Family Office Due Diligence Checklist With Red Flags That Matter
What should a family office due diligence checklist include?
A family office due diligence checklist should cover governance and legal structure, investment oversight, operations and compliance, and people and succession. It should also mark red flags beside each item, including undocumented overrides, unexplained fees, same-person payment initiation and approval, incomplete audit trails, unresolved findings, and one-person dependency.
How to Use This Family Office Checklist
This checklist is a repeatable due diligence process, not a one-time screen. It supports selection, monitoring, and internal challenge, but the evidence bar rises from stated capability to operating proof. Family office due diligence also has to test stewardship fit, reporting fit, privacy expectations, and multigenerational alignment, not just technical competence.
- Use it in selection to compare models and test whether thorough due diligence fits the family's operating needs.
- Use it in monitoring to track drift and whether the diligence process still matches the office's scope.
- Use it in internal audit to test whether controls and reporting can be evidenced, not just described.
- Adjust the checklist by office model, because control and visibility sit in different places.
Use It for Selection, Monitoring, and Internal Audit
The categories stay the same, but the decision changes. Selection tests fit, monitoring tests drift, and internal audit tests whether the same framework is backed by evidence strong enough for decision making.
| Review mode | Primary purpose | What the reviewer looks for | Evidence standard |
|---|---|---|---|
| Selection | Choose the right partner | Capability, scope fit, role clarity, and stewardship fit | Stated process, sample materials, and clear explanations may support an initial screen |
| Monitoring | Track drift over time | Service changes, unresolved exceptions, and gaps between promises and delivery | Recurring outputs, follow-through, and issue patterns should support the same framework in practice |
| Internal audit | Test control effectiveness | Whether approvals, reporting, and oversight operate as described | Documented proof, traceable records, and repeatable evidence are required |
How Office Type Changes the Diligence Process
Office structure changes where the diligence process should press hardest. In a single family office, scrutiny centers on internal depth and visible control. In shared or delegated models, the practical difference is where authority, standardization, and oversight can weaken.
| Office type | Where control sits | Where scrutiny should concentrate | What can become harder to see |
|---|---|---|---|
| Single-family office | Inside one family-owned structure | Decision authority, segregation of duties, reporting depth, and continuity | Whether internal controls are strong enough when a small group holds broad discretion |
| Multi-family office | Across a shared platform | Standardization, conflict management, service consistency, and exception handling | Whether one family's needs are diluted by a common model |
| Outsourced model | Across delegated providers and retained family authority | Role boundaries, vendor oversight, approvals, and escalation paths | Whether accountability is clear when execution and oversight sit in different hands |
What Makes This Family Office Specific
Family offices are not evaluated like a one-time manager search or generic vendor review. diligence here has to test whether stewardship fit holds under privacy demands, whether reporting fits family decision habits, and whether the office can support long term wealth preservation across generations.
Technical competence alone is not enough. Some families need coordination closer to the oversight of a general partner, while others need tighter visibility across entities, advisers, and family offices acting as long-term stewards. The next test is governance, because authority and accountability should be traceable before any deeper review of investments or operations begins.
Governance and Legal Structure Checklist
Governance comes first. A family office should be able to show who holds authority, which documents define it, and how exceptions are approved without slipping into informal habit. Weak structure can also give a dominant principal or adviser pricing power by making challenge and oversight harder.
- Confirm that current organizational documents, not verbal history, explain the structure.
- Check each decision-maker's role, authority limit, and escalation route.
- Look for separate paths for routine actions, material approvals, and documented exceptions.
- Treat undocumented overrides, unclear fiduciary language, or missing records as signals to pause and investigate.
Entity Structure and Fiduciary Roles
Complexity is manageable. A structure that only makes sense after repeated verbal explanation is not. A credible entity map should show who owns assets, who administers them, who may act in a fiduciary capacity, and where authority sits. If that chain is unclear, tax considerations, tax liabilities, and IP ownership become harder to assign or challenge.
- Request a current entity map for each trust, company, partnership, or holding vehicle.
- Verify that the map matches organizational documents and delegated authority records.
- Check whether fiduciary roles are stated plainly, including who advises, administers, and approves material actions.
- Separate beneficial ownership, management authority, and oversight responsibility rather than blending them into one informal role.
- Ask whether any entity exists for liability segregation, tax considerations, or asset holding, and whether that purpose is documented.
- Flag any structure that needs oral explanation to identify responsibility for decisions, records, or reporting.
- Confirm that role descriptions stay consistent across engagement letters, policy documents, committee materials, and organizational charts.
Authority Approvals and Override Rights
Authority is only credible when approvals follow a visible path. A family office should show who can approve routine spending, bind material contracts, authorize a potential investment or investment opportunity, and trigger higher review. That matters for manager hiring, commitments to private equity funds, and mandate changes tied to an investment thesis, because missing records leave fund managers and principals operating on memory instead of governance.
- Map the approval path for cash movements, manager changes, mandate revisions, and major vendor or material contracts.
- Check whether investment committees review decisions that exceed routine authority or create long-term exposure.
- Confirm that dual controls exist where one person initiates an action and another reviews or approves it before execution.
- Ask how urgent exceptions are handled, and require a documented exception stating who approved it and why.
- Test override rights directly by asking who may bypass policy, under what conditions, and what record is created.
- Review whether thresholds are defined by action type, commitment size, or strategic significance rather than informal seniority.
- Flag any pattern in which verbal instructions from a founder, executive, or senior adviser outrank the documented approval path.
How Governance Checks Differ by Office Type
Governance pressure shifts with the operating model. The questions stay similar, but scrutiny changes with where authority sits.
| Office type | Primary governance pressure point | What to test more closely | Why it matters |
|---|---|---|---|
| single family office | Authority concentrated around a founder, principal, or small inner circle | Whether the entity map, approval path, and override rights still work when one person dominates decisions | Control can speed action, but it can also hide informal approvals and customer concentration with key advisers or vendors |
| Multi-family office | Shared committees and staff serving multiple families | Whether fiduciary roles, reporting lines, and conflict escalation stay clear across clients | Shared infrastructure can blur accountability if responsibilities are not separated cleanly |
| Outsourced office or platform model | Delegated execution without delegated accountability | Whether contracts, reporting, and approvals show who advises, executes, and retains decision authority | The risk is diffusion: limited partners, family members, and outside providers may each assume someone else owns the decision |
The governing standard is simple: authority should be traceable through documents, approvals, and accountability.
Governance Red Flags to Escalate
Some governance gaps are not clerical. They change the credibility of the entire review.
Investment Oversight Checklist
Authority determines who can act. Investment due diligence asks whether those decisions deserve trust. In a family office, that means testing how family office investments connect to mandate fit, disclosed economics, monitoring, and decision ownership. A useful diligence checklist turns financial due diligence into visible checks rather than a narrative.
- Use the investment due diligence checklist to test strategy, liquidity, complexity, and asset class exposure.
- Trace costs so due diligence and the due diligence checklist show fees and incentives in plain language.
- Confirm monitoring uses relevant financial statements and shows what changed after review.
- Identify who recommends, who approves, and what evidence supports the decision if diligence raises questions.
Strategy Mandate and Asset Class Exposure
A strategy can sound coherent and still fail the mandate. The test is whether the portfolio matches objectives, liquidity needs, and downside protection before any asset class or opportunity is justified.
- Test mandate fit against objective, risk tolerance, spending needs, and liquidity profile.
- Check whether any asset class, manager, sector, or geography creates concentration the mandate cannot justify.
- Compare illiquidity with real cash timing, including distributions, tax payments, and reallocation needs.
- Assess complexity only if the office can show why unusual structures or payoff logic earn a place.
- Ask for a valuation policy for hard-to-price holdings and how uncertainty affects decisions.
- Review venture capital and venture capital funds with the same discipline for time horizon and portfolio role.
- Look for explicit exclusions so out-of-scope asset class exposure or deal types are defined in advance.
- If entry discipline matters, ask how purchase price affects expected return and downside protection.
Fee Transparency and Conflict Disclosures
Opaque economics usually point to weak oversight, not merely dense paperwork. Fee transparency means the family can trace every compensation layer without translation, while conflict disclosures should make potential conflicts understandable in plain language instead of burying incentives inside broad legal language. If cost or bias cannot be mapped clearly, the process is harder to trust even when performance sounds strong.
| Category | What the family should see clearly | Why it matters |
|---|---|---|
| Advisory fees | Who is paid, how the charge is calculated, when it is billed, and which entities bear the cost | Shows the true cost of oversight and prevents compensation from disappearing across accounts or entities |
| Manager fees | Underlying management and incentive charges for each external strategy or vehicle | Helps separate gross results from net outcomes and reveals where economics may be layered |
| Transaction or deal costs | Placement, execution, structuring, or other deal-specific charges when applicable | Clarifies whether costs rise with activity and whether they change the attractiveness of the investment |
| Affiliated relationships | Whether the office, adviser, or related parties benefit from recommending a product, manager, or vehicle | Makes conflict disclosures concrete enough to judge incentive alignment |
| Referral or revenue-sharing arrangements | Any indirect payment tied to introducing managers, custodians, lenders, or products | Shows where recommendations may be influenced by compensation outside the visible headline fee |
| Proprietary or preferred product use | When the office favors in-house, affiliated, or repeatedly preferred offerings and why | Reveals whether selection follows mandate fit or a built-in product bias |
The standard is visibility, not volume. A long explanation that still leaves the family unable to say who gets paid and where incentives sit is a control failure.
Manager Review Including Emerging Managers and Co Investment
Manager selection should be evidence-based before it becomes relationship-based. A credible review shows why an investment manager was eligible, how the track record was tested, whether historical performance fits the current mandate, and what triggers deeper review or removal. Emerging managers and co investment opportunities deserve tighter scrutiny because access can hide uneven underwriting.
- Confirm documented eligibility criteria before performance drives the discussion.
- Verify the track record in context, including strategy, decision-maker role, time frame, and market-setting.
- Test mandate relevance. Strong historical performance elsewhere does not automatically support this allocation.
- Review monitoring cadence, including what is reviewed, how often, and what prompts deeper diligence.
- Look for removal triggers so the office can say what breaks confidence and when exposure should be reduced.
- Apply tighter standards to emerging managers because organizational depth and operating proof may be thinner.
- Raise the bar for each co investment by asking why it fits the mandate, who led diligence, and how it will be monitored after closing.
How Investment Checks Differ by Office Type
| Office type | Primary investment diligence focus | Where risk shifts |
|---|---|---|
| Single-family office | Test whether the internal process is strong enough for the scope and complexity it manages | Risk concentrates in discretion, internal challenge, and whether the single family office can prove consistent review without relying on a few trusted individuals |
| Multi-family office | Test suitability across different families, allocation fairness, and whether access and economics are applied consistently | Risk shifts toward cross-client conflicts, uneven opportunity access, and model portfolios that fit the platform better than the family |
| Outsourced office or adviser-led model | Test transparency around manager selection, monitoring cadence, and how outside recommendations are validated | Risk shifts toward black-box selection logic, limited look-through, and weak evidence behind delegated decisions |
Investment Red Flags for Decision Making
Some weaknesses change decision making because they make skill, alignment, and accountability harder to verify.
Operations and Compliance Checklist
Operational diligence tests whether the office can prove what happened when cash moves, access changes, an incident occurs, or a control fails. The standard is not policy polish. It is whether due diligence can trace operational risks through named actions, retained records, and a form of risk management that holds up under pressure.
- Check whether cash flow activity shows who initiated, approved, recorded, and reconciled each material transaction.
- Test whether operational due diligence can reconstruct exceptions, manual workarounds, and access changes without relying on memory.
- Review whether diligence around cybersecurity, screening, and incident handling follows repeatable routines rather than one-time setup.
- Treat unresolved findings, weak vendor oversight, and missing audit evidence as operational risk signals, not administrative gaps.
Internal Controls for Cash Movement and Audit Trails
Cash controls reveal whether discipline is real. Segregation of duties means no one person controls initiation, approval, recording, and reconciliation across the same movement of funds, and the audit trail should let a reviewer reconstruct the sequence quickly, from system evidence rather than explanation after the fact.
- Confirm that each material transaction shows a named initiator, a separate approver, and a reconciler whose review is documented.
- Verify that dual-approval rules exist for sensitive payments, account changes, and wire activity, with exceptions logged and time-stamped.
- Check whether manual journal entries, spreadsheet workarounds, and emergency payment paths require documented rationale and follow-up review.
- Ask whether the office can pull the full support for a sampled transaction, including request, approval, release, posting, and reconciliation, without gaps.
- Escalate immediately when the same person can initiate and approve a payment, when dual approvals are missing, or when unexplained manual entries appear in the record.
Cybersecurity, AML, KYC, and Adverse Media
Security and screening routines matter only when they repeat. A credible incident response process, access-control discipline, and AML KYC adverse media routine should reduce regulatory risk by showing that the office can identify changes, contain problems, and revisit regulatory exposure after onboarding rather than treating compliance as a static file.
- Review access control by role, approval for privilege changes, periodic access review, and prompt removal of dormant or departed user credentials.
- Test incident response through named owners, escalation paths, retained logs, and evidence that the office can show what happened, what was contained, and what changed after the event.
- Check whether AML KYC adverse media screening is refreshed on an ongoing basis for entities, counterparties, and higher risk relationships rather than completed once at onboarding.
- Ask how adverse media review is documented, how alerts are resolved, and who decides whether regulatory exposure requires follow-up or escalation.
- Look for consistency across complex relationships, including private equity firms, VC firms, PE firms, and similar structures where changing counterparties can widen regulatory exposure.
Audit History, Findings, and Remediation
Past findings matter because they show how the office behaves after a weakness is exposed. Remediation is credible only when each issue has a clear owner, a timeline, evidence of completion, and proof that the control now operates differently, especially when the same weakness has appeared before.
- Match each finding to a remediation owner, target date, and current status rather than accepting a general statement that the matter was addressed.
- Look for supporting evidence such as updated procedures, changed approvals, retraining, or retesting that shows the fix moved beyond discussion.
- Treat repeat findings in the same control area as a warning that management may be accepting the weakness rather than resolving it.
- Escalate open findings without visible remediation because the issue is no longer the report. It is the control culture behind it.
Vendor Counterparty and Background Screening
Third-party exposure sits inside the control environment, not outside it. Vendor dependency risk rises when fund administration, banking workflows, data access, or communications move into outsourced hands without parallel oversight. Background screening should test whether those relationships create hidden weaknesses across private markets activity as well as routine operations.
- Identify which vendors or counterparties can move money, access records, handle reporting, or influence instructions, and map the control reliance on each one.
- Review due diligence files for financial stability, control maturity, service continuity, and contract terms that define approval rights, escalation paths, and audit access.
- Check whether outsourced fund administration receives oversight through reconciliations, service reviews, and exception follow-up rather than implied trust.
- Include background screening where a provider or counterparty has meaningful access to assets, information, or private equity workflows.
- Treat concentrated dependence on one administrator, custodian, or specialist provider as a control question, especially when no practical backup exists.
How Operations Checks Differ by Office Type
Control design has to match staffing reality. The same checklist applies across models, but the blind spots differ depending on how much a single family office keeps in-house, how much a multi-family platform standardizes, and how much an outsourced structure delegates to third parties.
| Office type | Typical blind spot | What to test |
|---|---|---|
| Single-family office | Combined duties and informal exceptions around trusted staff | Whether approvals, reconciliations, and access reviews stay separate despite a lean team |
| Multi-family office | Standardized controls that may not fit complex client structures | Whether exception handling, escalation, and screening remain consistent across entities and accounts |
| Outsourced or hybrid office | Reliance on subcontractors, handoffs, and external records | Whether oversight extends through vendors, counterparties, and service-level evidence rather than stopping at the contract |
Operational Red Flags to Escalate
Some control failures should stop the review and force escalation.
People and Succession Checklist
Controls can look sound on paper and still fail when trust, access, and undocumented know-how sit with too few people. In a family office, the management team is part of the control environment, because continuity depends on whether sensitive work can continue without one gatekeeper. That is why human resources diligence belongs beside stewardship review rather than outside it.
- Test whether authority is distributed or concentrated in one relationship holder, approver, or trusted-operator.
- Check whether critical access, family context, and institutional investors reporting-related knowledge are documented well enough for another person to step in.
- Verify that role credibility, screening, and continuity planning support sensitive fiduciary work rather than relying on personal trust alone.
Key Person Dependence and Continuity
People risk becomes material when one individual holds the relationships, approvals, and undocumented judgment that keep the office running. The continuity question is simple: if a key person is absent, does service continue through process and distributed authority, or does it slow until that person returns? A resilient office treats business continuity as an operating design choice, not as a hope attached to loyal key personnel.
- Identify whether each critical function has a named backup who can act during leave, illness, turnover, or conflict.
- Check for written procedures that explain recurring approvals, family preferences, reporting routines, and exception handling.
- Review whether payment, investment, and communication authority is distributed across more than one trusted role.
- Ask whether another qualified person can retrieve records, answer family questions, and keep service stable without informal workarounds.
- Treat continuity as weak when core decisions depend on one person's memory, inbox, or personal relationships.
Credentials History and Background Screening
Titles do not establish trust on their own. The real test is whether professional background, claimed qualifications, and integrity signals match the duties a person actually performs, especially when that role includes discretion over family information, money movement, or fiduciary coordination. Background screening should stay factual and role-linked: confirm what can be verified, review employment agreements for role clarity and retention terms, and use authoritative sources during live diligence rather than assumptions or rumors.
- Match credentials to the actual role so technical designations are relevant to investment, legal, accounting, or operating responsibilities.
- Review the person's professional background for experience that supports the current scope of authority.
- Check employment agreements for duties, restrictions, notice terms, and incentives that affect continuity or conflicts.
- Treat regulatory sanctions, litigation history, or material discrepancies in stated experience as trust issues that require clarification.
- Use background screening to verify identity, work history, and role-fit facts, not to make unsupported accusations.
Succession Planning Beyond One Individual
A named successor is not enough. Succession planning is credible only when the office can show how leadership, investment oversight, operations, and family relationships transfer under defined conditions, with documented handover steps and evidence that the process has been tested. The issue is not whether a replacement name exists; it is whether stewardship can continue without improvisation.
- Confirm emergency backups for essential decision makers and relationship owners.
- Look for transition steps that state who assumes which responsibilities, in what order, and with what approvals.
- Check cross-functional role coverage across leadership, investments, operations, and family communications.
- Verify that succession triggers are defined, such as incapacity, departure, conflict, or retirement.
- Ask for evidence of a documented handover process, including records, contacts, calendars, and pending matters.
- Give more weight to plans supported by drills, walkthroughs, or other tested procedures than to plans that exist only as an org chart.
How People Checks Differ by Office Type
People diligence varies with staffing depth and service design. The same checklist still applies, but the main risk changes from thin bench strength in a single family office to coverage strain across multiple client teams or overreliance on one external relationship lead.
| Office Type | Primary People Risk | What to Check |
|---|---|---|
| Single family office | A small team may concentrate authority, family knowledge, and approvals in too few roles. | Test backup coverage, cross-training, and whether one executive informally carries the office. |
| Multi-family office | Bench depth may look stronger, but staff can be stretched across families or accounts. | Check team capacity, reassignment coverage, and whether service depends on a few senior contacts. |
| Outsourced or adviser-led model | Continuity may rest on one relationship manager instead of institutional process. | Verify documented procedures, team-based coverage, and whether continuity survives staff turnover. |
| Investment-led specialist model, including pe deal teams | Technical talent may be deep in one lane but thin outside it. | Check whether investment expertise is matched by relationship continuity, oversight coverage, and handoff discipline. |
People-Related Red Flags to Escalate
Printable Checklist and Follow-Up Tracker
The work should now become portable. This final tool turns the earlier diligence review into a working record for selection, monitoring, or internal audit without rebuilding the framework each time.
- Use One Line per Checklist Item With a Status Field: acceptable, incomplete, or escalated.
- Place a red-flag marker beside any item that may require deeper review or a pause in the decision.
- Assign a follow-up owner so each open point has clear accountability.
- Add a next action field that states the required document, clarification, or approval.
One-Page Summary Checklist
A compact summary keeps due diligence usable during live review. The goal is not to replace longer due diligence questionnaires, but to distill the core diligence points into a format that supports faster note-taking, clearer comparisons, and consistent escalation.
- Governance: confirm entity structure, fiduciary roles, approval authority, and override rights. Status: ____ | Red-flag marker: Yes or No | Follow-up owner: ____ | Next action: ____
- Investment Oversight: confirm mandate clarity, asset-class exposure, fee transparency, conflict disclosures, and manager review discipline. Status: ____ | Red-flag marker: Yes or No | Follow-up owner: ____ | Next action: ____
- Operations and Compliance: confirm internal controls, cash movement controls, audit trails, cybersecurity, AML and KYC review, audit history, and vendor screening. Status: ____ | Red-flag marker: Yes or No | Follow-up owner: ____ | Next action: ____
- People and Succession: confirm key-person coverage, background screening, credentials review, and succession planning beyond one individual. Status: ____ | Red-flag marker: Yes or No | Follow-up owner: ____ | Next action: ____
- Use the summary as a live diligence questionnaire when speed matters, and keep longer due diligence questionnaires for document-heavy diligence that needs more space.
How to Record Findings and Follow Up
Good diligence workflows depend on a clean decision trail. Each finding should move through the same sequence so open questions, red flags, missing evidence, and final decisions stay visible.
- Capture the issue in plain terms, tied to the checklist line that triggered the review.
- Classify it as an open question or a red flag so the team separates routine follow-up from escalation.
- Assign a follow-up owner who is responsible for collecting the response or document.
- Set a deadline for the next review point so the item does not disappear into fragmented diligence workflows.
- Define the evidence needed, such as a policy, approval record, disclosure, report, or background check result.
- Close the item when the evidence resolves the concern, or escalate it when the gap remains material.
That sequence turns diligence into a repeatable control, not a one-time review.