Guide

AI governance and compliance consulting practice due diligence

Due diligence on an AI governance and compliance consulting practice centres on four documents — the professional-liability insurance policy, every material retainer agreement, the practice’s own published frameworks and deliverables, and its data-handling policy for confidential client AI-system information — because those four are where this sub-sector’s deals actually break down.

Reviewed

Due diligence on an AI governance and compliance consulting practice looks different from due diligence on a business with inventory or equipment, because almost every finding that matters here is documentary rather than physical. There is no facility to inspect and little machinery to appraise; instead, a buyer’s advisor is reading contracts, insurance policies and the practice’s own published material for the specific findings that have killed deals in this sub-sector before, and knowing what those findings look like in advance is most of the work. The goal at every step is the same: confirm on paper what the seller has represented in conversation, because in a practice this intangible, the gap between the two is exactly where the risk hides.

Start with the professional-liability insurance policy itself

Pull the actual policy, not just a certificate of insurance, and confirm what happens to it on a change of control — whether coverage for advice given before closing continues under a tail policy or endorsement, and what a new owner has to show, in terms of credentials or claims history, to be underwritten going forward. Ask for the practice’s claims history, including any claim that was reported but not paid, and treat a policy that does not clearly answer the change-of-control question as unresolved risk rather than assume it will sort itself out after signing. This is consistently the single finding most likely to actually delay or kill a deal in this sub-sector, and it is also the easiest one to check early.

Read every material retainer and engagement agreement

Go through each significant client agreement for what it actually says about assignment on a sale — whether the client’s consent is required, whether that consent has to be sought before or after closing, and whether any agreement is written to name a specific practitioner personally rather than the firm. A retainer that reads as a personal engagement with the founder, with the corporate entity mentioned only in passing, is functionally a different asset than a retainer that names the firm as the party of record, and the difference matters enormously to what you are actually buying. Cross-check the agreements against the revenue report to confirm the retainer base is not more concentrated in one or two accounts than the seller’s summary suggested. Where an agreement is silent on assignment altogether, treat that silence as a risk rather than an oversight to smooth over later, since a client with no contractual obligation to stay is free to walk the moment ownership changes.

Review the practice’s published frameworks and client deliverables

Request the assessment frameworks, checklists and sample client deliverables the practice actually uses, and read them specifically for how they describe evolving law — federal AI policy direction that has not yet settled into enacted legislation, and provincial privacy obligations, including Quebec’s Law 25, that continue to develop. A framework or report that presents a proposed rule as though it were already binding is a liability exposure sitting inside every deliverable the practice has issued, and depending on how many clients received that material, the exposure can be larger than it first appears. This review also tells you how proprietary the methodology genuinely is — a framework that is mostly a repackaged public standard is a different asset than one built from the practice’s own analysis. Pay particular attention to any framework built around a regulated sector — health, financial services, legal — since a sector regulator tends to move faster and enforce more concretely than general AI policy does, and a framework that has not kept pace with that sector’s own expectations is a sharper liability than one addressing AI policy generally.

Check how confidential client AI-system information is handled

This practice routinely holds sensitive material about its clients’ own AI systems — model inventories, internal risk assessments, impact-assessment drafts — and a documented data-handling policy governing how that information is stored, who can access it and how it is disposed of is a basic diligence item, not a nice-to-have. Its absence is itself a finding, because it means the practice cannot demonstrate to its own clients, let alone to you as a buyer, that the material it holds on their behalf is being protected the way clients likely assume it is. Confirm this policy exists, that it is actually followed rather than written and forgotten, and that it covers subcontractors or associates who may have had access to the same material.

What a finding here actually means

  • A policy that will not confirm change-of-control coverage means you may be buying uninsured liability along with the client list, not a minor administrative gap
  • A retainer written to the founder personally, with no clear firm-level assignment language, is revenue that may not survive closing regardless of what the seller believes will happen
  • A framework describing draft regulation as settled law is a liability exposure already sitting with every client who received it, not a future risk
  • A missing data-handling policy for confidential client AI-system material is a finding about how the whole practice is run, not an isolated gap

Sources

Every requirement and figure referenced in this guide traces to a primary source. Links were last confirmed on the dates shown.

  1. 01
    Treadstone LawLegal commentary
    Are Your Contracts Assignable?
    treadstonelaw.ca·Checked Aug 14, 2026
  2. 02
    Treadstone LawLegal commentary
    Key-Person Dependency
    treadstonelaw.ca·Checked Aug 14, 2026
  3. 03
    Treadstone LawLegal commentary
    Cybersecurity and Data Privacy Due Diligence When Buying a Business in Ontario
    treadstonelaw.ca·Checked Aug 14, 2026
  4. 04
    Office of the Privacy Commissioner of CanadaGovernment
    The Personal Information Protection and Electronic Documents Act (PIPEDA)
    priv.gc.ca·Checked Aug 14, 2026
  5. 05
    Commission d'accès à l'information du QuébecRegulator
    Principaux changements aux lois sur la protection des renseignements personnels
    cai.gouv.qc.ca·Checked Aug 16, 2026
  6. 06
    Canada Revenue AgencyGovernment
    Selling a business
    canada.ca·Checked Aug 14, 2026

Deavo is an advertising and listings platform, not a brokerage, law firm or valuation firm. This page is general information, not legal, tax, accounting or valuation advice, and rules differ by province. Confirm anything you rely on with a qualified professional before you act on it.