IT Due Diligence in M&A: The Questions Buyers Aren’t Asking (But Should Be)

IT due diligence in M&A

Buy a business today and almost everything about it gets examined before you sign. The financials, the legal exposure, the tax position, the commercial pipeline, the culture, and increasingly the environmental and governance record are all scrutinized in detail.

One part, however, is missing. The technology and systems the entire operation runs on rarely get the same scrutiny as the numbers, even though the numbers are produced by them.

The problem is not that these questions get answered badly. It’s that they never get asked. A deal team is built around finance, law, and commercial strategy, and technology sits outside all three seats, so a predictable set of questions goes unasked in deal after deal. The answers still arrive. They just arrive after closing, as the buyer’s cost.

Why These Questions Get Skipped

The reason is structural instead of careless. A deal team is assembled from the disciplines that have always defined risk: finance, law, tax, and commercial strategy. Technology has never had a permanent seat, so no one at the table owns it.

That leaves one source of answers: the target’s own people. Ask them whether the systems are sound, and the response is almost always yes, offered by the same team that built and runs those systems. It’s rarely dishonest, just not independent, and the absence of a clear “no” gets read as a “yes.”

Add the pressure of a live deal, where timelines are tight and attention flows to the areas everyone already knows how to price, and the technology review quietly falls off the list. The same gap opens deal after deal.

Here are the questions buyers should be asking. Each one looks technical, but they’re really about the value on the table.

1.    What Breach Is Already Inside the Business We’re Buying?

This question gets skipped because a breach nobody has detected looks exactly like no breach at all. The target reports a clean record and on paper it has one.

The trouble is how long breaches stay hidden. According to IBM’s 2025 Cost of a Data Breach Report, the average breach takes 241 days to identify and contain, and breaches that run past 200 days cost significantly more than those caught earlier. A network compromise that began before the deal can sit undetected well beyond closing, which means the buyer, not the seller, is the one who eventually finds it.

When you acquire a company, you acquire its security history along with it. The right time to find a breach is before it becomes yours to fix.

2.    If One Person Left Tomorrow, Would the Systems Still Run?

In most businesses, one person quietly holds things together. They know:

  • which undocumented fixes keep a fragile system running
  • where the passwords live that were never written down
  • why the environment is built the way it is and what breaks if you change it

Everything runs smoothly right up until that person walks out the door.

This question gets skipped because the dependency is invisible on paper. There’s no line item for knowledge that lives in a single person’s head, and the one person best placed to flag the risk is usually the one the business can least afford to lose.

For a buyer, the honest answer tells you how much of what you’re acquiring depends on someone staying. Retention packages, documentation, and rebuilt processes all carry a cost, and it’s a far higher one when the gap surfaces after signing instead of before.

3.    What Will It Actually Cost to Integrate These Two Environments?

Every deal model has a number for integration. The real question is where that number came from and whether anyone has looked at the two technical environments closely enough to trust it.

This one gets skipped because integration is treated as a line to be estimated rather than a problem to be examined. The figure gets set early, often before anyone has mapped how the target’s systems are built or how well they’ll fit alongside the buyer’s own. By the time the real picture emerges, the deal is done and the estimate has become a commitment.

The gaps often show up as a run of smaller costs: overlapping systems that duplicate the same function, licenses renegotiated at a worse rate, data that won’t move cleanly between platforms, and the lost time while two businesses try to operate as one. Each is manageable on its own. Together, they turn a projected synergy into a cost the buyer quietly absorbs.

For a buyer, the honest answer tests whether the deal thesis survives contact with the target’s actual systems. Integration is where the value of a merger is realized or eroded, and the difference usually comes down to how well the cost was understood before anyone signed.

4.    How Much of the Target’s Compliance Exposure Becomes Ours?

The answer is all of it. When a deal closes, the target’s compliance position transfers to the buyer exactly as it stands, including the gaps the seller never mentioned and the ones the seller never knew were there. Regulatory obligations don’t wait for an integration plan.

This question gets skipped because compliance looks like paperwork and the paperwork is usually on file. But a policy on file isn’t the same as a control that works and the distance between the two is where the exposure sits. The target’s own team is rarely the one to point it out.

For a buyer, the honest answer shows what you’re taking on the instant you own the business: the obligations tied to the data it holds, the contracts it has signed, and the rules it operates under. A gap in any of them stops being the seller’s problem the moment you sign, which makes closing the gap part of the deal, rather than an afterthought once it’s done.

5.    Is This Technology Built for Where We’re Taking the Business?

Every acquisition is a bet on the future, but the technology being acquired was built for the past. It works today, which isn’t the same as being ready for what you plan to do next.

This question gets skipped because a system that runs is easy to mistake for a system that will scale. The strain doesn’t show until you push more volume, users, or locations through it, which is exactly what a buyer intends to do. That’s when technical debt comes due, and it’s rarely small: McKinsey research puts it at 20 to 40 percent of the value of a company’s entire technology estate. Systems quietly nearing end of life become urgent, unbudgeted replacement projects, and the platform meant to carry the growth plan becomes the thing that limits it.

Infrastructure built for the business a company used to be isn’t right for the business a buyer is trying to create. The honest answer tells you whether the technology can carry the plan or whether the cost of rebuilding it belongs in the price.

Ask These Questions Before You Sign

These questions often go unasked because the deal table has no seat for technology, and the only people who can answer sit inside the business being sold.

That’s the gap an independent, pre-deal technology review is built to close. A Quality of IT Assessment puts all five questions on the table before the letter of intent, examines the answers independently rather than through the team that built the systems, and reports back in business terms: what’s sound, what carries risk, what it will cost to put right, and what that means for the value on the table.

It doesn’t slow the deal down, but it does make sure the price reflects what you’re actually buying.

The right time to ask these questions is before the deal is done. See how a Quality of IT Assessment protects the value of your next transaction.

 

 

IT due diligence in M&A