Aurora AITell us your case

Offering

ServicesProductsCase studies

For whom

Private EquityEnterpriseSMB
ServicesProductsCase studiesAboutBlogContact

Knowledge base

Start hereWikiGlossaryGuides

Guide

For PE funds

Who should run AI due diligence: Big 4, boutique or in-house

How to choose who runs AI due diligence before a deal: Big 4, a technical boutique or the fund's own team, what to ask and which red flags to check.

AI due diligence can be run by a Big 4 firm, a specialist technical boutique or the fund's own team, and in many deals a combination works well. The choice depends on whether you need a broad due diligence package or a deep review of code, data and model-vendor dependence, and on who will turn the findings into a 100-day plan after close.

First decide what the AI due diligence must answer

Before you compare providers, write down the one question the review has to answer. That question tells you who you need.

Scope. An AI audit in a deal separates three layers: the model, the data and the system around them. Our AI/IT due diligence guide covers what to check in each one. Here you only need to decide whether the review covers all three layers or just one, such as the provenance of the training data. If the real question is how much value AI creates in the company rather than deal risk, see how an AI audit differs from a proof of concept.

Timing. Before signing, the review feeds into price and deal terms. After close, it becomes the starting point for the first 100 days. These are two different engagements, and not every provider does both.

Output. Whoever runs it, the result should fit into three points: a one-sentence verdict, the three largest risks with the cost of closing them, and an action list for the first 100 days. If a provider proposes a different format, ask how it will land in the investment memo.

Criteria for choosing a provider

The most important criterion is access: a provider who never sees code, data and logs assesses claims, not the system. The second is independence: a lock-in assessment from a firm that implements the same vendor's products needs a separate check.

CriterionWhy it mattersEvidence to ask for
Hands-on access to the systemInterviews and documents show what the company claims, not what runsA list of what the provider will access: repository, data, pipeline, logs
Independence from model and cloud vendorsA vendor-dependence assessment is only credible if the assessor doesn't earn from that vendorA disclosure of partnerships, resale and implementation work for vendors
Data provenance and licensingData debt stays with the buyer after close (hidden AI risks in a deal)An example of how the provider checks consents, licences and dataset sources
Governance and AI Act exposureA policy document doesn't prove that AI governance worksWhether they check the system register and human-in-the-loop controls, not just the policy; for where Polish supervision stands, see our blog
Deal-side experienceThe investment committee needs a decision, not a technical reportA redacted board summary or memo section
Continuity into the 100 daysFindings with no owner after close get lostHow risks become a 100-day plan
Time-box and formatAn open-ended review sprawls, and an essay is hard to compareA fixed schedule agreed upfront and a sample risk map
Conflict of interestA provider who later sells the fix has a reason to inflate the riskA statement on whether they intend to bid for remediation work

Three provider types

A Big 4 firm brings a broad due diligence package and a format investment committees know. A technical boutique brings depth in the AI review. The fund's own team brings knowledge of the thesis and continuity after close. The combined model is a separate AI workstream with its own lead, running next to the main DD team.

Big 4 and large advisory firmsTechnical boutiqueThe fund's own team
Typical scopeAI as one part of a broad DD: financial, legal, tax, technologyA narrow, deep review of model, data and systemTesting the thesis, management sessions, overseeing advisors
StrengthsOne coordinator for the whole DD, a format committees knowWorks directly on code, data and pipelineKnows the investment thesis and stays with the company after close
What to checkWhether the scope includes hands-on review of code and dataWhether the output translates into deal languageWhether it has the time and AI experience across several live deals
When to choose itA large deal where AI is one of many areasAI is a material part of the thesis or valuationAI is a side element of the thesis and the fund has the skills in-house
What to askWho exactly does the AI part, and with what access?Who turns the findings into a 100-day plan?Who takes over when the thesis starts to rest on AI?

Big 4 and large advisory firms

Large advisory firms run the full due diligence package and are often already on the deal as lead advisor, which makes them a natural home for the AI scope. Before you engage, check a few things: does the AI part include hands-on review of code and data, or does it rely on interviews and documents? Who exactly runs it? Does the firm have ties to the model vendors whose lock-in it is meant to assess?

Technical boutique or independent operator-architect

A narrower scope, but a deeper review: the model, evaluation, data, cost per response and the exit plan from the vendor. A boutique usually works next to the main DD team, not instead of it. Check that its output can go straight into an investment memo and that someone on its side understands how a deal works.

The fund's own team

An operating partner, a technical advisor or an outside operator-architect who works with the fund. Their advantage is knowledge of the thesis and continuity, since the same people often run the first 100 days. The limits tend to be time and technical depth when AI sits at the core of the valuation.

The combined model

The main DD team leads the whole process, and AI gets its own workstream with its own lead, checklist and red flags. That is the position we set out in what a fund looks at before a deal. The workstream lead can come from any of the three types. What matters is that they have access to the system and own a single, shared verdict.

Operator's rule: don't pick a provider, pick the lead of the AI workstream. The firm on the engagement letter matters less than who sees the code and who signs the verdict.

DD software and data rooms are not a provider

Due diligence software and virtual data rooms organise documents, permissions and Q&A. They help you gather evidence, but they don't judge it. The verdict on whether a company's AI is an asset or a wrapper comes from a person who has looked at the system.

Questions to ask before you engage

You can check each of these before you sign. They apply the same way whether the deal is in Poland or elsewhere in Central Europe.

  1. Will you see code, data and logs, or only documents?
  2. What does the deliverable look like, and can we see a redacted sample?
  3. How do you assess dependence on the model vendor and the margin's sensitivity to its pricing?
  4. Who exactly does the work, and who signs the verdict?
  5. Do you have commercial ties to model or cloud vendors?
  6. What is the time-box, and what happens if the company is late granting access?
  7. How do you check data provenance and licences?
  8. How do findings convert into a plan for the first 100 days?
  9. Will you bid for remediation work after close?

Red flags when choosing a provider

These flags are about the provider, not the target company. For red flags on the company side, see the AI/IT due diligence and hidden AI risks in a deal guides.

How to set up a repeatable AI DD workstream in the fund

A repeatable AI DD workstream comes down to three things: a question checklist owned by a named person, a register of red flags from past deals, and a short framework for valuing AI risk.

  1. A checklist with an owner. Five questions for the company's management, added to the standard DD package. One person owns it: an operating partner, a technical advisor or an outside operator-architect.
  2. A red-flag register. Kept like an incident log, so the next deal team learns from earlier deals instead of repeating them.
  3. A risk valuation framework. Which system stays, which gets rebuilt in the first ninety days, and which needs the vendor contract renegotiated.

With that in place, choosing a provider for each deal comes down to one question: who leads the AI workstream on this one. The five questions and the full context are in AI due diligence: what a fund looks at before a deal. If you're building a workstream like this, tell us about your case.

Terms in this guide

Assessing a company or portfolio for AI? Tell us your case.

Tell us your case See how we help

Frequently asked questions

Can a Big 4 firm run AI due diligence?
Yes. Large advisory firms run technology due diligence and increasingly include AI in it. Before you engage, check whether the scope includes hands-on review of code, data and model-vendor dependence, or only interviews and documents, because that sets how deep the assessment goes.
How is AI due diligence different from standard technical due diligence?
Standard tech DD checks infrastructure, code and the team. AI due diligence adds questions that are usually missing there: data provenance and licences, whether evaluation exists, how much the margin depends on a model vendor's pricing, and AI Act exposure. It runs in parallel, as a separate workstream.
When is the fund's own team enough?
When the fund has an operating partner or technical advisor with AI experience and the company's investment thesis does not rest on AI. When the thesis assumes AI-driven margin growth, add an independent technical review.
Can the due diligence provider implement AI in the company afterwards?
It can, but that is a potential conflict of interest: whoever assesses the risk then earns from fixing it. Agree on this at the start and ask the provider to disclose ties to model and cloud vendors.
What should an AI due diligence deliverable include?
A one-sentence verdict (asset, wrapper, or asset with conditions), the three largest risks with the cost of closing them, and a list of actions for the first 100 days, in a form that fits an investment memo.