Risk AssessmentCritical riskConsensus useful

AI M&A Due Diligence — Regulatory Liability & Hidden Exposure Assessment Playbook

Your PE firm is 30 days from closing a $340M acquisition of a specialty government contractor with 62% revenue concentration in a single DoD IDIQ. Post-LOI diligence has surfaced three items: a DCAA audit finding from 18 months ago that was never formally closed, an unresolved qui tam suit under seal, and a CAS non-compliance disclosure that management described as 'immaterial.' Your deal team has 10 days to complete regulatory diligence.

When to use this playbook

  • Use this playbook when the decision looks like the situation above: Your PE firm is 30 days from closing a $340M acquisition of a specialty government contractor with 62% revenue concentration in a single DoD IDIQ.
  • It is a fit when you have source files in hand and need a structured, reviewable analysis — not a generic chat answer about "M&A Due Diligence — Regulatory Liability & Hidden Exposure Assessment".
  • Do not use it as a substitute for licensed, legal, clinical, or authorized official judgment in the domain.

What you'll need

  • Source documents specified in the workflow

The Prompt

You are a regulatory due diligence counsel and M&A advisor conducting pre-close regulatory risk assessment for a government contractor acquisition.  I am attaching: - DCAA audit finding letter and company response - CAS non-compliance disclosure and cost impact statement - Government contract portfolio (all active awards) - Representations and certifications on file with SAM.gov - Management's regulatory risk disclosure in the data room

Work only from the attached source files. If a conclusion is not supported, say so.

Produce:
1. Assess the DCAA audit finding — determine whether the open finding creates a risk of cost disallowance, contract price adjustment, or suspension/debarment, and whether the company's response adequately addressed DCAA's concerns.
2. Evaluate the CAS non-compliance disclosure for actual cost impact — assess whether management's 'immaterial' characterization is supported by the cost impact statement, and identify the potential government claim exposure under FAR 52.230-6.
3. Review the full contract portfolio for revenue concentration risk, novation requirements post-close, and any contracts with organizational conflict of interest provisions that could be triggered by the acquisition.
4. Cross-check the SAM.gov representations and certifications for accuracy given the disclosed regulatory findings — identify any certifications that may be false or require immediate update post-close.
5. Produce a regulatory risk register quantifying each exposure, a list of pre-close remediation actions, and recommended representations and warranties for the purchase agreement.

Call out where independent models are likely to disagree, and list follow-up documents a reviewer should request.

What to expect

  • Multi-model consensus on regulatory risk classification and deal impact
  • DCAA exposure quantification with worst-case and expected-case scenarios
  • CAS non-compliance cost impact assessment
  • Contract portfolio novation and OCI risk register
  • Regulatory risk register with pre-close remediation priorities and model-agreement score

Review before you act

  • Validate this output against source files before relying on it: Assess the DCAA audit finding — determine whether the open finding creates a risk of cost disallowance, contract price adjustment, or suspension/debarment, and whether the company's response adequately addressed DCAA's concerns.
  • Validate this output against source files before relying on it: Evaluate the CAS non-compliance disclosure for actual cost impact — assess whether management's 'immaterial' characterization is supported by the cost impact statement, and identify the potential government claim exposure under FAR 52.230-6.
  • Validate this output against source files before relying on it: Review the full contract portfolio for revenue concentration risk, novation requirements post-close, and any contracts with organizational conflict of interest provisions that could be triggered by the acquisition.
  • Validate this output against source files before relying on it: Cross-check the SAM.gov representations and certifications for accuracy given the disclosed regulatory findings — identify any certifications that may be false or require immediate update post-close.
  • Confirm every cited figure, date, counterparty, or requirement against the attached originals — models compress and can drop a qualifier.
  • Treat disagreement between models as a review item, especially on classification, materiality, and recommended next action.
  • Do not authorize an operational, clinical, legal, credit, or enforcement action solely because the models agree.

Why compare models on this

For M&A Due Diligence — Regulatory Liability & Hidden Exposure Assessment, running the same attachments across independent models is useful because the hard part is classification and completeness, not fluency. The workflow is already designed to surface multi-model consensus on regulatory risk classification and deal impact; dcaa exposure quantification with worst-case and expected-case scenarios; cas non-compliance cost impact assessment; contract portfolio novation and oci risk register. Those are comparison artifacts — they only exist if more than one model runs. Threshold-splitting, sanctions hits, and exam-readiness calls are exactly where models diverge. Record the split and the human resolution.

US FederalM&A Regulatory Due DiligenceRisk AssessmentCriticalDocuments

See governed multi-model AI on your own prompt

Compare GPT-5, Claude, and Gemini side by side, with human review and a decision record built in.