A due diligence report is a measurement. That framing is worth holding onto, because it explains almost everything about why the standard model of fund diligence quietly stopped working.
Any measurement of a system that changes over time starts to go out of date the moment it’s taken. A thermometer reading is accurate for an instant. A map is accurate until the roads change. And a diligence report is accurate on the day it’s completed, after which it begins, slowly and invisibly, to describe a company that no longer entirely exists.
Point-in-time diligence treats that decaying measurement as a permanent fact. It runs the check, files the report, and behaves as though the answer holds indefinitely. Continuous monitoring treats the same measurement as what it actually is: a reading that needs refreshing, because the thing being measured won’t sit still.
The question worth asking isn’t which of the two is better. They answer different questions, and a serious fund needs both. The question is how fast the first one’s answer expires — and for funds specifically, the answer is: faster than almost anyone realises. This piece works through why, what the alternative actually involves, where the regulators are heading, how to choose a platform, and how to make the change without the usual disruption.
Two questions, not two methods
The “versus” in the title is a little misleading, so it’s worth clearing up before going further. Continuous monitoring and point-in-time diligence are not rival techniques competing to do the same job. They do different jobs.
Point-in-time diligence answers a question about the moment of decision. Is this entity acceptable, right now, as things stand today? That’s the question a fund asks before it wires money, and it’s exactly the right question to ask at that moment.
Continuous monitoring answers a question about every day after. Is this entity still acceptable? That’s a different question, it can’t be answered at a single point in time by definition, and it’s the one most funds have historically had no way to answer at all.
The mistake was never running point-in-time diligence. The mistake was assuming that answering the first question also answered the second. It never did, and the gap between them is where this whole discussion lives.
Where point-in-time diligence came from
The snapshot model deserves a fair hearing, because it wasn’t lazy. It was well matched to the world it was built for.
Go back a couple of decades. Diligence meant pulling corporate filings that were updated once a year, calling a few references, reading a credit report, and checking a name against a short list. The information moved slowly. A snapshot taken in June was still broadly accurate in December, because the underlying facts changed at roughly the speed the filings did, which was to say, not very fast.
In that world, a point-in-time check made complete sense. The metabolism of the data matched the cadence of the review. If a company’s situation shifted, it usually shifted slowly enough that the next scheduled review would catch it before it mattered.
That model didn’t get worse. The world sped up around it. Registries digitised and started updating continuously. News moved from a daily cycle to a rolling one. Sanctions regimes began publishing changes across most weeks of the year. And the entities being diligenced — startups, crypto companies — started changing shape at a speed the old corporates never did. The snapshot stayed exactly as good as it always was. What changed is how quickly it goes stale.
The half-life of a diligence report
Here is a more useful way to think about it, borrowed from the idea of radioactive decay, which turns out to fit surprisingly well.
On the day a diligence report is completed, treat it as fully accurate. It describes the entity as it actually is. From the next day onward, a small probability starts to accrue that some material fact has changed — a director has resigned, the company has redomiciled, a new counterparty has appeared, a founder has been named in a suit, the regulatory classification of the product has shifted. Any single one of these is unlikely on any given day. But the probability compounds, and it never resets.
At some point, enough has changed that the report describes the past about as much as it describes the present. That point is the report’s half-life: the moment its accuracy has decayed to the flip of a coin.
Consider a single portfolio company, and the things that can change about it inside one year. Its directors. Its registered jurisdiction. Its cap table. Its principal banking and settlement relationships. Its key personnel. Its founder’s legal and reputational standing. The regulatory treatment of what it does. Assign each of those even a modest annual probability of changing, and the probability that at least one of them has changed within a few months is already high, because they compound rather than average.
Now scale it. A fund doesn’t hold one company. It holds thirty, or forty, or sixty. The probability that something material has changed somewhere in a portfolio that size, this week, is not high. It is close to certain. Something in the portfolio is almost always out of date with its diligence, at any given moment, and the only open question is whether anyone knows which thing.
The report was accurate when it was written. It is simply, increasingly, a description of the past.
Why funds sit at the steepest part of the curve
Every organisation that relies on diligence faces this decay. What makes funds a special case is that they face the worst version of it, on three axes at once.
The first is the holding period. A fund that takes a position expects to hold it for seven or eight years. Which means the diligence performed at entry has to stay meaningfully accurate for seven or eight years, and nothing else in finance asks a single check to hold for anything like that long. A bank re-verifies. A lender reprices. A fund wires once and holds, and the original report is expected to carry the whole way.
The second is the velocity of the entities themselves. Startups and crypto companies are among the fastest-changing organisations that exist. They pivot, restructure, redomicile, swap out executives, and rewire their cap tables at a rate mature businesses never approach. Corporate registries show how routine this churn is once anyone looks. The subjects of fund diligence change faster than almost any other entities a diligence process is ever pointed at.
The third is the absence of a refresh trigger, and it’s the subtlest of the three. A bank touches a customer’s risk profile every time money moves, so the relationship generates a natural stream of moments to look at again. Sanctions regimes give another external prompt — OFAC and its equivalents publish changes constantly. A fund holding a minority stake has none of that. No money moves through it on the company’s behalf. The position sits silently. Nothing in the ordinary course of the relationship ever forces a fresh look, so unless the fund deliberately builds one, no look happens.
Put those together and the picture is close to a worst case. The longest required accuracy, the fastest-changing subjects, and no natural trigger to refresh. Of all the actors in finance who rely on diligence, funds sit at the steepest point of the decay curve, which is a strange place to be running the lightest-touch version of monitoring.
Why continuous monitoring beats the periodic audit
This argument is not new, and that’s worth saying plainly, because it has already been won somewhere adjacent. The security and compliance world went through exactly this shift a few years ago, moving from annual audits to continuous control monitoring, and nobody seriously wants to go back.
The logic that won there transfers directly. A periodic check tells you the state of things on the day it was performed and stays silent about every other day. If a control failed, or a vendor lapsed, or an entity changed, the day after the audit, the periodic model wouldn’t catch it until the next scheduled review — by which point the problem has had months to compound. Continuous monitoring closes that window. It catches the change when it happens, not at the next calendar checkpoint.
There are three advantages the periodic model can’t match. The first is simply time-to-detection: the gap between a change occurring and someone knowing about it shrinks from months to something much shorter, and in risk, that gap is most of what determines whether a problem stays small. The second is that early detection is cheaper detection — a problem caught as it emerges is almost always less expensive to resolve than the same problem discovered after it has grown. The third is that continuous evidence is simply more credible than a once-a-year snapshot, whether the audience is a regulator, an auditor, an LP, or an internal committee. “We monitor this continuously” is a stronger position than “we checked it last March.”
The one honest caveat is that a periodic audit and continuous monitoring aren’t mutually exclusive, and the strongest programmes run both — the deep periodic review to establish and re-establish a thorough baseline, and continuous monitoring to catch what moves in between. The point is not to abolish the snapshot. It is to stop relying on it alone.
The benefits, stated concretely
Pulling the advantages together, a continuous approach delivers a handful of things a point-in-time model structurally cannot.
Earlier warning, which is the headline. Problems surface while they’re still small and still cheap to deal with, rather than after they’ve had months to grow in the dark between reviews.
A shorter and known detection latency. Instead of an unstated “we’ll find out eventually,” there’s an actual answer to how long it takes to learn that something material has changed — and an owner for that number.
Better evidence. A continuous record of what was known and when it was known is more defensible in front of any scrutineer than a periodic report that describes a single moment now well in the past.
Less wasted effort, counterintuitively. A good continuous system does the watching so people don’t have to, which frees the team from the low-value work of periodically re-checking things that haven’t changed, and points their attention at the few things that have.
And a genuine baseline that improves over time. Because monitoring is anchored to an established picture of each entity, the system gets better at distinguishing normal change from meaningful change the longer it runs against a given portfolio.
Where the regulators are heading
None of this is happening in a vacuum. The regulatory direction of travel has been toward continuous oversight for years, across several domains at once, and it’s worth reading accurately rather than alarmingly.
In financial crime, the principle of ongoing due diligence is long settled. FATF Recommendation 10 expects institutions to conduct ongoing diligence on business relationships, not a single check at onboarding, and the mature expression of that expectation — perpetual monitoring rather than periodic review — has steadily hardened from good practice into assumed practice in regulated finance.
In compliance oversight more broadly, the same shift is visible. Supervisory guidance such as the CFPB’s treatment of third parties treats ongoing monitoring of service providers as a standing component of a compliance programme, not a box ticked at the start. The consistent message across regimes is that a point-in-time check no longer discharges the obligation.
Most venture and crypto funds sit outside the direct reach of these supervisory regimes, and it would be dishonest to imply otherwise. Nobody is going to examine a seed fund next quarter for failing to run perpetual monitoring. But regulation tends to move in one direction on questions like this, and the expectations set for banks have a way of arriving, eventually, as the expectations LPs set for the funds they back. The funds building continuous oversight now are, among other things, getting ahead of a bar that is still rising.
What continuous monitoring actually is
The phrase invites a misunderstanding worth heading off, because it makes the whole thing sound heavier and noisier than it is.
Continuous monitoring does not mean running full diligence over and over, forever. That would be ruinously expensive and would bury the team in repeated versions of information it already had. It is a different activity entirely.
Diligence builds a baseline — a detailed picture of what an entity is at a moment. Monitoring watches for deviation from that baseline, and surfaces only the deviations that matter. The two are not alternatives. They depend on each other. Without the baseline the diligence established, “change” has no meaning, because there’s nothing to measure change against.
So the honest way to describe the relationship is that continuous monitoring completes point-in-time diligence rather than replacing it. The snapshot tells you where things stood. The monitoring tells you when that stops being true. A good monitoring layer has four properties: it’s anchored to the diligence baseline, it’s driven by events rather than by the calendar, it filters hard so that only material change reaches a human, and every signal it raises traces back to a source that can be opened and verified.
How to choose a continuous monitoring platform
If the case for continuous monitoring lands, the next question is what to actually run, and the selection criteria that matter are not always the ones that show up first in a demo.
Coverage matched to the risk, not raw breadth. The relevant question is whether a platform watches the specific things that carry your risk — the right registries, the right sanctions and watchlists, adverse media in the languages and regions your entities actually operate in — not how large a source count it can advertise. Broad coverage of things that don’t concern you is not coverage.
Signal quality above all. The entire value of continuous monitoring is filtering, so the false-positive rate is the number that matters most. A platform that raises hundreds of low-grade alerts will be ignored within weeks, at which point its coverage is irrelevant because nobody is reading the output. Ask directly how much of what it surfaces warrants action.
Source traceability. Every signal a platform raises should link back to a primary source that can be opened and checked. As more tools generate AI summaries, this matters more, not less — an unverifiable conclusion sitting in a file, however confident it looks, is a liability rather than an asset. The right answer to “where did this come from” is a link.
Timeliness. A monitoring tool is only as useful as it is currently. How quickly a change in the world becomes a signal in the platform — hours, days, or longer — determines whether the detection latency you gain is real or theoretical.
Integration with how the team already works. A platform that pushes what matters into the channels the team already lives in will be used. One that requires logging into a separate dashboard nobody remembers to open will not, regardless of how good its detection is.
The broader question of how the various risk and monitoring categories fit together — and which one you actually need — is mapped separately here.
How to make the transition
Moving from a point-in-time model to a continuous one is more a change in operating habit than a single installation, and the way it’s rolled out largely determines whether it sticks.
The sensible first move is to establish the baseline properly, because continuous monitoring measures against it and a weak baseline makes for weak monitoring. For most funds this means a thorough current-state diligence pass on the existing portfolio, so the system knows what “normal” looks like for each entity before it starts flagging change.
Then start narrow rather than switching everything on at once. Picking the highest-risk entities and the most material signal types first — sanctions, ownership changes, adverse media on the companies that matter most — lets the team build trust in the output before the scope widens. A monitoring programme that floods everyone from day one gets muted by week two, and trust, once lost, is slow to rebuild.
Ownership has to be settled before anything is switched on. A signal that reaches nobody in particular reaches no one, so deciding in advance who acts on what, and within what window, is what turns an alert stream into an actual control rather than a noticeboard.
Thresholds should be treated as something to tune continuously rather than set once. Whatever sensitivity is chosen at the start will be wrong in one direction or the other, and the programmes that are still working eighteen months later are the ones whose owners kept adjusting rather than declaring the setup finished.
And the periodic deep review shouldn’t be abandoned in the process. The strongest arrangement keeps a thorough periodic re-baselining alongside the continuous layer — the former to re-establish the full picture, the latter to catch what moves in between. The two reinforce each other; dropping either weakens the whole.
The challenges, and how to handle them
Continuous monitoring has difficulties like anything else, but they’re wildly unequal in importance, so it’s worth spending the space where it’s warranted.
Almost all of it comes down to alert fatigue, and it deserves more than a line because it’s the single most common reason these programs die.
Here’s the shape of it. A tool gets switched on, and the alerts start. For a fortnight everyone reads them, because the thing is new. Then the hit rate settles somewhere low, ignoring an alert turns out to cost nothing, and the channel drifts into the same mental bucket as building-maintenance email. Nobody decides to stop reading it. They just do. And the trap is that it looks like the tool is working the whole time, because technically it is — it’s detecting things nobody is looking at.
The fix isn’t more discipline, because you can’t instruct people out of a rational response to a noisy feed. It’s fewer, better alerts. Severity tiers, hard filtering, and the discipline to leave things unsurfaced even when they could be surfaced. A short channel that’s right most of the time keeps getting read. A comprehensive one that’s mostly noise does not.
The remaining two are real but minor by comparison. A monitoring tool that sits outside the team’s workflow gets bypassed, so signals need to arrive in the tools people already use. And software is not the whole solution — it surfaces and filters, but it can’t own a decision or carry responsibility, so without a response process and named owners, even good monitoring goes nowhere. That last one is more about process than tooling.
What this changes in practice
The shift from snapshot to continuous shows up in a few concrete ways, beyond the tooling.
Diligence stops being a gate and becomes a baseline. The report is no longer the end of the risk process for an entity. It’s the beginning of it — the reference state against which everything afterward is measured.
Detection latency becomes a number the fund actually owns. Instead of “we’ll find out if something comes up,” there’s a stated answer to how long it takes to learn that something material has changed, and someone accountable for it.
Risk review moves off the calendar. Rather than looking at the portfolio once a quarter because the quarter has ended, the fund looks at a specific company because something about it has changed. The trigger becomes the event, not the date.
And the governing question shifts. It stops being “did we diligence them?” — a question about the past, answerable with a filed report — and becomes “what’s changed since?”, a question about the present that a filed report cannot answer at all.
The broader case for why risk doesn’t stop when a deal closes is set out separately in Beyond Onboarding. This piece is the mechanism underneath that argument — not just that risk keeps moving, but how fast, and why funds feel it more than anyone. And for what the decay actually costs when a change goes unnoticed, there’s a full ROI model.
Frequently Asked Questions
What actually matters: does it filter well enough that people keep reading it, does it watch the risks that genuinely apply to you, can every alert be traced to a real source, is it current, and does it reach the team where they already are.
The measurement, and its shelf-life
The snapshot model was never wrong. It was appropriate to a slower world, and it remains appropriate for the one thing it was built to do: judge an entity at the moment of decision. Where it falls short is everything after that moment, and it falls shortest precisely where funds operate — long holds, fast entities, no natural prompt to look again.
Treating a diligence report as a permanent fact was always a small act of optimism. It’s a measurement of a moving target, accurate when taken and decaying from there, and the sensible thing to do with a measurement like that is to keep taking it.
That’s what Beady AI does: it holds the baseline and watches for the changes that matter — across sanctions, adverse media, corporate registries and impersonation — with every signal traced back to its source. Book a session and it will run against a live portfolio, which is the quickest way to see how much has moved since the last time anyone looked.