Beyond Onboarding: Why Risk Doesn’t Stop After the Deal Closes

By Mike North Jul 14, 2026

The wire goes out on a Thursday. Somebody drags the DD folder into an archive directory. The deal memo gets its final version number and stops being opened.

And from roughly that moment, for most funds, risk visibility on that company drops to zero.

Not reduced. Not degraded. Zero. There is no process running. Nobody is looking. If something changes at that company next month, or in March, or in the fourteenth month of the holding period, the fund finds out the way funds usually find out. From the founder, late. Or from somebody else’s lawyer, later still.

Here’s the part worth sitting with. Nobody decided this. There was no partner meeting where someone argued that post-close risk didn’t matter and the room agreed. It simply fell out of how diligence got structured in the first place. DD was built as a gate. You do the work, you clear the gate, the gate is behind you. Whatever happens on the far side belongs to somebody else, or more accurately, to nobody.

Call it the onboarding fallacy: the quiet assumption that the risk profile you diligenced is the risk profile you own.

Your due diligence is probably fine

Let’s be clear about something first, because this argument doesn’t work if it opens by insulting the reader.

Most funds we work with run genuinely rigorous pre-close diligence. Founder background checks. Reference calls that go three degrees out from the obvious names. Entity verification, sanctions screening, litigation history, cap table review, sometimes a forensic look at the tech. Good funds do this well and it catches real things. We have watched deals die at DD for exactly the reasons DD exists.

So the pre-close process is not the problem. It does what it was designed to do.

What it was designed to do is establish a baseline. It answers one question, and it answers it properly: who are we getting into business with, as of today?

Good question. Today is the operative word.

The question due diligence never asks

Because there’s a second question, and almost nobody has built anything capable of answering it. What changes after today, and will we know when it does?

That isn’t a harder version of the first question. It’s a different question. Different cadence, different data, different failure modes, and it needs an entirely different machine behind it.

A fund that answers the first question brilliantly and never asks the second isn’t running incomplete diligence. It’s running complete diligence and then calling that a risk programme, which is a considerably stranger thing to do once you look at it directly.

Seven things you will not find in a data room

Here’s what actually surfaces after close. Seven categories, drawn from what we watch appear across live portfolios.

The founder’s background changes. Not “we missed something.” New events. A lawsuit naming them personally. A prior venture that collapses and spills reputationally onto yours. An undisclosed advisory role at a company that turns out to be a competitor, or something worse than a competitor.

The entity structure drifts. New subsidiaries appear. The company redomiciles. In crypto this is close to routine: raise the round, migrate to BVI or Cayman or the UAE, and the regulatory picture you diligenced is now a picture of a company that no longer exists in that shape. Directors change. Shares move to parties who were never in front of you. Registries like OpenCorporates will show you all of it, if anyone is looking. Usually nobody is.

Sanctions exposure emerges. A counterparty gets designated. A banking partner. A customer. Occasionally an entire jurisdiction. OFAC publishes new designations on a rolling basis, and your diligence was a photograph of a moment that has since moved on.

Counterparty infrastructure fails. The portfolio company’s exchange partner collapses. Its custodian gets sanctioned. Its primary banking relationship evaporates on a Tuesday with no notice. Your position is impaired by something the company itself didn’t do, and there’s a decent chance nobody tells you for weeks.

New investors land on a cap table you already own part of. The next round is somebody else’s diligence process. You are bound by its result and you did not run it.

Impersonation campaigns start. Fake Telegram groups. Cloned X accounts. A spoofed support channel draining users of a product that, on the day you closed, had no users. You could not have diligenced this. There was nothing there to diligence.

The rules change underneath a product that didn’t. A token gets reclassified. A service becomes a money services business in a jurisdiction where it wasn’t one last year. The company did nothing at all. The perimeter moved.

An example, because the abstraction slides past

A fund closes a seed round into a payments company in February. Clean diligence. Nothing on any list, no red flags anywhere in the file.

In September the company signs a settlement partnership with a regional exchange. The exchange is entirely fine in September. In January the exchange’s principal shareholder is designated, and the company’s fiat rail is now a live compliance problem sitting inside a portfolio company that the fund has not formally examined in eleven months.

Nothing in the February data room could have shown this. The partnership hadn’t been signed. The designation hadn’t happened. Every single person involved did their job correctly.

The argument that closes the door

Look again at three of those seven. Sanctions designations. Impersonation campaigns. Regulatory reclassification.

None of them are diligence failures. They cannot be, because at the moment diligence was performed they had not happened.

This is the whole case, and it deserves to be said bluntly. You cannot diligence an event that does not yet exist. No amount of pre-close rigour catches a designation that lands in month fourteen. Not a better analyst, not a better data vendor, not a longer diligence window. The event was not there to be found.

Which leaves exactly one thing that catches it. Something that is still looking in month fourteen.

That’s it. That’s the argument.

Banking sorted this out about twenty years ago

None of this is a new idea. It’s just new to venture.

In regulated finance, ongoing customer due diligence is settled doctrine. FATF Recommendation 10 is explicit that financial institutions are expected to conduct ongoing diligence on business relationships, not a single check at onboarding. EU AML directives codify the same principle. The industry even has a term for the mature version of it, perpetual KYC, complete with vendors, frameworks and a reasonably developed body of practice.

Banks did not arrive here voluntarily. Regulators dragged them, over roughly two decades, at considerable expense and with a great deal of complaining.

And now the honest part, which can be stated carefully, because getting it wrong would undermine everything above. Most venture and crypto funds are not currently subject to those requirements. You sit largely outside that perimeter. Nobody is going to fine you next quarter for failing to monitor a portfolio company.

The point isn’t that you’re required to. The point is that the doctrine exists next door, it exists for reasons that map almost perfectly onto your situation, and the absence of an enforcement officer is a poor reason to conclude the reasoning is wrong.

The thing venture is missing is a name

A compliance function in a bank knows exactly what pKYC means. What it costs, what it’s for, who owns it, what happens when it fails.

Venture has no equivalent term. Which means it has no equivalent conversation. Which means the gap never gets budgeted for, because nobody has articulated what the gap actually is.

So call it perpetual due diligence, and mirror the structure deliberately. Legibility is the point.

Operationally it comes down to three things. Continuous screening across the same categories your DD already covers, running indefinitely rather than once. Escalation triggered by events rather than by the calendar, because risk has never respected a quarter boundary. And a named owner with a defined response path, because an alert nobody owns is a note, not a control.

That isn’t a heavy lift. It’s mostly a decision.

The perimeter is moving anyway

There’s a version of this argument that ends with “and one day the regulator will come for you,” and I don’t much like it, because it’s both true and cheap.

But the direction of travel is real and worth reading accurately. LP operational diligence questionnaires increasingly ask about ongoing portfolio oversight, not just initial screening. ILPA’s due diligence framework has steadily expanded what allocators expect funds to demonstrate. Crypto-specific AML expectations are tightening across most major jurisdictions, and the annual Chainalysis crime reports make it fairly clear why. Funds are not always as far from the perimeter as they assume they are.

Funds that build this now build it on their own terms, at their own pace, at a cost they control. Funds that wait build it against a deadline, under pressure, badly. That’s not a prediction about regulation. It’s just what happens to any operational capability that gets deferred long enough.

So what’s actually being claimed here

Worth being precise, since it would be easy to overreach.

Nobody is saying pre-close diligence is worthless. It isn’t, and funds that do it well should carry on doing it well. Nobody is saying every portfolio company needs daily surveillance. Most don’t, and pretending otherwise is how you end up with a monitoring programme nobody reads.

The claim is narrower than that, and harder to shake once you’ve seen it. The gate model is a category error. Due diligence isn’t a door you walk through once. It’s a position you hold, for as long as you hold the asset. Everything else follows from that.

If you want to see what that looks like against real holdings rather than an argument, Beady AI runs a look-back: take your current portfolio, and show what has moved since each deal closed. Book a session and we’ll run it on your actual companies. In our experience the answer is never “nothing,” which is either reassuring or not, depending on how you feel about surprises.

Mike North
Ceo and Cofounder of Company Name

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Mauris tincidunt vulputate efficitur. Pellentesque nec massa sed ante pharetra elementum. Phasellus ac ante vitae quam ultricies tincidunt ac vel odio.

Lorem ipsum dolor sit amet

Lorem ipsum dolor sit amet, consectetur adipiscing elit.

    Lorem ipsum dolor sit amet

    Lorem ipsum dolor sit amet, consectetur adipiscing elit.

    Ready to get started?

    Helping you go live in days, not weeks.