Insights · Investor ODD

Investor ODD: the IT questions allocators actually ask

Investor ODD · Published 14 July 2026 · 6 min read

Before an institutional investor commits capital to a fund, they run operational due diligence — ODD — on how the manager actually operates. IT and cybersecurity have become a standing part of that review, and a weak showing can stall or sink an allocation regardless of investment performance. If you are raising from institutions, family offices or funds-of-funds, it pays to know what they will ask before they ask it.

Why allocators care about your IT

An allocator's job is to rule out operational risk — the ways a manager could lose or mishandle capital that have nothing to do with markets. A cyber incident, a data loss, a prolonged outage or a fraud enabled by weak controls all fall squarely in scope. Increasingly, allocators treat a manager's cyber maturity as a proxy for operational discipline generally: if the IT is run tightly, the rest of the operation probably is too.

The questions that come up again and again

  • Access and authentication. Is MFA enforced everywhere, including admins and remote access? How is access granted, reviewed and revoked when someone leaves?
  • Backup and recovery. What is backed up, how often, and when did you last test a restore? What is your recovery time objective if systems go down?
  • Business continuity / disaster recovery. Is there a written BCP/DR plan? Has it been tested? Where would staff work if the office were unavailable?
  • Cybersecurity controls. Endpoint protection, email security (SPF/DKIM/DMARC), patching cadence, and monitoring — who runs them and how are they evidenced?
  • Vendor and third-party risk. Which providers touch your systems and data, and do you hold due-diligence records and SLAs on them?
  • Incident history and response. Have you had an incident? Is there a written response plan, and has it been rehearsed?
  • Cyber insurance. Do you carry it, and what does it cover?
  • Regulatory alignment. How do your controls map to the SFC's cybersecurity expectations?
The tell. Allocators are not only reading your answers — they are watching how fast and how completely you can produce evidence. A manager who returns a documented pack the same week signals a well-run operation. A scramble signals the opposite.

How to be ready before the questionnaire arrives

The efficient approach is to assemble the evidence once and keep it current, rather than reconstructing it under time pressure for each allocator. A readiness pack typically contains an IT and cybersecurity summary, an asset inventory, proof of MFA and patching, a tested-restore record, a BCP/DR plan, a vendor due-diligence pack, and an incident-response plan. Notably, this is the same evidence the SFC expects — so a firm that has prepared for the regulator has largely prepared for ODD as well. The two reviews reward the same discipline.

Turning a hurdle into a selling point

Handled well, ODD is not just a hurdle to clear — it is a chance to look more institutional than firms of your size usually do. Managers who can demonstrate mature, documented IT controls stand out precisely because so many small firms cannot. For the regulatory side of the same picture, see our SFC Type 9 IT and cybersecurity checklist.

Where Komstadt fits. We assemble and maintain the ODD evidence pack for you — so the next allocator questionnaire is an attachment, not a scramble. Book a free assessment →