
The data room says the IT is fine. The data room always says that.
Independent technology due diligence for acquirers and investors: real integration cost, real risk, and the value levers the seller's deck leaves out.
Our principals have sat on the buying side of twelve M&A integrations and reviewed technology environments for two decades. Deal-breaking IT problems are rarely visible in a data room: they live in unsupported systems held together by one irreplaceable person, licensing that does not survive a change of control, security debt priced at zero, and integration costs estimated by optimism. We find them before the price is set, while they are still negotiating leverage.
Scope Your Due DiligenceChange-of-Control Surprises
Licences and contracts that terminate, reprice or require consent on acquisition, discovered after completion instead of priced into the deal.
Key-Person Systems
The critical platform only one employee understands, and the retention risk nobody has valued.
Inherited Security Debt
You acquire their breach history and their unpatched estate on day one. Warranty clauses are cold comfort mid-incident.
Optimistic Integration Estimates
Synergy models built on integration costs no technologist has verified are how deals underperform quietly for years.
What We Test
- Architecture and scalability against the investment thesis
- Contracts and licensing under change-of-control, itemised
- Security posture and inherited risk, independently verified
- Integration cost and timeline, estimated by people who have done it
- Key-person and vendor dependency mapping
- Post-completion technology value levers: the upside diligence misses
The Deliverable
The Technology Deal Report
Deal-grade findings in deal language: price adjustments, conditions, warranties and the 100-day technology plan.
- Red flag register with deal-impact ranking
- Integration cost model with stated assumptions
- Change-of-control exposure schedule
- Security and compliance position summary
- 100-day post-completion technology plan
Standards and regulations we assess against
Deal-grade technology diligence has to speak the language your lawyers, insurers and regulators use. Depending on the target's sector, the assessment maps against: the ACSC Essential Eight (security posture and inherited risk), the Privacy Act 1988 and Australian Privacy Principles (data holdings and breach exposure you acquire on day one), APRA CPS 234 and CPS 230 where the target touches regulated financial services, the Security of Critical Infrastructure Act where relevant, and ISO 27001 alignment where the target claims it. Contracts are reviewed specifically for change-of-control, assignment and consent triggers, the clauses that reprice deals after signing.
Integration scenarios, costed honestly
| Scenario | When it fits | What we cost |
|---|---|---|
| Run separate | Platform plays; targets kept at arm's length | Standalone run-rate, key-person risk, minimum governance uplift |
| Partial integration | Shared corporate services, separate operations | Identity, finance and security consolidation; the seams where most integration pain lives |
| Full integration | Synergy-case acquisitions | Complete migration cost and timeline, estimated by people who have led twelve of them |
The technology due diligence checklist
What the review actually covers, in the categories a data room rarely organises itself around:
- Strategy and spend: IT cost base versus benchmark, contract register, committed future spend
- Applications: core platform viability, licensing transferability, technical debt register
- Infrastructure and cloud: architecture scalability against the investment thesis, hosting commitments
- Security: Essential Eight posture, incident history, insurance position, inherited breach risk
- Operations and support: internal capability, MSP dependencies, service levels, exit terms
- People: key-person concentration, retention risk on critical systems knowledge
- Data: what personal and commercial data is held, where, under what obligations
- Change-of-control: every contract that terminates, repricies or requires consent on completion
Straight Answers
2x value identified, or you don't pay.
The 4-Week Commercial IT Health Check is fixed fee, non-disruptive, and guaranteed in writing: if we don't identify value worth at least twice our fee, we refund it.
