People — the third P
Who the 3Ps Audit is for.
Three sides of the same table — founders being diligenced, investors doing the diligence, and the programs that have to screen at scale. The framework is the same; what changes is who the report is written for.
Audience 01
Founders & operators
Preparing for a raise, a grant application or an exchange listing — or simply wanting to close gaps before an outside party finds them.
The report becomes a supporting document in your data room and a work plan for your team. Teams that walk into diligence already holding their own risk register negotiate from a different position than teams discovering their gaps live, in someone else's meeting.
Audience 02
VCs & angel investors
An independent, technical second opinion on a deal before capital moves.
Financial diligence tells you what a company has done. Operational diligence tells you whether it can do it again at three times the size. I look at the second question: whether the delivery system, controls and governance behind the numbers would survive the plan you are funding.
Reports are written for an investment committee audience — findings, severity, and the specific conditions worth attaching to a term sheet.
Audience 03
Grants, incubators & accelerators
A consistent way to screen operational risk and assess potential across a portfolio.
Programs usually have strong selection criteria at intake and very little visibility afterward. The same 3Ps scorecard applied at intake, mid-program and at exit turns anecdote into a comparable series — which cohort improved, on which dimension, and where the program's own support is thin.
I have managed government and tech grant funding from the delivery side, which is the fastest way to learn where reported progress and real progress diverge.
Honest scoping
When this is not the right instrument.
Saying so on the first call costs me a sale and saves you a month. It comes up often enough to be worth stating here.
- Idea stage with no product. There is no operating system to audit yet. Strategy and business-model work is the better spend.
- You need a smart-contract security audit. That is a specialist code audit from a security firm — different discipline, and I will point you to one.
- You need a statutory financial audit. That requires a licensed audit firm. This is operational and technical diligence, not an attestation.
- You want a document that says everything is fine. The report says what it finds. That is the only reason it is worth showing anyone.
Next step
Not sure which side of the table you are on?
Most engagements start with a conversation about what you are actually trying to find out. Bring the question; I will tell you whether the audit answers it.
Confidential · NDA on request · Typical turnaround 1–2 weeks