Skip to content

Decision guide · IT due diligence for M&A

The deal price rarely includes the integration bill.

Technology risk and the cost of combining two IT estates are decisions to make with evidence - before the deal closes, not after the first month of surprises.

Two working IT estates do not simply add together.

A merger or acquisition brings a second set of identities, licenses, contracts, devices, and security assumptions into an organization that already has its own. On paper it looks like a bigger version of what exists. In practice it is two operating models that were never designed to meet.

IT due diligence is the decision to examine that second estate honestly before committing - and to price the integration, not just the acquisition. The goal is not a clean bill of health; it is a clear-eyed list of what will cost time, money, and risk to combine.

Done before signing, it informs the price and the plan. Done after, it becomes a series of expensive discoveries that leadership has to absorb without the leverage the negotiation would have given.

Boundary

Due diligence surfaces and prices technology risk. It does not replace legal, financial, or security assessment by the appropriate specialists.

Diligence lenses

Six things to verify before the deal is priced.

  • Identity and accessHow are accounts, permissions, and directories run, and how far apart are the two models?
  • Licensing and contractsWhat agreements transfer, what re-prices on change of control, and what auto-renews?
  • Security postureWhat baseline exists, what incidents are known, and what obligations follow the data?
  • Technical debtWhat runs on unsupported systems or single points of knowledge that leave with people?
  • Integration surfaceWhich systems must connect, migrate, or be retired, and in what order?
  • Key dependenciesWhich vendors, staff, or custom work is the acquired business quietly dependent on?

Working process

Assess, then decide the integration path.

  1. Inventory the second estate

    Establish what the acquired business actually runs - identity, licensing, contracts, devices, and security baseline - from evidence, not a summary.

  2. Price the integration options

    Compare absorbing, running parallel, or retiring each system, with the effort and risk each path carries.

  3. Flag deal-affecting findings

    Separate routine integration work from findings material enough to change the price, timeline, or terms.

  4. Sequence the first hundred days

    Decide what must happen immediately for continuity, and what can wait, so day one has a plan rather than a scramble.

Two directories combining is an identity governance decision first

Hypothetical example

Two collaboration platforms, one workforce

An acquired company runs a different collaboration and email platform than the buyer. The naive plan migrates everyone immediately; the real decision weighs identity dependencies, user disruption, contract timing, and how much overlap actually exists. Vendor consolidation and disaster-recovery expectations both shift the moment two estates combine - and the useful answer is a sequence, not a single-quarter deadline.

See how consolidation frames this

Next step

Bring the deal before the integration surprises arrive.

A focused brief can turn a target's technology estate into a priced integration plan and a short list of deal-affecting findings.