The compliance failures that show up in diligence
They are almost never the ones the company was worried about. A short list of what buyers, investors and exchanges actually find, and why the fix is documentary before it is technical.
Perspectives. August 19, 2026. 3 minutes.
A company preparing for a raise, a listing or a sale spends its compliance energy on the risks it already knows about. Diligence then finds something else. Having sat on both sides of that table, the pattern is consistent enough to write down.
The control that exists only in one person
The most common finding is a control that works because a particular individual does it, and that has no existence outside them. The revenue cut-off review is done by the controller from memory. The related-party check is done by the general counsel because she knows the founders. The disclosure committee meets, but the minutes are three lines and the agenda is in someone's head.
Diligence does not test whether the control worked last quarter. It tests whether the control would work if that person left. The finding is written as a design deficiency, and it is correct. The fix is documentary: a written procedure, a checklist with evidence, a second person who has performed it at least once.
The policy with no evidence of operation
Most companies going through diligence have a policy binder. Code of conduct, insider trading, whistleblower, related-party transactions, delegation of authority. Diligence asks a different question of each one: show me it operating. Show me the pre-clearance log for trades. Show me the whistleblower hotline test. Show me the last related-party transaction that went through the approval the policy describes.
A policy with no evidence of operation is treated as not existing. This is not unfair. A policy nobody has ever invoked has never been tested, and diligence cannot tell whether it would hold.
The material weakness that was fixed but never closed
Companies that have reported a material weakness usually have a remediation plan and a good story about it. What they often do not have is closure: the documented testing that proves the new control operated, for enough periods, to be relied upon. Management says it is fixed. The auditor has not yet said so. Diligence reads that gap as an open weakness, because until the testing is done it is one.
The fix is procedural. A remediation plan is not complete when the control is designed. It is complete when it has operated for the required periods, been tested by someone independent of the person who runs it, and the evidence has been filed where the auditor can find it.
The disclosure that does not agree with the numbers
The last recurring finding is the one that does the most damage: a statement in the investor deck, the press release or the management discussion that a careful reader cannot reconcile to the financial statements. A customer count that includes trial accounts. A backlog figure that includes options. A cash runway that assumes a raise that has not closed.
Nobody in the company thinks of these as compliance failures. Diligence does, because the exchange and the regulator do. The fix is a disclosure control: one person who reads every external statement against the numbers before it goes out, with the authority to hold it.
Why the fix is documentary first
Every one of these findings has the same shape. The company was doing something reasonable. It could not show that it was doing it, or that it would continue to if circumstances changed. Diligence is not an assessment of intent. It is an assessment of evidence.
The practical consequence is that a company six months from a transaction should spend the first month not on new controls but on documenting the ones it has, testing them, and closing the ones it has said it fixed. That work is unglamorous. It is also the difference between a finding that costs a week and a finding that costs the deal.