State of M&A Data Rooms — Q2 2026 Read the report →

LP Operational Due Diligence (2026): What Institutional LPs Actually Test — and How Managers Pass

Co-founder at Peony. Former M&A at Nomura, early-stage VC at Backed VC, and growth-equity / secondaries investor at Target Global. I write about investors, fundraising, and deal advisors from the deal-side perspective I spent years in.

LP Operational Due Diligence (2026): What Institutional LPs Actually Test — and How Managers Pass

I'm Sean Yu, co-founder of Peony, and I spend most of my days around managers raising institutional capital and the allocators writing the checks. Today 6,800+ customers run their rooms on our platform, and one moment repeats until it is almost a rite of passage for an emerging manager. The investment team at a pension or endowment loves the strategy, everyone is talking close dates, and then a second team you have barely spoken to, the operational due diligence team, sends a 250-question list and schedules an "operational" call. That team is not evaluating whether you will make money. It is evaluating whether the firm can be trusted to hold, value, and account for capital without losing it to something unrelated to the investment thesis. And at most institutional allocators, it can veto the commitment the investment side wants to make.

Quick answer: LP operational due diligence (ODD) is the institutional limited partner's review of a fund manager's non-investment machinery — back office, controls, service providers, valuation governance, compliance, cash handling — run by a separate team that typically holds an independent veto over the investment team. It runs on the ILPA Due Diligence Questionnaire (DDQ 2.0, released November 2021). The load-bearing tests: the fund administrator's SOC 1 Type II (financial-reporting controls, not SOC 2); a written valuation policy with a committee and ASC 820 Level 1/2/3 discipline; the custody rule audited-financials exception (audited GAAP financials to investors within 120 days of year-end, 180 for funds of funds); Form ADV and Form PF; the side-letter and MFN register; and the ODD call, where analysts reconcile every document against every other. Our DDQ post owns the questionnaire contents; this post owns the process.

Last updated: August 2026


I run Peony, a data room company, so let me put the bias on the table and then argue from workflow. Nothing in the substance below depends on whose software you run — the veto structure, the SOC report you ask the administrator for, the custody-rule mechanics, the valuation-governance tests, and the shape of the ODD call are the same whether you stage documents in Peony, a competitor's room, or a shared drive you will regret. Where the product fits, kept to one section, is the last mile: staging disclosure of the sensitive items an ODD team demands, and seeing what the reviewer actually read. This is written for the emerging GP facing a first institutional ODD, the fund CFO or COO assembling the document inventory before the questionnaire lands, the allocator-side analyst building a test framework for a sub-$500 million manager, the compliance consultant scoping a remediation, and the IR lead running the process without it stalling. The question is not "what is ODD" in the abstract — it is what the team tests, in what order, and what a passing answer looks like.

What is LP operational due diligence, and how is it different from investment due diligence?

LP operational due diligence is the review an institutional limited partner runs on the manager's operations — everything that is not the investment thesis — to decide whether the firm can safely custody, value, and account for the capital it is being trusted with. Investment due diligence asks a different question: will the strategy make money? The two are run by different teams at most institutional allocators, and the separation is the whole design: if one team both fell for the returns and cleared the operations, return-chasing would override control problems every time. Splitting the function means an operational finding can stop a commitment the deal team wants — and at most allocators it does, because the ODD function carries an independent veto that reports through a COO, a CRO, or a risk committee rather than the deal partner.

A disambiguation that trips people up: "operational due diligence" names two different exercises. One is the LP-on-manager review this post is about. The other is a buyer's review of a target company's operations in an M&A deal — the people, processes, and systems audit an acquirer runs on a business it is buying, which has its own full treatment in our operational due diligence guide. If you landed here looking for the 8-system audit of an acquisition target, that is your post. Everything below is the fund version — and the reason it matters is that emerging managers routinely rehearse the investment story and treat the operational questionnaire as a formality for IR to handle the week it arrives. Passing the investment review is necessary but not sufficient: a second gate exists, its reviewers are looking for reasons the firm cannot safely hold money, and it does not care how good the returns look.

Does the ODD team really have veto power over the investment team?

At most institutional allocators, yes — and understanding why reframes how a manager should prepare. The ODD function is deliberately placed outside the investment team's reporting line so an operational finding can override an investment decision. The deal partner who wants the allocation does not get to overrule the analyst who found that the fund administrator is a two-person shop with no SOC 1, that the auditor is not PCAOB-registered, or that one person can initiate, approve, and reconcile a wire. Those are decline-grade findings at a serious allocator, not repricing items.

I want to be careful about numbers, because this is the kind of claim that attracts a fabricated statistic — "X% of allocations are vetoed on operational grounds," cited with a confidence the data does not support. So state it as what it is: an established convention among large allocators that a meaningful share of otherwise-attractive managers get declined or deferred on operational grounds, without a manufactured percentage. What is not in dispute is the structural fact — the veto exists, it is independent, and it is real. For the allocator-side reader building an ODD program for smaller managers, the corollary from the other chair is that the defensible pass/fail line is not "are the returns good enough to tolerate some operational mess," but whether the firm's controls, service providers, and governance clear a floor that protects capital regardless of performance — which means distinguishing the gaps that compensating controls can close from the ones that cannot.

What is the ILPA DDQ, and how do LPs use it in ODD?

The ILPA Due Diligence Questionnaire is the standardized question set the Institutional Limited Partners Association publishes so allocators do not each build a bespoke questionnaire and managers do not answer a hundred mutually incompatible formats. The current version is ILPA DDQ 2.0, released November 1, 2021. Its sections span the firm and its ownership, investment strategy and process, the team, the track record, fees and economics, compliance and conflicts, valuation and reporting, operations and service providers, and dedicated ESG and diversity modules — the ESG section draws on the PRI Responsible Investment DDQ. Allocators rarely send it unmodified; most layer 30 to 60 house-specific questions on top. But it is the floor, and — this is the part that matters for ODD — the operations-and-service-providers, valuation-and-reporting, and compliance sections are precisely the ones the operational team owns.

I am not going to reproduce the ILPA question bank here, because we have a dedicated home for it: our due diligence questionnaire guide carries the full LP-to-GP template contents, the five-workstream question banks, and the green/yellow/red scoring rubric an allocator uses to band each answer. What this post covers is the layer above the questions: the process the questionnaire sets in motion. A DDQ answer is a claim; ODD is the discipline of verifying it — tying "our administrator strikes NAV monthly under a written policy" to an actual SOC 1 Type II, an actual valuation policy, and actual committee minutes — then pressure-testing it live on the call. And because the best LP DDQs do not die at close but become the ongoing annual monitoring framework, your first response is the master version of a narrative that gets re-checked against reality every year you hold that LP's capital.

SOC 1 vs SOC 2 for the fund administrator: which report, and why?

For the fund administrator, the report an ODD team asks for is the SOC 1 Type II, and the reason is precise. A SOC 1 report covers controls at a service organization relevant to user entities' internal control over financial reporting — and the administrator's core job (striking the NAV, keeping the fund's books, processing subscriptions and redemptions, calculating management fees and carried interest) is exactly that financial-reporting machinery. SOC 1 is governed by the SSAE 18 attestation standard (section AT-C 320), and an independent CPA firm performs the examination.

The Type I versus Type II distinction is the difference between a design opinion and an operating opinion. A Type I opines only that the controls were suitably designed at a single point in time; a Type II tests whether they actually operated effectively over a period, usually six to twelve months. A Type I says the controls looked right on one day; a Type II says they worked for a year. Insist on the Type II.

Where does SOC 2 come in? A SOC 2 report reports against the Trust Services Criteria (security, availability, processing integrity, confidentiality, privacy) and is the right question for a technology or data provider, not the entity that computes your NAV. The manager's own software stack, or a third-party investor-portal vendor holding LP personal data, is where a SOC 2 belongs. The clean rule: SOC 1 Type II for the administrator, SOC 2 for the tech and data layer. Accepting a SOC 2 in place of a SOC 1 from a NAV-striking administrator is a category error a sharp analyst catches.

One mechanic separates prepared managers from unprepared ones: the bridge letter (or gap letter). A SOC 1 report covers a fixed period that almost never ends on your commitment date. If coverage ends, say, three months before an LP's diligence, the LP asks for a bridge letter in which the administrator's management represents that no material control changes occurred between the report's end date and the current date. Having it ready looks mature; a missing or evasive bridge letter is itself a finding.

What does an ODD team test on valuation governance?

The ODD team tests whether valuation is a governed process with independence built in, rather than a number the portfolio manager can set unilaterally. It is one of the highest-weighted sections of the review, because valuation is where a manager's incentives and an LP's interests diverge most sharply — an optimistic mark flatters performance, inflates carry, and can mask a problem for quarters. The artifacts they want, in order:

  • A written valuation policy specifying the methodology per asset type — how public and private positions are priced, what inputs feed each, and how often marks are refreshed.
  • A valuation committee with defined membership, a quorum, and a documented cadence, whose minutes show it actually challenges marks rather than rubber-stamping the PM's numbers.
  • ASC 820 fair-value-hierarchy discipline. ASC 820 sorts inputs into three levels: Level 1 is quoted prices in active markets for identical assets; Level 2 is observable inputs other than quoted prices (comparable transactions, similar-asset quotes); Level 3 is unobservable inputs, where most private-equity, venture, and private-credit holdings live. Level 3 is the judgment zone, and it is where the team looks hardest.
  • Independent checks on the hard marks — a third-party valuation firm for the Level 3 positions, and a year-end auditor who signs off on fair value. The real question: who, other than the person whose bonus depends on the mark, verifies it?

Side pockets — segregated illiquid positions carved out from the main portfolio — get probed for how they are valued and disclosed, because they are a natural hiding place for a stale or generous mark. And the regulator reads the same territory: the SEC's FY2026 examination priorities, published November 17, 2025, emphasize the fair valuation of illiquid assets — particularly in volatile markets — alongside fees, expenses, and conflicts that disadvantage limited partners. When the SEC and the LP's ODD team read the same part of your firm, a real policy with minuted committee meetings and a third-party valuer for the Level 3 book is the pass condition; a one-paragraph "policy" and a committee of one is a documented failure, and remediation means building those exact artifacts.

How does the custody rule apply to a private fund, and what is the audit exception?

The starting point is the SEC custody rule — 17 CFR 275.206(4)-2 — which governs how a registered investment adviser with custody of client assets must handle them. The default regime is demanding: assets held with a qualified custodian (a bank, a registered broker-dealer, a futures commission merchant, or an eligible foreign financial institution), account statements to clients, and an annual surprise examination by an independent accountant. Almost no private fund runs the default regime, and it matters why.

Private funds rely on the rule's audited-financials exception for pooled investment vehicles. If the fund distributes audited financial statements — prepared under U.S. GAAP by an independent public accountant registered with and subject to inspection by the PCAOB — to all investors within 120 days of fiscal year-end, the adviser is relieved of the account-statement and surprise-examination requirements; the audit substitutes for the surprise exam. The deadline stretches for stacked structures: 180 days for a fund of funds, and 260 days for a "top-tier" fund that invests into funds of funds — extensions the SEC staff granted through no-action relief on top of the rule text's 120-day baseline, reflecting that the upper fund's audit cannot finish until the underlying audits land.

What the ODD team verifies against the rule is specific and checkable:

  1. A qualified custodian genuinely holds the assets. Self-custody is a bright red flag; the analyst wants custodian confirmations, not assurances.
  2. The auditor is PCAOB-registered, not merely a licensed CPA firm. The exception only works with a PCAOB-registered, PCAOB-inspected auditor — a local accounting firm that lacks that registration voids the manager's reliance on it.
  3. Audited financials have historically gone out on time. A pattern of late audits — investors receiving GAAP financials well past the 120-day (or 180-day) mark — signals an under-resourced back office or an audit struggling to close, and either reads as operational risk.

A manager who custodies with a real qualified custodian, audits with a PCAOB-registered firm, and has a clean history of on-time audited financials passes almost automatically; one who is fuzzy on any of the three has just told the ODD team where to dig.

What does an LP read in the manager's Form ADV and Form PF?

For a registered adviser, the ODD team reads the Form ADV before the call as the independent public baseline against which everything the manager says gets checked. Two parts do the work. Part 1 is structured regulatory data — assets under management, ownership and control persons, regulatory footprint, disciplinary history. Part 2A, the brochure, is the plain-English narrative: how the firm makes money, its fee schedule, its conflicts, and — in the disciplinary-information item — any legal or regulatory events. The analyst reads it less for content than for consistency: does Part 1's AUM reconcile to the deck and the DDQ, does the 2A fee narrative match what the LP is quoted, does the conflicts disclosure match the call? Divergence between the ADV and everything else is one of the most productive threads an ODD team pulls.

Form PF is the confidential systemic-risk filing larger private-fund advisers make to the SEC. LPs do not receive it, but the ODD team will ask whether the manager is required to file, whether it does, and whether it is prepared for the amended Form PF requirements; a manager who cannot speak fluently to its own filing obligations has revealed a compliance-function gap. Beyond the forms, the team asks for the compliance manual, the code of ethics, and the personal-trading policy, including how employee trades are pre-cleared and monitored, because a firm's ability to police its own people is one of the cleanest reads on its control culture. A code of ethics that exists only as an unread PDF is a different signal from one with a functioning pre-clearance process behind it.

Are side letters and MFN clauses part of operational due diligence?

Yes — and it is a review item that gets skipped more than it should, which is why a thorough ODD and legal review makes a point of it. Side letters are the individually negotiated agreements that grant particular LPs terms the main fund documents do not: fee discounts, co-investment rights, enhanced reporting, excuse or exclusion rights, key-person provisions, transfer flexibility. They matter for two reasons that are easy to underestimate.

First, the most-favored-nation (MFN) mechanism turns a stack of bilateral deals into an interlocking system: an MFN clause lets qualifying LPs elect terms other investors negotiated, so a favorable term granted to one LP can propagate to others. The package is a connected web, not a set of private one-offs, and the manager has to run the election cleanly. The menu of electable terms is typically tiered by commitment size — a larger commitment unlocks a broader set — and the carve-outs (terms not subject to MFN, often the most bespoke) have to be defined and defensible.

Second, the operational question underneath it all is whether the manager can actually track and honor what it has signed. A reviewer who asks for the side-letter register and receives a folder of un-versioned Word files, with no single source of truth for which LP holds which entitlement and which terms are MFN-electable, has found a genuine weakness — because a manager who cannot keep its own obligations straight will eventually breach one. The fix is a clean, current register of every term and MFN entitlement, and disclosure discipline: side letters are among the most sensitive documents in the fund data room and should sit behind their own access gate. Thinner ODD write-ups skip side letters entirely; a real review does not, because the terms one LP negotiated can bind the fund's economics toward every other.

What actually happens on the ODD call?

The ODD call is a structured working session, usually one to three hours, and it is worth walking through end to end because it is the part of the process most managers picture least clearly. On the allocator's side: the ODD analysts, frequently supported by an outside ODD consultant the LP retains for exactly this. On the manager's side: the COO, CFO, and CCO, often with the head of IR, and pointedly not the portfolio manager as the center of gravity — this is not an investment discussion, and a firm that sends the PM to answer operational questions has misread the meeting. A representative agenda walks the operating model in blocks:

  1. Firm structure and segregation of duties — the org chart, who does what, and where roles are split so no one person controls a full transaction cycle.
  2. Service providers — the fund administrator (and its SOC 1 Type II), the auditor, the custodian, legal, and the technology stack.
  3. NAV and valuation — the valuation policy, the committee, and how specific hard-to-value positions were marked.
  4. Cash controls — wire procedures, dual authorization, and callback verification.
  5. Compliance — the compliance manual, the code of ethics, personal trading, and the Form ADV story.
  6. Technology and cybersecurity — access controls, data protection, and incident response.
  7. Business continuity — what happens to operations if the office, a key person, or a critical system goes down.

The heart of the call is reconciliation. The analysts arrive holding the DDQ answers, the Form ADV, the audited financials, and the service-provider reports, and they work the seams between them: why the ADV reports an AUM the deck does not, why the administrator's SOC 1 period ended four months before the audit date and where the bridge letter is, how a specific Level 3 position was valued and who checked it. The manager with every referenced document staged and access-controlled turns each into a thirty-second answer and a link; the one who has to go find things turns the call into a run of "we'll follow up on that," which is how a two-week process becomes a two-month one.

Afterward the team writes a memo that lands in one of three places. A clean pass: operations clear the floor and the commitment proceeds. A conditional pass contingent on remediation (fix the concentration-of-duties gap, formalize the valuation committee, engage a third-party valuer, tighten the callback procedure), usually with a re-review. Or a decline, when a finding is severe enough that no reasonable remediation closes it in time. For emerging managers the conditional-pass-with-remediation path is common and is not a rejection; it is a punch list, and clearing it cleanly and quickly is often what converts the commitment. The biggest lever a manager controls over which outcome they get is how reconcilable their documentation is when the call starts.

How do LPs test track-record integrity in ODD?

Operational due diligence tests whether the track record is real and consistently presented — a controls question wearing a performance costume. The team is not re-underwriting the strategy; it is checking that the marketed numbers can be trusted and tie to independent records. Three exercises carry the weight.

Gross-to-net reconciliation. The analysts walk the bridge from gross returns to the net returns an LP actually earns, confirming management fees, carried interest, fund expenses, and any fee offsets are all reflected — and that the net figure is not quietly flattering. A net number that cannot be rebuilt from the gross number and the fee terms is a reconciliation problem, and reconciliation problems are control problems.

Deck-versus-audited-financials tie-out. Performance figures in the pitch have to reconcile to the audited financial statements and the administrator's records. The audited financials — signed by a PCAOB-registered auditor — are the independent anchor; the deck is marketing. Where they diverge, the audited number governs, and an unexplained gap is a serious finding. The same audited financials that satisfy the custody-rule exception are the yardstick the track record gets measured against.

Restatement check. A prior-period restatement of NAV or performance is a bright red flag. Not every restatement is improper, but one goes straight to whether the valuation and accounting controls held and whether the numbers an LP is shown have been stable. A clean, restatement-free history clears the section; a quietly re-cut track record is where the team spends real time — and no amount of strategy quality substitutes for it.

What cash controls does an ODD team look for?

The ODD team is looking for one thing above all: evidence that no single person can move money out of the fund alone. Unilateral cash control is the shortest path to a loss that has nothing to do with the investment thesis and everything to do with fraud or error, and it is the failure mode behind the worst operational blowups. Three controls do most of the protecting.

  • Segregation of duties. The person who initiates a payment is not the person who approves it and not the person who reconciles the bank account. Splitting these roles means moving money improperly requires collusion rather than a single bad actor. This is the foundational cash control and the first thing an analyst maps.
  • Dual authorization (maker-checker, or four-eyes). Any wire above a defined threshold requires two authorized people to release it — the maker prepares, the checker independently approves, and neither can complete the transfer alone.
  • Wire callback (out-of-band verification). Before funds move to a new or changed beneficiary, someone calls a known, pre-verified phone number — not one from the payment instruction itself — to confirm the request. This is the standard defense against business-email-compromise fraud.

At a small manager the same person legitimately wears several hats, and rigid textbook separation is not always achievable in-house. That is not automatically a fail; the answer is compensating controls: the administrator as an independent second approver, bank-enforced dual control, and documented, actually-followed callback procedures. What the team will not accept under any framing is a single individual who can initiate, approve, and reconcile a wire with no independent check. That is the exact setup behind the losses this discipline exists to prevent, and it is a decline-grade finding.

How should a manager structure the fund data room for LP operational due diligence?

Structure the room so it mirrors the ILPA DDQ section order, because that is the order the ODD team thinks in, and matching it turns their review from a scavenger hunt into a guided walk. When an analyst working the valuation section goes straight to a "Valuation and Reporting" folder and finds the policy, the committee minutes, and a sample report together, you have removed friction at the exact moment friction becomes follow-up email. The top-level structure that works:

  • Firm and ownership — formation documents, org chart, ownership structure, regulatory registrations.
  • Investment strategy and process — strategy memo, process documentation, pipeline approach.
  • Team and key persons — bios, key-person provisions, succession.
  • Track record — performance by vintage and fund, and the gross-to-net bridge that ties to the audit.
  • Fees and economics — the LPA's economic terms, fee schedule, expense allocation policy.
  • Compliance — Form ADV Parts 1 and 2A, the compliance manual, the code of ethics, the personal-trading policy.
  • Valuation and reporting — the written valuation policy, valuation-committee minutes, sample LP reports.
  • Operations and service providers — the administrator's SOC 1 Type II and any bridge letter, auditor and custodian confirmations, the business-continuity plan.
  • Legal — the LPA, subscription documents, and a tightly gated side-letters and MFN sub-folder.

Then stage the sensitive tiers. The LPA, the side-letter register, key-person insurance, and employee-level compliance records are not first-touch documents; they belong behind an NDA gate that opens only to a qualified LP that has cleared the earlier stages, so disclosure is staged, not dumped. This is the same logic our Reg D data room guide applies to private placements and our SPV and co-investment guide applies to single-deal syndicates — the room controls not just who gets in but what opens at which phase — and for private-credit managers it extends into ongoing reporting via our borrower-reporting guide and, post-close, our investor-portal software note.

Here is the product case, and then I stop. Engagement analytics matter more in ODD than most managers expect: seeing which documents a reviewer opened, and where they lingered, tells the IR lead which reconciliation questions are coming. If the analyst spent twenty minutes in the valuation-committee minutes and the SOC 1 report, valuation is the call's center of gravity and you can prepare the answer before it is asked — which is the whole claim-and-verify loop the investment due diligence checklist is built around, run from the responder's side.

This is where Peony fits. Data Room pricing is flat, per admin — $52 per admin per month billed annually, or $75 monthly — with unlimited viewers free, so every LP, analyst, and outside consultant you invite costs nothing, which matters when one process pulls in a dozen reviewers. Median setup runs 4 minutes and 19 seconds because AI auto-indexing organizes the document set rather than making you hand-build a folder tree; NDA-gated tiers stage the LPA, side letters, and key-person insurance; and page-level analytics run on every reviewer. Over 6,800+ customers run their rooms on the platform, and funds managing more than $26.3 billion stage their LP diligence on it. None of that changes what the ODD team tests — it changes how prepared you are when they test it.

About the author: Sean Yu is co-founder of Peony, the data room used by 6,800+ M&A, private equity, venture, and private-credit teams, with funds managing more than $26.3 billion staging LP diligence on the platform. He was previously a venture investor at Backed and Target Global.