IT Due Diligence in M&A
What you need to know about the target company's IT before signing.
Related topics
IT Due Diligence – the foundation for successful business integration
IT is rarely a dealbreaker in the M&A process – but it is often an underestimated price driver. Worn-out systems, expensive contracts, vendor dependencies, and open compliance issues typically only emerge after closing, when there is no room for negotiation. We assess the target company's IT landscape before signing – neutrally, structurally, and with a focus on what each finding means for the purchase price and integration.
Detailed and neutral IT due diligence is essential before a company transaction.
What's really inside the target company's IT – before you sign?
Most M&A transactions assess finances, customers, and the market with great care. IT, however, often remains underestimated – even though it frequently holds the most expensive surprises after closing. bitformer makes IT risks visible before they burden your transaction.
A superficial risk analysis is not sufficient for this. What is required is an approach that, alongside IT processes, also covers strategy, personnel, applications and infrastructure, while identifying both potential savings and necessary investments.
When carried out correctly, it creates transparency and forms the basis for informed decisions. Investors benefit from improved risk minimisation, the identification of synergy potential and accelerated integration of the target company's IT.
The problem
IT risks that only become visible after closing are the most expensive.
Buying a company also means buying its technical debt: outdated systems, expiring licenses, dependencies on the previous owner, or undocumented in-house developments. If these risks are only discovered after signing, there is no longer any room for negotiation.
In practice, a structured IT due diligence uncovers risks in almost every project that were not factored into the purchase price – from short-term migration costs to multi-year licensing disputes. The question is not if, but when you will find out about them.
The eight risk tiles
Eight risks that we are checking
01 | IT investment backlog
Necessary modernisations have been postponed for years, critical systems are not up to date, and core processes are running with a high proportion of manual workarounds.
Impact: The investment requirement materialises after closing and weighs on the business case. The planned EBITDA improvement is delayed by exactly those IT measures that no one had planned for beforehand.
02 | ERP and core systems
Historically evolved, heavily customised system landscapes without clean interfaces, coupled with software licences containing change-of-control clauses, expiring contracts and a lack of documentation regarding licensed usage rights.
Impact: The integration is delayed, synergies are being realised later than planned, and the effort required for harmonisation and system adjustments is increasing. In the worst-case scenario, licensing issues will turn into a multi-year legal dispute.
03 | Carve-out and Separation
Systems and data are not cleanly separated, there are complex interdependencies with existing group structures, and a reliable TSA and transition strategy is lacking. Shared services, jointly used infrastructure or ERP instances fall away at closing without anyone having had them on their radar.
Impact: The deal is being delayed by an unclear separation, and the separation costs are exceeding the original planning.
04 | Scalability and technical debt
High manual effort in core business processes, technical legacy issues that prevent rapid further development, and systems that are not designed for future growth.
Impact: Growth is only possible with disproportionately rising costs. Value creation is being slowed down by technical debt instead of benefiting from the system lever.
05 | IT operating model
Unclear responsibilities and a lack of governance, a central dependency on individual key personnel, and knowledge that is neither adequately documented nor sustainably secured.
Impact: The risk of post-closing operational disruption increases, and integration and transformation measures are delayed because the organisation cannot bear them.
06 | Cyber Security, Data Protection and Compliance
No reliable assessment of current vulnerabilities, lack of monitoring and an unclear incident history. Security measures are not implemented systematically, coupled with GDPR gaps, missing records of processing activities and non-compliant system configurations.
Impact: An unclear security situation is a transactional risk. After closing, both the stabilisation effort and the regulatory risk lie with the buyer.
07 | Data and controllability
Inconsistent data models across core systems, manual reporting without central validation, and a lack of transparency regarding key metrics.
Impact: The management view following the closing remains restricted. The company's performance and development can only be assessed with limited reliability.
08 | Integration capability
No defined target architecture and no integration strategy, heterogeneous systems and processes without standardisation, little experience with transformation. In addition, systems that appear compatible at first glance, but upon closer inspection require a complete migration.
Impact: The post-merger integration is delayed, synergies are being realised later, and the effort required for coordination, migration and harmonisation is higher than estimated in the business case.
Our approach
Structured, fast, without disturbing operations
An IT due diligence runs parallel to the ongoing transaction process under time pressure. Our approach is designed for this.
Week 1
Kick-off and document analysis
Joint briefing with the buy side and M&A advisors: focus topics, access situation, timetable.
In parallel: structured evaluation of available documents from the data room – system lists, contracts, IT organisation charts, security reports.
Week 1-2
Expert interviews on the landing page
Structured interviews with IT management, system administrators, and – where possible – key individuals from business departments.
Objective: To gather the informal knowledge that is not documented but is crucial for risk assessment.
Week 2-3
Technical Analysis & Risk Assessment
Evaluation of all collected information: system landscape, contractual framework, security situation, dependencies, technical debt. Each identified risk will be assessed according to likelihood of occurrence, potential financial impact, and time criticality.
Week 3-4
Report & Recommendations
Structured IT risk report with prioritised recommendations for action – prepared for purchase price negotiations, the legal team and management.
Upon request, we present the results directly to the deal team and answer any questions.
Why IT Due Diligence
With IT due diligence vs. without
without IT due diligence
- IT risks only become apparent after closing, when there is no longer any room for negotiation.
- Dependencies on the previous owner jeopardise operational capacity from day 1.
- Licence and compliance gaps become buyer liability
- Integration costs are surprising, the synergy plan must be revised
- IT teams on both sides are starting without a common baseline
With bitformer IT Due Diligence
- Risks are known before signing and are included in the purchase price or guarantees.
- Dependencies are documented, and the Day 1 planning is purposely built on them
- Compliance gaps have been identified, which the legal team can then secure.
- The integration cost framework is established, the synergy planning has a realistic basis
- The foundation for the integration blueprint has been laid
At its core, it is all about strategy
- Is there an IT roadmap with traceable objectives and clear responsibilities?
- Is it compatible with the buyer's corporate strategy?
- Where are adjustments necessary, where are they possible?
A frequently missing component is the transparent overview of ongoing contracts, recurring costs and planned project expenditure, in other words, the IT budget. Although IT expenditure is recorded in cost accounting and the balance sheet, it is often distributed across the cost centres of the business departments or ends up lumped together under miscellaneous costs.
For many companies, it is therefore barely possible to quantify actual IT expenditure or produce a reliable forecast. The consequence is a creeping backlog of investment, which becomes a particular risk for the buyer. This is precisely where Risk 01 a.
Before the closing is after the closing.
Arrange initial consultation
In an initial 30-minute consultation, we will be happy to work out together at which stage of your integration process we have the greatest leverage. Without a sales pitch, without obligation.
30 minutes of IT Due Diligence consultation – non-binding and free

