A due diligence report arrives as a PDF, and the question the recipient rarely asks out loud is whether any of it means anything. Some reports are two hundred pages of database output behind a cover sheet. Others are twelve pages a credit committee, a bank or a court could follow line by line. Both cost money, both look thorough, and only one of them holds up when the transaction goes wrong and somebody asks what you knew and when you knew it.
The difference is not length. A serious report is an evidence document: every statement traceable to a named, dated record, every gap named as a gap, and a conclusion somebody is willing to sign. A report that lists everything and concludes nothing is not analysis — it is the decision handed back to you, wrapped in paper. What follows is what a proper report contains, how to read one in the order that exposes its weaknesses fastest, and where these documents quietly fail the people who paid for them.
A due diligence report is an evidence document, not a search result
Three activities get collapsed into one word, and the collapse is where most disappointment starts. Searching is asking an index whether a string appears in it. Verification is establishing whether the thing the index returned is in fact your subject, and what it actually asserts. Reporting is recording that reasoning so a third party who was not there can test it. A database returns step one in seconds. A large part of the market sells step one and presents it as step three.
In the United States this matters more than elsewhere, because there is no single place to look. Companies are creatures of state law and the authoritative records sit with fifty separate state offices, plus court dockets, lien indexes, licensing boards and sanctions lists that were never designed to be read together. Coverage, search logic and naming conventions differ from one state to the next. There is no national company registry, and since FinCEN’s final rule of 11 August 2026 — which permanently exempts U.S. companies and U.S. persons from beneficial ownership reporting and directs FinCEN to delete information it reasonably believes relates to U.S. persons — there is no federal record of who owns a U.S. entity either. The value of a report is therefore in assembly and attribution, not in access. Anyone can buy the same raw data.
The second discipline that separates a real report from a printout is the handling of three different kinds of statement. A fact is what a named record says on a stated date: the entity was formed in Delaware on this date, this judgment was entered by this court, this lien was filed against this debtor name. An inference is what the analyst concludes from the facts — that an address shared with dozens of unrelated entities and no payroll footprint suggests no operating presence — and it must be labeled as reasoning, not smuggled in as observation. An allegation is what somebody else asserts: a complaint, an article, a charging document. That a complaint was filed is a fact. What the complaint alleges is not. Reports that blur these three either mislead the buyer or expose the preparer, and often both.
The anatomy of a serious report — and how to read one
The structure below is not stylistic preference. Each element exists because a specific kind of failure happens when it is missing, and a redacted due diligence report example from any provider can be judged against it in about five minutes. Read the right-hand column first when you are evaluating a report you have already received.
| Section | What it must state | How it fails |
|---|---|---|
| Scope and mandate | The questions asked, what was expressly excluded, the as-of date, the standard applied | Written after the findings, or so vague that nothing was ever out of scope |
| Subject identification | The exact legal entity — state of formation, entity number, formation date — or the individual with identifiers, plus every alias and trading name | The report names a brand or a similarly named affiliate instead of the party that signs and gets paid |
| Sources consulted | Each register, docket, list and database by name, with the date it was accessed | A generic list of source categories with no dates, so nothing can be re-run |
| Sources unavailable | What could not be reached and why: sealed, offline, no public index, fee-barred, pending FOIA | Omitted entirely; silence reads to the client as coverage |
| Findings by risk area | Corporate standing and ownership, financial position and liens, litigation and regulatory, sanctions and integrity, adverse media, operational verification | Everything dumped chronologically, leaving the reader to sort material from trivial |
| Red flags | Each flag with a severity and, separately, its materiality to this transaction | Every hit listed at the same weight, severity assigned generically |
| Unresolved items | What remains open and precisely what would close it | The list is empty |
| Conclusion or risk rating | A stated position with the reasoning that produced it | Information is "presented for the client's consideration" |
| Preparer and use | Named preparer, date of issue, and who may rely on the document | Unsigned, undated, and worthless the moment it is challenged |
Reading one properly is a discipline, and it is not the discipline most people apply. The executive summary is written to be quotable and is the last thing you should read, not the first.
- Start with the scope and the limitations. The summary tells you what was found; the scope tells you which risks were never examined. When the two disagree, the scope wins, and it is the scope a regulator or an opposing counsel will read.
- Check the date on every underlying record, not the date on the cover. A certificate of good standing speaks only as of the day it was issued. A docket search speaks as of the day it was run. A commercial extract speaks as of its last refresh, which is rarely stated anywhere in the file.
- Read «no records found» as a statement about one index. It means nothing was located in that jurisdiction, under that spelling, within that date range. Absence of a record is not evidence of absence — acutely so for U.S. vital records, which are state and county records with no national marriage registry, and for state-by-state corporate and lien indexes of uneven quality.
- Separate a name match from an identity match. «A person of this name appears on a watchlist» is not a finding. «The individual in this transaction, identified by these attributes, is or is not that designated person» is a finding. Everything between those two sentences is the actual work.
- Distrust a file with no unresolved items. Real files always have some: a sealed matter, a jurisdiction with no public index, a question the counterparty would not answer. A report with nothing open is either extraordinarily narrow in scope or is not telling you something.
Where the standard record set does not resolve the question — opaque ownership layered across jurisdictions, nominee directors, unexplained source of funds — the honest answer is that the file needs enhanced due diligence rather than a longer database run. A report that recommends that, and says why, is doing its job.
What the official guidance does not tell you
Aggregator reports recycle stale data and almost never disclose it. Commercial products resell state and county data on a refresh cycle, merge legally distinct entities that share a name, and carry forward records that were corrected at the source months ago. A report built on them inherits the refresh date, not today’s date, and the reader is given no way to know the difference. The same applies to criminal history: a «national background check» is an aggregation of county and state records, not a federal record. The FBI Identity History Summary is the only federal criminal history record an individual can obtain about themselves, and no commercial product is a substitute for it.
A clean report on the wrong legal entity is worse than no report at all. No report at all leaves you cautious; a clean one on the wrong subject buys false confidence. Entity names are unique only within a single state, corporate groups routinely run a dozen similarly named vehicles, and the entity on the letterhead is often not the entity in the signature block or on the wire instructions. Reconciling those is the first step in verifying a U.S. company against the state record, and a report that skips it has verified a stranger.
«Adverse media: none» is meaningless without the languages and the date range. A media search that ran English-only sources for the last three years will return nothing on a subject whose difficulties were reported in Spanish, Portuguese or Mandarin in 2016. A serious report states which languages were searched, over which period, and against which classes of source, so the reader can judge how much weight the negative finding deserves. Unstated parameters are how a negative result becomes a liability.
Screening hits are overwhelmingly name collisions, and the disambiguation is the deliverable. Any common name against the SDN list produces matches. The value is in the identifiers that eliminate them, or the evidence that confirms one. Sanctions exposure also runs past the named list: OFAC’s 50 Percent Rule blocks entities owned 50 percent or more, directly or indirectly, in the aggregate, by blocked persons, even where the entity appears on no list. A clean name match is therefore not a clean result unless the beneficial owners behind the entity have been established — and no federal registry will supply them.
A report with no named preparer and no date is unusable the moment it matters. If the transaction is ever litigated, examined by a regulator or reviewed by a bank, an anonymous document proves nothing about what was known and when. Date the legal premises too: the framework moves. FinCEN’s exceptive relief of 13 February 2026 changed when covered institutions must re-verify beneficial owners, and the August 2026 final rule changed the reporting picture entirely. A report that states its regulatory assumptions and their date ages honestly. One that does not simply becomes wrong without warning.
The most common mistakes and what they cost
Relying on a report whose scope never covered the risk that materialized. This is the most expensive failure we see, and it is always visible in hindsight on page two. The buyer wanted comfort on ownership and litigation; the mandate covered corporate standing and sanctions. When the undisclosed pledge over the shares surfaces, the report does not protect anyone. It documents that the question was never asked. Scope is negotiated before the work starts, against the specific exposures of the specific deal, or it is decoration.
Circulating the report without checking its use restrictions. Reports are normally addressed to a named recipient for a stated purpose. Forwarding one to a lender, a co-investor or a counterparty can breach the terms of engagement, and the recipient may have no right to rely on it in any event. There is a second exposure: reports contain personal data, allegations and commercial information whose onward disclosure carries its own consequences. Decide who needs reliance at the outset; adding an addressee afterwards is not always possible.
Commissioning the report after the term sheet is signed. Findings that arrive before pricing change price, indemnities, escrow, conditions precedent and closing mechanics. The same findings after signature can do only one thing: justify walking away, at the cost of the deal, the fees and the relationship. Diligence is leverage while terms are open and nothing but bad news afterwards.
Treating an open item as a closed one because the deal is in a hurry. «Registered agent unresponsive» and «financial statements unaudited and unreconciled» are not administrative notes. They are the reasons files get rebuilt from scratch three months later, when nobody can say which findings can still be trusted and the same money is spent twice. That rebuild is usually longer than the original assignment.
How Compliance Officers resolves your due diligence report
We run these files continuously, which means we already know which office answers which question, where a search index will quietly betray you, and which records are worth paying for on a given transaction. You do not chase Secretary of State offices, argue with docket interfaces, or try to work out whether a screening hit is your counterparty. You give us the subject and the decision you have to make. We return a document written to be tested.
- Scope defined against your transaction, in writing, before any work begins — including what is deliberately excluded and why, so nobody discovers the boundary after a loss.
- Subject identification fixed first, to the exact legal entity or individual, reconciled against the party that will sign, invoice and be paid, using the document set a complete file requires.
- Findings sourced individually, each to a named record with the date it was issued and the date it was obtained, with fact, inference and allegation kept visibly apart.
- Red flags rated twice: once for severity in themselves, once for materiality to your specific deal, because those are different questions and only the second one drives your decision.
- Limitations and open items stated plainly, with what would close each one, and a conclusion or risk rating we are prepared to stand behind and explain to your bank, your board or your counsel.
Everything is handled remotely, wherever you and the subject are located, and the output is one document in English that a non-specialist can read and a specialist can audit. Zero paperwork for you, zero errors, zero unnecessary delays. If you are holding a report you do not trust, or you are about to commission one and want the scope right the first time, contact us to evaluate your case.
Frequently Asked Questions
How do I read a due diligence report if I am not a lawyer or an analyst?
Read in this order: scope, limitations, unresolved items, red flags, then the executive summary last. That order shows you what was not examined before you are told what was found. Then check three things at random: does this statement name its source, does that source carry a date, and does the conclusion follow from the findings. We build reports to survive exactly that reading.
What does a due diligence report cost?
It depends entirely on scope: how many jurisdictions are involved, whether ownership has to be established through documents rather than a register, whether court and lien searches are required, whether adverse media runs in more than one language, and whether federal records are requested. Government and court fees vary by jurisdiction. Rather than publish a figure that would mean nothing, contact us to evaluate your case and we will define the scope your decision actually requires.
How long does a due diligence report take to produce?
Corporate standing, sanctions screening and lien searches move quickly. Timing extends when the subject operates in several states, when litigation records need genuine review rather than a name search, when ownership sits behind layered entities, or when federal records are sought through FOIA, which is a request process with statutory response timelines and nine exemptions rather than a live database. We tell you at the outset which elements set the schedule.
Am I legally required to obtain a due diligence report?
The Customer Due Diligence Rule at 31 CFR 1010.230 binds covered financial institutions — banks, brokers and dealers in securities, mutual funds, futures commission merchants and introducing brokers — not ordinary operating businesses. Sanctions law is different: OFAC obligations are strict liability and reach every U.S. person and business. For most companies the report is commercial self-protection and evidence of diligence, and frequently a condition imposed by their own bank. We scope it to your real exposure.
Can I share the report with my bank, my buyer or my investors?
Only if the engagement allows it. Reports are addressed to a named recipient for a stated purpose, and third parties often have no right to rely on them. Adding an addressee later is not always possible and sometimes changes the work required. Tell us at the start who will need to rely on the document and we will structure the mandate so it can be used where you need it.
How long does a due diligence report stay current?
A report speaks as of its as-of date and nothing later. Corporate status, liens, litigation and sanctions designations all change without notice, and covered institutions have their own recordkeeping obligations — identifying information retained five years after an account is closed under 31 CFR 1010.230(i). In practice a report should be refreshed at signing, at funding, and whenever a trigger appears: an ownership change, a new jurisdiction, adverse news. We handle targeted refreshes without redoing the whole file.
Do you need a due diligence report that will still hold up when someone challenges it?
Compliance Officers runs the verification end to end: zero paperwork for you, zero errors, zero unnecessary delays.
Phone and WhatsApp: +1 305 647 3000







