IT Due Diligence (Technology DD) examines the technological substance of a company. In the digital era, it is becoming increasingly important, especially for technology-driven business models.
Definition and Purpose
What is IT Due Diligence?
IT DD systematically analyzes: - IT infrastructure and systems - Software and licenses - Cybersecurity - IT organization and costs - Technology risks
Why is IT DD Important?
| Reason | Explanation |
|---|---|
| Digitalization | IT is a core part of the business |
| Costs | IT costs often underestimated |
| Risks | Cyber, legacy, compliance |
| Integration | IT integration is complex and expensive |
Audit Focus Areas
IT Infrastructure
| Audit Point | Analysis |
|---|---|
| Hardware | Servers, network, endpoints |
| Datacenter | In-house, colocation, cloud |
| Network | Architecture, redundancy |
| System age | Investment backlog? |
Application Landscape
| Audit Point | Analysis |
|---|---|
| ERP system | Version, customizations |
| CRM | Usage, data quality |
| Industry software | Critical applications |
| Custom developments | Documentation, maintainability |
Cloud Usage
| Aspect | Audit |
|---|---|
| IaaS | AWS, Azure, GCP |
| SaaS | Which applications |
| Costs | Ongoing expenses |
| Dependencies | Lock-in risks |
Software Licenses
| Audit Point | Risk |
|---|---|
| License agreements | Compliance |
| Transferability | During transaction |
| True-up risks | Underlicensing |
| Open source | License conditions |
Cybersecurity
Security Assessment
| Area | Audit |
|---|---|
| Security policies | Available, current |
| Access management | Permissions |
| Data encryption | Standards |
| Incident response | Processes |
| Penetration tests | Conducted? |
Typical Risks
| Risk | Consequence |
|---|---|
| Data leaks | GDPR fines, reputation |
| Ransomware | Business interruption |
| Legacy systems | Security vulnerabilities |
| Missing updates | Vulnerability |
Compliance
| Requirement | Audit |
|---|---|
| GDPR | Data protection measures |
| ISO 27001 | Certification? |
| Industry standards | PCI-DSS, HIPAA, etc. |
IT Organization
Structure and Resources
| Aspect | Audit |
|---|---|
| IT team | Size, competencies |
| Outsourcing | Share, partners |
| Key persons | Dependencies |
| Documentation | Quality |
IT Governance
| Aspect | Audit |
|---|---|
| Strategy | IT roadmap available |
| Budget | IT costs/revenue |
| Projects | Ongoing initiatives |
| Decision processes | Governance |
IT Costs
Cost Analysis
| Cost Category | Typical Share |
|---|---|
| Personnel | 40-50% |
| Licenses/Software | 20-30% |
| Infrastructure | 15-25% |
| Services/Outsourcing | 10-20% |
Industry benchmarks for IT cost distribution.
Benchmarks
| Industry | IT Costs/Revenue |
|---|---|
| Banks | 7-10% |
| Insurance | 4-6% |
| Retail | 1-3% |
| Manufacturing | 2-4% |
| Tech companies | 15-25% |
Industry IT cost benchmarks. Actual values vary by digitalization level and business model.
Integration Planning
Integration Scenarios
| Scenario | Characteristics |
|---|---|
| Full integration | Merge systems |
| Best-of-breed | Select best systems |
| Coexistence | Parallel operation |
| Carve-out | Separate systems |
Typical Integration Costs
| Area | Cost Factors |
|---|---|
| ERP migration | Licenses, implementation |
| Data migration | Effort, quality assurance |
| Interfaces | Adaptations |
| Training | Employee training |
Results and Reporting
IT DD Report
| Chapter | Content |
|---|---|
| Executive Summary | Key findings, risks |
| Infrastructure | Status, investment needs |
| Applications | Landscape, critical systems |
| Security | Assessment, risks |
| Organization | Team, governance |
| Costs | Analysis, benchmarks |
| Integration | Recommendations, effort |
Risk Assessment
| Risk | Quantification |
|---|---|
| Investment backlog | X EUR |
| License compliance | Y EUR |
| Security gaps | Z EUR (+ reputation risk) |
| Integration costs | XX EUR |
Red Flags
Warning Signs
| Red Flag | Risk |
|---|---|
| Outdated systems | Investment needs, security |
| Missing documentation | Dependency on individuals |
| No backups | Data loss risk |
| No incident plan | Response capability |
| High technical debt | Maintenance burden |
Implications for SPA
Typical IT Clauses
| Area | SPA Provision |
|---|---|
| Licenses | Transferability guaranteed |
| IP rights | Custom developments belong to target |
| Security | No known breaches |
| Compliance | GDPR conformity |
Transitional Services
Often required in carve-outs: - Time-limited IT services - Data migration - System separation
Relationship with Other DD Streams
IT DD has interfaces with:
| Stream | Relevance |
|---|---|
| Financial DD | IT costs, investments |
| Legal DD | License agreements, IP |
| Commercial DD | Digital value creation |
| Operational DD | Process support |
Conclusion
IT Due Diligence is becoming increasingly critical:
- Substance: Evaluate technological foundation
- Risks: Identify cyber, legacy, compliance issues
- Costs: Realistically estimate IT expenses
- Integration: Plan complexity and costs
A thorough IT DD prevents unpleasant surprises during integration.
Analyze company structures: Firmium provides company data for your Due Diligence.