Essay
AI lets PE buyers check every product's compliance before the deal closes
Document-level compliance baselining across a target's supply chain, and why it moves regulatory risk out of the indemnity and into the pro forma.
In every acquisition I have sat on either side of, the regulatory folder in the data room was the thinnest one, and the sentence in the purchase agreement about it was the longest. The folder held a few certificates for the products that carried the revenue. The sentence said the seller represented that every product complied with every applicable law in every market it was sold into.
Nobody believed the sentence. That is why it was insured. Counsel scoped a review of the product lines that mattered, a consultant pulled a sample of supplier declarations, the deal team wrote a compliance rep, and a representations and warranties policy priced the gap between the sample and the truth. The process was rational under one constraint: reading supplier documents was slow, expert work, and the deal had a clock.
That constraint has gone. So here is the claim I want to defend. Compliance diligence has always been sampled because reading was the expensive part. Once reading is cheap, it becomes a census, and a census turns a rep and warranty into a line in the pro forma.
What the sample was hiding
Product compliance in a physical supply chain is a population problem. Under REACH, the EU chemicals regulation, a supplier of an article must tell its customer when any substance on the Candidate List is present above 0.1 percent weight by weight, and must answer a consumer who asks within 45 days.1 Under RoHS, the restriction on hazardous substances in electrical equipment, ten substances are capped at 0.1 percent (cadmium at 0.01 percent) by weight in each homogeneous material, meaning each material that cannot be mechanically separated into different materials.2 The unit of compliance is smaller than the product. It is the solder, the plating, the plasticizer in one cable jacket.
The population is correspondingly large. By February 2022, sixteen months after the SCIP database opened for submissions, industry had sent the European Chemicals Agency over 15 million notifications of Candidate List substances in articles, from nearly 7,000 companies, covering 7 million searchable articles.3 That is one obligation, in one jurisdiction, for one list of substances.
And the base rate of non-compliance is not small. In 2024, enforcement authorities across 29 European Economic Area countries ran 2,603 checks on imports under REACH. Against the restriction annex, the overall non-compliance rate was 16 percent, 214 of 1,329 products; for articles specifically it was 17 percent.4 Those are regulators inspecting goods already on the market, which is what a buyer inherits at close.
Set that against how diligence is actually scoped. The firms that do this work describe it as "in-depth compliance assessments of targeted product lines driving the 'deal'."5 The product lines driving the deal, not the long tail, and not the parts inside them. What the sample misses shows up later as a claim. Aon's 2025 claims study, covering policies placed since 2019, found compliance with laws to be "the most frequent breach type at 20%," ahead of tax at 17 percent and financial statements and material contracts at 13 percent each, and found that 49 percent of claims arrive more than twelve months after closing.6 Its 2026 study found that roughly 18 percent of policies bound between 2019 and 2023 have seen at least one claim notification.7
I read those numbers as a description of sampling error. The compliance rep is the most-breached rep because it is the one whose underlying population was least read.

What the research says about the cost of reading
The economics of the sample rested on the cost of a trained reader. Martin and colleagues put that cost in a table. They gave ten procurement contracts to senior lawyers to set a ground truth, then had junior lawyers, a legal process outsourcer, and eight language models review them for compliance with predefined standards. On issue determination, GPT-4 scored an F-score of 0.871 against 0.860 for the junior lawyers and 0.874 for the outsourcer. The junior lawyer took 56 minutes and cost $74.26 per contract; the best model took under five minutes and cost 25 cents.8 The authors work for a legal-software vendor and the sample was ten contracts, so treat the precision loosely. The direction is not in doubt, and the task, checking a document against a stated standard, is what a compliance reviewer does to a supplier declaration.
What that table does not say is that you can drop a supply chain into a prompt. Current frontier models advertise a context window of one million tokens, and a single request can carry up to 600 PDF pages.9 A mid-sized manufacturer's supplier document set runs to tens of thousands of pages, and the advertised length is not the usable length. The RULER benchmark evaluated 17 long-context models and found that "while these models all claim context sizes of 32K tokens or greater, only half of them can maintain satisfactory performance at the length of 32K."10 Liu and colleagues showed the failure has a shape: performance "significantly degrades when models must access relevant information in the middle of long contexts, even for explicitly long-context models."11 A census that trusts a single long prompt will lose the declarations in the middle of the pile.
The mechanism
So the census is a pipeline with six stages, and the first is inventory. The target's bill of materials is resolved to a list of parts, each tied to a supplier and to the products and markets it ships into. This is the sampling frame the old process never built.
Classification comes next. Every document in the data room, and everything the target's purchasing team can pull from suppliers, is sorted by type: full material declaration, certificate of conformity, test report, safety data sheet, Article 33 letter, exemption claim. A certificate is a supplier's promise; a material declaration is a list of substances by homogeneous material. They carry different evidentiary weight and are labeled as such.
Extraction is where the model does its work. Each document is read and its content written into a fixed schema. The right target already exists. IEC 62474, the electrotechnical industry's material declaration standard, defines a Declarable Substance List and an XML exchange format, and allows a "simplified true/false declaration against each entry in a Declarable Substance List," indicating whether each substance is present above threshold.12 Extracting into that schema, per part, per homogeneous material, is what turns prose into data.
Evaluation applies the rules to the data deterministically, one jurisdiction at a time: RoHS Annex II thresholds, the current Candidate List, the rules of every market on the revenue ledger. No model sits in this stage; I made the case for that separation in the last essay.
Coverage is the output. Every part lands in one of three states per jurisdiction: compliant with evidence, non-compliant with evidence, or no evidence. The third state is the one a sample cannot report, and it is where the diligence value is. A part with no declaration is an unpriced question, and the census counts the questions.
Pricing joins the coverage map to revenue by product and market. Non-compliant parts price as the revenue that cannot ship until they are fixed. No-evidence parts price as the cost to close the question: a supplier request, a lab test, or a redesign, each with a known cost and lead time. Add the two and you have a number a model can hold.

A worked example
At Certivo, the request that arrives from a deal team looks like this. The target makes industrial sensors, ships to the EU, the UK and California, and has about 12,000 purchased parts. The data room holds 3,000 supplier documents; the target's purchasing system holds 20,000 more. All of it is ingested in a day. For EU RoHS the coverage map comes back at, say, 61 percent of parts compliant with evidence, 2 percent non-compliant on the evidence supplied, 37 percent with no evidence. The 2 percent sits on three product families that carry a fifth of European revenue. The 37 percent is mostly commodity fasteners and passives, with 400 parts that would need testing.
The figures are illustrative; the shape is not. The deal team now has three numbers a sampled review could not give it: the revenue exposed today, the cost and lead time to close every open question, and the list of parts where the answer turns on a person's judgment about an exemption. The compliance engineer is still in the process. She is reading the 400, not the 12,000.
What the pro forma can hold now
Once the number exists, the instrument changes. A rep and warranty says the seller believes it is fine and will pay if not, and a policy prices that belief. A pro forma line says closing the gap costs this, over this many months, and until then this revenue is at risk. One is a hedge against not knowing. The other is a plan.
It also extends forward, and a hold period is long enough for that to matter. Bain reports buyout funds sitting on $3.8 trillion in unrealized value with average holding periods at exit drifting toward seven years.13 The universal PFAS restriction proposed under REACH would cover over ten thousand substances; the socio-economic committee's final opinion is expected at the end of 2026, a Commission decision in the third quarter of 2027, and restrictions from 2029.14 A company bought this year will be sold into that regime. With a coverage map in hand, "which of our parts contain a PFAS, in which products, in which markets, and what does the derogation schedule give us" is a query. Without it, the answer at exit is another thin folder and another long sentence, this time written by the buyer's counsel about you.

Three things follow for an operating partner. Ask for the coverage map before exclusivity ends, and put the no-evidence percentage into the negotiation rather than into a special indemnity. Put the cost to close the gap into the hundred-day plan as a line with an owner, since it is now a known cost on a known schedule. And run the census again every year: the Candidate List keeps growing and the population moves with every supplier change, so a baseline is only a baseline on the day it is drawn.
The same shape elsewhere
The pattern is general: a large, heterogeneous population of documents; a rule set that is deterministic once the facts are known; and a decision made on a sample because reading the population was too expensive. Customs and rules-of-origin work has that shape, with tariff classifications and supplier affidavits standing in for material declarations. So does forced-labor import screening, where the population is supplier relationships several tiers deep. So does loan-file review in a securitization, where the reps on a loan tape have always been backed by a sample of files. So does a portfolio-wide answer to a new regulation, where the question is how many of twenty companies comply. In each case the sample was the best available approximation of a census nobody could afford.
The strongest objection
The strongest case against this argument is that the census is only as good as the reader, and the reader is a language model. Magesh and colleagues at Stanford tested commercial legal research tools built on retrieval-augmented generation and found hallucination rates of 17 percent for Lexis+ AI and Ask Practical Law AI and 33 percent for Westlaw's AI-Assisted Research, defining a hallucinated response as one that "is either incorrect or misgrounded."15 If a census reads 12,000 parts with a one-in-six error rate, a sample read by an expert may be closer to the truth.
They are right that the error rate is not zero and that vendors overstate it. Where the objection is weaker is the shape of the task. Their tools were asked open questions and generated prose; a compliance census extracts stated values from a document into a schema, and every extracted value carries the page it came from. The error is per document, visible, and cheap to check, which is what lets the compliance engineer review the flagged margin rather than the whole. A misgrounded extraction that says a part is compliant when its declaration does not is the dangerous case, and it is why the decision stage must be deterministic and why "no evidence" has to be a first-class state rather than a default to "compliant." I would rather have a census with a known, auditable error rate than a sample with an unknown one, but only under those two conditions.
None of this makes the compliance engineer redundant. It gives her a population instead of a pile, and it gives the deal team a number instead of a sentence. The rep and warranty was a way of insuring something we could not count. We can count it now. Stop insuring it.
— Kunal
Sources
- Regulation (EC) No 1907/2006 (REACH), Article 33, "Duty to communicate information on substances in articles," paragraphs 1 and 2.↩
- Directive 2011/65/EU (RoHS), Annex II, "Restricted substances referred to in Article 4(1) and maximum concentration values tolerated by weight in homogeneous materials," as amended to 31 December 2020.↩
- European Chemicals Agency, "7 million searchable articles in SCIP database improve transparency on hazardous chemicals," Helsinki, 2 February 2022.↩
- ECHA Enforcement Forum, REF-12 project report on REACH duties for imported substances, mixtures and articles, inspections conducted in 2024, published 10 December 2025; figures via TÜV SÜD's summary of the report.↩
- Bergeson & Campbell, P.C., "Mergers and Acquisitions/Due Diligence Services in the Chemical Sector," lawbc.com, accessed 6 September 2026.↩
- Aon, 2025 Transaction Solutions Global Claims Study, Chapter 3, "North America: Breach Type and Notification," 26 June 2025; policies placed since 2019.↩
- Aon, 2026 Transaction Solutions Global Claims Study, June 2026; R&W policies bound 2019–2023.↩
- Lauren Martin, Nick Whitehouse, Stephanie Yiu, Lizzie Catterson, Rivindu Perera, "Better Call GPT, Comparing Large Language Models Against Lawyers," arXiv:2401.16212, 24 January 2024; Tables 2, 4 and 5. The authors are at Onit's AI Centre of Excellence.↩
- Anthropic, "Context windows," Claude Developer Platform documentation, accessed 6 September 2026.↩
- Cheng-Ping Hsieh et al., "RULER: What's the Real Context Size of Your Long-Context Language Models?", arXiv:2404.06654v3, 6 August 2024.↩
- Nelson F. Liu, Kevin Lin, John Hewitt, Ashwin Paranjape, Michele Bevilacqua, Fabio Petroni, Percy Liang, "Lost in the Middle: How Language Models Use Long Contexts," Transactions of the Association for Computational Linguistics 12 (2024); arXiv:2307.03172.↩
- IEC 62474:2018, Material declaration for products of and for the electrotechnical industry, second edition, November 2018; via the IEC TC 111 factsheet.↩
- Bain & Company, Global Private Equity Report 2026, "Welcome to a New Era," 22 February 2026.↩
- Covington & Burling LLP, "ECHA Launches a New Public Consultation on a Proposed Universal Ban on PFAS in the EU," 26 March 2026.↩
- Varun Magesh, Faiz Surani, Matthew Dahl, Mirac Suzgun, Christopher D. Manning, Daniel E. Ho, "Hallucination-Free? Assessing the Reliability of Leading AI Legal Research Tools," Journal of Empirical Legal Studies 22 (2025), doi:10.1111/jels.12413.↩