dependencies prevent an informed commitment.
  • Stop or replace: The proposed approach cannot meet the agreed need or boundaries; evaluate alternatives.

Avoid a single maturity score that masks missing evidence. Record what was inspected, what remains unknown, and which decisions that uncertainty affects.

Further reference. The NIST AI Risk Management Framework is a useful reference for organizing governance, evaluation, and risk controls. The sequences and checklists on this page are Meru’s practical recommendations, not a NIST certification or prescribed implementation method.

For cost measurement, the FinOps Foundation’s unit economics guidance helps frame technology spending around defined business units rather than spend alone.

Bring one workflow, the business problem it creates, and the decision you need to make. There is no need to prepare a technical specification.

Start a conversation

Do not share passwords, confidential client records, or regulated information in an initial inquiry.

Prepared from Meru’s implementation experience and consulting delivery materials. This is an operating guide, not an account of a private equity client engagement or a guarantee of financial results. Adapt the gates and controls to the company’s risk, systems, and contractual obligations.