IT and technology due diligence

A plain-English assessment of a company's IT before you buy, invest or merge. What you're getting, what it will cost to fix and what could go wrong.

Why IT due diligence matters

Financial and legal due diligence are standard. Technology often gets a single page in the information memorandum and a reassuring call with the target's MSP. Yet IT is where some of the most expensive post-deal surprises sit: unlicensed software, an unsupported platform at the heart of operations, a security incident that hasn't been disclosed, or a key system that only one person understands.

What we assess

  • Infrastructure and platforms. What exists, how old it is, what's out of support and what it will cost to bring up to standard.
  • Security posture. Identity, device management, backups, incident history, Cyber Essentials or ISO 27001 status and insurance position.
  • Licensing and contracts. Microsoft and other licensing compliance, supplier contracts, notice periods and change of control clauses.
  • Key person risk. Where knowledge sits with one employee or one supplier.
  • Software and data. Bespoke systems, technical debt, data protection compliance and where the data actually lives.
  • Integration. What it will take to bring the business onto your platforms, with a rough cost and timeline.

What you get

A short written report that ranks findings by risk and cost, so the deal team can use it in negotiation. Every red flag comes with an estimate of what it would cost to fix and how urgent it is. We present the findings in a call and answer the deal team's questions.

Engagements are fixed scope and fixed fee, and can be turned around in days where the deal timetable demands it. Everything is under NDA.

After the deal

The same consultant can lead the integration or provide fractional IT leadership to the acquired business for the first year, so the findings turn into a plan rather than a filed report.

Common questions

What is technical due diligence?

Technical or IT due diligence is an independent assessment of a business's technology before an acquisition, investment or merger. It covers infrastructure, security, licensing, contracts, key person risk and integration costs.

How long does IT due diligence take?

A typical SME assessment takes one to two weeks, and can be faster if the deal timetable requires it.

Do you work for buyers or sellers?

Usually buyers and investors. We also help sellers prepare, so that their IT stands up to a buyer's scrutiny and doesn't knock value off the deal.

Is the work confidential?

Yes. All due diligence work is carried out under NDA.

Clouds gathering? Book a call.

Tell us a little about your business and what's on your mind. We reply personally, usually within one working day.

Book a call