PE Tech DD Red-Flag Scan — 10 questions we ask of a target's AI stack in 5 business days
A five-business-day AI/data red-flag scan for private-equity deal teams. Ten questions, ten evidence artifacts, one memo. Priced $8–12K on the strength of the pattern alone — no client name required to buy. Follow-on Full DD ($25–45K) and post-close AI Acceleration retainer available where the target survives the scan.
Outcome metrics
- Turn-around
- 5 business days from data-room access to memo
- Deliverable shape
- 1-page red-flag memo + 5-slide annex
- Price band
- $8–12K (Red-Flag Scan) → $25–45K (Full DD)
- Follow-on offering
- AI Acceleration retainer, post-close
The question
"Is there anything in this target's AI or data stack that would kill our thesis, and can you tell us in five business days for the price of a lunch meeting?" That is the question the PE deal team is really asking. It is a red-flag question, not a full architecture review. Comuvia answers it by running a standardized ten-question scan against the target's data room and any technical materials the deal team can extract in the diligence window.
The ten questions
Every Red-Flag Scan runs the same ten questions in the same order. The questions are load-bearing on the deal thesis — not on best-practice checklists — so a "no red flag" answer means something concrete, not "everything is fine."
- Data provenance. Where do the training / inference inputs come from, and does the target have redistribution rights for the volume it operates at? Red flag: any input class with unclear licensing that materially affects the product economics.
- Model dependence. Which third-party models does the target depend on for inference, and what is the switching cost in weeks + revenue-at-risk if that provider changes pricing or terms? Red flag: single-provider dependence with switching cost > one quarter of runway.
- Fine-tune vs prompt. Does the target actually train / fine-tune anything, or is the "AI" a series of prompt templates over a hosted model? Red flag: prompt-only pipelines described as "our AI" in the CIM.
- Evaluation coverage. How does the target measure whether the model is doing the job? Is there an evals harness with published pass/fail rates on tasks that map to revenue? Red flag: no evals, or evals on toy tasks that don't map to what customers pay for.
- Latency + cost per task. For the actual production path, what is the p50 / p95 latency and per-task marginal cost, and how does that trend against unit economics as usage grows? Red flag: task cost is a rising fraction of ARPU with no visible optimization path.
- Data leakage exposure. What customer data (or model outputs derived from customer data) crosses the target's boundary into a third-party model provider, and is that disclosed to end-customers in terms that would survive a regulator? Red flag: undisclosed leakage that would require a term-sheet renegotiation with enterprise customers.
- Provider concentration on the ops side. Beyond model providers — hosting, vector DB, orchestration, observability. How many single-provider concentrations exist, and what is the migration cost per concentration? Red flag: three or more concentrations where the top single-provider outage would kill the product.
- AI-generated content policy. Does the target ship model output directly to customers, and if so, what is the human-in-the-loop / review policy, and is it consistent with the emerging content-policy regime in the target's geographies? Red flag: fully-automated output shipped to end-users in a regulated vertical without review policy.
- Team composition. How many people on the team can actually diagnose a model regression, versus how many are prompt-authoring in a shared doc? Red flag: no one on the team has ever shipped a model retraining pipeline; the "AI team" is a prompt-authoring team.
- Roadmap credibility. Does the AI roadmap in the CIM contain any milestones that require infrastructure or personnel the target is not currently building? Red flag: a roadmap that assumes future capability the current team cannot produce.
The evidence artifacts
Each question maps to a specific artifact Comuvia asks for from the data room. The list is provided to the deal team on day 1 so the target can be pinged in one batch; the scan runs on whatever comes back within 72 hours.
| # | Artifact | Question served |
|---|---|---|
| 1 | Training + inference data-inventory register | 1, 6 |
| 2 | Model-provider contracts + pricing tiers | 2, 5 |
| 3 | Training pipeline code (or Notebook) + one recent run log | 3, 9 |
| 4 | Evals harness README + last four run reports | 4 |
| 5 | Cost dashboard / FinOps view for the AI path | 5 |
| 6 | Data-flow diagram + boundary map | 6, 7 |
| 7 | Provider list with contract terms + failover posture | 7 |
| 8 | Content-review policy + last quarter's review-queue metrics | 8 |
| 9 | Team org chart with AI-relevant roles marked | 9 |
| 10 | 12-month roadmap + hiring plan | 10 |
Where an artifact is missing, that is itself a signal — noted in the memo. A target that cannot produce artifact 5 (the FinOps view) in 72 hours is running blind on unit economics, which is a red flag on question 5 even before the analysis runs.
The deliverable
- One-page red-flag memo. Ten questions, each with one of three verdicts —
PASS,WATCH,RED FLAG— and a one-sentence justification. This is the artifact the deal partner reads. - Five-slide annex. Slide 1: verdict summary + confidence. Slides 2–4: the two-to-three highest-severity findings, each with the evidence trail. Slide 5: what would upgrade a
WATCHto aRED FLAGin a follow-on Full DD.
Nothing in the annex requires the target's identity to be inferable. The methodology is portable across sectors — the same ten questions apply to a SaaS target, an AI-product target, or a data-service target.
What disqualifies a target from a Red-Flag Scan
Not every target is worth scanning at this price band.
- Deal thesis does not depend on the AI/data stack. If the AI is decorative to the thesis, spend the diligence budget elsewhere.
- Data room has zero technical materials. The five-day turn-around assumes the artifacts above land within 72 hours; a target that offers only sales collateral is not scanably.
- Target is a foundation-model provider. The scan is calibrated for application-layer targets — a foundation-model target needs a different diligence structure and is more like an infrastructure DD.
Price band + follow-on path
- Red-Flag Scan: $8,000–$12,000 for a 5-business-day scan against a single target. Fixed price at the top of the band for targets with more than 500 employees; discounted at the bottom band for pre-B targets.
- Full DD: $25,000–$45,000. Triggered when the Red-Flag Scan surfaces
WATCHfindings the deal team wants converted to actionable severity. Runs 2–3 weeks; produces a full-thesis document + rebuild-cost estimate + integration plan. - AI Acceleration retainer (post-close): fractional Architecture Advisor engagement for the portfolio company, 8–20 hours/month, to convert the DD findings into a 90-day remediation plan and then track execution against it.
Why five days
The five-day window is deliberate. It matches how PE deal teams actually work: technical DD gets a slot between finance DD and legal DD, not a month of its own. A red-flag answer that lands in the five-day window changes what the finance and legal teams look for in weeks 2–3. A red-flag answer that lands in three weeks changes nothing because the deal is priced.
Request a sample redacted memo
Sample one-page memos are held in a private vault. Access is restricted to PE GPs and operating partners on request. Use the contact form and mention "PE Red-Flag Scan sample" in the message; access is granted the same business day.
Related offerings
- Fractional Architecture Advisor — the retainer the AI Acceleration engagement chains into.
- Simulation Decision Pack — parallel offer for allocators (LPs, family offices) rather than direct-deal GPs. Different question, different deliverable.