Why IT Is the Most Overlooked Part of M&A Due Diligence
Why IT due diligence gets deprioritized in most acquisition processes, what that costs acquirers, and what a real IT assessment looks like in the context of a deal.
Walk through the typical M&A due diligence checklist and you'll find quality of earnings, legal review, environmental assessment, HR, real estate, customer contracts. IT gets a line item. Usually it says something like "technology review" and it gets assigned to whoever is available.
The result is a surface-level document that describes what systems exist without assessing their condition, identifies no security exposures, and produces integration cost estimates that bear no relationship to what integration actually costs.
This pattern is consistent enough to be worth examining directly.
Why It Happens
IT due diligence gets deprioritized for a few reasons that make sense in isolation but not together.
Most deal teams don't have deep IT expertise. The financial, legal, and operational due diligence workstreams are staffed with people who do that work every day. IT is staffed with whoever is available -- sometimes a generalist consultant, sometimes an IT person from the acquiring company's internal team who has never done acquisition work before.
IT also tends to be treated as a solvable problem post-close. The assumption is that whatever is there can be figured out after the deal is done. This is true in a narrow sense -- IT problems can always be fixed eventually. The question is what they cost to fix and who pays.
And timelines compress. In competitive processes, due diligence windows shrink. The workstreams that are perceived as deal-critical get the time they need. IT often gets what's left.
What Gets Missed
The things that surface in a real IT assessment -- and don't surface in a cursory one -- fall into a few consistent categories.
Software licensing is one of the most common problem areas. Software licenses are often not transferable to new ownership, meaning the acquiring company inherits a compliance exposure the moment the deal closes. Remediating this post-close means purchasing new licenses at full price, often under time pressure that removes any negotiating leverage.
Security is another. An organization with a poor security posture creates liability for the acquirer that begins on day one of ownership. In healthcare, that liability includes HIPAA exposure. In financial services, it includes regulatory reporting obligations. In any industry, it includes the possibility of a breach that the acquirer is now responsible for.
Integration complexity is routinely underestimated. The estimate usually comes from someone who hasn't looked at both sides of the integration. When someone does look -- at the network architecture, the identity systems, the business applications, and the data that needs to move -- the actual scope is consistently larger than the estimate. Sometimes two or three times larger.
What It Costs
The cost of inadequate IT due diligence shows up in a few ways.
Direct remediation cost: the expense of fixing things that would have been identified and potentially negotiated pre-close. License remediation, security fixes, infrastructure replacement. These costs are real and often significant.
Integration overrun: when integration costs twice what was projected, the budget comes from somewhere. Usually from the operational budget of the portfolio company at a time when it needs to be performing, not absorbing unexpected IT spend.
Operational disruption: integration problems that weren't anticipated cause operational disruptions. In a healthcare practice, that might mean clinical systems are unavailable during a transition. In a service business, it might mean staff can't access the systems they need to do their jobs. That disruption has a cost even when it's hard to quantify directly.
What a Real IT Assessment Looks Like
A real IT due diligence assessment takes five to ten business days depending on the complexity of the target. It requires access to the systems, not just documentation about them. It produces findings in business terms, not technical ones.
The output should answer three questions clearly: What is the condition of what we're buying? What are the risks we're taking on? What will it actually cost to integrate this into our existing environment?
It should be done by someone who has done this work across real acquisitions in the relevant industry, not by a generalist working from a template. The specific knowledge matters. A healthcare acquisition involves systems and compliance requirements that an assessor without healthcare IT experience will not evaluate correctly.
The Opportunity Cost of Getting This Right
Organizations that conduct real IT due diligence consistently use the findings as a negotiating tool. Issues that surface pre-close can affect purchase price, representations and warranties, holdbacks, or the decision to proceed at all. That's leverage that disappears the moment you close.
For PE organizations doing multiple acquisitions per year, the cumulative value of this leverage across a portfolio is meaningful. The cost of the assessments is not.
Extenia LLC provides fractional IT leadership and hands-on technology execution for multi-site organizations. Based in West Bloomfield, Michigan, serving clients nationally.
Start a Conversation