info@lighthc.london

+44 2078710485

UK Guide to Operational Due Diligence

You can have a clean model, tidy contracts, and a board pack that all look sensible, then watch the deal unravel because the business cannot run the way management described. That's the bit people miss in disputes, acquisitions, insurance claims, and fraud work, the gap between reported order and operational reality. In practice, that gap is where cash leaks, claims fail, synergies disappear, and litigation turns nasty.

For UK buyers, lenders, and boards, operational due diligence is often the first proper stress test of whether a business is investable or just well presented. It's also where objections tend to surface fast. People worry about cost, delay, internal friction, and what a report might reveal. Those concerns are real, but they're manageable when the work is scoped properly and anchored to evidence rather than theatre.

The right approach is blunt. Test the controls, test the dependencies, and test whether the company can keep trading if one supplier, one system, or one key person stumbles. That's far more useful than a generic tick-box exercise, and it's why diligence can prevent the post-deal disasters that so often follow a rushed sign-off.

When the Numbers Look Fine but the Deal Still Goes Wrong

The spreadsheet can look respectable right up until the point the deal closes and the problems appear. I've seen this in mid-market acquisitions where the financial model held together, the legal pack looked neat, and yet the business relied on one overstretched manager, one fragile supplier chain, or one undocumented IT dependency. I've also seen the same pattern in shareholder disputes and insurance claims, where the headline numbers were never the issue, the issue was whether the operation could deliver what the papers implied.

That's why people who only review historic performance often miss the point. A target can post reasonable results and still be badly run underneath. If the work depends on informal habits, weak segregation of duties, or vendors nobody has properly challenged, the value can disappear quickly once pressure rises. The buyer inherits the consequences, not the narrative.

The UK market learnt this the hard way after the financial crisis. The Financial Services Authority's 2011 review of hedge funds found that only 34% of firms received a formal operational review at the investment level, while 29% had no operational review at all, which helped push operational scrutiny from a niche control exercise into mainstream governance for UK allocators, especially where investor protection depended on proper pre-investment testing of controls, custody, valuation, liquidity, segregation of duties, and service-provider oversight. Business Screen's summary of the FSA review remains a useful reminder that performance forecasts don't protect capital on their own.

Practical rule: if the deal only works when management's optimistic version of operations is true, the deal already has a problem.

For founders, the objection is usually, “our numbers are fine, why drag the team through this?” The answer is simple. Fine numbers don't prove the business is resilient, and resilience is what lenders, boards, and acquirers pay for. If you want a useful primer on how diligence prevents avoidable post-deal damage, the point is set out clearly in this short guide on post-deal disasters.

What Operational Due Diligence Actually Tests

Operational due diligence tests whether a business can keep creating cash, stay within UK legal and regulatory boundaries, and integrate without hidden execution gaps. That's different from financial due diligence, which focuses on whether the reported numbers are fair, and different again from legal due diligence, which focuses on the contract set and the rights attached to it. ODD asks a more awkward question: can the target do what it says it does, under pressure and with the current control environment?

The discipline usually sits on four pillars, people, process, systems, and third parties. People covers management depth, incentives, and key-person dependence. Process covers how work moves through the business, not how the policy manual says it should. Systems covers IT, data, resilience, and cyber controls. Third parties covers suppliers, outsourcers, administrators, and logistics or service providers that the business can't function without.

A good UK engagement doesn't stop at desktop review. Desktop work is useful for triage, but it rarely exposes how control breakdowns show up in practice. On-site walks, management interviews, reconciliations to source data, and exception testing matter because they show whether the business performs as described or just appears consistent in a spreadsheet. That's why regulators, lenders, and insurers increasingly want evidence they can follow, not just a management story they can repeat.

Here's a useful external resource if you want to compare ODD thinking with other buyer-side checklists, the PEO Metrics PEO selection tools checklist is a practical reference point for buyers who need to structure questions properly.

A diagram illustrating the three key pillars of operational due diligence: financial controls, supply chain, and IT systems.

The best ODD files don't prove perfection. They prove the investigator asked the right questions and checked the right records.

For readers who want a more finance-led explanation of where this sits alongside the numbers work, this guide to financial due diligence is a sensible companion piece.

The Seven Workstreams That Cover a UK Target

A proper UK file now works best as a seven-workstream review. That structure reflects where risk sits, at the intersection of operations, controls, compliance, and outside dependence, rather than in one tidy metric. If one workstream is weak, the damage usually spreads into valuation leakage, integration delays, remediation spend, or a post-close dispute about who should have seen the issue earlier.

The practical benchmark is simple. Don't just ask whether each workstream exists, ask whether there's evidence the target can sustain cash generation under stress, comply with UK rules, and integrate without hidden gaps. That is the difference between a paper exercise and diligence that changes a decision.

A target with a strong model but weak supplier oversight can still fail. A business with tidy HR files but poor access controls can still leak value. A firm with solid trading performance but vague ESG or regulatory records can still become expensive to own.

Here's the map that practitioners usually work from.

Workstream What it tests Typical UK evidence
Financial Cash quality, working capital, margin resilience Management accounts, reconciliations, aged debt, covenant packs
Legal and regulatory Compliance position, licences, disputes, contract exposure Key contracts, filings, claim letters, board minutes
Commercial Customer concentration, pricing power, churn, pipeline quality Customer schedules, renewal data, contracts, sales reports
Operational Capacity, continuity, process stability, supplier dependence SOPs, KPI packs, outage logs, supplier terms
People and integrity Key-person risk, conduct, incentives, continuity HR files, org charts, disciplinary history, references
Technology and IP System reliability, cyber posture, ownership of IP, data control Asset lists, access rights, incident logs, licence register
ESG Environmental, social, governance exposure and reporting credibility Policies, audits, incident reports, supplier codes

The Neotas investment due diligence framework is useful here because it treats operational risk as something spread across people, process, systems, and third-party exposure, not a standalone box-tick. Neotas' due diligence checklist also reflects a practical truth, weak coverage in one area often turns into downstream cost elsewhere.

For manufacturing and distribution businesses, a unified operating backbone matters too. A unified system for manufacturers can reduce some visibility gaps, but only if the underlying data is clean and the controls are used. Software doesn't fix weak discipline on its own.

How an ODD Engagement Actually Runs in the UK

A decent UK engagement usually moves faster than people expect, but only if the scope is tight. Mid-market work often lands in a 2 to 6 week window, while regulated targets usually take longer because the evidence stack is heavier and the questions are more sensitive. The key is to keep momentum without turning the exercise into a document dump.

The engagement usually starts with scope

The first conversation should pin down the transaction type, sector, and risk areas. A buyer of a logistics business needs different testing from a lender reviewing a private services group or a board checking a possible acquisition target. The point is to decide where the fragility is likely to sit before anyone starts requesting files.

Then the evidence has to be real

A proper file normally includes management accounts, control documents, supplier terms, operational packs, interview notes, and where needed, walk-throughs on site. If the business says a control exists, the next question is whether it leaves a trace. That trace might be a reconciliation, a log, a sign-off trail, or a system report that can be checked against source data.

The report then needs to stand up in negotiation, disciplinary processes, or court if matters worsen. A neat summary that can't be substantiated is not much use to anyone.

A diagram outlining the four stages of the Operational Due Diligence (ODD) engagement process in the UK.

For a practical checklist lens on acquisition work, this acquisition due diligence checklist is a useful reference point.

Sector Red Flags Worth Stopping the Deal For

The red flags that matter most are sector-specific. Retail and consumer businesses fail in different ways from manufacturers or airlines, and a generic template can give false comfort. Good diligence teams look for the point where operational dependence becomes fragile enough to affect price, structure, or whether the deal should proceed at all.

Retail and consumer goods

Supplier concentration and stock integrity are the obvious pressure points. If a business cannot evidence stock movement properly, then margin claims become shaky very quickly. The right question is whether inventory records, shrinkage controls, and supplier terms match what management says in meetings.

Logistics and aviation

Safety culture, maintenance records, and contractor reliance matter more than polished KPIs. A business can look efficient on paper and still be exposed if external contractors carry too much of the operational load. If maintenance or compliance records are thin, that is not a minor admin issue, it's a sign the control environment may be weak.

Manufacturing

Capacity bottlenecks and single-source components can break a deal's economics. A plant that relies on one machine or one critical input needs far more scrutiny than a standard checklist provides. If the management team can't show credible contingencies, the forecast may be built on hope rather than capacity.

Financial services and claims-heavy businesses

Valuation policies, custody arrangements, and segregation of duties deserve close review. In claims work, policy wording and actual exposure often diverge, which is why operational evidence matters as much as the headline contract. In public and not-for-profit work, grant compliance and procurement controls can be the pressure points that later create embarrassment, clawbacks, or reputational damage.

This sector red-flag guide is worth watching alongside a live file review because the same weakness can look harmless until it's tested in context.

An infographic titled Sector Red Flags showing potential business risks for retail, manufacturing, and technology industries.

If the sector's key risk sits outside the template, the template is the wrong tool.

Why Macro Pressure Quietly Distorts UK Diligence

A static checklist gives a false sense of comfort in a moving economy. Wage pressure, higher borrowing costs, and strain on suppliers do more than dent the P&L. They can change whether the operating model still works the way management says it does. That matters most in SMEs and mid-market targets, where optimism often fills the gap between what is documented and what the business can afford.

The UK labour market still feeds straight into diligence. The ONS reported 5.3% regular pay growth in the three months to May 2025, and 5.4% private-sector regular pay growth over the same period. Staffing assumptions, margin forecasts, and working-capital plans can drift if the target has not reset its model properly. The ONS labour market release matters because macro pressure changes how much confidence you can place in management's numbers.

An infographic showing how macro pressures like wage growth and supplier price increases impact UK operational due diligence.

The interest-rate side matters too

The Bank of England kept Bank Rate at 4.25% in June 2025, so refinancing pressure and debt service remain live constraints for borrowers and acquirers. That affects covenant headroom, acquisition financing, and whether the business can absorb a weaker trading period without cutting the controls it needs to stay safe. The Bank of England's June 2025 decision sits in the same picture.

The useful diligence question is not just whether controls are documented. It is whether those controls can survive today's wage base, supplier costs, and financing terms. If subcontractors are already expensive, if payroll keeps rising, or if management is relying on cheap refinancing that no longer exists, the operating model is more fragile than it first appears.

For UK deals, I would ask management three blunt questions. Can the workforce model still absorb wage pressure without service quality slipping? Can the business refinance or service debt without raiding working capital? Can the supply chain cope if one vendor re-prices or exits? Those questions often tell you more than a 60-page questionnaire.

Evidence That Withstands Scrutiny

A policy on file doesn't prove a control works. A sign-off sheet doesn't prove the sign-off was meaningful. And an ISO badge doesn't tell you whether the business follows the process when the pressure is on. In disputes, claims, and regulatory reviews, the only evidence that really counts is evidence you can trace back to source records and reconcile to what happened in practice.

That distinction matters because management representations are not the same as verifiable proof. A founder can describe a process confidently and still not run it consistently. A finance director can believe the controls are sound and still rely on a junior team member to patch exceptions informally. When a claim, valuation, or fraud allegation lands, those informal habits are exactly what get exposed.

The weight of evidence also changes depending on who prepared it. Independent reporting from a Chartered Management Accountant carries more force than an internal memo that repeats management's position. In a contested business interruption claim, a shareholder valuation dispute, or an internal fraud investigation, the question is usually not whether documents exist, it's whether they prove the thing they're meant to prove.

Practical rule: if the evidence can't be checked against source data, it won't survive much pressure.

There's a reason document-only reviews fail. They accept the appearance of control as if it were the same as control itself. In practice, a business can have neat policies, a tidy portal, and poor operating discipline. That gap is where litigation starts.

Working With Lighthouse Consultants

The common objections are predictable. Cost, delay, internal resistance, and fear of what the review might uncover. None of them are unusual, and none of them are a good reason to skip the work. A structured engagement can keep the scope tight, reduce noise for management, and still produce evidence that helps in negotiations, internal decisions, or formal proceedings.

Lighthouse Consultants is a London-based team of Chartered Management Accountants that handles forensic investigations, business interruption quantification, due diligence, internal audits, risk assessments, sustainability audits, and expert witness work. The firm's model is straightforward, free discovery, scoped action plan, and results reporting, which is useful when you need the work done properly without turning the deal team upside down. For cross-border or multi-jurisdictional matters, its collaboration with Andersen Global can add capacity where needed.

If you're facing a transaction, dispute, claim, or control issue and you need the operational reality tested rather than assumed, start with a discovery call. It costs nothing to map the risk properly, and it often saves far more than it costs.


Lighthouse Consultants helps UK businesses, boards, lenders, and advisers test operational fragility, quantify financial risk, and produce evidence that stands up in negotiation, hearing, or court. If you need practical operational due diligence, forensic accounting, or a defensible control review, visit Lighthouse Consultants and start with a discovery call.

Share this article:

Facebook
Twitter
LinkedIn
Email

Other Articles