Private digital intelligence bureau Lawful OSINT — Cyber monitoring — Due diligence
Investment analyst cross-checking filings, an ownership structure and neutral risk cards

Decision guide · 11 min

A due diligence checklist that informs decisions without manufacturing certainty.

A useful review does not maximise information. It verifies material claims, ranks discrepancies and prepares questions before an investment, partnership or appointment.

Published 15 September 2026Reviewed by IIS editorial team

At a glance

Four rules for a useful review.

  • Match depth to the decision.
  • Verify entity, people and relationships.
  • Document discrepancies, not just alerts.
  • Turn each signal into a verifiable question.

Step-by-step method

A reproducible path from question to conclusion.

  1. 1

    Frame the decision

    Specify value, access, countries, urgency and consequences of error. Risk determines depth.

  2. 2

    Verify legal existence

    Check name, registration, address, officers and history through official sources appropriate to the jurisdiction.

  3. 3

    Understand ownership and control

    Map declared relationships, lawful beneficial-ownership information, subsidiaries and significant changes. Mark opaque areas without over-interpreting them.

  4. 4

    Test material claims

    Corroborate references, careers, partners, assets, licences and claimed performance using dated independent sources.

  5. 5

    Assess reputation and proceedings

    Consider public facts, outcome, age and source quality. An allegation is not a ruling.

  6. 6

    Write decision conditions

    Classify confirmed, clarification and blocking points. Set the documents or commitments required before proceeding.

Depth proportionate to risk

The same checklist cannot fit an occasional supplier and a partner receiving funds, data or strategic access. Define escalation thresholds before research to reduce hindsight bias.

Follow applicable rules for personal data, sanctions, employment screening and international transfers. Open-source due diligence does not replace legal or regulatory advice.

Interpret a red flag in context

A director change, shared address or young company can be routine. A signal matters when it contradicts a material claim, converges with other discrepancies or prevents identification of the responsible party.

A polished online presence does not erase documentary gaps. Each finding should connect to the decision under review.

Deliver an actionable decision

Separate sources, facts, analysis and recommendations. State confidence, geographic or language limits and the date through which checks remain current.

A good output is not merely yes or no. It explains what can proceed, under which conditions, and what events should trigger review.

Common pitfalls

Four shortcuts that weaken the result.

Collecting without ranking

The number of results says nothing about importance or reliability.

Treating allegation as fact

Find the original source, procedural status and any outcome.

Ignoring namesakes

Confirm several identifiers before attributing information to a person.

Hiding limitations

Unavailable languages, jurisdictions and databases must be explicit.

Practical questions

Frequently asked questions.

Which sources should be prioritised?

Competent registries and authorities, original documents, published decisions and identifiable independent sources. Availability varies by country.

Does no red flag guarantee a partner?

No. It only means no relevant signal was found within the reviewed scope, sources and period.

When should due diligence be refreshed?

Before a material decision, and after changes in control, activity, jurisdiction or incidents, on a risk-based cycle.

Editorial scope

Written and reviewed by Internet Intelligence Service on 15 September 2026. This educational guide describes a lawful, defensive method. It is not legal advice, an emergency service or authority instruction.