Amazon Bedrock AgentCore、M&A 実務の迅速化を支援
本文の状態
日本語全文を表示中
詳細モードで約18分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
AWS Machine Learning Blog
Amazon は Bedrock AgentCore を活用したマルチエージェントシステムにより、M&A のデューデリジェンスにおけるデータ収集や分析の自動化を実現し、従来数週間かかった作業を数時間で完了させる可能性を示した。
Continue in AI NEW LAB
このニュースを、実務の判断につなげる
AI NEW LABで、試したことや先に確認したい条件を共有できます。まずはログインなしで読めます。
AI NEW LABで論点を見るAI深層分析を開く2026年8月14日 01:13
AI深層分析
キーポイント
M&A デューデリジェンスの課題
アナリストが手動で財務データベースや規制書類を検索・照合するプロセスは時間がかかり、リソースを浪費し、重複作業が発生しやすい。
AI エージェントによる自動化
Amazon Bedrock AgentCore は自律的なデータ収集と分析を行い、数週間の作業を数時間で完了させることで、反復的な検索・要約ループから人間を解放する。
ガバナンスと監査可能性
法務およびコンプライアンスチームの懸念に応えるため、AI 生成の洞察が正確で追跡可能であり、出典引用によって裏付けられる仕組みを構築する。
組織的知識の蓄積
完了した分析結果が共有メモリ層に蓄積され、過去の取引からの知見を活用することで、将来的な取引における研究効率を高める。
組織的知識の蓄積と共有
完了した分析が共有メモリ層を強化し、過去の調査やバリュエーション仮定から未来の取引が利益を得る。チームは文脈を最初から作り直す必要がなくなる。
重要な引用
work that previously required weeks of analyst time was completed in hours because the agent handles the repetitive search-and-summarize loop without human intervention
governance concerns slow AI adoption because legal and compliance teams require confidence that AI-generated insights are accurate, traceable, and supported by source citations
Each completed analysis enriches a shared memory layer so that future deals benefit from prior research, valuation assumptions, and integration lessons.
Governance is built into the agent workflow from the start, not added as an afterthought.
編集コメントを表示
編集コメント
このブログ記事は、単なる概念ではなく具体的な実装アーキテクチャとサンプルリポジトリを提供しており、実務レベルでの AI エージェント適用を可能にする。特にガバナンスと監査可能性への言及は、大規模企業における AI 導入の障壁を取り除く重要な示唆を含んでいる。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
M&A(合併・買収)チームが直面する恒久的な課題は、スピードと分析の厳密性を保ちながら、複数の買収対象に対して入念なデューデリジェンスを行うことです。多くのチームでは、実現可能な機会を特定するまでに数週間を費やして手作業で対象企業を検証しています。
Amazon Bedrock AgentCore は、あらゆるフレームワークやモデルに対応し、大規模にエージェントの構築・接続・最適化を実現するプラットフォームです。このプラットフォームは、定義されたガードレール内でデータ収集、分析、コンプライアンスチェックを自律的に処理する AI エージェントをオーケストレーションすることで、デューデリジェンスのプロセスを加速させます。
本稿では、Amazon Bedrock AgentCore 上でマルチエージェントによるデューデリジェンスシステムを構築する方法を紹介します。エージェントのオーケストレーション、知識検索、ガバナンス制御を組み合わせた参照アーキテクチャを提示し、完全なサンプルリポジトリを使用してソリューションを展開・実行する手順を解説します。
M&A デューデリジェンスの課題
例えば運輸・物流業界では、アナリストが金融データベースや市場調査アプリケーション、規制関連の届出書類、社内ナレッジベースからデータを抽出し、それらを人手で照合しています。このプロセスは時間がかかり、リソースを大量に消費します。
チーム間で作業が重複すると、問題はさらに複雑化します。業界調査やバリュエーションモデル、競合分析などは、過去の取引から蓄積された組織的な知見を基盤にせず、新規の取引ごとに毎回作り直されてしまいます。一方、ガバナンスに関する懸念が AI の導入を遅らせています。法務部門やコンプライアンスチームは、AI が生成したインサイトが正確であり、追跡可能で、出典の根拠が明確であることを確信できない限り、その活用には慎重になるからです。
これらの4つの圧力(サイクルの遅延、データの断片化、作業の重複、ガバナンス要件)こそが、AI エージェントがデューデリジェンスの運用方法を根本から変える絶好の機会となっています。
AI エージェントがデューデリジェンスを変革する仕組み
AI エージェントは、自律的なデータ収集、インテリジェントなルーティング、永続的な記憶機能、そして組み込まれた監査可能性を組み合わせることで、これらの課題に立ち向かいます。
データ収集の現場では、エージェントが金融データベースやナレッジベース、市場データ API といった複数のソースに対して自律的にクエリを実行し、その結果を統合して暫定的な評価レポートを作成します。テストの結果、従来はアナリストが数週間かけていた作業が、人間が介入することなく反復的な検索と要約のループを処理するエージェントによって、わずか数時間で完了することが確認されました。
優先順位付けにおいて、エージェントは戦略的基準に基づいて機会を評価し、高優先度の取引を適切な専門家にルーティングします。すべての対象を順次レビューするのではなく、システムは最も有望な候補者を最初に提示し、より深い分析が必要な特定の次元(財務パフォーマンス、戦略的適合性、コンプライアンスリスク)にフラグを立てます。
エージェントはまた、時間とともに組織の知見を構築していきます。完了した各分析が共有メモリ層を強化するため、今後の取引では過去の調査、バリュエーションの前提条件、統合からの教訓を活用できます。チームは文脈をゼロから作り直す必要がなくなります。
ガバナンスはエージェントワークフローに最初から組み込まれており、後付けで追加されるものではありません。システムは各エージェントが発行する主張が引用に基づき、引用チェック評価器によって検証されるように構成されています。各エージェントの呼び出しには監査証跡が生成され、ガードレールがランタイムで組織ポリシーを強制します。コンプライアンスチームは、各引用された主張をそのソースドキュメントまで遡って追跡できます。
アーキテクチャ判断:統合スイートかカスタムビルドか
異なる組織のニーズに適した2つの実装パスを紹介します。
オプション1: Amazon Quick(統合ソリューション)
Amazon Quick は、ビジネスインテリジェンスや調査ワークフローに特化した、すぐに使える AI 機能を備えています。標準的な分析パターンに合致するニーズであれば、本番環境への迅速な導入が可能です。
Amazon Quick Research は、専門的でエクスポート可能な詳細レポートを生成します。Amazon Quick Flows は、事前構築されたワークフローで反復作業を自動化します。また、Amazon Quick Index は、接続されたデータソース全体にわたる統一検索を提供します。
迅速な展開を希望する場合や、ワークフローが標準的なビジネスインテリジェンスのパターンと一致している場合、カスタム開発よりもフルマネージドサービスを選好する場合は、Amazon Quick が適しています。詳細情報や参考アーキテクチャについては、Announcing Amazon Quick をご覧ください。
また、独自の評価モデルや戦略的適合性フレームワークなど、専門的な要件に対応するために、カスタムの Amazon Bedrock AgentCore エージェントで Quick の機能を拡張することも可能です。このパターンの実用的な例については、Building Intelligent Contract Management with Quick and AgentCore を参照してください。このブログ記事では、Amazon Quick が文書管理とユーザーインターフェースを担い、Amazon Bedrock AgentCore が専門的なエージェントの協力を支える仕組みが紹介されています。
Option 2: Custom architecture with Amazon Bedrock AgentCore
Amazon Bedrock AgentCore(Amazon Bedrock AgentCore)を使えば、エージェントの動作やメモリ管理、調整を細かく制御できます。このアプローチは、独自の調査手法を持つ M&A チームや、複雑なマルチエージェント協調が必要なケース、専門的な社内システムとの連携が求められる場合、あるいはエージェントの動作やモデル選択を完全にコントロールしたい場合に特に適しています。
本稿では、運輸・物流分野のデューデリジェンス事例を具体例として、このカスタムアーキテクチャの詳細を探ります。実際に動作するマルチエージェントシステムを構築し、合成されたターゲットに対して実行、自動引用チェック評価器を通じて出力を検証します。
参照アーキテクチャ
カスタムパスを選択した M&A チーム向けに、以下の参照アーキテクチャが各コンポーネントの連携をエンドツーエンドで示しています。

図 1: Amazon Bedrock AgentCore を活用したマルチエージェント M&A デューデリジェンスアーキテクチャ
本アーキテクチャでは、Amazon Bedrock AgentCore を用いてマルチエージェントによるデューデリジェンスワークフローをオーケストレーションします。スーパーバイザーエージェントが 4 つの専門エージェントを調整し、それぞれがデューデリジェンスプロセスの異なるフェーズを担当します。ユーザーは Jupyter ノートブックまたはターミナルインターフェースを通じてシステムと対話しますが、AgentCore ランタイムがエージェントの実行と協働を管理します。本システムは、生成拡張検索(RAG)、構造化された財務分析、外部ツールとの連携、メモリ機能、ポリシーベースのガバナンスを組み合わせており、実運用レベルのデューデリジェンスワークフローをサポートしています。
エージェントオーケストレーション層
Amazon Bedrock AgentCore ランタイムは Strands Agents SDK を介して複数の専門エージェントを調整します。スーパーバイザーエージェントは「ツールとしてのエージェント」パターンを活用し、タスクの要件に応じてドメイン固有の専門家へリクエストをルーティングします。
ターゲットスクリーニングエージェントは、自然言語によるクエリを SQL に変換し、Amazon Aurora PostgreSQL に対して実行することで、買収候補の特定を行います。アナリストが「収益が 1 億〜5 億ドルで EBITDA マージンが 12% を超える中堅物流企業」を問い合わせた場合、エージェントはこれをパラメータ化されたクエリに変換します。その後、一致する行を取得し、ナレッジベースからの物語的な文脈情報を付加して結果を補完します。
財務分析エージェントは、構造化データと非構造化データの両方を用いて企業価値評価を行います。割引キャッシュフロー(DCF)分析や同業他社比較分析といった標準的なバリュエーション手法を適用し、AgentCore Gateway を介したツールを通じて市場乗数データを取得します。生成された初步的な企業価値には根拠となる仮定がインラインで明記され、経営陣の予測と過去の業績との乖離がある場合はフラグを立てて警告します。
戦略的適合性エージェントは、統合リスク、シナジー効果、組織間の整合性を評価します。AgentCore のメモリ(専用の prior_deals 名前空間を使用)から過去の取引に関する文脈情報を取得し、現在の買収対象企業のプロファイルが完了した買収事例と比較されます。これにより、ソースとなるメモへの言及を伴う統合リスクが特定されます。
コンプライアンス検証エージェントは、M&A ガバナンスチェックリストに基づいて回答内容の監査を行います。すべての事実上の主張を検証し、裏付けとなる出典引用がない記述をフラグ立てするカスタムの引用チェック評価器(AWS Lambda 関数として実装)を呼び出します。
主要なアーキテクチャコンポーネント
本アーキテクチャは、構造化データと非構造化データを組み合わせてエージェントの回答を検証済みの情報源に基づかせることで、信頼性を高めています。
Amazon Aurora PostgreSQL Serverless v2 は、構造化された財務データや運用データを保存します。Target Screening Agent は自然言語から SQL を生成し、RDS Data API を介してクエリを実行するため、アナリストが SQL を記述する必要なく、対象企業の指標を高速に取得できます。
Amazon Bedrock Knowledge Bases は Amazon Bedrock 内のフルマネージド型 RAG 機能であり、機密情報メモランダム(CIM)、財務諸表、プレスパック、内部ガバナンスチェックリストなどのデューデリジェンス文書をインデックス化します。エージェントは関連する記述を取得し、文中に引用を埋め込むことができます。
AgentCore Gateway は Amazon Bedrock AgentCore の機能の一つで、モデルコンテキストプロトコル(MCP)対応の統合を通じて、エージェントが外部ツールやサービスと安全に連携できるようにします。本アーキテクチャでは、エージェントはゲートウェイを介して AWS Lambda ベースのマーケットデータサービスを呼び出し、Cedar ポリシーによってツールの利用やエージェント間のやり取りに対する決定論的なアクセス制御が適用されます。
AgentCore memory は、対話全体を通じて文脈状態と再利用可能な組織的知識を維持します。セッションメモリは会話の継続性を保ち、長期的な prior_deals 名前空間には完了した買収からの教訓を保存し、将来の分析に役立てます。
Amazon Bedrock AgentCore の機能である「AgentCore Evaluations」では、Lambda ベースの評価器を使用して、出力の品質、引用の正確性、およびドメイン固有の基準を自動的に検証します。引用チェック評価器は、サポート対象と非対応の主張の数をカウントした構造化された合格/不合格の結果を返します。
Amazon Bedrock Guardrails は、ワークフロー全体を通じて安全性と応答制御を適用するものであり、スーパーバイザーレベルで適用されるため、専門家の出力も組織のポリシーチェックを通過できます。
すべての呼び出しにおいて、Amazon CloudWatch のログストリームが生成され、AWS X-Ray トレースによって、スーパーバイザーから専門家、ツールへの呼び出し階層全体が記録されます。これにより、エンドツーエンドの観測性が確保されます。
セキュリティ
M&A のデューデリジェンスでは、企業が扱う最も機微なデータが扱われます。未公開の財務情報、取引条件、統合計画などです。そのためセキュリティはアーキテクチャにおいて最優先事項となります。
エージェントが呼び出せる IAM 権限はすべて、ワイルドカードではなく特定の Amazon Resource Name (ARN) にスコープを限定しています。AgentCore Gateway のマーケットデータツールはさらに一歩進み、Cedar ポリシーエンジンを用いてデフォルト拒否と属性ベースの認可を実装しています。このツールが実行されるのは、要求された業種コードが承認された垂直領域に一致する場合のみです。それ以外は実行前にすべて拒否されます。
データベース層は、仮想プライベートクラウド (VPC) エンドポイントの背後にあるプライベートでインターネットから隔離されたサブネット内に配置されています。データストアは KMS によって保存時に暗号化され、Amazon Bedrock Guardrails がすべてのスーパーバイザー応答に対して有害なコンテンツや個別化された金融アドバイスがないかスクリーニングします。
この IAM、Cedar、ネットワーク分離、暗号化による多層防御モデルは、機密性の高い取引データを扱うシステムにおけるさまざまな障害モードに対応しています。
サンプルのデプロイと実行
完全な参照実装は、M&A Due Diligence Multi-Agent Sample リポジトリで利用可能です。このサンプルには合成データ(実際の企業や財務情報、個人を特定できる情報は含まれていません)、ワンコマンドでのデプロイ機能、Jupyter ノートブックによる解説が含まれています。
完全なデプロイ・実行・クリーンアップサイクルにかかる推定費用は 5 ドル未満です。
前提条件
デプロイ前に、以下の準備を確認してください。
- Amazon Bedrock のモデルアクセス権限が有効になっている AWS アカウント。Anthropic Claude および Amazon Nova を利用可能な場合は、AWS リージョン別の対応状況について Amazon Bedrock のリージョン別サポートモデル を参照してください。
- AWS Command Line Interface (AWS CLI) v2.15 以降。
- Python 3.11 以降。
Node.js 20 以降。
AWS Cloud Development Kit (AWS CDK) v2 (npm install -g aws-cdk)。
ローカル環境に Docker をインストールする必要はありません。エージェントのコンテナイメージは、AWS CodeBuild で構築されます。
デプロイ先として、us-east-1、us-west-2、ap-southeast-2、または eu-central-1 のいずれかの対応リージョンを選択してください。
ステップ 1: スタックのデプロイ
リポジトリをクローンして、デプロイスクリプトを実行してください。初回のデプロイには 20〜25 分かかります。
# macOS / Linux
git clone https://github.com/aws-samples/sample-ma-due-diligence-agentcore.git
cd sample-ma-due-diligence-agentcore
./deploy.sh# Windows
git clone https://github.com/aws-samples/sample-ma-due-diligence-agentcore.git
cd sample-ma-due-diligence-agentcore
.\deploy.ps1デプロイスクリプトは、リージョンとモデルへのアクセス権限を確認し、仮想環境を作成した上で cdk deploy --all を実行します。さらに合成データの初期化を行い、デプロイ後の簡易テスト(スモークテスト)も実施されます。
また、プロジェクトは編集可能なモードでインストールされるため、次のステップでエージェントを呼び出す際に使用するコマンドラインツール mna が登録されます。
ステップ 2: エージェントの呼び出し
mna CLI を使用して、個別の専門家にプロンプトを送信するか、スーパーバイザーにルーティングさせることができます。
# Let the supervisor orchestrate across specialists
mna invoke supervisor "Screen the mid-market logistics targets with revenue 100M-500M, then run a DCF on the top hit." --session-id walkthrough-session-00000000-0001
# Target Screening: text-to-SQL on Aurora + KB narrative enrichment
mna invoke target_screening "Screen the target pipeline for transportation companies with revenue between 100M and 500M USD, EBITDA margin above 12%, and fleet size above 200. Surface the top three and tell me what the CIM says about the leader's growth trajectory." --session-id walkthrough-session-00000000-0001
# Financial Analysis: KB retrieval + Gateway-backed market data tool
mna invoke financial_analysis "Run a DCF on Example Corp using the CIM in the knowledge base. Flag any management projection that diverges from historical performance by more than 20% and pull comparable multiples for transportation-logistics mid-market." --session-id walkthrough-session-00000000-0001
# Strategic Fit: AgentCore Memory long-term retrieval
mna invoke strategic_fit "Compare Example Corp' integration profile against our three most recent completed acquisitions. Identify the top three integration risks and cite the source memos." --session-id walkthrough-session-00000000-0001各呼び出しの実行後には、フッターに trace_id が表示されます。その呼び出しに対する完全な X-Ray トレースを確認するには、mna trace コマンドを使用してください。
ステップ 3: イヴァリューターで出力を検証する
mna evaluate サブコマンドは、専門家の出力に対して citation-check エビデンス評価器を実行します。
# Capture a response in JSON format
mna --json invoke financial_analysis "Run a DCF on Example Corp using the CIM." --session-id blog-demo-session-00000000-000002 > run.json
# --session-id accepts any string between 33 and 256 characters --- AgentCore Runtime enforces this length range for runtimeSessionId. The value above is just an example; use a unique string per session (a UUID works well) if you want to keep invocations isolated or omit --session-id entirely to let the client generate one for you.
# Extract response text and citations
python -c "import json,pathlib;d=json.loads(pathlib.Path('run.json').read_text());pathlib.Path('response.txt').write_text(d['text'])"
python -c "import json,pathlib;
d=json.loads(pathlib.Path('run.json').read_text());
pathlib.Path('citations.json').write_text(json.dumps(d['citations']))"
# Run the citation-check evaluator
mna evaluate --response-file response.txt --citations-file citations.json評価器は、合格または不合格を示す構造化された結果を返します。ここには総主張数、裏付けられた主張数、そして裏付けられていない主張のリストが含まれます。パスした場合の終了コードは 0、失敗の場合は 1 となり、CI パイプラインで組み込み可能です。
ステップ 4: ノートブックの確認
同じワークフローをセル単位で順を追って確認するには、ガイド付きノートブックをご利用ください。
jupyter lab notebooks/walkthrough.ipynbこのノートブックでは、環境の検証、データの概要、各専門家エージェントごとの処理(レンダリングされた回答と引用を含む)、そしてトレースの確認までを順に解説しています。
リソースの整理
継続的な課金を防ぐため、確認作業が完了次第、デプロイしたすべてのリソースを直ちに削除してください。
# macOS / Linux
./cleanup.sh# Windows
.\cleanup.ps1クリーンアップスクリプトは cdk destroy --all --force を実行し、依存関係の逆順でスタックをすべて破棄します。その後、検証を実行します。
原文を表示
Mergers and acquisitions (M&A) teams face a persistent challenge: conducting thorough due diligence on multiple acquisition targets while maintaining speed and analytical rigor. Teams often spend weeks manually reviewing targets before identifying viable opportunities. Amazon Bedrock AgentCore is a platform to build, connect, and optimize agents at scale, with any framework or model. It can accelerate this process by orchestrating AI agents that handle data gathering, analysis, and compliance checks autonomously within defined guardrails.
In this post, we show how to build a multi-agent due diligence system on Amazon Bedrock AgentCore. We present a reference architecture that combines agent orchestration, knowledge retrieval, and governance controls, then walk through deploying and running the solution using a complete sample repository.
The M&A due diligence challenge
In transportation and logistics, for example, analysts pull data from financial databases, market research applications, regulatory filings, and internal knowledge bases, then reconcile that information by hand. The process is slow and resource intensive.
The problem compounds when teams duplicate work. Industry research, valuation models, and competitive analyses get recreated for each new deal instead of building on institutional knowledge from prior transactions. Meanwhile, governance concerns slow AI adoption because legal and compliance teams require confidence that AI-generated insights are accurate, traceable, and supported by source citations.
These four pressures (slow cycles, fragmented data, duplicated effort, and governance requirements) create an opportunity for AI agents to fundamentally change how due diligence operates.
How AI agents transform due diligence
AI agents address each of these challenges through a combination of autonomous data gathering, intelligent routing, persistent memory, and built-in auditability.
On the data-gathering front, agents autonomously query multiple sources (financial databases, knowledge bases, market data APIs) and synthesize the results into preliminary assessments. In our testing, work that previously required weeks of analyst time was completed in hours because the agent handles the repetitive search-and-summarize loop without human intervention.
For prioritization, agents evaluate opportunities against strategic criteria and route high-priority deals to the right specialists. Rather than reviewing every target sequentially, the system surfaces the most promising candidates first and flags the specific dimensions (financial performance, strategic fitness, compliance risk) that warrant deeper analysis.
Agents also build institutional knowledge over time. Each completed analysis enriches a shared memory layer so that future deals benefit from prior research, valuation assumptions, and integration lessons. Teams stop recreating context from scratch.
Governance is built into the agent workflow from the start, not added as an afterthought. The system is configured so that each assertion the agent emits is grounded in a citation, validated by the citation-check evaluator. Each agent invocation produces an audit trail, and guardrails enforce organizational policies at runtime. Compliance teams can trace each cited claim back to its source document.
Architecture decision: integrated suite or custom build
We present two implementation paths, each suited to different organizational needs.
Option 1: Amazon Quick (integrated solution)
Amazon Quick provides ready-to-use AI capabilities tailored for business intelligence and research workflows. It offers a fast path to production if your needs align with standard analysis patterns. Amazon Quick Research generates professional, exportable in-depth reports. Amazon Quick Flows automates repetitive tasks with pre-built workflows. Amazon Quick Index delivers unified search across connected data sources.
Choose Amazon Quick if you want to deploy rapidly, your workflows align with standard business intelligence patterns, and you prefer fully managed services over custom development. For additional information and reference architecture, see the Announcing Amazon Quick.
You can also extend Quick with custom Amazon Bedrock AgentCore agents for specialized requirements such as proprietary valuation models or strategic fit frameworks. For a practical example of this pattern, see Building Intelligent Contract Management with Quick and AgentCore. That post demonstrates how Amazon Quick handles document management and the user interface while Amazon Bedrock AgentCore powers specialized agent collaboration.
Option 2: Custom architecture with Amazon Bedrock AgentCore
Amazon Bedrock AgentCore gives you fine-grained control over agent behavior, memory, and coordination. This approach suits M&A teams with proprietary methodologies, complex multi-agent coordination requirements, integration with specialized internal systems, or a need for complete control over agent behavior and model selection.
The remainder of this post explores this custom architecture in detail using a transportation-and-logistics due diligence scenario as context. We deploy a working multi-agent system, invoke it against synthetic targets, and validate outputs through an automated citation-check evaluator.
Reference architecture
For M&A teams choosing the custom path, the following reference architecture shows how the pieces fit together end to end.

**Figure 1: Multi-agent M&A due diligence architecture with Amazon Bedrock AgentCore
The architecture uses Amazon Bedrock AgentCore to orchestrate a multi-agent due diligence workflow. A supervisor agent coordinates four specialist agents, each responsible for a distinct phase of the due diligence process. Users interact through a Jupyter notebook or terminal interface, while AgentCore runtime manages agent execution and collaboration. The system combines Retrieval Augmented Generation (RAG), structured financial analysis, external tool integration, memory, and policy-based governance to support production-ready due diligence workflows.
Agent orchestration layer
Amazon Bedrock AgentCore runtime coordinates multiple specialized agents through the Strands Agents SDK. The supervisor agent uses the agents-as-tools pattern to route requests to domain-specific specialists based on task requirements.
The Target Screening Agent** identifies acquisition candidates by converting natural-language queries into SQL and executing them against Amazon Aurora PostgreSQL. When analysts ask for “mid-market logistics companies with revenue between 100M and 500M USD and EBITDA margins above 12 percent,” the agent translates that into a parameterized query. It then retrieves matching rows and enriches the results with narrative context from the knowledge base.
The Financial Analysis Agent performs valuation analysis using structured and unstructured data sources. It applies standard valuation methodologies including discounted cash flow (DCF) analysis and comparable company analysis, pulling market multiples through an AgentCore Gateway-backed tool. The agent generates preliminary valuations with supporting assumptions documented inline and flags management projections that diverge from historical performance.
The Strategic Fit Agent evaluates integration risks, synergies, and organizational alignment. It retrieves context from prior transactions stored in AgentCore memory (using a dedicated prior_deals namespace). It then compares the current target’s profile against completed acquisitions and identifies integration risks with citations to source memos.
The Compliance Validation Agent audits responses against the M&A governance checklist. It invokes a custom citation-check evaluator (implemented as an AWS Lambda function) that examines every factual claim in a response and flags assertions that lack a supporting source citation.
Key architecture components
The architecture combines structured and unstructured enterprise data to ground agent responses in verified sources.
- Amazon Aurora PostgreSQL Serverless v2 stores structured financial and operational datasets. The Target Screening Agent generates SQL from natural language and executes queries through the RDS Data API, providing fast access to target-company metrics without requiring analysts to write SQL themselves.
- Amazon Bedrock Knowledge Bases, the fully managed RAG capability in Amazon Bedrock, indexes due diligence documents including confidential information memoranda (CIMs), financial statements, press packs, and internal governance checklists. Agents retrieve relevant passages and cite them inline.
- AgentCore Gateway, a capability of Amazon Bedrock AgentCore, lets agents securely interact with external tools and services through Model Context Protocol (MCP)-compatible integrations. In this architecture, agents invoke an AWS Lambda-based market data service through the gateway, with Cedar policies enforcing deterministic access controls over tool usage and agent interactions.
- AgentCore memory maintains contextual state and reusable institutional knowledge across interactions. Session memory preserves conversation continuity, while a long-term prior_deals namespace stores lessons from completed acquisitions that inform future analyses.
- AgentCore Evaluations, a capability of Amazon Bedrock AgentCore, uses Lambda-based evaluators to automatically validate output quality, citation accuracy, and domain-specific criteria. The citation-check evaluator returns a structured pass/fail result with counts of supported and unsupported claims.
- Amazon Bedrock Guardrails enforces safety and response controls throughout the workflow, applied at the supervisor level so specialist outputs pass through organizational policy checks.
Every invocation produces an Amazon CloudWatch log stream and an AWS X-Ray trace that captures the full supervisor-to-specialist-to-tool call hierarchy, providing end-to-end observability.
Security
M&A due diligence involves some of the most sensitive data a company handles: unreleased financials, deal terms, and integration plans. Security is therefore a first-class part of the architecture. Every IAM permission the agents can invoke is scoped to a specific Amazon Resource Name (ARN) rather than a wildcard. The AgentCore Gateway market-data tool goes a step further with a Cedar policy engine that enforces default-deny, attribute-based authorization. The tool runs only when the requested industry code matches an approved vertical. Everything else is denied before it runs. The database tier lives in private, internet-isolated subnets behind virtual private cloud (VPC) endpoints. Data stores are encrypted at rest with KMS, and Amazon Bedrock Guardrails screen every supervisor response for harmful content and personalized financial advice. This layered model of IAM, Cedar, network isolation, and encryption covers different failure modes for systems that handle confidential deal data.
Deploy and run the sample
The complete reference implementation is available in the M&A Due Diligence Multi-Agent Sample repository. It ships with synthetic data (no real companies, financial data, or personally identifiable information), one-command deployment, and a Jupyter notebook walkthrough. The estimated cost for a full deploy-run-cleanup cycle is under USD $5.00.
Prerequisites
Before deploying, verify you have:
- An AWS account with Amazon Bedrock model access enabled for Anthropic Claude and Amazon Nova. For model availability by AWS Region, refer to Supported models by AWS Region in Amazon Bedrock.
- AWS Command Line Interface (AWS CLI) v2.15 or later.
- Python 3.11 or later.
- Node.js 20 or later.
- AWS Cloud Development Kit (AWS CDK) v2 (npm install -g aws-cdk).
- You don’t need Docker installed locally. The agent container image is built on AWS CodeBuild.
Deploy to one of the supported Regions: us-east-1, us-west-2, ap-southeast-2, or eu-central-1.
Step 1: Deploy the stack
Clone the repository and run the deploy script. First-time deployment takes 20–25 minutes.
# macOS / Linux
git clone https://github.com/aws-samples/sample-ma-due-diligence-agentcore.git
cd sample-ma-due-diligence-agentcore
./deploy.sh# Windows
git clone https://github.com/aws-samples/sample-ma-due-diligence-agentcore.git
cd sample-ma-due-diligence-agentcore
.\deploy.ps1The deploy script verifies your Region and model access, creates a virtual environment, runs cdk deploy --all, seeds synthetic data, and executes a post-deploy smoke test. It also installs the project in editable mode, which registers the mna command-line tool that you use to invoke agents in the next step.
Step 2: Invoke the agents
Use the mna CLI to send prompts to individual specialists or let the supervisor route across them:
# Let the supervisor orchestrate across specialists
mna invoke supervisor "Screen the mid-market logistics targets with revenue 100M-500M, then run a DCF on the top hit." --session-id walkthrough-session-00000000-0001
# Target Screening: text-to-SQL on Aurora + KB narrative enrichment
mna invoke target_screening "Screen the target pipeline for transportation companies with revenue between 100M and 500M USD, EBITDA margin above 12%, and fleet size above 200. Surface the top three and tell me what the CIM says about the leader's growth trajectory." --session-id walkthrough-session-00000000-0001
# Financial Analysis: KB retrieval + Gateway-backed market data tool
mna invoke financial_analysis "Run a DCF on Example Corp using the CIM in the knowledge base. Flag any management projection that diverges from historical performance by more than 20% and pull comparable multiples for transportation-logistics mid-market." --session-id walkthrough-session-00000000-0001
# Strategic Fit: AgentCore Memory long-term retrieval
mna invoke strategic_fit "Compare Example Corp' integration profile against our three most recent completed acquisitions. Identify the top three integration risks and cite the source memos." --session-id walkthrough-session-00000000-0001Every invocation prints a trace_id in its footer. Use mna trace to inspect the full X-Ray trace for that call.
Step 3: Validate outputs with the evaluator
The mna evaluate subcommand runs the citation-check evaluator against a specialist’s output:
# Capture a response in JSON format
mna --json invoke financial_analysis "Run a DCF on Example Corp using the CIM." --session-id blog-demo-session-00000000-000002 > run.json
# --session-id accepts any string between 33 and 256 characters --- AgentCore Runtime enforces this length range for runtimeSessionId. The value above is just an example; use a unique string per session (a UUID works well) if you want to keep invocations isolated or omit --session-id entirely to let the client generate one for you.
# Extract response text and citations
python -c "import json,pathlib;d=json.loads(pathlib.Path('run.json').read_text());pathlib.Path('response.txt').write_text(d['text'])"
python -c "import json,pathlib;
d=json.loads(pathlib.Path('run.json').read_text());
pathlib.Path('citations.json').write_text(json.dumps(d['citations']))"
# Run the citation-check evaluator
mna evaluate --response-file response.txt --citations-file citations.jsonThe evaluator returns a structured result indicating pass or failure, with counts of total claims, supported claims, and any unsupported assertions. The exit code is 0 on pass and 1 on fail, making it composable in CI pipelines.
Step 4: Explore the notebook
For a guided, cell-by-cell tour of the same workflow:
jupyter lab notebooks/walkthrough.ipynbThe notebook walks through environment validation, data overview, one cell per specialist agent (with rendered responses and citations), and trace inspection.
Clean up
To avoid ongoing charges, destroy all deployed resources as soon as you finish exploring:
# macOS / Linux
./cleanup.sh# Windows
.\cleanup.ps1The cleanup script runs cdk destroy --all --force to tear down every stack in reverse dependency order. It then executes a verificat
関連記事
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み