Resources · 05
Digital due diligence: a trust checklist before commitment
Verify an organisation, its leadership, dependencies and risk signals without turning the investigation into indiscriminate data collection.
· 16 min

What this guide helps achieve
- Verify identity beyond the sales narrative
- Connect digital signals to decision risk
- Separate facts, allegations and unknowns
- Set measurable conditions before commitment
Quick check
- Is the contracting entity unambiguous?
- Are beneficial owners and leaders consistent across sources?
- Do critical dependencies have a viable fallback?
- Are incidents dated, sourced and contextualised?
- What new fact would change the recommendation?
Step-by-step method
- 01
Frame the decision and proportionality
State the decision, value or impact at risk, jurisdictions, affected people and justified verification depth. Exclude data with no decision value.
Deliverable: verification mandate and stopping criteria.
- 02
Establish identity and control
Cross-check official registers, beneficial owners, directors, addresses, domains and institutional accounts. Document name collisions and inconsistencies instead of resolving them by intuition.
Deliverable: sourced identity file.
- 03
Map activity and dependencies
Connect products, sensitive customers, suppliers, hosting, subcontractors, licences and operating regions. Find concentrations and dependencies with no realistic alternative.
Deliverable: critical dependency map.
- 04
Qualify reputation and incidents
Build a timeline from primary sources: public decisions, official statements, incidents, corrections and organisational responses. Keep established fact separate from allegation.
Deliverable: qualified timeline.
- 05
Assess digital trust
Review external exposure, visible security practice, data governance, continuity, transparency and consistency between statements and supplied evidence.
Deliverable: trust grid and evidence requests.
- 06
Decide with conditions
Present scenarios, uncertainty, residual risk and compensating measures. Give every condition an owner, evidence criterion, due date and review trigger.
Deliverable: go, no-go or conditional-go note.
Management indicators
| Indicator | What it measures | First action |
|---|---|---|
| Evidence coverage | Decision-critical points connected to primary sources or supplied evidence | Resolve unknowns most likely to reverse the decision first |
| Freshness | Evidence still valid at the subject’s pace of change | Set expiry dates for critical items |
| Concentration | Dependencies whose failure stops an essential function | Secure an alternative or compensating measure |
| Conditions cleared | Reservations closed with compliant evidence | Reject declaration-only closure |
Common pitfalls
- Confusing no signal with no risk
- Collecting personal data without necessity
- Treating media repetition as independent sourcing
- Delivering a score without decision conditions
Frequently asked questions
Does digital due diligence replace legal and financial review?
No. It complements them by examining online identity, technical dependencies, exposure, public evidence and digital consistency.
Can any individual be investigated?
Collection must remain lawful, proportionate and tied to a legitimate purpose. Sensitive or decision-irrelevant data should be excluded.
How should contradictory information be handled?
Keep both versions, trace primary sources, date them, request clarification and state residual uncertainty in the recommendation.
