Ethics, Compliance, and Confidentiality

Ethics, Compliance, and Confidentiality

Commercial due diligence is performed under intense time pressure and with unequal access to information. That combination makes professional ethics non‑negotiable. Your credibility—and your client’s legal exposure—hinge on how you collect data, what you ask people to disclose, how you store and analyze evidence, and how you present conclusions. This chapter codifies the rules of the road: independence and objectivity; antitrust and pre‑close restrictions; privacy and data‑protection; anti‑bribery and sanctions; treatment of material non‑public information (MNPI); responsible use of vendors and expert networks; and the security and confidentiality practices that protect clients and sources.

We write these standards to be practical. They map directly to how you scope work, run primary and secondary research (Chapter 4), handle data rooms (Chapter 18.2), structure integration feasibility (Chapter 15.3), and compose decision‑grade deliverables (Chapter 18). Treat this as a living checklist: what you sign up to at kick‑off, what you monitor daily, and what you attest to before any page goes to a committee. 

19.1 Professional Standards Checklist

Use this checklist at engagement kick‑off, during weekly governance, and at final sign‑off. Every line should be either clearly “Yes” or “Not applicable—with rationale.” If any box is “No,” stop the line and escalate to the Engagement Lead and Legal/Compliance.

A. Engagement acceptance, independence, and scope

Independence & conflicts cleared

  • Formal conflict check complete across the firm and relevant affiliates.
  • Financial interests disclosed (team and immediate family); personal trading restrictions acknowledged.
  • No advisory roles or fee structures that bias conclusions; success‑fee components (if any) disclosed and approved.

Mandate & legal instruments executed

  • Signed engagement letter with scope, deliverables, timing, and liability limitations.
  • Mutual NDA and Data Processing Agreement (DPA) covering roles (controller/processor), purpose, retention, and security controls.
  • Clean‑team protocol approved by counsel, including rosters, data classes, and collaboration boundaries.

Regulatory footprint understood

  • Applicable regimes identified (e.g., antitrust/competition, privacy, sector rules such as HIPAA/PCI/FedRAMP, export controls/sanctions).
  • Outside counsel assigned for antitrust and pre‑close conduct; escalation path documented.

B. Antitrust, pre‑close (“gun‑jumping”) and fair‑competition guardrails

No joint operations or pricing pre‑close

  • No joint setting of prices, discounts, customer allocation, supplier terms, production, or marketing plans with the target.
  • Integration planning limited to what‑if and clean‑team analysis; no direction to the target’s business.

Clean‑team mechanics in force

  • Competitively sensitive data (customer‑level pricing, margins, future plans) accessible only to cleared clean‑team members; outputs aggregated/obfuscated per protocol.
  • Meeting agendas/materials pre‑cleared by counsel where sensitive topics may arise; minutes kept.

Information‑exchange discipline

  • Use third‑party or clean‑team aggregation for market data; avoid contemporaneous competitors‑specific forward‑looking details.
  • Any joint customer, supplier, or channel interactions are pre‑cleared with counsel and scripted.

C. Anti‑bribery, corruption, sanctions, and trade compliance

Zero tolerance for improper inducements

  • No facilitation payments, improper gifts, or contingent compensation to public officials or counterparties.
  • Gifts/hospitality within firm policy; pre‑clear exceptions.

Third‑party due diligence

  • Expert networks, market‑research vendors, and intermediaries screened for ABAC violations, sanctions, and adverse media.
  • Contractual clauses include anti‑corruption, sanctions, and audit/cooperation provisions.

Sanctions and export controls observed

  • No engagement with sanctioned individuals/entities or restricted geographies; data transfers/export classified where relevant.

D. Handling material non‑public information (MNPI) and insider‑trading controls

MNPI identification and controls

  • Team trained to recognize MNPI; “if in doubt, treat as MNPI and escalate.”
  • Restricted list and personal‑trading blackout acknowledged; wall‑cross events logged with date/time and roster. 

Need‑to‑know access

  • MNPI and highly sensitive materials limited to essential staff; separate storage/workspaces where policy requires.

E. Data privacy, confidentiality, and information security

Data minimization by design

  • Collect only data needed to answer the hypotheses (Chapter 2.1); avoid PII/PHI unless strictly necessary and covered by DPA.
  • Prefer anonymized/pseudonymized datasets; hash IDs for customers, employees, and individuals.

Lawful basis & cross‑border transfers

  • Lawful basis documented (contract, legitimate interests, consent).
  • Cross‑border transfers are protected (e.g., SCCs or equivalent) and recorded.

Security controls in place

  • Approved firm systems only (no personal email, consumer cloud drives, or unauthorized LLMs).
  • Encryption in transit and at rest; strong authentication (SSO + MFA); role‑based access and least‑privilege permissions.
  • VDRs configured per 18.2 (watermarking, download controls, audit logs); breach‑response plan with 24‑hour internal escalation.

Retention & destruction

  • Retention schedule set at kick‑off; legal hold respected if applicable.
  • Secure destruction of client data at project close; certificates retained.

F. Primary research ethics (interviews, surveys, mystery shopping)

Transparent and lawful outreach

  • Identity and purpose disclosed unless documented mystery‑shop exception is legal and approved by counsel.
  • Consent for interviews/surveys obtained; call‑recording complies with local consent laws; opt‑out respected.

No solicitation of prohibited information

  • Do not request others’ confidential information, trade secrets, or MNPI.
  • Current employees of competitors only questioned on public/personal opinions and non‑confidential processes.

Compensation and incentives

  • Reasonable, pre‑set honoraria aligned with market‑research norms; no outcome‑contingent payments.
  • No payments to public officials without counsel review; adhere to anti‑gift policies.

Expert networks

  • Use approved networks; comply with their compliance prompts; avoid restricted topics; log expert IDs and attestations.

G. Secondary research, IP, and license compliance

Respect terms of use

  • Use licensed databases and publications; no scraping behind paywalls or violating robots/ToS.
  • Cite sources; preserve evidence of license/usage rights in the workpapers. 

Attribution and fair use

  • Quote minimally; transform and analyze rather than reproduce; mark third‑party charts and trademarks appropriately.

H. Responsible analytics and AI use

Approved tools only

  • Client or firm‑approved AI/analytics platforms; no client data in public LLMs or unapproved tools.
  • Document prompts and outputs that materially influence conclusions; human review mandatory.

Model risk management

  • Treat AI outputs as hypotheses; verify with primary sources (invoices, settlement files, GL, VoC).
  • Avoid generating or fabricating citations; maintain an audit trail.

I. Evidence integrity and reporting standards

Reproducibility

  • Every number in the deck reproducible from named model cells in ≤3 clicks (Chapter 18.1); evidence registry maintained (18.2).

Balanced presentation

  • Separate passive vs. managed outcomes; cost the response; show scenario ranges and confidence labels.
  • State limitations and assumptions clearly; no cherry‑picking or selective omission.

No investment, legal, or tax advice

  • Include appropriate disclaimers; route legal interpretations through counsel; keep to commercial analysis.

J. Communications, marketing, and disclosure

Client confidentiality

  • No external sharing or marketing use of client name, data, or results without written consent.
  • Sensitive calls/meetings held in private spaces; screen‑sharing hygiene enforced (no unintended windows).

Document classification

  • Mark materials (Confidential/Attorney‑Client Privileged/Attorney Work Product) per counsel instruction.

K. Team conduct, inclusion, and safety

Professional conduct

  • Zero tolerance for harassment, discrimination, or retaliation; inclusive interviewing and outreach practices.
  • Reasonable working hours and psychological safety norms; encourage “speak‑up” on risk/ethics concerns.

L. Governance, escalation, and incident response

Issue logging and escalation

  • Red flags (Chapter 16.2) logged within 24 hours; severity assessed; Engagement Lead and Legal informed.
  • Data incidents/MNPI concerns trigger immediate containment, counsel notification, and client notice per contract/law.

Decision rights

  • Only named approvers can release deliverables, change scope affecting legal exposure, or authorize exceptions to policy.

M. Final sign‑off (no deliverable leaves without these)

Compliance attestation

  • Engagement Lead and Compliance sign off that: (i) conflicts and clean‑team rules were observed; (ii) privacy/security controls applied; (iii) ABAC/sanctions screens are clean; (iv) MNPI handled under policy.

Workpaper archive

  • Model, evidence registry, and key exhibits archived with version stamps; retention clock started; access locked down.
  • Request to share or discuss current/future pricing, discounts, customer allocation, or production plans between deal parties pre‑close.
  • Any team member receives or suspects they have received MNPI or a competitor’s non‑public confidential information.
  • Pressure to alter a conclusion, omit a material caveat, or misstate uncertainty.
  • Instruction to put client data into non‑approved tools, personal email, or consumer cloud storage.
  • Proposed payments, gifts, or benefits that could be construed as inducements.
  • Data breach indicators (unexpected access, lost device, misdirected email with sensitive attachments).

Red‑flag checklist for primary research (fast screen before every call)

  • Have we disclosed our identity and purpose (unless a counsel‑approved mystery‑shop)?
  • Are we avoiding prohibited topics (confidential info, MNPI, future pricing, trade secrets)?
  • Is the incentive reasonable and pre‑cleared?
  • Do we have consent to record, and are we complying with local laws?
  • Are we logging the call and the expert/network attestations in our evidence registry?

72‑hour compliance sprint (what “good” looks like by Day 3)

  • Day 0: Execute NDA and DPA; publish clean‑team protocol and roster; stand up secure VDR and access model; conflict/MNPI attestations signed.
  • Day 1: Configure evidence registry; set retention/destruction schedule; load template consents and survey scripts; brief the team on antitrust and MNPI rules.
  • Day 2: Vet and contract expert networks/vendors; stand up approved AI/analytics workspace; test breach‑response drill.
  • Day 3: Hold a compliance checkpoint; clear any open exceptions; lock the sign‑off workflow for deliverables.

Acceptance criteria for compliance‑ready due diligence

  • All A–M checklist items are Yes or N/A with rationale; no “No”s outstanding.
  • Clean‑team, privacy, and security controls verified; access logs demonstrably active.
  • Evidence registry complete; every headline number in the deck is traceable in ≤3 clicks.
  • Red‑flag and incident‑response playbooks ready; team trained; escalation paths tested.
  • Final compliance attestation signed before any client or lender read‑out.

Hold yourselves to this standard and you protect not just your client and counterparties—but also your judgment. Ethical discipline is a competitive advantage: it preserves access, accelerates decisions, and ensures the dollars you underwrite can stand up to scrutiny long after the deal closes.

19.2 Conflict-of-Interest Screening Guide

Conflicts of interest (COIs) erode trust faster than analytical errors. In commercial due diligence they can also create legal exposure—particularly around antitrust, MNPI, and pre‑close conduct. This guide gives you a practical, repeatable way to detect, assess, mitigate, and document COIs before they compromise independence or delay a decision. Use it at three moments: (1) before proposal, (2) at engagement kick‑off, and (3) as a standing weekly control through close.

What counts as a conflict—working definitions

  • Actual conflict: a current relationship or incentive that a reasonable person would conclude biases judgment (e.g., advising the target’s closest competitor on pricing strategy this quarter).
  • Potential conflict: a circumstance that could mature into a conflict with new facts (e.g., active proposal to the seller while pitching the buyer).
  • Perceived conflict: appearance of bias even if controls are effective (e.g., senior advisor holds a visible board seat in a related company).
  • Direct vs. indirect: direct = you/your firm; indirect = immediate family/household, controlled entities, subcontractors, expert networks engaged on your behalf.

Scope of screening (always check all five)

  • Entity relationships: current, recent (lookback 36 months), and planned work with the buyer, target, seller, top competitors, top customers, key suppliers, lenders, and co‑investors.
  • People relationships: board seats, advisory roles, employment history in the last 24 months, immediate family ties with decision makers or materially relevant employees.
  • Financial interests: personal and household holdings (public and private), carried interest, co‑invests, side letters, success‑fee arrangements, earnouts, tokens/convertibles.
  • Information exposure: MNPI wall‑crosses, clean‑team memberships, access to competitively sensitive data, prior NDAs with scope overlaps.
  • Third parties: expert networks, subcontractors, data providers, law/accounting firms working on both sides, and any vendor paid contingent on deal success.

Step‑by‑step COI process (use this sequence every time)

1) Pre‑proposal screen (same day)

  • Run a firmwide engagement search for the last 36 months across buyer, target, seller, top 10 competitors, top 10 customers, lenders, and co‑investors.
  • Query the restricted list and insider list for all named entities; record any wall‑cross dates and rosters.
  • Check the fee model: prohibit or pre‑clear any success‑contingent elements; document how incentives are neutralized.
  • Draft a pre‑proposal COI note: list hits, preliminary risk rating (High/Medium/Low), and proposed mitigations.

2) Kick‑off clearance (within 24–48 hours of LOE/NDA)

  • Collect team attestations (personal holdings, board/advisory roles, immediate family conflicts, prior employment, gifts/hospitality over policy).
  • Confirm clean‑team protocol (roster, data classes, aggregation rules) and that access controls match the protocol.
  • Screen subcontractors/expert networks (ABAC, sanctions, independence, MNPI policies); embed contractual COI reps and audit rights.
  • Obtain client disclosures on any exclusivity, multi‑track processes, club deals, or lender overlays; align on whom else they’ve engaged.

3) Weekly COI refresh (15 minutes)

  • New names check (accounts added, alternate bidders, lenders, regulators, marketplace/platform owners).
  • Team changes: backfill → re‑run attestations; recuse as needed.
  • Review MNPI events (new wall‑cross, expanded clean‑team scope); verify information barriers and logs.

4) Close‑out (before any external deliverable)

  • Re‑affirm attestations; document recusals; archive the COI register with the model version and deliverable list; issue a COI clearance memo signed by Engagement Lead and Legal/Compliance.

COI materiality rubric (how to rate what you find)

  • Proximity: same decision (High), same company different decision (Med), adjacent market (Low).
  • Recency: <6 months (High), 6–24 months (Med), >24 months (Low).
  • Information sensitivity: MNPI/clean‑team (High), confidential but not sensitive (Med), public/aggregated (Low).
  • Economic incentive: success fee/equity or carry (High), fixed fee (Low).
  • Control effectiveness: no barrier (High), ring‑fenced with audit (Med), separate firm entity/fully independent team (Low).

Decision rule:

  • High → decline or obtain written client waivers and run full separation (dual teams + monitored barriers) with independent QA.
  • Medium → disclose and mitigate; Legal/Compliance sign‑off required before work.
  • Low → document and monitor; included in the COI register.

Mitigation toolbox (pick the smallest control that works)

  • Ring‑fencing: separate physical/IT workspaces, repositories, and collaboration tools; dedicated channels; no cross‑staffing; access at least privilege.
  • Dual‑team structure: independent leadership chains; separate QA; independent financial review; mandatory delay between personnel moving sides.
  • Recusals: remove specific individuals; document start/end dates; scrub notes/devices/archives.
  • Independent review: third‑party or separate internal reviewer validates deliverables against scope and COI plan.
  • Scope limits: no pricing advice if counterpart work exists; clean‑room analytics using anonymized/aggregated data only.
  • Disclosure and consent: written client acknowledgment of the conflict and chosen mitigations; renewal of scope changes.
  • Compensation neutralization: remove success fees; separate billing centers; cap variable comp tied to close.
  • Audit trail: immutable logs for access, exports, and barrier breaches; quarterly audit of multi‑month.

Red flags and stop‑the‑line triggers (escalate immediately)

  • Simultaneous or near‑simultaneous advice to buyer and seller on the same asset.
  • Team member with board seat, carry, or side letter in the target, buyer, or a principal competitor.
  • MNPI wall‑cross plus overlapping staffing without effective barriers.
  • Success‑contingent fee tied to the transaction closed without explicit Legal approval and client disclosure.
  • Instruction to share competitor pricing, customer lists, or future plans across parties pre‑close.
  • Expert, subcontractor, or data provider engaged by both sides with unclear access controls.
  • Personal relationship (immediate family/intimate partner) with a decision maker on either side of the deal.
  • Legal or compliance pushback on documenting the conflict and mitigations.

Special contexts (raise the bar)

  • Private equity with portfolio conflicts: check portfolio company overlaps by market, customer, and supplier; watch co‑invests and sidecar funds; ensure carry alignment disclosed.
  • Lenders/credit funds: if preparing both equity and lender cases, maintain dual‑team separation and distinct deliverable scopes; avoid sharing borrower‑sensitive covenants.
  • Public sector/regulated: stricter procurement ethics; cooling‑off periods for former officials; gift and lobbying rules; segregation of pre‑decisional documents.
  • Platform/marketplace owners: policy enforcement and listing decisions create latent conflicts; prohibit pre‑close strategy sharing that could be seen as coordination.
  • Audit/assurance affiliates: independence rules may restrict consulting; confirm whether any affiliate provides audit/attest services to entities in scope; obtain independence clearance.
  • Sanctions/export controls: any party on a watchlist is a hard stop without Legal approval.

COI register—required fields (keep one list, not many)

  • Engagement identifiers; buyer/target/seller and counterparties (competitors, customers, suppliers, lenders, co‑investors).
  • Conflict description; type (actual/potential/perceived); source (firm/personal/third‑party).
  • Materiality rating and rationale; information sensitivity (public/confidential/MNPI).
  • Mitigation plan (barriers, recusals, scope limits, disclosures); effective date and owner.
  • Approvals (Engagement Lead, Legal/Compliance, Client acknowledgments); renewal dates.
  • Incident log (breaches, escalations, remediations); final disposition at close.

Team attestation—what every member signs

  • No undisclosed financial interests (equity, options, carry, tokens) in named entities; no side letters or finder fees.
  • No board/advisory roles or immediate family ties that create bias; disclose outside employment in relevant markets.
  • Agreement to MNPI, clean‑team, and information‑barrier policies; no use of unapproved systems.
  • Commitment to report gifts/hospitality, political contributions that could create perceived bias, and any new conflicts within 24 hours.

Vendor and expert network screening (don’t skip the plumbing)

  • Written ABAC/sanctions warranties and MNPI policies; audit/cooperation clause; immediate termination for breach.
  • Expert eligibility checks (no current employees of restricted competitors unless under compliant topics); logs of network attestations.
  • Payment terms that are not contingent on deal outcome; clear scope of permissible topics.

Fee structure guardrails (keep incentives clean)

  • Default to fixed or time‑and‑materials; prohibit fees contingent solely on close.
  • If performance‑based elements exist (e.g., tied to milestones), disclose and cap; ensure they reward work quality not transaction outcome.
  • Never take equity/equivalents in the buyer, seller, or target while providing diligence.

Communications do’s and don’ts (reduce perceived conflicts)

  • Do disclose early and in writing; use consistent language in proposals, SOWs, and read‑outs.
  • Do identify who is on which side; share ring‑fence diagrams if dual teams exist.
  • Don’t joke about “both sides of the table”; don’t imply outcome dependence; don’t share anecdotes that could expose client strategies.

Decision tree (accept, mitigate, or decline)

  • Accept only if materiality is Low and controls are inherent (no MNPI, no overlapping staffing, no success fees).
  • Mitigate if materiality is Medium and mitigations are practical, measurable, and auditable; require written client acknowledgment.
  • Decline if materiality is High, MNPI overlaps exist, or mitigations would be performative (barriers in name only).

COI Questionnaire (issue at kick‑off; update on role changes)

  • List all financial interests (you and household) in named entities; include options, carry, tokens, SAFEs, side letters.
  • Current/last‑24‑month employment, board, advisory, or consulting roles related to entities in scope.
  • Family/close personal relationships with executives, directors, key managers, or deal team members at named entities.
  • Gifts/hospitality over policy thresholds received from or provided to named entities in the last 12 months.
  • Prior clean‑team/MNPI access and dates; current restricted‑list status.
  • Outside income sources that could intersect (expert calls, teaching, paid writing) with entities in scope.
  • Acknowledgment of policies (antitrust, MNPI, privacy/security, ABAC, sanctions) and agreement to report changes within 24 hours.

72‑hour clearance sprint (from blank page to decision‑grade COI file)

  • Day 0: Run firmwide search and restricted‑list checks; draft preliminary COI map; propose mitigations; decide proposal go/no‑go.
  • Day 1: Collect team attestations; set clean‑team roster and barriers; screen vendors/experts; align fee model.
  • Day 2: Obtain client disclosures; finalize mitigations (ring‑fences, recusals, scope limits); secure Legal/Compliance sign‑off.
  • Day 3: Publish the COI register and clearance memo; embed a 15‑minute weekly COI checkpoint in governance.

Acceptance criteria for a conflict‑clean engagement

  • A single COI register exists, current, and approved by Legal/Compliance; all team members have signed attestations.
  • Any Medium/High issues are disclosed in writing to the client with explicit consent and dated mitigations.
  • Information barriers and clean‑team mechanics are operational (separate repositories, access controls, logs).
  • Compensation structure is independent of deal outcome (or explicitly approved and neutralized).
  • Vendors/experts are screened and contracted with COI, MNPI, ABAC, and sanctions clauses.
  • A close‑out memo confirms no barrier breaches and archives the register with the final deliverables and model version.

Run this checklist with rigor and your work remains defensible: the team is independent, the analysis is trusted, and the record shows you identified, mitigated, and documented conflicts before they could compromise the deal—or your reputation.

19.3 Information Security Protocol Template

Information security in commercial due diligence is not an IT add‑on; it is a deal enabler. Clients, lenders, counterparties, and regulators expect the same controls you would use to protect production systems—applied to the VDR, the model, primary research, clean‑team work, and every deliverable. This template gives you a complete, copy‑ready protocol you can adopt at kick‑off, monitor weekly, and attest to before any read‑out. It aligns to widely used control frameworks (e.g., NIST CSF, ISO 27001, SOC 2) and to this playbook’s mechanics (data room in 18.2, risk in 16, story and model in 17–18).

Purpose and scope

This protocol protects the confidentiality, integrity, and availability of diligence data and work products across their lifecycle—ingest → store → analyze → share → archive/destroy—covering people, processes, and technology used by the engagement team and approved vendors. It applies to all formats (structured data, documents, recordings, notes), all environments (VDR, modeling workspace, collaboration tools), and all participants (client, target, advisors, third‑party experts), with additional restrictions for clean‑team handling of competitively sensitive information.

Roles and accountability

Name people, not functions. Each role has explicit authorities and daily routines.

  • Engagement Lead (EL): owns protocol adoption; signs final compliance attestation.
  • Security Officer (SO): configures access, monitors logs, runs incident response; escalation owner.
  • Clean‑Team Lead (CTL): enforces segregation and aggregation rules; approves outputs that leave the clean room.
  • Data Steward (DS): curates the evidence registry, validates source lineage, tracks retention/destruction.
  • Model Owner (MO): keeps the model in a secured repo; maps driver cells to sources; controls model exports.
  • Vendor Manager (VM): screens expert networks and processors; ensures DPAs and sub‑processor lists are current.

Publish the names and backups on Day 0; no analyst should be uncertain who to call for a security decision.

Data classification and handling rules

Classify every artifact when you ingest it; the label travels with the file and governs storage, sharing, and destruction.

  • Public: already public; no restrictions
  • Internal: playbook methods and non‑sensitive notes; share within the firm only.
  • Confidential: client or target information with business sensitivity; store in VDR or approved workspace; share on a need‑to‑know basis.
  • Restricted (Clean‑Team): competitively sensitive data (customer‑level pricing, forward plans, detailed margins); accessible only to clean‑team roster; outputs must be aggregated/anonymized before leaving the clean room.

Handling rules that apply to Confidential/Restricted:

  • Minimize: collect only what is necessary to test hypotheses (Chapter 2).
  • Pseudonymize: hash or tokenize customer, employee, or individual identifiers; avoid raw PII/PHI unless strictly required and contractually covered.
  • Label & watermark: every file carries sensitivity label, source code, extract date, perimeter, and currency.
  • No shadow IT: never move data to personal email, consumer cloud drives, or unapproved devices.

Access control and authentication

Grant the least privilege needed, review weekly, and revoke immediately on role change.

  • SSO + MFA mandatory for all systems (VDR, code repos, modeling workspace, chat, file shares).
  • Role‑based access with explicit groups for Clean‑Team vs. Non‑Clean‑Team; deny by default.
  • JML (Joiner‑Mover‑Leaver) process: access provision within 4 hours of joining; review on every role change; removal within 2 hours of departure.
  • Just‑in‑Time access (JIT): temporary elevated rights expire automatically after the task window.
  • Device posture: only managed devices with full‑disk encryption, EDR/anti‑malware, host firewall, and screen‑lock ≤10 minutes idle. USB storage disabled by policy.

Secure environments

Use only approved and logged systems; configure each per the checklist.

  • VDR (primary store): watermarking; download/print controls per role; IP allow‑listing when feasible; activity logs with user, file, action, timestamp; weekly log review.
  • Modeling workspace: version‑controlled repository; protected branches; signed commits; secrets kept outside spreadsheets; model exports tagged with model version ID and perimeter notes.
  • Collaboration tools: project‑scoped channels; external guests gated; file previews only for Restricted data; no forwarding outside the workspace.
  • Primary research tools: survey and interview platforms with consent capture and data residency options; recording defaults off unless consented.
  • Secure sandboxes: open untrusted files (e.g., macro‑enabled spreadsheets) in isolated viewers; never enable macros by default.

Encryption and key management

  • In transit: TLS enforced for all endpoints; reject weak ciphers; prefer modern TLS configurations.
  • At rest: server‑side encryption (AES‑256 or better) for VDR and sanctioned stores; full‑disk encryption on endpoints.
  • Keys: managed by the platform or the firm’s KMS; access limited to SO; rotation at least annually or on compromise; never embed secrets in files or code.

Logging, monitoring, and audit trail

What you do not log, you cannot defend. Maintain a single security logbook with:

  • Access logs: who viewed, downloaded, exported, or shared which files and when; kept ≥1 year or per contract.
  • Administrative actions: changes to permissions, group memberships, clean‑team rosters.
  • Data lineage: evidence registry entries linking deck numbers and model drivers to exact source files/rows and extract dates (Chapter 18.2).
  • Alerting: failed logins, abnormal download volumes, access from unexpected geographies, disabled EDR.
  • Reviews: SO reviews weekly; escalates anomalies within 24 hours; documents outcomes in the logbook.

Third‑party and vendor controls

No third party touches data without screening and a contract.

  • Due diligence: ABAC/sanctions screening, security posture review, privacy policy and breach history, data residency and sub‑processor list.
  • Contracts: NDAs + DPAs with purpose limitation, retention/destruction, incident‑notice windows, audit rights, and sub‑processor transparency.
  • Access: least‑privilege, time‑boxed; vendor accounts segregated and labeled; logs retained alongside internal logs.
  • Expert networks: require expert eligibility attestations (no MNPI, no current employer confidentials), topic guardrails, and recorded consent.

Clean‑team protocol (segregation and outputs)

  • Segregated stack: separate VDR workspace, channels, and model branch; Non‑Clean‑Team cannot access or search within it.
  • Roster & training: named CTL approves membership; every member completes antitrust/clean‑team training before access.
  • Outputs: only aggregated/anonymized analyses may exit the clean room; CTL signs off, and legal retains a copy.
  • Audits: barrier tests run weekly (attempted cross‑access checks); incidents escalate immediately.

Primary research security

  • Consent first: inform identity and purpose (unless counsel‑approved mystery shop); obtain recording consent; honor opt‑outs; comply with local recording laws.
  • Sanitize notes: remove names and contact details; replace with hashed IDs; store transcripts in approved systems only.
  • Prohibited topics: do not solicit trade secrets, MNPI, or forward‑looking competitor plans; stop the interview if such topics arise and note the incident.

AI and analytics safeguards

  • Approved tooling only: use firm‑approved analytics/AI platforms; no client or target data in public LLMs or unsanctioned tools.
  • Prompt hygiene: redact sensitive fields before analysis; keep prompt/output logs where material to conclusions; human review required for any AI‑assisted output.
  • Provenance: AI‑generated insights must be verified against primary sources (invoices, settlement files, GL, VoC) before inclusion in the deck.

Incident response (IR)

Write this section like a runbook. When a control fails, seconds count.

  • Severity levels:
    • S1: confirmed leakage of Restricted data, MNPI exposure, or suspected criminal compromise.
    • S2: unauthorized access to confidential data, malware on a managed device, or failed barriers.
    • S3: policy violations without evidence of access (e.g., attempted export blocked).
    • S4: false positives and routine exceptions.
  • The first hour (all severities):
    • Contain: disable affected accounts; revoke tokens; quarantine devices; freeze VDR sessions.
    • Assemble: EL, SO, CTL, Legal, VM; open an IR case; assign a scribe.
    • Preserve: snapshot logs; do not delete artifacts; note exact timestamps.
    • Assess: severity; impacted data classes; jurisdictions; notification requirements.
  • Next 24–72 hours:
    • Eradicate: remove malware; rotate keys; reset credentials; patch vulnerabilities.
    • Notify: client and affected parties per contract/law; coordinate with counsel on regulator notifications.
    • Recover: restore from known‑good backups; re‑enable access gradually; monitor closely.
    • Root cause: five‑whys; document control gaps; open corrective actions with owners and dates.
  • Close‑out: post‑mortem (18.4), updated risk heat‑map (16.1), and protocol adjustments.

Business continuity (BC) and disaster recovery (DR)

  • Backups: versioned, encrypted backups for model, evidence registry, and critical workpapers; test restores quarterly; define RPO ≤24 hours and RTO ≤24 hours.
  • Loss scenarios: stolen laptop, VDR outage during read‑out, cloud identity provider failure; pre‑baked workarounds (spare managed devices, read‑only deck copies, alternate identity fallback).
  • Vital records: store engagement roster, contacts, escalation trees, and acceptance criteria in a separate, replicated location.

Retention and destruction

  • Retention plan: declare periods at kick‑off (e.g., 12–24 months unless contract specifies otherwise); hold exceptions documented by Legal.
  • Destruction: cryptographic wipe or platform delete; destroy local caches and working copies; revoke shared links; obtain certificates of destruction from vendors; DS logs completion.
  • Archival set: minimal set retained for defensibility (final deck, model version, evidence registry, decision log, COI register, clean‑team charter, IR records).

Secure deliverables

  • Packaging: watermark “Confidential”; include model version ID, perimeter, currency, and extract dates for key sources.
  • Transmission: share only via VDR or secure link with expiry; no email attachments for Restricted data.
  • Content hygiene: no PII/PHI, named customer pricing, or competitor‑sensitive details in the main deck; anonymized samples for appendix if counsel permits.

Daily and weekly operating rhythm

  • Daily: JML updates; review overnight security alerts; validate any new data ingests have labels and registry entries.
  • Weekly: access reviews; VDR log scan; clean‑team barrier test; vendor sub‑processor list check; risk/incident review with open actions and owners.
  • Pre‑read‑out gate: run the “Final Sign‑off” checklist below; no exceptions without EL + Legal approval.

Copy‑ready artifacts (drop into your SOW or kickoff pack)

Security Statement (SOW language)
“We maintain role‑based, least‑privilege access; SSO + MFA; encryption at rest and in transit; clean‑team segregation for competitively sensitive data; logging and weekly review of access; approved tools only (no client data in public LLMs); incident response with 24‑hour escalation; and retention/destruction per contract.”

Clean‑Team Charter (excerpt)
“Restricted data is accessible solely to the Clean‑Team roster in segregated environments. Outputs leaving the clean room are aggregated/anonymized and must be approved by the Clean‑Team Lead and counsel. Attempts to bypass barriers trigger immediate incident escalation.”

Incident Notification Clause (client‑facing)
“We will notify Client’s Security and Legal contacts of any confirmed or reasonably suspected unauthorized access to Confidential or Restricted information within the earlier of 48 hours or the contractual requirement, providing scope, timeline, mitigations, and next steps.”

Certificate of Destruction (template language)
“We certify that on [date], all Client‑provided Confidential/Restricted information and derivatives in our possession or control were securely destroyed, except for archival records retained under legal hold. Methods: [method]. Covered systems: [systems]. Signed: [SO/EL].” 

Day‑0 to Day‑3 spin‑up checklists

Day 0 (before data lands)

  • Execute NDA and DPA; publish Clean‑Team roster and charter.
  • Stand up VDR with labels, MFA, watermarking, and logs enabled; create role groups.
  • Configure modeling repo and collaboration channels; restrict external sharing; disable downloads for Restricted by default.
  • Post the protocol and roles; schedule the weekly security review.

Day 1

  • Provision users via SSO; validate device posture; confirm JML workflow.
  • Load the evidence registry shell; align source codes and extract date format.
  • Screen vendors/experts; execute contracts with DPAs and audit rights.
  • Run a breach‑response drill (table‑top) for a plausible scenario.

Day 2

  • Ingest first data drops; apply labels and watermarks; complete lineage entries.
  • Turn on alerts for abnormal downloads and fail MFA; run a clean‑team barrier test.
  • Publish retention schedule; tag any legal holds.

Day 3

  • Perform the first weekly access review; fix access drift; document outcomes.
  • Verify backup and restore of the model and evidence registry; record RPO/RTO test.
  • Issue a short “security status” note with open actions and owners.

Final sign‑off checklist (no deliverable leaves without these)

  • Roles named; protocol posted; JML running; device posture confirmed.
  • VDR logs enabled, reviewed, and archived; modeling repo protected; collaboration channels scoped.
  • Data classified and labeled; evidence registry complete for all deck numbers; reproducibility in ≤3 clicks from model to source.
  • Clean‑team segregation proven by a barrier test; outputs approved by CTL and legal.
  • Vendors screened and contracted; DPAs on file; sub‑processors listed.
  • IR runbook tested; contact tree verified; no open S1/S2 incidents.
  • Retention/destruction plan published; archival set identified; certificate language readied.
  • EL and SO sign the Compliance Attestation.

Acceptance criteria for an information‑secure engagement

  • Every artifact is labeled; every access is logged; every number can be traced to a source; every sensitive flow has a named owner and a tested control.
  • Clean‑team rules are operational, not theoretical; barriers tested; outputs aggregated.
  • Only managed devices and approved tools touch data; encryption is enforced end‑to‑end.
  • Incidents are contained and escalated within defined windows; post‑mortems close gaps.
  • Retention is deliberate; destruction is certified; archives are minimal but defensible.

Adopt this protocol as written and you make security predictable: clear roles, visible controls, short feedback loops, and auditable evidence—so diligence can move at deal speed without putting clients, counterparties, or your reputation at risk.

19.4 Anti-Bribery & Corruption Checklist

Anti‑bribery and corruption (ABAC) is not a side policy—it is a deal‑gate. Diligence teams operate under high time pressure, interact with third parties (expert networks, intermediaries, survey vendors), and often touch government‑adjacent sectors. This checklist turns principles into operating controls you can run on Day 1 and attest to at sign‑off. It is designed for three use cases: (1) running your own engagement ethically, (2) diligencing a target’s ABAC program, and (3) translating residual ABAC risk into terms, reserves, and post‑close actions.

Use this as a living document: complete at kick‑off, review weekly in governance, and certify before any external read‑out. When in doubt, stop the line and call counsel. This guidance is commercial and operational; it is not legal advice.

How to use this checklist

  • Mark each item Yes / N/A (with rationale).
  • If No, assign an owner and a date; pause any dependent activity.
  • For target‑company items, record evidence paths (policy, logs, samples) and exceptions priced into the case.

A. Tone, governance, and scope (engagement team)

  • Engagement acceptance includes ABAC risk screen (country/sector exposure, state‑owned enterprise (SOE) customers, tenders, permits, customs).
  • ABAC accountability named: Engagement Lead owns decisions; Compliance contact listed; escalation path visible to the team.
  • Team trained on ABAC do’s/don’ts, gifts & hospitality (G&H), interactions with public officials, and red‑flag recognition; attestations signed.
  • Policy set: zero tolerance for bribery and kickbacks; no facilitation payments; clear rules for G&H, donations, sponsorships, political activity, and lobbying.
  • Clean‑team & antitrust boundaries reinforced (no pre‑close operational direction; aggregated outputs only).

B. Third‑party due diligence (TPDD)

Applies to expert networks, survey panels, country “fixers,” interpreters, local consultants, intermediaries, channel partners used for research, and any subcontractor.

  • Identity & ownership verified: legal name, registration, beneficial owners, government ties, PEPS/relatives.
  • Screening: sanctions, adverse media, enforcement history, debarment lists; recency ≤ 12 months.
  • Risk rating: Low/Med/High based on country, sector, government touchpoints, compensation structure, and scope.
  • Contract clauses present: compliance with applicable anti‑corruption laws; audit/cooperation; books‑and‑records; no facilitation payments; right to withhold/terminate; sub‑contractor approval; conflict‑of‑interest disclosure.
  • Compensation controls: fees commensurate with market; no success‑only payments; no cash or crypto; bank account in vendor’s own name in country of incorporation unless pre‑cleared; itemized invoices tied to deliverables.
  • Training & certification: High‑risk third parties complete ABAC training/attestation before work starts.
  • Ongoing monitoring: re‑screen on scope change; log and review exceptions.

C. Gifts, hospitality, travel (G&H) controls

  • Prohibited: cash or cash‑equivalents (gift cards), per diems in cash, personal travel, “social” events with no business purpose, lavish venues, spousal/guest travel, anything linked to an active decision.
  • Public officials & SOEs: treat employees and board members of SOEs as public officials; pre‑approval from Compliance for any spend; keep stricter thresholds.
  • Pre‑approval thresholds: set per person/per event caps; aggregate by calendar year; document business purpose, attendees, and value.
  • Transparency: enter all G&H in a register within 5 business days; receipts required; management review monthly.
  • Symmetry test: would you be comfortable seeing this on the front page with names and amounts? If not, do not do it.

D. Payments, books & records

  • No off‑book accounts; no slush funds; no “miscellaneous” expense codes for High‑risk countries or activities.
  • Invoice quality: detailed description, dates, locations, rate cards; match to SOW; three‑way match where feasible.
  • Banking rules: pay only to the contracted entity’s account; no third‑country or personal accounts; no splitting invoices to dodge thresholds.
  • Approvals: dual approvals for High‑risk vendors/geographies; exception logs maintained.
  • Reimbursements: original receipts required; round‑sum and duplicate claims rejected; per‑diem cash discouraged.

E. Donations, sponsorships, and community projects

  • Prohibited if requested by or linked to a decision‑maker or a public official.
  • Due diligence: charity legitimacy, beneficial owners, ties to officials; use the same TPDD rigor.
  • Control: written agreement, defined outcomes, payment to organizational account, verification of impact; log in a donations register.
  • Political contributions & lobbying: prohibited unless explicitly permitted by policy and counsel; never via third parties.

F. Interactions with public officials

  • Definition: includes officials, candidates, party officials, SOE employees, and employees of public international organizations.
  • Meeting hygiene: agenda, business rationale, two‑person rule for meetings when feasible; keep minutes; log any offered or requested items of value immediately.
  • Permits/tenders/customs: no “expedite fees”; use approved brokers with TPDD; document timelines and fees.

G. Red‑flags (and first responses)

If any trigger appears, freeze related spend, open an exception case, and escalate to Compliance within 24 hours.

  • Unusually high commissions or unexplained success fees; vague SOWs for “consulting” or “marketing support.”
  • Requests for payment in cash, to personal accounts, or to accounts in a third country; split‑billing.
  • Intermediary has close ties to a public official or decision maker; refuses to disclose beneficial owners.
  • Pressure to move quickly “before decision day”; insistence on secrecy; refusal to include ABAC clauses.
  • Charity/sponsorship “suggested” by a decision maker; selection of a charity with opaque ownership.
  • Hospitality invites during an active tender; travel upgrades or spousal travel requests.
  • Off‑invoice credits or rebates tied to “approval,” “permit,” or “listing.”
    First response: suspend the transaction, collect documents (SOW, emails, invoices, bank details), preserve messages, and notify Legal/Compliance.

H. Target‑company ABAC diligence (what to request and test)

  • Policy & governance: ABAC policy; G&H, donations, sponsorships, political activity; third‑party standard; investigation procedure; board oversight.
  • Training & attestations: coverage in the last 24 months, role‑based modules, completion rates, refresher cadence.
  • Third‑party files: due‑diligence records, risk ratings, contracts with ABAC clauses, payment terms, renewal reviews.
  • Registers & logs: G&H, donations/sponsorships, conflicts of interest, hotline cases (anonymized), investigations and outcomes.
  • Books & records tests (sample 25–50 High‑risk entries across 24 months): “consulting/marketing” expenses, customs/broker fees, facilitation flags, cash accounts, rebates/credit notes, petty cash, year‑end journal entries, and round‑sum payments; tie to contracts and deliverables.
  • Sector‑specific: samples around tenders, listing/placement fees, formulary decisions, certifications/inspections, licensing and permitting.
  • Culture & speak‑up: hotline availability, non‑retaliation policy, case cycle times, remediation discipline.

I. Contractual protections (deal terms and vendor SOWs)

  • Reps & warranties: compliance with anti‑corruption laws; no violations in look‑back period; accurate books & records; no undisclosed government relationships.
  • Covenants: maintain ABAC program; immediate notice of investigations; audit rights; training obligations for High‑risk third parties; right to withhold/suspend/terminate on suspicion.
  • Conditions precedent: high‑risk third parties replaced or re‑papered; training completed; investigation close‑outs provided.
  • Earnouts/bonuses: tie to clean KPIs, not regulatory or listing events; include clawbacks for ABAC breaches.

J. Investigations and incident response

  • Intake channels: visible reporting email/line; anonymous hotline for target employees during diligence if appropriate.
  • Preservation: legal hold on relevant data; stop automatic deletion; secure images of key devices where feasible.
  • Triage: severity rubric; immediate containment (stop payments); counsel‑led investigation; documented findings and remediation.
  • Disclosure: follow counsel on regulator and counterparty notifications; never self‑disclose without coordination.

K. Post‑close integration (100‑day ABAC plan)

  • Issue Day‑1 ABAC policy; roll out training to all in‑scope employees and high‑risk third parties.
  • Refresh third‑party due diligence; re‑paper with ABAC clauses; rationalize intermediaries.
  • Stand up G&H and donations registers; close petty‑cash loopholes; harmonize expense codes.
  • Forensic review of High‑risk accounts (last 24 months); investigate outliers; remediate root causes.
  • Launch speak‑up campaign; confirm non‑retaliation; track case handling SLAs.

L. Roles, records, and attestations (engagement team)

  • Named ABAC owner; escalation contacts (Legal, Compliance) posted; 24‑hour response expectation.
  • Registers maintained: third‑party screening, G&H, donations/sponsorships, exceptions, investigations, training.
  • Final ABAC attestation signed by Engagement Lead before any external deliverable: confirms screening, controls, exceptions, and escalations.

Copy‑ready artifacts (use verbatim)

  • Third‑party ABAC clause (short‑form):
    “Counterparty represents and warrants compliance with all applicable anti‑corruption laws, has not and will not offer, promise, give, request, or accept anything of value to improperly influence any act or decision, and maintains accurate books and records. The counterparty agrees to audit and cooperation rights, prohibits facilitation payments, and permits immediate suspension or termination for suspected breach.”
  • Gifts & hospitality approval note (fields): business purpose; counterparties and affiliations; event/date/venue; itemized value per attendee; prior YTD amount to same recipient; approver; register entry ID.
  • Red‑flag incident card (fields): trigger observed; party and scope; payments halted (Y/N); documents preserved; counsel notified date/time; next actions; owner.

72‑hour ABAC sprint (engagement and target)

  • Day 0: name ABAC owner; brief the team; publish zero‑tolerance and G&H rules; load template registers; start TPDD on all vendors/experts; insert ABAC clauses into SOWs.
  • Day 1: collect target ABAC policies, registers, top‑50 High‑risk payments and vendor list; pull 25–50 sample transactions; stand up incident intake.
  • Day 2: complete screenings; review samples; log red flags and exceptions; draft deal‑term asks (reps, audit rights, CPs); pre‑approve any unavoidable G&H with counsel.
  • Day 3: finalize ABAC section of risk pack: findings, residual risk, mitigations, terms; obtain Legal/Compliance sign‑off.

Acceptance criteria for an ABAC‑clean diligence

  • All third parties screened, risk‑rated, contracted with ABAC clauses, and paid via compliant channels; no cash or success‑only fees.
  • G&H and donations registers are active; no public‑official spend without pre‑approval; all items documented.
  • No unresolved red flags in sampled payments; exceptions documented with actions and owners.
  • Target program assessed with evidence; residual ABAC risk translated into terms and a 100‑day plan.
  • Engagement ABAC attestation signed; escalation path tested; team trained; records complete.

Stop‑the‑line triggers (escalate immediately)

  • Request for cash, off‑book payment, third‑country account, or split invoices.
  • Any payment or favor tied (explicitly or implicitly) to a decision, listing, permit, or inspection.
  • Third party refuses ABAC clauses or disclosure of beneficial owners.
  • Hospitality or donation requested by a public official or decision‑maker.
  • Evidence of falsified invoices, duplicate reimbursements, or “consulting” with no deliverables.

Run this checklist and ABAC becomes a management control, not a compliance afterthought: clear rules, named owners, documented proofs, and fast escalation—protecting your client, your counterparties, and the integrity of the deal.

Commercial Due Diligence Playbook 2025

Request the Umbrex Commercial Due Diligence Playbook