TECHNICAL DUE DILIGENCE — EVIDENCE AND DECISION CHECKLIST Editable worksheet — adapt to the actual scope and company. Version: 2026-09-10 PURPOSE AND BOUNDARIES Decision supported: [investment / acquisition / supplier appointment / other] Sponsor and decision date: [ ] Systems, entities and time period included: [ ] Excluded areas and separate specialist reviews: [ ] Evidence access owner and approved sharing location: [ ] HOW TO RECORD EACH FINDING Finding ID / question / observed fact / evidence reference / date / owner. Status: verified / partly verified / not verified / not applicable with reason. Separate the consequence, likelihood assumptions and proposed response. An unanswered question is not a pass. Record why evidence is missing and who can supply it. Do not paste credentials or customer records; reference approved repositories. PRODUCT AND ARCHITECTURE [ ] Identify critical user journeys and the services needed to complete them. [ ] Obtain a current architecture view; ask an engineer to trace one real request. [ ] Record external dependencies, failure effects and single-owner knowledge. [ ] Compare the architecture described with available deployment evidence. [ ] Identify known constraints, deferred decisions and planned replacements. Evidence / unresolved questions / owner / next action: [ ] CODE AND DELIVERY [ ] Establish repository ownership, access controls and change-review responsibilities. [ ] Review a representative change from proposal through release and observation. [ ] Inspect meaningful test evidence for critical behavior and failure paths. [ ] Distinguish unsupported quality claims from reproducible checks. [ ] Record release, rollback and incident follow-up procedures and recent examples. Evidence / unresolved questions / owner / next action: [ ] OPERATIONS AND RECOVERY [ ] Identify operating owners, support hours, escalation and supplier dependencies. [ ] Examine incident records and how recurring causes are addressed. [ ] Ask for a recent recovery exercise and evidence of application usability afterward. [ ] Record recovery assumptions, untested dependencies and accepted limitations. [ ] Compare capacity and cost assumptions with available workload evidence. Evidence / unresolved questions / owner / next action: [ ] ACCESS, DATA AND SPECIALIST REVIEW [ ] Identify privileged-access ownership and joiner/mover/leaver processes. [ ] Establish data categories, locations, retention owners and known obligations for specialist review. [ ] Request the scope, date and unresolved findings of relevant security assessments. [ ] Identify licenses, material contracts and intellectual-property questions for qualified review. This worksheet is not a security certification or legal opinion. Evidence / unresolved questions / owner / next action: [ ] TEAM AND CONTINUITY [ ] Map responsibilities, capacity, key-person dependencies and recruitment assumptions. [ ] Ask the next owner to locate and explain a critical operating procedure. [ ] Record supplier exit requirements and company-controlled records. DECISION PAPER Verified strengths: [ ] Material findings with evidence and consequence: [ ] Unknowns that could change the decision: [ ] Actions required before proceeding / owner / acceptance evidence: [ ] Actions proposed after proceeding / resource and timing assumptions: [ ] Residual risks and authorized acceptance owner: [ ] Decision, rationale, date and next review: [ ] Related guide: https://fractionalctoexperts.com/technical-due-diligence-investors