Investor ODD: the IT questions allocators actually ask
Before an institutional investor commits capital to a fund, they run operational due diligence — ODD — on how the manager actually operates. IT and cybersecurity have become a standing part of that review, and a weak showing can stall or sink an allocation regardless of investment performance. If you are raising from institutions, family offices or funds-of-funds, it pays to know what they will ask before they ask it.
Why allocators care about your IT
An allocator's job is to rule out operational risk — the ways a manager could lose or mishandle capital that have nothing to do with markets. A cyber incident, a data loss, a prolonged outage or a fraud enabled by weak controls all fall squarely in scope. Increasingly, allocators treat a manager's cyber maturity as a proxy for operational discipline generally: if the IT is run tightly, the rest of the operation probably is too.
The questions that come up again and again
- Access and authentication. Is MFA enforced everywhere, including admins and remote access? How is access granted, reviewed and revoked when someone leaves?
- Backup and recovery. What is backed up, how often, and when did you last test a restore? What is your recovery time objective if systems go down?
- Business continuity / disaster recovery. Is there a written BCP/DR plan? Has it been tested? Where would staff work if the office were unavailable?
- Cybersecurity controls. Endpoint protection, email security (SPF/DKIM/DMARC), patching cadence, and monitoring — who runs them and how are they evidenced?
- Vendor and third-party risk. Which providers touch your systems and data, and do you hold due-diligence records and SLAs on them?
- Incident history and response. Have you had an incident? Is there a written response plan, and has it been rehearsed?
- Cyber insurance. Do you carry it, and what does it cover?
- Regulatory alignment. How do your controls map to the SFC's cybersecurity expectations?
How to be ready before the questionnaire arrives
The efficient approach is to assemble the evidence once and keep it current, rather than reconstructing it under time pressure for each allocator. A readiness pack typically contains an IT and cybersecurity summary, an asset inventory, proof of MFA and patching, a tested-restore record, a BCP/DR plan, a vendor due-diligence pack, and an incident-response plan. Notably, this is the same evidence the SFC expects — so a firm that has prepared for the regulator has largely prepared for ODD as well. The two reviews reward the same discipline.
Turning a hurdle into a selling point
Handled well, ODD is not just a hurdle to clear — it is a chance to look more institutional than firms of your size usually do. Managers who can demonstrate mature, documented IT controls stand out precisely because so many small firms cannot. For the regulatory side of the same picture, see our SFC Type 9 IT and cybersecurity checklist.