Strategy & Funding Practice

Build a controlled diligence request register

Connect each authorised request to an authoritative document, owner, exception, and access boundary.

Preparation
Until the evidence owners, authorised decision owners, independent counsel, and relevant jurisdiction advisers complete their reviews
Difficulty
Advanced
Task
Prepare an investor diligence record
Back to the Task: Prepare an investor diligence record

Before you start

Get what you need before you start

  • Confirm the company body and people authorised to own this decision.
  • This Practice provides an internal evidence workflow. It does not provide legal, financial, tax, investment, or valuation advice.
  • Obtain named pre-upload approval for the workspace, plan, account settings, retention settings, and each approved document category.
  • Treat privileged, personal, customer, employee, security, and third-party information as prohibited. Keep it out of this workspace and use a separately approved system.
  • Verify plan-dependent data controls and retention before use. Test access with a non-owner account before sharing.
  • Keep unsupported facts, missing documents, conflicts, and disagreement visible.
  • Treat Tool output as an internal draft that a person checks against every cited source.
  • Independent counsel and the qualified advisers for each applicable jurisdiction must review every external communication and transaction decision before use.

Steps

Work through the method

Use the listed inputs and tools. Check the evidence when you need to verify a step.

  1. Approve the request and document categories

    Record the requester, purpose, category, owner, version, privilege or confidentiality status, approval state, intended recipients, access expiry, and missing material. Counsel approves categories before any upload.

    Why it matters: The request purpose and document status must be known before disclosure or Tool use.

    Input
    The request, counsel-approved disclosure rules, authoritative records, and document owners.
    Output
    A request register with purpose, privilege, approval, recipient, expiry, and exception fields.
    Tools in this stepChatGPT evidence workspace

    Evidence for this step

  2. Prepare and test bounded access

    Reconcile each approved document to its authoritative record. Configure the recipient’s minimum access, test it as that recipient, and record download limits and unresolved exceptions.

    Why it matters: A configured permission needs a recipient-view test and an external access record.

    Input
    The approved register, response documents, room configuration, and recipient list.
    Output
    A counsel-reviewed response set, exception record, tested recipient access, and expiry schedule.
    Tools in this stepChatGPT evidence workspace

    Evidence for this step

  3. Log disclosure and close access

    An authorised person approves each disclosure and records what was shared, when, with whom, and under which controls. At expiry or process end, revoke access, request deletion where applicable, and record completion and exceptions.

    Why it matters: OpenAI describes deletion windows and exceptions, so the record must avoid claiming immediate erasure.

    Input
    The tested response set, approvals, access schedule, and retention rules.
    Output
    A disclosure record with access revocation, deletion request, completion status, and retained exceptions.
    Tools in this stepChatGPT evidence workspace

    Evidence for this step

Success checks

Check the result before you finish

  • Every request records requester, purpose, owner, version, privilege, approval, recipients, expiry, and exceptions.
  • Counsel approved each category before upload or disclosure, and the recipient view passed an access test.
  • The close record shows revocation, deletion requests, completion status, and any retention exception without claiming immediate erasure.

Failure modes

Watch for these problems

  • A document category, recipient, purpose, or upload lacks current approval. Do not upload or disclose the material.
  • The response uses an outdated document, hides an inconsistency, or marks missing evidence complete. Hold the request and return it to the authoritative owner.
  • The recipient access test fails, or privilege, privacy, confidentiality, security, or contract status is unclear. Stop sharing, restrict access, and escalate the item to counsel and the responsible owner.

Tools

Choose the tools you need

Sources

Read the sources behind this practice

Check what each source supports and where the advice has limits.