Digital Hound
Field NotesA stack of official documents and folders with a single ochre-colored magnifying glass resting on top, symbolizing investigation and verification.

July 24, 2026 · 13 min read

Due Care and Due Diligence: Definitions, Differences, and Legal Application

Learn how due care and due diligence differ in law, where each standard creates liability, and how counsel can document both for a defensible position.


Due care and due diligence are related but legally distinct standards. Due care is the ongoing obligation to act as a reasonable, prudent professional would, while due diligence is the structured, pre-decisional investigation conducted before a transaction or commitment. Conflating them creates separate liability exposure that neither standard alone can cure.

Understanding Due Care and Due Diligence as Legal and Operational Concepts

Common law developed both concepts across centuries of negligence doctrine and corporate governance litigation, yet both are routinely conflated in boardrooms and courtrooms alike. Understanding where each standard originates, and why the distinction survived that long commercial history, is the first discipline any competent advisor must master.

What is due care, and how is it defined in law and professional practice?

Due care is the standard of conduct expected of a reasonable, prudent professional operating in the same role and circumstances. Its lineage runs directly to 19th-century tort law, where negligence doctrine required defendants to act as a hypothetical reasonable person would. Canadian courts apply an objective test: what would a prudent professional in like circumstances have done? The care involves an ongoing, behavioural obligation, not a one-time act. The CISSP certification curriculum, within its governance domain, frames due care as "doing the right thing," a formulation that captures its continuous character. Reasonable care is the accepted legal synonym in Canadian negligence analysis.

What is due diligence, and what does a proper investigation actually entail?

Due diligence is a structured, pre-decisional investigation designed to surface material risk before a transaction, engagement, or commitment is made. Where due care is ongoing, due diligence is time-bounded and produces a deliverable. ISO 31000, the international risk-management framework published by the International Organization for Standardization, contextualises the assessment process within a broader governance and risk-management standards architecture. A proper investigation draws on publicly available primary sources: corporate registries, court records, and regulatory filings. For a detailed methodology, see our guide to corporate due diligence investigations. SEDAR+ securities filings and CanLII court decisions are standard primary-source layers in a Canadian investigation.

Why both standards matter to litigation counsel and in-house advisors

Failure to satisfy either standard independently creates separate liability exposure. A director can satisfy a diligence obligation at transaction close and still breach due care through post-closing neglect. The Canadian Business Corporations Act, at section 123(4), provides a statutory due diligence defence for directors who relied in good faith on professional reports, but that defence does not extend to subsequent conduct. In-house counsel increasingly requires documented evidence of both standards for board reporting and regulatory requirements audits. Organisations that maintain contemporaneous records of both the pre-decisional investigation and the ongoing governance programme are materially better positioned when a regulator or plaintiff's counsel reviews the file.

How Do Due Care and Due Diligence Differ From Each Other?

Think of due diligence as conducting a structural inspection before purchasing a building, and due care as the maintenance programme you commit to for every year you own it. One is a pre-decisional investigation; the other is an ongoing standard of conduct. The legal consequences of confusing them are significant.

DimensionDue DiligenceDue Care
TimingBefore a decision or commitmentContinuously, after the decision
Nature of obligationInvestigative, time-boundedBehavioural, ongoing
Who bears itDecision-makers, acquirers, boardsDirectors, officers, the organisation
Legal standardStructured inquiry producing a deliverableObjective reasonableness in conduct
Consequence of failureLiability for uninformed decisionsLiability for neglect or inadequate monitoring

The procedural distinction: investigation versus ongoing conduct

Due diligence is a bounded process with a defined scope, methodology, and deliverable. Due care is a continuous practice: an organisation's security posture, monitoring regime, and incident-response readiness. NIST SP 800-53 illustrates what adequate organisational controls look like across control families ranging from access management to audit and accountability. Assessment of whether an organisation satisfied due care often turns on whether those control families were implemented and maintained, not merely documented at inception.

Temporal differences: what happens before a decision versus what follows it

Due diligence precedes the triggering event: a transaction, a hire, or an engagement. Due care governs every action taken thereafter. Courts examine both phases when assessing whether an organisation acted reasonably across the full lifecycle of a decision. A gap in either phase, even if the other was executed competently, can constitute a breach. Canadian courts have addressed both standards in proceedings dating to the 1990s, confirming that the temporal divide is not merely academic. Risk management obligations do not dissolve once a contract is signed; they shift in character from investigative to supervisory.

How courts and regulators distinguish the two when liability is assessed

A court conducting a negligence or statutory analysis typically asks two sequential questions: did the organisation conduct a proper investigation before acting, and did it maintain appropriate conduct after acting? Securities regulators and privacy commissioners in Canada assess due care through audit trails and monitoring records. For cross-border matters, the California Attorney General has published compliance expectations that parallel Canadian obligations and are relevant for organisations with US exposure. Enforcement reviews in both jurisdictions have focused on the absence of documented monitoring as the pivotal evidentiary gap. For a litigation-ready approach to the pre-decisional phase, see our litigation-ready due diligence framework.

Practical illustration: a corporate transaction where both standards must be satisfied simultaneously

Consider a hypothetical Canadian acquirer evaluating a target company. During the 30- to 90-day due diligence window common in Canadian M&A practice, the acquirer commissions an OSINT-based investigation: corporate registry searches across all relevant jurisdictions, court record reviews, regulatory filing analysis, and adverse media screening. That work satisfies the diligence limb. Post-closing, however, the acquirer must maintain adequate cybersecurity measures, incident-response protocols, and monitoring of acquired assets, including any virtual data environments inherited from the target. Compliance obligations do not end at signing. Failure at the post-closing care stage, even where pre-closing diligence was thorough, can expose the acquiring organisation to liability. Both standards must be satisfied across the full transactional lifecycle, and the evidentiary record must reflect that continuity.

Legal Implications of Due Care: Standards, Liability, and Defensibility

A director who conducts thorough pre-transaction diligence but then delegates security monitoring to an understaffed team without oversight has not satisfied due care, and no amount of pre-closing documentation will cure that gap when a regulator or plaintiff's counsel comes looking.

What is the legal definition of due care, and which standard of reasonableness applies in Canada?

Canadian courts apply an objective reasonableness standard under CBCA section 122: what would a prudent director or officer in like circumstances have done? The provision, materially reformed during the 2001 CBCA amendments, distinguishes the objective care obligation from the subjective good-faith element that applies separately. Senior management cannot satisfy the standard by asserting honest intent; conduct is measured against what a competent peer would have done. CISSP certification bodies codify similar distinctions in their governance domain, reinforcing the principle that professional-standard frameworks inform what courts regard as reasonable conduct.

How a failure of due care exposes directors, officers, and counsel to civil liability

Three principal vectors of exposure arise from a due care failure. First, shareholder derivative actions where the board's neglect caused loss to the organisation. Second, regulatory enforcement by securities commissions or privacy commissioners acting on the absence of documented monitoring. Third, counterparty claims in commercial disputes where the wrong conduct, action falling below the reasonable-person standard, caused measurable harm. Ontario Securities Commission enforcement actions have increased materially over the past decade, with monitoring failures cited repeatedly. An organisation that suffers a data security incident with no documented cybersecurity policies or incident-response programme will find it difficult to demonstrate due care before a tribunal. The trigger is not intent; it is the gap between actual conduct and the objective standard.

Documenting reasonable conduct so it withstands scrutiny in litigation

Documentation is the evidentiary bridge between conduct and legal defence. Board minutes, written policies and procedures, audit logs, vendor-assessment records, and periodic risk-review reports collectively constitute the record a court or regulator will examine. ISO/IEC 27001, last revised in 2022, and NIST frameworks provide evidence of a structured, reasonable programme aligned with recognised standards. A live expert CISSP engaged as a witness or internal resource can speak to whether implemented controls satisfy professional norms, but certification alone does not substitute for implemented controls. The written record must demonstrate comprehensive ongoing monitoring, not merely an initial assessment. Maintaining security posture across the full post-decision period is what the documentation must reflect, and periodic review reports are the clearest sign of that commitment.

The Due Diligence Process: Structured Steps for Defensible Investigations

Corporate fraud losses reported to Canadian courts and regulators run into hundreds of millions of dollars annually, and a consistent pattern in post-incident reviews is that a structured due diligence process was either absent or insufficiently documented before the relevant business relationship was formed.

Scoping the investigation: defining the subject, jurisdiction, and risk threshold

Scope definition is the most consequential decision in any investigation. An under-scoped investigation creates false assurance and can itself become evidence of inadequate diligence. A structured scoping process should follow five steps:

  1. Define the subject entity or individual with precision, including all known aliases and associated legal entities.
  2. Identify the jurisdiction or jurisdictions and the applicable legal standards governing disclosure in each.
  3. Set the risk threshold and materiality criteria that determine investigation depth.
  4. Specify authorised source categories, distinguishing primary from secondary sources.
  5. Establish the deliverable format and citation standard required for the intended use.

Canada's 13 provincial and territorial registry systems each constitute a distinct source layer, and all 13 must be considered when the subject's registration history is uncertain.

Primary source research: corporate registries, court records, and regulatory filings

Specific primary sources form the foundation of a litigation-grade investigation. Corporations Canada and provincial registries such as the Ontario Business Registry confirm incorporation status, officer and director history, and registered addresses. SEDAR+ replaced SEDAR in 2023 as Canada's primary securities disclosure platform and is the authoritative source for material change reports and annual filings. CanLII provides searchable court decisions across all Canadian jurisdictions. Land title offices confirm property ownership. The NIST SP 800-30 risk assessment methodology provides a recognised framework for structuring the analytical phase once source data is collected. Primary sources are required for a litigation-grade report because their provenance is verifiable and their content is not filtered through a third-party aggregator.

What publicly available information sources are considered reliable for a litigation-grade report?

Primary sources establish facts; secondary sources corroborate them. Corporate registries, court records, and official regulatory databases are primary. News archives, professional profile platforms such as LinkedIn, and corporate websites are secondary. LinkedIn, with over 1 billion registered users globally, is a significant secondary-source layer for professional-history verification and identification of undisclosed affiliations, but its content is self-reported and must be cross-referenced against primary sources before it can be relied upon. Canadian courts have admitted OSINT-sourced evidence where the methodology is documented, the source is publicly accessible, and the chain of custody is transparent. A comprehensive report treats secondary sources as corroborating, not establishing, and notes any material discrepancy between the two layers. For guidance on sensitive data handling and digital source methodology, our digital due diligence guide for Canadian counsel addresses the full source architecture.

Cross-border and multilingual research considerations for Canadian matters with international exposure

Canadian commercial matters frequently involve counterparties incorporated in multiple jurisdictions: Delaware, British Columbia, and offshore financial centres such as the British Virgin Islands. Each jurisdiction has distinct registry access, language requirements, and source reliability considerations. Canada's 10 provinces and 3 territories each maintain separate corporate registries, creating at least 13 domestic source layers before any cross-border layer is added. Offshore jurisdictions such as the British Virgin Islands have limited public registry disclosure, and that limitation must be documented transparently in any report rather than papered over. Multilingual OSINT requires verified translation protocols; machine translation alone is insufficient for a defensible report where the translated content is relied upon as evidence. Risk management across multi-jurisdictional matters requires systematic source mapping before research begins, and the process must be reproducible.

Producing a fully cited written report that satisfies evidentiary standards

A litigation-grade report must cite every source with its URL, access date, and the date of the underlying record. It must disclose methodology, state limitations, and be reproducible by a reader with access to the same public sources. Hearsay challenges are reduced materially when the source is a government registry or court record, because those documents are self-authenticating in many Canadian proceedings. A standard report typically documents 10 or more distinct source categories, ensuring that the compliance and decision-support value of the report is grounded in traceable evidence rather than unverifiable assertions. The action of producing a fully cited report is itself a form of due care: it demonstrates that the investigation was conducted methodically. For a complete practitioner's framework, see our practitioner's guide to corporate due diligence.

Due Diligence as a Risk Management Instrument in Corporate Disputes and Litigation

When a commercial dispute is already in motion, is it too late for due diligence to add value, or is that precisely when a structured intelligence-gathering process becomes most important to counsel's strategy?

How does due diligence support risk identification and assessment before a dispute escalates?

Pre-litigation OSINT investigations serve functions that overlap with but are distinct from transactional diligence. Asset investigation prior to judgment enforcement is a recognised litigation strategy in Canadian courts, allowing counsel to identify attachable property before committing to enforcement proceedings. Skip tracing using publicly available sources is lawful and routinely used to locate defendants for service of process. Fraud analysis using OSINT can surface beneficial ownership structures concealed through corporate layering, a pattern that becomes visible when registry records across multiple jurisdictions are aggregated and cross-referenced. CISA's guidance on risk identification and assessment practices provides a reference standard for how organisations should structure their risk-identification programmes, and counsel can reference that standard when advising clients on pre-litigation intelligence gathering. Pre-litigation OSINT reports also inform decisions on settlement strategy and quantum assessments, providing counsel with an evidence base before negotiations begin.

Key Takeaways

  • Due care is an ongoing behavioural obligation measured against an objective reasonableness standard; due diligence is a time-bounded, pre-decisional investigation with a documented deliverable. Confusing the two creates distinct and separate liability exposure.
  • Canadian directors face liability under CBCA section 122 for due care failures that occur after a transaction closes, even where pre-closing diligence was thorough and well-documented.
  • A litigation-grade due diligence report cites every primary source with URL, access date, and record date, and is reproducible by any reader with access to the same public sources.
  • Cross-border and multilingual investigations require jurisdiction-specific source mapping and verified translation protocols; offshore registry limitations must be disclosed transparently rather than omitted.
  • Documentation of ongoing monitoring, periodic risk reviews, and incident-response protocols is the evidentiary foundation of a due care defence and should be maintained continuously, not assembled retrospectively.

FAQ

What is the simplest way to explain the difference between due care and due diligence?

Due diligence is what you do before making a decision: a structured investigation to surface material risk. Due care is what you do after the decision is made: maintaining a reasonable standard of conduct on an ongoing basis. Both standards apply independently. Satisfying one does not discharge the obligation to satisfy the other. The temporal divide is the clearest practical marker.

Does the CISSP certification curriculum address due care and due diligence?

Yes. The CISSP certification governance domain formally distinguishes the two concepts as a testable topic. It frames due care as the obligation to "do the right thing" on a continuous basis, and due diligence as the prior investigation that informs a decision. Practitioners preparing for the CISSP examination, and organisations designing governance programmes, use this distinction to structure their security and compliance frameworks.

Can a director rely on a due diligence report as a complete defence to liability?

Not on its own. The CBCA section 123(4) defence allows directors to rely in good faith on professional reports, but that defence applies to the decision itself, not to subsequent conduct. A director must also satisfy the ongoing due care standard under section 122. A strong pre-decision report combined with documented post-decision monitoring and governance is a much more defensible position than either element alone.

What sources are acceptable for a litigation-grade due diligence investigation in Canada?

Acceptable primary sources include:

  • Corporations Canada and provincial/territorial corporate registries
  • SEDAR+ for securities filings
  • CanLII for court decisions
  • Land title offices for property records
  • Federal and provincial regulatory databases

Secondary sources such as LinkedIn and news archives may corroborate findings but should not establish material facts independently. Every source must be cited with its URL and access date.

Is OSINT-based due diligence admissible as evidence in Canadian proceedings?

Canadian courts have admitted OSINT-sourced evidence where the methodology is documented, the sources are publicly accessible, and the chain of custody is clear. Government registries and court records carry inherent reliability. Secondary sources require corroboration. The key factor is reproducibility: a reader with access to the same public sources should be able to verify every finding in the report.