Key Takeaways
- Standard ESG checklists fail in private equity due diligence because they measure policy existence rather than actual operational behavior.
- Applying the Pareto principle allows deal teams to target the critical 20 percent of operational risk areas that drive 80 percent of actual downside exposure.
- Effective integrity due diligence must fit onto a single PowerPoint slide using 10-to-12-point font, or it fails to drive post-close governance.
- Anti-fraud mechanisms require practical two-way speak-up channels so frontline field intelligence reaches executive leadership.
- Evill outlines this operational diligence method in Evill's 3 Cs Integrity Risk Assessment Framework.
The Evill 3 Cs Integrity Risk Assessment Framework
Rupert Evill strips integrity and anti-fraud assessments down to three operational pillars. “You can have every framework under the world,” Evill notes. “It doesn't matter if you don't know what it is or how to implement it and it's not right-sized to your context, your controls, and your culture.”
1. Context
Distill the foundational operational parameters: what do you do, how do you do it, who do you do it with, and where? Establish the specific risk profile (e.g., high-capex regulated offshore energy vs. decentralized residential retail) to ground all subsequent analysis. Evill explains: “The context is the simple questions that people love to complicate, but really can be distilled down to what do you do, how do you do it, who do you do it with, where?”
2. Controls
Apply the Pareto principle to design right-sized controls addressing the 20% of risk areas that generate 80% of actual exposure, rather than implementing exhaustive, generic compliance checklists. Evill stresses focusing resources directly where capital is exposed instead of auditing non-material documentation.
3. Culture
Align the internal environment with the company's operating context, focusing on trust, behavioral accountability, and practical two-way speak-up mechanisms so frontline intelligence reaches leadership. “Risk or ethics or integrity is entirely context dependent,” Evill states. “So the controls for one versus two have to be very different and the culture in the business needs to be reflective of that.”
When This Works (and When It Doesn't)
This framework works when evaluating growth-stage or decentralized portfolio companies where investors need to prioritize material integrity risks on a single page instead of relying on generic ESG templates. It cuts through the administrative clutter typical of hundred-page compliance questionnaires that mid-market management teams routinely ignore.
It breaks down in heavily audited financial institutions or defense contractors where regulatory bodies mandate hundreds of static, prescriptive controls regardless of operational context. In those environments, substituting regulatory compliance with a 20 percent Pareto filter invites immediate regulatory penalties.
Why It Matters
Private equity sponsors face increasing LP pressure to demonstrate real risk mitigation without burdening portfolio company operations with red tape. Evill argues that bloated compliance memos obscure real fraud, whereas concise assessments create board accountability. As Evill observes, “If you can't fit the action plans onto one PowerPoint slide in sort of 10 to 12 font if that gives people a framework into a table then you haven't really done your job very well.” Deal teams that treat integrity as an operational filter rather than a moral exercise catch deal-breaking governance blind spots before signing.