All posts

Perspectives

Can AI Do Due Diligence? Where Human Review Still Wins

Chris Stefaner11 min read
Can AI Do Due Diligence? Where Human Review Still Wins

Yes, AI can do parts of due diligence. It can search a controlled document set, extract clauses and figures, compare repeated items, summarise evidence and keep a review workflow moving. It cannot decide whether a finding changes the investment thesis, negotiate the risk allocation or accept responsibility for recommending that an investment committee proceeds. That distinction is already visible in the market: Deloitte's 2026 Generative AI in M&A Pulse Study reports that 90% of surveyed organisations currently use AI in M&A, while identifying human review as the leading requirement for high-stakes use.

So, can AI do due diligence end to end? No. A defensible operating model treats AI as an analysis and workflow layer inside a human-led process. The human team still defines scope, tests contradictory evidence, decides materiality and signs its name to the conclusion. The same governance applies to cost: faster analysis can create more follow-up work, and diligence budgets still overrun when that expanding scope is not priced until the invoice arrives.

Key Takeaway

AI can accelerate document analysis and workflow administration in due diligence, but it cannot own judgement, negotiation or accountability. Human reviewers must define the question, verify source-grounded outputs, decide what is material and approve any resulting change in scope or deal terms.

What can AI do in due diligence?#

AI can perform bounded, repeatable diligence tasks where the source universe and required output are clear. It is strongest as a first-pass analyst and workflow assistant, not as the final decision-maker.

Document analysis is the obvious use case. A purpose-built system can classify files, extract renewal dates and change-of-control clauses, compare policy language, find exceptions in a contract population and return answers linked to the underlying text. In financial and operational workstreams, it can help map accounts, detect anomalies, compare management data with defined benchmarks and organise questions for the quality-of-earnings (QoE) team. These are valuable capabilities because they reduce search and transcription work. They do not establish whether a clause is enforceable, whether an anomaly is benign or whether a customer concentration risk should change price.

Workflow assistance is a separate job. AI can group duplicate questions, draft a request list, route an issue to an owner, flag an overdue response and produce a first-pass status summary. The distinction matters because a VDR, project-management tool and diligence cost tracker each govern a different object. Adding AI to any one of those tools does not make it responsible for the entire diligence process.

Deloitte's 2025 GenAI in M&A Study, based on 1,000 senior US corporate and private-equity leaders, found that 35% of organisations in the active-use phase applied GenAI to due diligence. The figure is adoption evidence, not proof of accuracy or better investment outcomes. It also combines many different use cases under one label, from document support to benchmark analysis.

The cleanest test is reversibility. If a reviewer can inspect the source, correct the output and rerun the task without having committed the buyer, AI is a sensible candidate. If the output commits capital, changes the SPA, waives a condition or narrows the investigation, a named human should own it.

Where does AI due diligence still fail?#

AI due diligence still fails where context is incomplete, sources conflict or materiality depends on the buyer's thesis. The dangerous output is often not nonsense; it is a fluent answer that is almost right and difficult to challenge under time pressure.

Legal research offers a useful warning, although it is not a like-for-like benchmark for reviewing transaction documents. In Hallucination-Free? Assessing the Reliability of Leading AI Legal Research Tools (2025), Stanford researchers Varun Magesh, Faiz Surani, Daniel E. Ho and colleagues tested proprietary retrieval-augmented systems on a preregistered set of more than 200 open-ended legal queries. The three systems returned answers that were both correct and grounded at materially different rates:

Correct and grounded answers in a legal AI benchmark

Source: Magesh, Surani, Dahl, Suzgun, Manning and Ho, Journal of Empirical Legal Studies, 2025

The chart does not say that an M&A contract-review tool will achieve those rates. The tested products, queries and 2024 model versions are specific, and the systems will have changed. It does show why retrieval alone is not a control: an answer may cite a real authority that does not support the proposition. Daniel E. Ho, Stanford RegLab director and senior author, and his co-authors therefore frame professional supervision and verification as an unresolved responsibility, not an optional final polish.

Three failure modes deserve explicit controls:

  1. Missing context. A model sees the data room, but not the chair's risk appetite, the deal team's prior interactions with management or the strategic reason the buyer can tolerate one risk but not another.
  2. False completeness. A polished summary can obscure absent documents, inconsistent definitions or evidence that never entered the retrieval set. “No issue found” is not the same as “the evidence was complete”.
  3. Automation bias. Reviewers may check an AI-produced conclusion less rigorously because it looks structured and cites sources. Time saved in first-pass review can be lost if the second pass becomes a rubber stamp.

Erik Dilger, managing director and US lead for Deloitte's end-to-end M&A GenAI work, makes the operating requirement concrete in AI in M&A: Where art and science meet: humans should validate results, conclusions should remain traceable to original data and review should be regular rather than ceremonial. That is a stronger standard than placing “subject to human review” in a policy and leaving the review step undefined.

Why does human review still win in M&A?#

Human review wins where due diligence becomes a judgement about consequence rather than a search for information. A reviewer must decide whether evidence is reliable, what it means for this buyer and who will defend the decision later.

Materiality is contextual. The same customer termination right could be tolerable for a strategic buyer with replacement volume and fatal for a sponsor underwriting stable recurring revenue. The same working-capital anomaly may be a cut-off error, evidence of aggressive accounting or a seasonal feature already reflected in price. AI can surface the evidence and propose hypotheses. It cannot know which commercial trade-off the investment committee has authorised unless humans first express that trade-off as a rule, and many of the hardest calls cannot be reduced to a rule without losing what makes them hard.

Accountability is also indivisible. The legal lead owns the advice on contractual exposure. The financial diligence partner owns the QoE conclusion. The deal lead owns the recommendation to proceed. A model cannot be cross-examined on which contradictory document it trusted, asked to negotiate a warranty or held to an engagement letter. Human reviewers therefore need a visible chain from source, to finding, to judgement, to decision.

The National Institute of Standards and Technology's Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (2024) gives this principle an operational form. It calls for differentiated human-AI roles, proportionate independent evaluation, acceptable-use policies and oversight across the system lifecycle. For a deal team, that means naming the reviewer and approval right before the first prompt, not after a contentious finding appears.

That human layer is not a defence of manual drudgery. It is an argument for directing scarce expert time towards contradiction, materiality and negotiation. The point of due diligence automation is to move the professional up the judgement stack, not to remove the professional from it.

How should a deal team govern AI-assisted diligence?#

A deal team should govern AI-assisted diligence by assigning each use case a source boundary, an accountable reviewer and a decision limit. The control should follow the risk of the task, not the novelty of the technology.

Start with a use-case register rather than a vendor feature list. For each task, record the approved data sources, expected output, known failure mode, reviewer and action the output may trigger. A contract-clause extraction can generate a review queue. It should not amend the risk register without approval. A financial anomaly detector can propose a QoE question. It should not label revenue unsustainable or change the valuation model on its own.

Require evidence at the point of use. Every factual output should link to the page, cell or record that supports it; reviewers should test both the claim and whether the retrieved source is the right source. Sample testing should deliberately include awkward cases, such as amendments, scanned schedules, conflicting definitions and documents from the wrong jurisdiction. Easy documents prove very little.

Separate approval rights from workflow rights. An AI system may create a task or draft a question, while the workstream lead approves its release. A workstream lead may validate a finding, while the deal lead or IC retains authority over materiality, scope and capital. This is the same discipline used when multiple diligence advisors need one accountable owner across workstreams.

Finally, log the downstream work. AI can increase coverage and identify more exceptions, which is useful, but each exception can create advisor hours. The team should route additional investigation through a priced diligence change-request process, with a decision to approve, decline or descope elsewhere. Speed without scope governance can accelerate the budget in the wrong direction.

What does AI change about diligence cost and scope?#

AI changes the shape of diligence cost, but it does not remove the need to control it. Search and extraction may become cheaper while verification, exception handling and specialist follow-up expand.

That shift can make a fixed fee misleading. An engagement letter priced around manual sampling may no longer fit a tool that reviews the full population and produces a longer exception list. Conversely, a time-and-materials workstream may consume fewer junior hours but more senior review. Deal leads should agree which efficiency benefits flow to the buyer, what constitutes an out-of-scope query and how validation time will be charged before the work starts.

Advilink sits only on this cost-and-scope side of the process. It does not analyse documents, draft diligence output or score transaction risk. It is designed to hold the agreed advisor scope beside committed and actual spend, so the deal lead can see whether AI-generated follow-up is changing the run-rate and carry that explanation into an IC-ready diligence cost report.

The next maturity test for AI in diligence will not be how quickly a tool produces a summary. It will be whether a deal team can reconstruct, six months after signing, which evidence the system used, which professional challenged it, which scope change followed and who approved the final call.

Frequently Asked Questions#

Can AI replace due diligence professionals?#

No. AI can replace parts of the search, extraction, comparison and administration workload, but professionals still test the evidence, judge materiality, negotiate consequences and remain accountable for the advice. The strongest model is supervised augmentation, not unsupervised substitution.

What due diligence tasks are best suited to AI?#

Bounded, repeatable tasks with inspectable sources are the best fit: document classification, clause and figure extraction, duplicate-question detection, comparison against defined criteria and first-pass summaries. Each output should cite its source and enter a human-owned review queue before it changes scope or informs a deal decision.

Why is human review necessary in AI due diligence?#

Human review is necessary because a grounded answer can still omit context, rely on the wrong source or misjudge what matters to a particular buyer. A named reviewer must validate the evidence and own the consequence, especially for legal exposure, QoE adjustments, valuation and the recommendation to proceed.

Does due diligence automation always reduce cost?#

No. Automation may reduce first-pass review time while increasing document coverage, exceptions and specialist follow-up. Deal teams need to track the resulting change requests and committed advisor spend against the original workstream scope, or faster analysis can simply make scope drift happen faster.

Sources#

  1. 2026 Generative AI in M&A Pulse Study. Deloitte, 2026. Current adoption and the continuing requirement for human review in high-stakes M&A use.
  2. 2025 GenAI in M&A Study — Deloitte, 2025. Survey of 1,000 senior US corporate and private-equity leaders; active use across the M&A lifecycle.
  3. Hallucination-Free? Assessing the Reliability of Leading AI Legal Research Tools — Varun Magesh, Faiz Surani, Matthew Dahl, Mirac Suzgun, Christopher D. Manning and Daniel E. Ho, Journal of Empirical Legal Studies, 2025. Preregistered evaluation of proprietary retrieval-augmented legal research tools.
  4. Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile — National Institute of Standards and Technology, 2024. Guidance on human-AI roles, evaluation, acceptable use and oversight.
  5. AI in M&A: Where art and science meet — Erik Dilger, Deloitte, 2025. Human validation, source traceability and governance controls for AI-supported deal work.

Bring cost discipline to diligence

Advilink helps deal teams budget advisor work, track it against scope, and produce IC-ready cost reporting without the manual chase.

Book a 20-minute walkthrough