An operating partner does not need a ceremonial integrity review in the first 100 days. They need a practical one.
After investment, the job changes. Before the deal, you are testing management’s story and deciding whether the risk is acceptable. After the deal, you need to work out what will change now they have the investment, what needs fixing now, and what can realistically be improved without overwhelming the business.
That means a post-investment integrity review should be less about whether a company has the right policy titles and more about whether leadership understands where pressure sits (or will sit as the investment spurs change and growth), where visibility drops away, and where small weaknesses could become more expensive later.
Start with the operating reality, not the diligence file
Diligence helps, but it rarely tells you enough on its own.
The first useful question is simple: what has changed now that the investment has happened? Growth plans, reporting expectations, leadership changes, new markets, add-on acquisitions, procurement shifts, customer concentration, and pressure to deliver the plan can all move risk quite quickly.
Operating partners should use the diligence file as a starting point, then ask:
- which concerns were genuinely resolved before close
- which points were only partially answered
- which assumptions now need testing in the business itself
- which issues have become more important because the strategy is moving faster
The goal is not to repeat diligence. It is to convert it into an operating view.
Look for where pressure, discretion, and dependency meet
Many integrity problems grow in predictable places.
Look for decisions or relationships where a small number of people can approve, justify, conceal, or accelerate important activity with limited challenge. In a portfolio company, that often means the overlap between:
- commercial pressure
- weak segregation of duties
- founder or leadership concentration
- third-party dependence
- poor operational visibility
This may show up in sales incentives, procurement, recruitment, complaints handling, regulatory interactions, distributor management, sourcing, or cash and discount approvals. The pattern matters more than the label.
If you can see where pressure, discretion, and dependency combine, you are usually close to the issues that deserve first attention.
Test how the business handles bad news
One of the quickest ways to assess the real control environment is to ask what happens when something awkward appears.
If a complaint comes in, a customer raises a concern, a site misses a target, a distributor behaves strangely, or someone spots a numbers issue, how does that travel? Who hears about it first? Who can decide it matters? Who can bury it?
Operating partners should look for whether:
- concerns can be raised outside line management
- managers know when an issue becomes more than an HR or operational problem
- small incidents are tracked and joined up over time
- bad news reaches leadership before someone has cleaned up the story
- the board receives decision-useful reporting, not just reassurance
A company does not need a perfect speak-up infrastructure on day one. It does need a credible route by which awkward truths can surface.
Check the gap between formal controls and daily practice
Post-investment reviews often stall because the business can show policies, templates, and process charts that look respectable enough.
That is not useless. It just is not the same as operating evidence.
Try to establish:
- which controls people actually use
- which ones exist mainly for investors, auditors, or customers
- where approvals are routinely bypassed in the name of speed
- whether controls keep working when the founder or finance lead is away
- whether regional or site-level reality matches head-office confidence
Good reviews spend less time admiring the control design and more time checking whether it survives contact with growth, time pressure, and uneven capability.
Focus on third parties early
Third-party exposure often gets more important after investment, not less.
Growth plans may rely on distributors, introducers, outsourced operations, labour providers, customs support, contract manufacturers, or new suppliers. That can create distance between management and the real conditions under which work is being won or delivered.
Operating partners should ask:
- which third parties matter most to growth or delivery
- which ones operate with the least oversight
- where payment logic is hard to explain cleanly
- where supply-chain, labour, environmental, or community risk could sit
- whether the business can distinguish a critical partner from an ordinary vendor
If the company cannot identify its high-dependency or high-exposure third parties quickly, that is already useful information.
Look at reporting quality, not just reporting volume
Portfolio companies can become very good at producing board packs without becoming much better at seeing risk.
What matters is whether reporting helps someone decide, challenge, or intervene. A useful post-investment review should look at whether leadership and the board receive information that shows:
- repeated control failures, not just isolated incidents
- exceptions and overrides
- overdue remediation actions
- complaints themes and unresolved cases
- unusual payments, margins, stock movements, or discounts
- areas where the business has weak data and is relying on management judgement alone
If reporting is polished but unprovocative, it may be functioning more as comfort than as oversight.
Ask what the business is not built for yet
This is often the most commercially useful question in the whole review.
Many portfolio companies are not failing because they are reckless. They are failing because the business model has outrun the systems, leadership depth, or operational habits needed for the next stage.
You are trying to identify where the company is not yet built for:
- larger volumes
- more geographies
- more complex third-party chains
- more formal complaints or investigations
- more external scrutiny from customers, lenders, regulators, or buyers
That creates a more forward-looking review. Instead of asking only “is there a problem now?”, you also ask “what becomes fragile if the plan works?”
Prioritise actions the business can actually absorb
An operating partner’s value is not proved by producing a heroic action list.
The better outcome is a short, credible plan that management can own. Usually that means distinguishing between:
- issues that need immediate containment or escalation
- issues that need clearer ownership and better visibility
- issues that can wait until the operating platform is stronger
In practice, the first post-investment integrity plan may be about clarifying third-party ownership, improving complaints escalation, cleaning up delegated authorities, tightening reporting on a few exceptions, and identifying where site or country-level visibility is too weak.
That may sound unglamorous. Good. It is usually more useful than launching a grand ethics programme nobody can sustain.
A good output for operating partners
If the review is working, it should leave you with clear answers to five questions:
- Where is the business most exposed today?
- What would management be slow to notice?
- Which issues could grow fastest as the value-creation plan accelerates?
- What needs board visibility now?
- Which two or three actions would reduce the most risk in the next quarter?
That is the standard worth aiming for.
Operating partners are often at their best when they make risk legible without making the business defensive. A good post-investment integrity review does exactly that. It turns scattered concerns, inherited diligence points, and half-seen operating weaknesses into a manageable set of priorities the company can actually act on.
