By Dario Garcia Giner
We used to live in a world underpinned by cheap trust where the need to do due diligence was rare. Your cousin visited Nigeria, he drank some beers with the right locals, and the two joined in business to make some money. Business used to be almost exclusively about the right signet rings, the right handshake – and a gentleman’s word.
Though much of business has certainly not changed, the expansion into a digitally globalised world and the onset of industrial development have fuelled a rush into niche sectors for outsized gains. This has expanded the comfort zone of business into areas beyond initial circles of trust; business sectors you’re ignorant of, individuals with no existing family or religious ties, and places you’ve never been to.
This has run parallel with the politicisation of money. No longer can you afford to have a Zambian business partner who provides lavish gifts to the authorities, or happily receive tickets to the VIP section of Formula 1 as a government employee. Now, you need to know who’s a Politically Exposed Person (PEP) – and Becky from HR will bite your head off if you don’t complete your AML and KYC training.
Both of these trends have fuelled the rise of corporate intelligence services – and have run concomitantly with the increase in public demands for transparency.
We now seek transparency in business, in government, and in the family home. We assume such developments ought to be helpful – to make of this world something moral and, hopefully, more stable.
That’s why green and red flags are so sought after; in the idealised and transparent world of good business, distinguishing a good partner from the bad should be plain and simple. Yes or no.
Unfortunately, there has also been a nasty by-product of transparency that is underappreciated. Humans may be somewhat changeable, and our natures may be a little editable, but on the whole, we do not change.
Ergo, this drive towards transparency has resulted in a toxic drive towards secrecy.
Stop expecting to find your risks written on a wall. Stop expecting to see them hand-in-hand with un-picked bins and tin-thatched roofs on the streets of poor countries.
In the globalised drive for profit, where openly bad practices are being increasingly persecuted, the real risks are being driven underground. Especially in those places with the greatest incentives for transparency – the developed, ‘low-risk’ world. As bad actors continue to adapt to this transparency-incentivising system, finding a red flag will increasingly be a matter of luck. Relying on finding nuanced ‘tells’, strange behaviour, and things that just stand out will be your first (and perhaps only) line of defence amidst the increased uncertainty of globalised deal-making.
The risks are right in front of you. Or, unfortunately, they may be right under you.
In the butcher’s shop that is Europe, we have achieved transparency by removing the meat from the storefront. Held in the basement, it is rotting and extending in unknown ways.
By the time you notice a small corner of your shop has turned mouldy, the foundations may have swollen with rot.
Therefore, here is a comprehensive guide to the key underlooked factors that should be considered when undertaking a due diligence process; yellow flags or risks.
The difference between good and bad DD
Good due diligence is the difference between getting interviewed by the SEC and enjoying a margarita on an Eames chair in St. Tropez.
Some others might say it is the difference between completing a successful $44bn takeover or having the entire legal system and media complex turn on you.
Risk, as we are all coming to understand, is a relative concept. Losing your fortune, your good name, and control of your core business, however, is not.
Having worked at a top-tier investigations firm for close to three years, the most under-appreciated factor when conducting due diligence exercises is the relativity of risk; notably, the prevalence of fat-tailed potential risks in low-risk jurisdictions.
Picture yourself building a data centre in Nairobi, Kenya. You would thoroughly vet your new business partners and their associates using an expensive investigative team, replete with source inquiries and related-party risk analyses. Travelling on-site with your lawyers to carefully examine the paperwork and the location, you even enjoy drinks with some vice-minister who personally guarantees the investment’s integrity.
It’s a risky jurisdiction and treated as such.
Juxtapose that with the need to build a backup data centre in Germany. Your business partners are Europeans, wear nice suits (or occasionally a black polo-neck), and hold multiple PhDs. Just to be safe, you hire a few quick compliance reports on your associates – they are (unsurprisingly) not flagged on any watchlist or sanctions list. You meet for a drink in London and toast to the Germanification of Mallorca, the business deal having been shaken on. What’s the worry? It’s Germany, after all.
Unfortunately, the clients I worked with often only recognised risk when facing their personal expectations of what risk looks like.
Business deals in Africa, Asia, and even Southern Europe were thoroughly vetted – again and again, and again – often exceeding 30-50k per pre-transactional investigation. Not so for lower-risk jurisdictions. For associations with British, German, or Danish businessmen working in their respective countries, the due-diligence budget was rarely over 10k.
However, reality begs to differ with such assumptions; the perceived variance between low-risk and high-risk jurisdictions is often a false friend.
You’re just thinking you could do with some credit, and a well-dressed German with adventurous tales in the middle east arrives with promises to offer low-interest credit for small businesses. Perfect presentation and approach – a great deal all in all! He’s so kind, he will even assign you his own high-flying accountant to help with the books – and you know how competent Germans are! Meeting your family, he brings his delightful wife, and you have some wholesome fun. Your own wife was delighted; “Honey, I LOVED Greta and Richter!!”
It’s only well after that you bear the unfortunate IRL experience of being duped. Pretty faces can hide ugly truths.
Indeed, history teaches us, instead, that the greatest risks lie where you don’t expect to find them. This sphere of risk is best represented by the term yellow risk or potential risks.
This is why you’re doing your due-diligence wrong: a focus on identifying the obvious and objective ‘green’ risks or ‘red’ risks can leave extremely fat-tailed, subjective yellow risks sneaking past.
What is a yellow risk or flag?
Let’s break this down by summarising some common concepts of risk:
- Green flags: Either no risk or an unsubstantial event that probably does not equate to any underlying risk.
A previous company of your potential business partner defaulted owing to a market rout. That’s business. Even if the flag may highlight something slightly distasteful, they are usually things one can work on (brush your teeth, Gary).
- Red flags: Probable or definite high and substantial risk.
Your potential business partner shows up on an Interpol watchlist for money laundering. You thank your lucky stars you did your due diligence and you file the opportunity away – plus, you just bought an interesting story.
However;
- Yellow flag: Potential risks, requiring more investigation, nuance and contextualisation.
Your investment manager, Julius, became a partner at a small bank with a minuscule online footprint in Hessen at the age of 28. The bank doesn’t seem to have a locatable office and holds a dysfunctional website. He associates with individuals involved in minor real-estate or cum-ex scandals, but he was never prosecuted. Your sleuths are smelling a fire, but all you can see is some hazy smoke. You’ve already spent 10k on this investigation – you tell yourself that people in this line of work are always prone to conspiratorial thoughts (which is not as true as you’d think). You confront your new business partner and your doubts are explained away. You sign on the dotted line.
Yellow flags are neither here nor there; they are question marks; we don’t know what Julius’ early promotion means. Similarly, are his friendships with shady individuals the result of a wide social circle, or is he also involved in business with them?
Question marks do not prove any culpability, and they can be seen by anyone willing to pay attention.
The key difference between a yellow risk and a green/red risk is that the latter categories are fixed.
Yellow risks are a question, therefore, this category is mobile; the answers can travel all the way up or down the risk spectrum, concealing anything from a leafy green to a devilish red in its innards.
It will throw the entire investigation in the air. Everything is now in doubt. You check. You double-check. The fees rack up, and budgets suddenly feel tight.
Furthermore, since a yellow flag can hide a dark red, it is worse than an identified red flag – because you don’t actually know how bad of a red flag it could be.
Therefore, a single yellow flag is both unavoidable, costly, and potentially deadly.
Ah, you say. I now know what a yellow flag is. I’ll just spend more on investigations.
Right?
Well.
Here’s the catch with yellow flags. They are entirely subjective.
Green and red flags are objective, but there’s nothing concrete about being a little sus.
To identify such flags means you are entirely reliant on:
- The agreed-upon scope of inquiry.
- The investigation manager and the analyst’s gut feel and experience.
- Sheer luck.
Not just unavoidable, costly, and dangerous – but also subjective and indeterminate.
There is a beam of hope at the end of the tunnel, however. The biggest problem with yellow flags, ultimately, is recognising them. Red flags shriek, and green flags hum, but yellow flags hide in tunnels…or in plain sight. Once you’ve found the yellow, however, the investigation can proceed as normal – while following the yellow trail.
Mostly, they’re fine.
But when they’re not, you may be in for more than a life lesson.
Yellow flags and where to find them
Let’s walk through some examples of yellow flags, all of which are real-life examples I have come across.
The process is so:
- You screen the target and identify yellow-ness.
- The yellow tinge indicates the thrust of a particular investigative inquiry.
- Finalising an inquiry, you will ideally have clarified which risk buckets it may finally sit in: yellow, green, or red.
Examples:
A very successful company is going to be acquired. Great name, client and industry reviews. Really up and coming. However, the company did not advertise their concrete origins in the ‘about’ section. Their history is difficult to find online. What’s stopping them from bragging?
We eventually discover the company’s history using the Wayback machine on their first website – the only location where their history could be found. Source inquiries later told of not one, not two, but three different types of origin stories. The target company’s executives had also managed to execute a curious reverse-takeover of their current owner, which the sources we spoke to mentioned had very mysterious elements.
No red flags, but a whole bellyful of yellow. The client wisely walked away.
You shake the hands of a potential business partner. He calls himself Alvaro Macías Daniel. UK Companies House list him as Alvaro García Daniel, while the Spanish registry lists him as Alvaro García. As a Mediterranean, always watch out for cultures with the custom for several names. They can and will be weaponised against unknowing Anglo-Saxons (so much for the centuries of British piracy).
A previous compliance report lands on your desk with instructions to expand on their so-called findings. You quickly realise this Alvaro hides everything behind different variations of his surname – clearly marking this a ‘yellow’ risk.
Madly searching through all possible name variations on different databases to clarify the risk, you find a lawsuit here, a bankruptcy there, and some or other involvement with politically-exposed persons.
A hustler does not make for a red flag, especially if your industry is not risk-averse. A few yellow flags, but mostly green. The client decided to proceed with the deal.
A successful and growing beverages company acquires a tiny pr company with little reach and poor Glassdoor reviews.
This tickles your interest. However, the pr company, despite its small reach, does possess nicely curated content and appears to be active. You decide the Glassdoor reviews must be the result of a few annoyed employees fired after the acquisition. Then the source inquiries come in: the CEO of the beverages company has been sleeping with the CEO of the pr company since before the acquisition.
A yellow flag turned a slightly negative green now becomes a teasing red – I suspect the PE company who hired us will have aimed stern questions at the CEO of the beverages company before deciding to acquire them.
How to combat the elusive yellow flag:
Thanks to what I learned as a private investigations analyst, I will attempt to divulge the only yellow flag risk mitigation strategies I know of.
Fortunately for us, we just need to wield the sword of common sense.
1. Let your target intelligence be ‘loose’
Once you know the name of your target, grab all the possible identifiers: phones, emails, last names, maiden names, etc. Don’t wait to hire your investigations firm. Do this beforehand.
Once you have, pass it around. Let your staff have a go, and encourage them to notice as many odd things as they can. For instance, make everyone look at the target’s LinkedIn. See if their progression makes sense or if their career was a little too impressive. Build a small cache of information you find weird and questions that need answering.
The same goes once you task your chosen investigation firm. Share everything you have on your desired subject. Don’t hold back and present your own findings or additional identifiers halfway through the investigation. Don’t be that client. You will antagonise the professionals running your investigation and will have wasted your own money letting the investigators get up to speed inefficiently.
The more people look at a piece of paper, the more you will know about it.
2. Be prepared to pay for investigative creativity
It goes without saying that a good investigation needs dolla dolla.
The more runway to an investigation, the more at ease a manager will be in letting the analyst pursue a wide variety of leads since they are confident they can finish the assignment within budget.
A cheap budget will encourage a cheap investigation. Not because the analyst granted will be of poorer quality, but because they cannot be creative.
This leads us to:
3. Always budget for source inquiries
A good budget will get you good source inquiries. I was SHOCKED at how rare it was for some clients to budget for source inquiries. Many just didn’t seem to care!
Source inquiries are usually the only difference between a thorough investigation and a rubbish one – no matter how good the investigations team is. Source inquiries are not optional.
Nobody ‘cracks’ anymore. Only a minority of companies break the law in the whiter-most layers of the investigations industry – in part because so much information is now open-source.
Unfortunately, your yellow-risk-but-is-actually-red investigative target also knows that. They may have engaged in counter-open-source measures, such as filing to shut down certain media reports or piling false positives into search algorithms.
The only way around the open-source quandary without cracking is to phone people. People talk, and will typically provide the most useful findings of any investigation (and if such intelligence can be cross-checked, even better).
Source inquiries will likely prove critical in the cracking of yellow risks in your future business deals.
In short: the more you pay, the better your results.
4. Define a good scope
Don’t burden some skilled investigators with the exhausting task of thoroughly mapping a corporate giant’s incorporation structure, the entire media profile of all secondary directors, or full sanctions checks for all related parties. You will rarely learn more, and you’ll exhaust the analyst whilst burning precious budget.
Always seek to press the scope away from thoroughness and towards lines of inquiry into disreputable activities and strange jurisdictions.
Boards like thoroughness, as do clients and managers. However, thoroughness is a flawed concept – its attaintment can eliminate many other investigative possibilities.
Phrases like “the client wants you to map X PLC’s entire corporate structure” make one want to jump out of a window.
Ensure the investigators know the few places where you’d like to be thorough so they don’t waste their time and your money. It will allow the analyst to focus on those companies and affiliated directors they judge curious.
You must encourage the analyst and manager’s nose – pressing them to tunnel into strange smells and gut feelings.
This is done with a defined and refined scope of inquiry.
Investors are used to actioning with a large hammer; big data sets, broad analysis, and definite conclusions. However, one investigates best with a small screwdriver; the smaller the piece of data, the more refined the analysis, the more focused a conclusion.
Define an accurate and precise scope so your investigators may think small.
5. Know what investigations firm, team, and person you’re hiring
- All companies have their specialities and their weaknesses.
Before you hire an investigation firm, call around to know what their capabilities are in each area. Don’t be put off by their lack of office locations in regions they claim to cover properly; a well-placed head office manager/analyst team and experienced local subcontractors can work miracles.
- Know the specialism of the manager in the investigations team you’re hiring and aim to place the correct manager in charge of your investigation.
Egos are everywhere. If you know a manager at an investigations firm because they dealt with your litigation support, chances are that manager will still fight tooth and nail to manage the next investigation, even if you’re now seeking solid due diligence that lies outside their area of expertise.
As a client, leverage your will in favour of specialists and experts to eliminate politically-motivated bad outcomes driven by insecure managers.
Research your investigators almost as thoroughly as your future business partner.
6. Know the limitations of compliance teams
Compliance can be useful when screening secondary targets like middle managers, second-file C-suite executives, or smaller subsidiaries in lower-risk jurisdictions. If and when these targets may show up on compliance sanctions or watchlists, they should be placed in the queue for a thorough investigative check-up.
That is because, for the most part, compliance’s box-tick-like methodologies mean they will rarely discover anything you cannot with a simple Google, as they lack the scope for any type of investigative creativity. Indeed, even one or two good keystrokes on Google can feed you more intelligence than some compliance reports.
Ignoring this advice means your future will be in the hands of a drooling, half-asleep, and overworked drone lazily copy-pasting your target’s name into different search boxes on Refinitiv and LexisNexis services through glazed eyes. You would have thought compliance workers have their minds on the “investigation”. Unfortunately, their minds are likely on choices for their next Tesco meal deal.
They have about as much chance of catching a yellow flag as Elon Musk has at keeping Twitter workers happy.
Compliance is the cheaper, quicker, and lower-quality alternative to a real investigation. Use them to deal with high volumes of unimportant targets and you won’t be disappointed.
(As an aside, those who do not want thorough due diligence should hire a compliance team).
7. Understand your exposure and biases
The following is a quick list of typical mistakes frequently repeated by clients of investigative firms.
- Letting the sunk costs in a business deal cloud your judgment.
- Allowing pride to cloud your instinct and common sense.
A deal will always be difficult to walk away from. As a proud and successful business owner/manager, it’s going to be hard to swallow a due diligence report that flies in the face of your initial assumptions.
You should fight this tendency tooth and nail. In our uncertain world, I would bet that investors and board members would be far more impressed with flexibility and caution, as well as the ability to frankly own up to mistakes.
The second series of mistakes are committed through little fault of the honest client – they relate to how bad actors ‘getcha’. Ask yourself:
- Why do I trust my potential business partner? What evidence have they presented that has built into my assumptions of my potential business partner as a worthy candidate for my time, trust, and money?
High-flying clients would come begging for aid having been duped and made to look foolish by a smart scammer or money launderer.
These individuals insert themselves into your trust by building a web of lies. Who introduced you to them? Is it a recent contact? Beware of introductions, even if they come from those you trust; good scammers often work by holding two sets of business partners – the highly respected business people they rely on for introductions (who are often unaware of the scammer’s tendencies for long stretches of time – think Theranos), and the less-known individuals they can safely fleece.
Furthermore, what small-scale events have tied into large-scale assumptions on your end; did he quickly show you his ‘healthy’ books or a media article flaunting his successes? Don’t forget how easily a document can be faked.
This point is effectively illustrated by the simple brilliance of this saying:
“If I say I’m Chinese, that does not make me Chinese. Furthermore, if I say my father is Chinese, that does not make him Chinese either.”
Stick to hard facts, listen and be guided by your gut, and try to forget everything else.