What IT due diligence means
IT due diligence is the review a buyer, investor or lender runs on a target company's technology before a deal closes. It tests whether the systems, infrastructure, security, software contracts and IT team can support the business plan, and what it will cost to fix what cannot.
In a private equity deal it usually runs during exclusivity, next to the quality of earnings, legal and commercial workstreams. The work is done by the sponsor's own technology lead, an operating partner with a technology remit or a specialist advisory firm, using management interviews, a document request list and, where allowed, read-only access to admin consoles. The output is a report with red flags, remediation costs, integration or separation needs and inputs for the 100-day plan.
Technology due diligence is often used as a synonym. Some advisors reserve that term for product and code review at software targets and use IT due diligence for the systems that run the business.
What does IT due diligence cover?
Most scopes fall into eight workstreams. The weight given to each depends on the deal thesis: a carve-out leans on separation, while a buy-and-build platform leans on scalability.
| Workstream | Typical questions | Documents requested |
|---|---|---|
| Systems inventory | Which applications run each function, who owns them, how many users? | Application list, IT org chart, user counts |
| Infrastructure and hosting | Cloud, on-premises or hybrid; any single points of failure? | Network diagrams, hosting contracts |
| Cybersecurity | Recent incidents, controls, cyber insurance, test results? | Policies, penetration test reports, incident log |
| Software contracts | Renewal dates, change-of-control clauses, license compliance? | Vendor contracts, license counts |
| Data management | Backups, retention, deletion, where data is stored? | Backup reports, retention schedule |
| IT organization | Key-person risk, outsourced providers, skills gaps? | Staff list, MSP agreements |
| IT spend | Run-rate cost, capex, upcoming renewals? | IT budget, vendor invoices |
| Integration or separation | What must change after closing; any transition services? | Integration plan, TSA drafts |
IT due diligence questions worth adding
Standard request lists focus on risk and cost. Five extra questions turn the same work into a map of the company's records:
- For each system, what is the oldest record still held, and when was it last migrated?
- Which systems were retired in the last ten years, and were complete exports kept?
- Does any retention policy or vendor plan delete history automatically?
- Do client contracts restrict how the company uses data it holds for clients?
- Who inside the company can run a full export from each core system?
None of these questions asks for record contents. They describe systems, dates and permissions, which is the level of detail a diligence team works at anyway.
Illustrative: reading an inventory for data-licensing signals
Illustrative, fictional example: a sponsor buys a 220-person IT services company as a platform. The IT diligence report lists 14 business systems, a ticketing platform with history back to 2013, an email archive kept through two migrations, Jira and Git repositories from 2016, and a CRM whose deal records carry won and lost reasons. It flags one problem: a document management system retired in 2019 with no export.
Read through a licensing lens, the same report describes many connected systems, a decade of tickets paired with outcomes and a full engineering record, which are the signals AI buyers look for. It also raises two questions to settle before any introduction: the lost archive, and whether client MSAs allow the company to license tickets that describe client environments.
| Inventory field | What the deal team uses it for | What it suggests about licensing potential |
|---|---|---|
| Number of systems | Complexity and integration cost | Breadth of connected records; strong companies often run 10-15+ systems |
| Years of history per system | Migration risk | Depth of the record of how work evolved |
| Retired systems and exports | Data loss risk | Whether older history still exists |
| Retention and deletion settings | Compliance | Whether history is disappearing right now |
| Client contract terms on data | Liability | Whether the company holds the rights to license |
| Export capability | Portability | Whether anyone can actually deliver the data |
Why operating partners should reread the IT report
Operating partners already own the 100-day plan, and IT diligence is one of its main inputs. McKinsey's Global Private Markets Report 2026 says multiple expansion and cheap leverage have faded, making operational value creation the likely primary source of private equity returns. A report that already catalogs every system and its history is a cheap place to look for one more lever.
The IT report does not settle the question on its own. It describes systems, not who owns their content, and it never asks whether an owner would consider an exclusive license. Treat it as a first screen, then test the company against the who qualifies baseline: a US business with 50+ full-time employees at peak (contractors excluded), several years of documented operations, the rights to license its records and an owner, CEO, CFO or other authorized sponsor willing to discuss it.
Keep the diligence report itself inside the deal team. It sits under the NDA and the company's control, and a referral partner never forwards it or describes record contents.
What IT due diligence means for a referral partner
An operating partner who spots the signals makes the introduction and steps back. The company's sponsor then works with SourceX on qualification, a data inventory, price and terms, buyer review, contracting and delivery. Redaction and de-identification rules are agreed before any work starts, and nothing is delivered without a signed agreement and the company's authorization. The page for private equity operating partners shows how this fits a portfolio routine, and the company fit checker gives a preliminary, non-binding read with no contact details required.
Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company. The reward becomes payable only after the buyer pays and SourceX receives its fee, and no reward is guaranteed; the explainer on paid on collection covers that trigger.
Related terms
- Minority recapitalization: minority investors also run IT diligence, but usually have less say over post-closing system changes.
- Entrepreneurship through acquisition: search fund buyers often find systems knowledge concentrated in one or two people, so mapping systems early protects history.
- Exit readiness: sell-side IT readiness reuses the same inventory before buyers ask for it.
Next step
Pull the IT diligence report for one portfolio company and answer the five extra questions above. If the answers point to deep, rights-clear history, register as a partner and introduce the CEO or CFO.