Sydney ODD Roundtable: Where Risk Priorities Are Shifting
Around 20 operational due diligence professionals from Australian superannuation funds, private wealth platforms, asset consultants, research houses, and auditors compared notes on how ODD priorities have changed, and what a maturing framework looks like today.
Thank you to everyone who joined the ODD Roundtable in Sydney, co-hosted with Aware Super. This summary reflects the discussion the group shaped together and is shared back as a resource. All insights are attributed to the group. No individual firm or participant is identified.
The room reflected the breadth of the Australian market: superannuation funds, private wealth platforms, asset consultants, research houses, and auditors. Several attendees were building new ODD frameworks or had recently moved into ODD leadership roles, which kept the conversation grounded in day-to-day practice rather than theory.
- AI governance has become a standard line of inquiry. The question has moved from whether a manager uses AI to how they govern, review, and take accountability for it.
- Valuation independence is under closer scrutiny in private markets, with documented policy increasingly treated as a baseline expectation rather than best practice.
- Evergreen funds raise governance questions that traditional closed-end due diligence wasn't built to answer, particularly around NAV transparency and allocation conflicts.
- Cyber risk is being read through a geopolitical lens, not just a technology one, given the volume and origin of attacks targeting managers.
- Auditor selection deserves more scrutiny than it typically gets, especially around GIPS verification, specialist coverage in venture, and partner rotation.
- The same manager launching a new fund is not automatically a lighter review. Vintage, structure, and service provider changes can introduce new risk that a prior clean history doesn't cover.
- ODD and IDD are converging as disciplines, even as resourcing lags the growth in manager coverage.
Section 1
Which Risks Rose, Which Faded
The room was asked a straightforward question: what was a top priority a few years ago that matters less today, and what replaced it?
The general view was that ODD standards have moved up steadily over the last five years, with more scrutiny applied to governance frameworks, segregation of duties, and conflicts of interest tied to organisational structure. As one participant put it, the group now looks at far more risk than it did five years ago. That shift seemed to reflect both regulatory pressure and a genuine broadening of what allocators consider in scope.
ESG and DEI came up as an example of a theme that has plateaued rather than disappeared. Several attendees felt Australian investors still hold a stronger focus here than U.S. peers, partly a reflection of political shifts in the U.S. that have pulled attention elsewhere. Electronic communications monitoring and regulatory change management followed a similar arc: still relevant, no longer the centre of the conversation they once were.
Disaster Recovery, Reframed
The old questions about physical infrastructure and backup sites have largely given way to cloud-based operating models. What replaced them is a focus on operational resilience and third-party dependency, reinforced in Australia by APRA's CPS 230 framework, which has pushed the industry to examine resilience arrangements more formally than before.
Section 2
A Geopolitical Risk as Much as a Technical One
Cybersecurity remained one of the most discussed operational risks, and the framing has shifted. Participants tied the increase in attempted attacks against investment managers directly to geopolitical tension, rather than treating it as a purely technical trend. As international relations have grown more strained, state-linked and opportunistic actors alike appear to be probing financial services more often, which changes the threat model allocators need to apply: it's not just a question of a manager's IT hygiene, but of whether that manager is a plausible target given its footprint, client base, or geography.
The practical implication for ODD is that policy review alone doesn't tell you much. Testing resilience, understanding incident response history, and asking how a manager's threat model has evolved matter more than confirming a document exists. There was also broad agreement that the increasing availability of data and intelligence platforms has materially enhanced the ability of ODD teams to identify and assess portfolio-wide risks. By providing a consolidated view across fund and firm auditors, fund administrators, custodians, credit providers and other critical service providers, these platforms enable practitioners to identify concentrations, common dependencies and emerging risk exposures across portfolios more efficiently. Participants noted that this capability has become increasingly important in the context of geopolitical risk, allowing ODD teams to assess exposures to specific jurisdictions, service provider locations, supply chains and operational dependencies that may be affected by geopolitical events, regulatory developments, sanctions regimes or broader macroeconomic disruption. This supports a more targeted and informed approach to due diligence, ongoing monitoring and risk assessment.
Section 3
Valuations Draw Closer Scrutiny
APRA has placed growing emphasis on how superannuation funds govern valuations of unlisted and illiquid assets, and that regulatory attention was reflected in the room. Several participants described valuation as owned by a dedicated internal team, sitting apart from the investment team that sources and manages the deal. That division changes what an ODD review is actually testing. The question isn't whether a given mark is correct, since that's not ODD's job to determine, but whether the governance around how the mark was set holds up: who has authority to challenge a manager's number, how disagreements get escalated and resolved, and how often the valuation policy itself is reviewed rather than just referenced. Several participants also described cross-checking a manager's reported asset values against what shows up in its own audited financial statements as a useful, low-cost independent check. A gap between the two doesn't prove a problem, but it's a concrete, specific thing worth asking the manager to explain.
Private markets took up a large share of the discussion, and valuations sat at the centre of it. Participants pointed to valuation policies, valuation committee governance, and reliance on third-party valuation providers as areas of growing focus.
How independent are "independent" valuations in practice? Are third-party valuers genuinely challenging assumptions, or largely validating what the manager has already supplied?
One attendee suggested that a fund without a documented valuation policy would now be treated as a meaningful gap, particularly in venture and growth equity, where marks are harder to benchmark against observable transactions.
Multi-Manager Blind Spots
A related challenge raised in the room concerned feeder structures, multi-manager portfolios, and offshore vehicles, where visibility into underlying valuations can be limited. That gap pushes more weight onto the manager's own governance and oversight, which is harder to verify at a distance.
Aging Funds and Continuation Vehicles
The conversation also touched on funds carrying elevated paper valuations with limited exit activity, a pattern some participants referred to informally as zombie funds, and on continuation vehicles that extend holding periods and reshape liquidity expectations for existing investors.
Evergreen Funds
Evergreen structures generated the most debate within this topic. Questions centred on whether traditional private market managers have the operating infrastructure for vehicles built for retail-style distribution, and whether NAV transparency, valuation frequency, and liquidity management are keeping pace with the growth in assets. Several attendees pointed to the U.S. market as a preview of what investor education needs to cover, including redemption gates, liquidity constraints, and how valuation actually works between reporting dates.
A related concern was allocation conflict when a manager runs both a closed-end fund and an evergreen vehicle side by side. Which investors get access to new deals, and can a perpetual vehicle end up disadvantaging investors in the legacy fund? The room didn't reach a settled answer, but agreed it's a question worth asking the manager directly rather than taking the arrangement at face value.
Section 4
From Disclosure to Accountability
AI came up repeatedly through the discussion, and the framing has shifted. Asking a manager whether they use AI no longer tells an allocator much on its own. The more useful questions are about governance: is there a policy, who owns it, how often is it reviewed, what training has staff received, and are outputs reviewed by a person before they're used. Several participants compared this to model risk management frameworks built for quantitative strategies, which suggests the industry already has a reasonable template to adapt rather than needing to invent one from scratch.
Reported use cases spanned the front office (research aggregation, security screening, portfolio construction support) and the middle and back office (drafting, reporting, data extraction, workflow automation). Adoption still varies by manager size, investment style, and culture, which makes a one-size-fits-all AI questionnaire less useful than a conversation tailored to how a given manager actually works.
Data Quality Underneath It All
Underneath the governance conversation sat a data quality concern: output is only as reliable as the data feeding it. Private market reporting was flagged as an area where AI adoption may be moving faster than the governance built to support it, since less standardised data makes errors harder to catch.
The Talent Question
A more unsettled discussion centred on ODD talent. Several attendees raised concerns about a hollowing out of junior analyst work and the loss of learning pathways that come from doing the work by hand, along with what one participant called the tension between token budgets and analyst budgets. There was no consensus on whether AI nets out as a productivity gain or a longer-term drag on how future decision-makers get trained, and the room seemed comfortable leaving that question open rather than forcing an answer.
Where the room did agree: AI can improve efficiency, but it doesn't replace judgment. Face-to-face meetings, challenge sessions, and testing whether answers stay consistent under pressure remain the core of the work.
Section 5
What the Response Reveals
NDAs are increasingly common, and some materials, including audit reports, AML documentation, and SEC exam materials, are only reviewable on-site. Larger global managers were generally described as more willing to host an on-site review than to send documents electronically.
The more useful signal, several participants noted, is rarely the document itself. It's how a manager responds to a reasonable request. A manager who pushes back, delays, or reframes the question is telling an allocator something, independent of what the underlying document actually says.
Meeting recordings and AI transcription came up as a related thread. Most attendees haven't seen meeting quality drop meaningfully once recording is disclosed upfront, though some managers stay more guarded when proprietary models or IP enter the conversation.
Section 6
What In-Person Reviews Still Surface
One of the clearer areas of consensus among participants was that on-site operational due diligence remains highly relevant despite continued improvements in virtual engagement tools. For most investment strategies, ODD teams indicated that in-person meetings provide materially greater insight than discussions conducted remotely. Attendees noted that physical site visits offer a more effective means of assessing team dynamics, key-person dependencies, organisational alignment and the quality of the partnership between stakeholders. They also provide greater visibility into interactions across front, middle and back-office functions, as well as governance arrangements such as valuation committees. In addition, on-site reviews facilitate the verification of supporting documentation that may not have been provided during the questionnaire process, including internal policies, procedures and regulatory correspondence such as SEC deficiency letters.
One specific pattern came up more than once: a manager brings several team members into the room, but only one of them actually answers questions, with the others largely silent. That's worth noting in itself, since it can point to how concentrated knowledge or decision-making really is on a team, independent of what the organisational chart shows.
For infrastructure and real estate strategies specifically, several attendees felt the on-site visit shouldn't sit with ODD alone. Given how much of the risk in those strategies lives in physical assets and operating partners, the investment team benefits from being on the ground as well, not just reviewing documentation after the fact.
Section 7
What Actually Fails a Review
The room walked through the issues that reliably move a manager from a pass to a fail. Most weren't single dramatic findings, but patterns that compound once you look closely.
- Segregation of duties, front office and back office. Overlap between people who generate trades or valuations and people who control or report on them remains one of the most consistent veto triggers, regardless of firm size.
- Suspicion of a lack of integrity. Inconsistent representations, answers that shift between meetings, or information from background checks that conflicts with what the manager has disclosed.
- Undisclosed affiliates or related-party relationships. Especially where they touch service provider selection, fee arrangements, or deal sourcing.
- Lack of transparency. Reluctance to provide information, inability to evidence controls that are claimed to exist, or a defensive posture toward reasonable requests.
- Board governance concentrated in the owner. At boutique and founder-led managers, a board that exists on paper but doesn't meaningfully constrain the owner's decisions was described as a common and often underweighted gap.
- A small or unknown auditor. Raised often enough that it warranted its own discussion, below.
Section 8
The Auditor Question Deserves More Time Than It Gets
A smaller but well-informed part of the discussion focused specifically on auditors, an area participants felt often gets a lighter review than it deserves relative to how much weight allocators place on a clean audit opinion.
GIPS Verification and Second-Tier Firms
Participants noted that GIPS verification work is increasingly being performed by second-tier audit firms rather than the largest global networks. That isn't automatically disqualifying, but it changes the diligence question: allocators should understand who is actually performing the verification, what their track record looks like across other clients, and whether their methodology and staffing are proportionate to the manager's complexity.
Specialist Coverage in Venture
Venture was raised as a case where specialist audit firms with genuine sector depth exist and are worth seeking out specifically. A generalist auditor without venture experience may be less equipped to challenge valuation assumptions on illiquid, early-stage positions, which is precisely where independent challenge matters most.
Audit Partner Rotation
Checking whether the audit partner has been rotated over time was raised as a simple but often-skipped step. Extended tenure on the same engagement, even at a reputable firm, can gradually narrow independence in practice, and it's a detail that's easy to verify directly.
Regulatory Oversight Context in the U.S.
It's worth noting that the PCAOB, which oversees U.S. audit firms, is itself in a period of transition. The SEC approved a reduced PCAOB budget for 2026, alongside new board leadership appointed earlier in the year, and the board has pushed back the effective date of its new quality control standard (QC 1000) to December 2026. None of this points to a specific finding about any given auditor, but a period of reduced funding and standard-setting delay at the regulator level is a reasonable input into how much independent verification allocators do themselves, rather than relying on the existence of PCAOB oversight as a substitute. As a result, attendees emphasised that allocators should continue to undertake their own verification procedures when assessing auditors. This may include reviewing publicly available PCAOB inspection reports, disciplinary actions, registration status and other regulatory information to gain a more informed understanding of an audit firm's track record and oversight outcomes.
Section 9
Why a Familiar Manager Still Needs a Fresh Look
A practical question came up toward the end of the session: when a manager that an allocator already knows launches a new fund, how should the diligence approach change? The room's view was that familiarity should shorten the process, not the substance.
Look for What's New
The instinct to treat a new fund from a known manager as a lighter-touch review was flagged as a risk in itself. A new fund often means a new strategy tilt, a new team member with more discretion, a new fee structure, or a new investor base with different liquidity expectations. The review should specifically target what has changed since the last approval, rather than re-confirming what's already on file.
Check Service Providers Across Vintages
One specific, practical check the room highlighted: confirm whether the fund administrator, auditor, and valuation agent are the same across the manager's prior vintage and the new fund. A change in any of these, even a seemingly administrative one, is worth understanding directly. It can reflect a legitimate scaling decision, or it can reflect a provider relationship that didn't work out for reasons the manager hasn't volunteered. In addition, a change in service provider can be accompanied by a change in the scope of services delivered, potentially affecting oversight arrangements, operational processes and control environments.
Section 10
How ODD Teams Are Built
Most organisations in the room sit within Investments or a dedicated Investment Governance function, which aligns to SPS 530, several attendees who have had experience sitting within different functions believe the investment team is the most appropriate. ODD and IDD functions appear to be converging rather than operating as separate silos, and organisations whereby ODD sits within investments maintain formal ODD gates before manager approval.
That resourcing figure suggests workload is growing faster than headcount in a number of teams, which is worth keeping in mind when interpreting how deep any single review can realistically go.
What the Room Leaves Us With
- AI governance has moved from a disclosure question to an accountability question.
- Private market valuation independence is drawing closer scrutiny, with evergreen funds adding new governance and investor education considerations.
- Cyber risk is increasingly read through a geopolitical lens, not just a technical one.
- Auditor selection, including GIPS verification quality, sector specialisation, and partner rotation, deserves more direct scrutiny than it typically receives.
- A new fund from a known manager still warrants a full look at what's changed, including whether service providers carried over from the prior vintage.
- Face-to-face due diligence continues to provide a distinct and important source of assurance that cannot be fully replicated through virtual interactions. ODD and IDD are increasingly working as one discipline, even as resourcing lags manager coverage.