// INTERACTIVE TOOL · NINE DOMAINS · 12–15 MIN · NO EMAIL

Diligence Radar

Score a SaaS or AI company across nine due-diligence domains on two axes. Exposure is how much a domain can move a deal for your company in particular. Readiness is how well you could prove your position today from evidence that already exists. The gap between them is the unmanaged transaction risk.

Twelve to fifteen minutes · Nothing stored, nothing sent · Free report · Not legal advice

// The radar Open full screen →

FAQs

What is the Diligence Radar?

A self-assessment that scores a SaaS or AI company across the nine domains a buyer or investor will run due diligence on. Every domain gets two scores out of ten: exposure, how much the domain can move a deal for this company, and readiness, how well the company could prove its position today from evidence that already exists. The gap between the two is the unmanaged transaction risk.

Who is the tool for?

Founders and boards of SaaS and AI companies preparing for a raise or a sale, and the investors and acquirers who will one day test them. It sits alongside Ortent's Board Radar for NHS boards, the Growth-Stage TOM, Partner Architecture and Five Questions.

What are the nine domains?

Chain of title, data provenance, revenue quality, commercial and change of control, privacy, security and resilience, AI governance and claims, sector and regulatory perimeter, and insurability and disclosure. Together they cover the questions a buyer's diligence team will ask about ownership, evidence, contracts, controls and disclosure.

How does exposure differ from readiness?

Exposure is set from the six-question company profile (product, buyer, data, markets, AI role, stage), not asked directly, so you are not marking your own exposure. Readiness comes from four evidence questions per domain, answered on a fixed four-rung ladder (no evidence, policy only, running but not proven, running and provable). Exposure minus readiness is the gap the tool leads with.

Is the readiness ladder honest?

It is designed to be. A written policy caps readiness at four out of ten, in line with the self-scoring prompt. A control that runs but is not tested, logged or fully traceable sits at six. A control that runs and can be evidenced end to end reaches nine. Silence is not readiness: unanswered questions are treated as no evidence, not as an assumed zero risk.

Does the tool store my answers or share them?

No. The tool runs entirely in your browser tab. Nothing is sent to Ortent and nothing is stored beyond the session. Refreshing the page will lose your answers. The report is generated in the browser; the download and copy actions produce a Markdown file for you to save privately.

Is this legal advice?

No. This is a commercial and governance read, not legal, tax, accounting or investment advice. What applies to your company depends on your product, your data, your customers and the markets you sell into. For a board-ready version taken from your own artefacts, use the self-scoring prompt or book a session at ortent.co/contact.

How is the AI role question worded?

Using the EU AI Act personas: provider (builds or brands an AI system), deployer (puts an AI system to use under its own authority), distributor (makes an AI system available in the chain of supply), importer (places an AI system from a non-EU provider on the EU market), runs agents (autonomous or semi-autonomous agents take actions on the company's behalf), or no AI. This maps directly to the buyer's first regulatory question.