Operational Due Diligence

We test whether the operation can carry the plan the deal is priced on, and what the improvement is worth once you subtract the cost to achieve it. Cost, capacity, supply chain, working capital, and people, sized into the model.
Contact us
Definition

What is operational due diligence?

Operational due diligence examines how a business actually produces and delivers: what it costs to make the product, how much more it can make without new capital, where the supply chain runs through a single supplier, how much cash is parked in inventory, and who has to stay for the plan to work. It answers two questions. Can the operation carry the volume and margin in the model, and what is the improvement worth after you subtract the cost of getting it.

  • Cost that actually flexes: A fixed versus variable split built from the general ledger, so the downside case knows which costs fall with volume and which do not.
  • Capacity against the plan: Utilization by line and by site measured against the volume the growth case assumes, with the binding constraint named and the cost to relieve it priced.
  • Concentration you inherit: Single-source suppliers with no qualified alternate, purchase price variance against standard cost, and contracts that reprice inside the hold period.
  • Cash trapped in the operation: Days inventory on hand by SKU class, slow-moving and obsolete stock against reserve policy, and the working capital the buyer funds on day one.
Services

What does operational due diligence cover?

Nine workstreams, scoped to the deal and the clock. Each one produces a number that goes into the model and a finding that carries into the first 100 days.

Cost structure and margin bridge
Capacity and throughput
Supply chain and procurement
Working capital and inventory
Org design and span of control
Key person and retention risk
Facilities and footprint
Quality and service levels
The improvement case and what it takes to get it

Cost structure and margin bridge

We rebuild the cost stack from the general ledger: fixed versus variable, direct labor and overhead absorption, and a margin bridge that separates price, mix, volume, and input cost. The output shows which costs actually flex when volume moves and which stay put, so the downside case is priced on how the plant behaves rather than on a percentage assumption.

More

Capacity and throughput

Utilization measured line by line and site by site against the volume in the growth plan. We name the binding constraint, quantify the overall equipment effectiveness gap behind it, and price the two ways out: a shift pattern change with labor, or capital with a lead time the plan has to absorb.

More

Supply chain and procurement

Spend by category and supplier, single-source parts with no qualified alternate, who owns the tooling, and lead times measured against real demand variability. We test purchase price variance against standard cost, read contract expiry and repricing terms, and size tariff and country exposure that moves landed cost.

More

Working capital and inventory

Days inventory on hand by SKU class, slow-moving and obsolete stock tested against reserve policy, receivable aging against stated terms, and payable days against what the contracts actually allow. We separate the working capital the business needs from the working capital it is holding, and quantify what a normal cycle would release.

More

Org design and span of control

Headcount by function and layer, span of control at each level, and the roles the plan needs that nobody holds yet. We compare cost per unit of output against the peer range and show where the structure has to change for the volume in the model, including the hiring lead time in tight labor markets.

More

Key person and retention risk

Who holds knowledge that was never written down, who sits on a contract that ends at close, and who leaves the day the deal is announced. We test the depth behind each critical role, read the retention terms already in place, and price the terms it will take to keep the people the plan depends on.

More

Facilities and footprint

Lease expiry and renewal terms read against the footprint the plan assumes, site condition and deferred maintenance, permits and environmental obligations that transfer at close, and utility and freight cost per unit.

  • Lease expiry, renewal terms, and rent steps by site
  • Owned property condition and deferred maintenance backlog
  • Permits and environmental obligations that transfer at close
  • Space utilization against the volume in the plan
  • Utility, freight, and inbound logistics cost per unit
  • Consolidation cases priced with exit, move, and requalification costs
More

Quality and service levels

Scrap, rework, warranty, and returns as a percentage of revenue, on-time in-full performance against what customers were promised, and the penalty terms in the contracts that carry them. We read the complaint and corrective action record to see whether a quality number is stable or drifting.

  • Scrap, rework, and warranty as a percentage of revenue
  • On-time in-full performance by customer and by line
  • Contractual service levels and the penalty exposure behind them
  • Complaint and corrective action history over three years
  • Supplier quality and incoming inspection results
  • Recall or field action exposure and reserve adequacy
More

The improvement case and what it takes to get it

Most operational diligence stops at a range: there is 8 to 12 percent of cost to go after. That number does not survive an investment committee and it does not survive month four. We take each initiative to a named owner, a start date, a phasing across the first four to eight quarters, and a cost to achieve that includes capital, severance, advisor time, and the productivity dip during changeover. A savings number with an owner and a date goes in the model. Everything else stays in the appendix.

  • Initiative list with a named owner for each line
  • Measured baseline and target, not a benchmark percentage
  • Phasing across the first four to eight quarters
  • Cost to achieve: capital, severance, and advisor time
  • The productivity dip assumed during changeover
  • The measure that proves delivery in the first 100 days
More
Our approach

How we run operational due diligence

Seven steps over three to five weeks, run by senior practitioners who have carried an operations budget. We start from the deal model, go to the sites, and finish with an improvement case that has owners, dates, and a cost to achieve attached to every line.
01

Frame the operating thesis

We start from the deal model: the volume, price, and margin the plan assumes, and the capital it allows. That defines what the operation has to deliver and which questions actually move the answer.

02

Build the cost and capacity baseline

General ledger detail, standard costs, routings, and production records rebuilt into a fixed versus variable split and a utilization picture by site and line. Everything after this measures against that baseline.

03

Visit the sites

Two to five days on the floor with the plant, supply chain, and service leaders. We walk the process, watch a shift where the constraint is contested, and read the maintenance, scrap, and scheduling records against what the data room claimed.

04

Test supply chain and working capital

Spend by supplier, single-source exposure, purchase price variance against standard, days inventory by SKU class, and reserve adequacy on slow-moving stock. Every finding is sized in dollars before it leaves the workstream.

05

Read the organization

Headcount, layers, span of control, and the roles the plan needs that nobody holds. We interview the people the plan depends on and assess who stays, who leaves at close, and what retention will cost.

06

Size the improvement case

Each initiative gets a measured baseline, a target, a named owner, a start date, and a cost to achieve covering capital, severance, and the productivity dip during changeover. Where the estimate is a range, we say what drives the range.

07

Hand it to the first 100 days

Findings arrive as a phased initiative list with the metrics that prove delivery, plus the items that belong in the purchase agreement or the day one checklist. Nothing gets rediscovered in month four.

contact us

Need to know whether the operation can carry the plan?

Send the model and the site list. We will tell you what can be sized in three weeks, what needs a longer look, and what the fee is.

Our Advantage

Why BD Emerson for operational due diligence

Senior practitioners on the file from scoping to readout, findings quantified into the model, and one firm running the financial, tax, technology, and cyber workstreams alongside this one, so the numbers reconcile instead of arriving in four separate reports.

People who have run the plant

The team walking your floor includes practitioners who have carried operations budgets, moved production between sites, and closed one. They can tell a schedule that is tight from a schedule that is fiction.

Findings sized into the model

Every operational finding arrives as a dollar figure with the assumption behind it, mapped to the line in the model it changes. Themes for the buyer to translate later do not make the report.

One team across the diligence

Financial, tax, technology, and cyber diligence run by the same firm, so the operating case reconciles to the quality of earnings and the technology plan rather than contradicting them in the appendix.

The plan survives close

The people who sized the improvement stay to sequence it. The improvement case becomes the first 100 days plan with the same owners, the same baselines, and the same numbers.

Reviews

What our customers say

Great consulting firms for scaling security, compliance, and appsec.

Outstanding partner in Technical and Cyber Due Diligence

Appsec maturity and application hardening.

BD Emerson helped us simplfiy our compliance management.

BD Emerson did such a phenomenal job. What started as privacy support quickly became a full partnership across compliance, engineering, and even business operations. They’re embedded with our team. They understand our product. They move fast. They’re simply invaluable.

Adam Ben Jacobs

CTO @ OneStep GPS

Great consulting firms for scaling security, compliance, and appsec.

Outstanding partner in Technical and Cyber Due Diligence

Appsec maturity and application hardening.

BD Emerson helped us simplfiy our compliance management.

BD Emerson did such a phenomenal job. What started as privacy support quickly became a full partnership across compliance, engineering, and even business operations. They’re embedded with our team. They understand our product. They move fast. They’re simply invaluable.

Adam Ben Jacobs

CTO @ OneStep GPS

We had a hard time finding the right company to partner with in support of our compliance journey. Some vendors sell the idea that they do the work, but then you end up doing everything. The ambiguity is what killed our last project. BD Emerson’s team has such great technical knowledge and understands the standard so well that they made us comfortable with moving fast. This has led to us closing major enterprise customers that were previously out of reach because of security and compliance.

Tom Watkins

CEO @ AMI AssetTrack

Lead an enterprise initiative to overhaul the organization's technology stack from ecommerce, corporate tech, and corporate security.

Supported ISO 42001 exercise and served as internal auditor.

Rubrik's privacy and compliance team began with the backbone of BD Emerson. BD Emerson supported building out the privacy program, GRC (ISO 27001, SOC 2, CMMC, FedRAMP), and the appsec function.

We needed a partner who could move quickly, without sacrificing precision. BD Emerson brought the expertise, structure, and speed we were looking for. Their team became an extension of ours, embedding themselves across the organization, guiding us step by step, and giving us confidence in areas we hadn’t tackled before. The internal audit they conducted was so detailed that even the external auditors called it out. Achieving ISO 27001 with zero nonconformities says everything you need to know about the quality of the partnership.

Walid Souilem

CTO @ FGI Worldwide

We had a hard time finding the right company to partner with in support of our compliance journey. Some vendors sell the idea that they do the work, but then you end up doing everything. The ambiguity is what killed our last project. BD Emerson’s team has such great technical knowledge and understands the standard so well that they made us comfortable with moving fast. This has led to us closing major enterprise customers that were previously out of reach because of security and compliance.

Tom Watkins

CEO @ AMI AssetTrack

Lead an enterprise initiative to overhaul the organization's technology stack from ecommerce, corporate tech, and corporate security.

Supported ISO 42001 exercise and served as internal auditor.

Rubrik's privacy and compliance team began with the backbone of BD Emerson. BD Emerson supported building out the privacy program, GRC (ISO 27001, SOC 2, CMMC, FedRAMP), and the appsec function.

We needed a partner who could move quickly, without sacrificing precision. BD Emerson brought the expertise, structure, and speed we were looking for. Their team became an extension of ours, embedding themselves across the organization, guiding us step by step, and giving us confidence in areas we hadn’t tackled before. The internal audit they conducted was so detailed that even the external auditors called it out. Achieving ISO 27001 with zero nonconformities says everything you need to know about the quality of the partnership.

Walid Souilem

CTO @ FGI Worldwide

BD Emerson didn’t just help us meet our compliance goals; they integrated security and privacy into the core of our operations. I highly recommend BD Emerson to anyone seeking SOC 2 or GDPR compliance, or simply looking to enhance their security team and boost customer trust in their product and services. Their dedication and expertise have been invaluable to our success.

Padraig Reilly

CEO, Boxcore

BD Emerson understood our business requirements and worked side-by-side with us. The policies and controls we developed together not only meet compliance standards but improve how we operate day to day.

Matt Meierdierks

IT Manager, Lincoln Industries

From day one, BD Emerson brought urgency, clarity, and a sharp understanding of what truly matters to our business — earning and keeping customer trust. They went beyond helping us meet compliance requirements; they helped build a foundation for secure, scalable growth. That kind of partnership is rare.

Jason Marker

CEO @ LifeLenz

BD Emerson didn’t just help us pass an audit—they helped us build a sustainable culture of security.

Alexey Indeev

CTO Spare

BD Emerson was essential in helping our company navigate the daunting process of leveling up our security infrastructure. BD Emerson’s impressive expertise and confidence throughout the process helped our team exceed HIPAA and SOC 2 Type 1 standards quickly, distilling what can be an overwhelming process into a streamlined, organized effort. From day one they began adding value and getting us on course. With their help we delivered on a massive security overhaul with both extreme efficiency and thorough attention to details. Because of BD Emerson’s support, we’ve increased our clients’ trust in Titan Intake and the life-changing work it accomplishes for those seeking specialist referrals.

Patrick Bruce

CEO, Titan Intake

BD Emerson didn’t just help us meet our compliance goals; they integrated security and privacy into the core of our operations. I highly recommend BD Emerson to anyone seeking SOC 2 or GDPR compliance, or simply looking to enhance their security team and boost customer trust in their product and services. Their dedication and expertise have been invaluable to our success.

Padraig Reilly

CEO, Boxcore

BD Emerson understood our business requirements and worked side-by-side with us. The policies and controls we developed together not only meet compliance standards but improve how we operate day to day.

Matt Meierdierks

IT Manager, Lincoln Industries

From day one, BD Emerson brought urgency, clarity, and a sharp understanding of what truly matters to our business — earning and keeping customer trust. They went beyond helping us meet compliance requirements; they helped build a foundation for secure, scalable growth. That kind of partnership is rare.

Jason Marker

CEO @ LifeLenz

BD Emerson didn’t just help us pass an audit—they helped us build a sustainable culture of security.

Alexey Indeev

CTO Spare

BD Emerson was essential in helping our company navigate the daunting process of leveling up our security infrastructure. BD Emerson’s impressive expertise and confidence throughout the process helped our team exceed HIPAA and SOC 2 Type 1 standards quickly, distilling what can be an overwhelming process into a streamlined, organized effort. From day one they began adding value and getting us on course. With their help we delivered on a massive security overhaul with both extreme efficiency and thorough attention to details. Because of BD Emerson’s support, we’ve increased our clients’ trust in Titan Intake and the life-changing work it accomplishes for those seeking specialist referrals.

Patrick Bruce

CEO, Titan Intake

Certificates

Our accreditations

At BD Emerson, we believe that our team's extensive certifications not only set us apart but also ensure that we provide the highest level of service to our clients.
FAQ

Frequently asked questions

What is operational due diligence?

How is it different from commercial and financial due diligence?

How long does operational due diligence take?

What happens during a site visit?

How is the improvement case sized and validated?

What does an operational red flag look like?

Is the work different on the sell side?

What data do you need to start?

How do findings carry into the first 100 days?

Who does the work?

What does operational due diligence cost?

Blog

Related Articles

Insights on strategy, transactions, technology, security, and compliance from BD Emerson's practitioners