What is IT due diligence, and what does its systems inventory reveal?

Short answer

IT due diligence is the review a buyer or investor runs on a target company's technology before closing: systems, infrastructure, security, software contracts, IT staff and costs. Its systems inventory, listing each application, its owner and how far back its history goes, is also an early signal of whether the company holds licensable operational records.

What is IT due diligence, and what does its systems inventory reveal?: overview of What IT due diligence means, What does IT due diligence cover?, IT due diligence questions worth adding, Illustrative: reading an inventory for data-licensing signals, Why operating partners should reread the IT report
Covered on this page: What IT due diligence means · What does IT due diligence cover? · IT due diligence questions worth adding · Illustrative: reading an inventory for data-licensing signals · Why operating partners should reread the IT report

What IT due diligence means

IT due diligence is the review a buyer, investor or lender runs on a target company's technology before a deal closes. It tests whether the systems, infrastructure, security, software contracts and IT team can support the business plan, and what it will cost to fix what cannot.

In a private equity deal it usually runs during exclusivity, next to the quality of earnings, legal and commercial workstreams. The work is done by the sponsor's own technology lead, an operating partner with a technology remit or a specialist advisory firm, using management interviews, a document request list and, where allowed, read-only access to admin consoles. The output is a report with red flags, remediation costs, integration or separation needs and inputs for the 100-day plan.

Technology due diligence is often used as a synonym. Some advisors reserve that term for product and code review at software targets and use IT due diligence for the systems that run the business.

What does IT due diligence cover?

Most scopes fall into eight workstreams. The weight given to each depends on the deal thesis: a carve-out leans on separation, while a buy-and-build platform leans on scalability.

WorkstreamTypical questionsDocuments requested
Systems inventoryWhich applications run each function, who owns them, how many users?Application list, IT org chart, user counts
Infrastructure and hostingCloud, on-premises or hybrid; any single points of failure?Network diagrams, hosting contracts
CybersecurityRecent incidents, controls, cyber insurance, test results?Policies, penetration test reports, incident log
Software contractsRenewal dates, change-of-control clauses, license compliance?Vendor contracts, license counts
Data managementBackups, retention, deletion, where data is stored?Backup reports, retention schedule
IT organizationKey-person risk, outsourced providers, skills gaps?Staff list, MSP agreements
IT spendRun-rate cost, capex, upcoming renewals?IT budget, vendor invoices
Integration or separationWhat must change after closing; any transition services?Integration plan, TSA drafts

IT due diligence questions worth adding

Standard request lists focus on risk and cost. Five extra questions turn the same work into a map of the company's records:

  • For each system, what is the oldest record still held, and when was it last migrated?
  • Which systems were retired in the last ten years, and were complete exports kept?
  • Does any retention policy or vendor plan delete history automatically?
  • Do client contracts restrict how the company uses data it holds for clients?
  • Who inside the company can run a full export from each core system?

None of these questions asks for record contents. They describe systems, dates and permissions, which is the level of detail a diligence team works at anyway.

Illustrative: reading an inventory for data-licensing signals

Illustrative, fictional example: a sponsor buys a 220-person IT services company as a platform. The IT diligence report lists 14 business systems, a ticketing platform with history back to 2013, an email archive kept through two migrations, Jira and Git repositories from 2016, and a CRM whose deal records carry won and lost reasons. It flags one problem: a document management system retired in 2019 with no export.

Read through a licensing lens, the same report describes many connected systems, a decade of tickets paired with outcomes and a full engineering record, which are the signals AI buyers look for. It also raises two questions to settle before any introduction: the lost archive, and whether client MSAs allow the company to license tickets that describe client environments.

Inventory fieldWhat the deal team uses it forWhat it suggests about licensing potential
Number of systemsComplexity and integration costBreadth of connected records; strong companies often run 10-15+ systems
Years of history per systemMigration riskDepth of the record of how work evolved
Retired systems and exportsData loss riskWhether older history still exists
Retention and deletion settingsComplianceWhether history is disappearing right now
Client contract terms on dataLiabilityWhether the company holds the rights to license
Export capabilityPortabilityWhether anyone can actually deliver the data

Why operating partners should reread the IT report

Operating partners already own the 100-day plan, and IT diligence is one of its main inputs. McKinsey's Global Private Markets Report 2026 says multiple expansion and cheap leverage have faded, making operational value creation the likely primary source of private equity returns. A report that already catalogs every system and its history is a cheap place to look for one more lever.

The IT report does not settle the question on its own. It describes systems, not who owns their content, and it never asks whether an owner would consider an exclusive license. Treat it as a first screen, then test the company against the who qualifies baseline: a US business with 50+ full-time employees at peak (contractors excluded), several years of documented operations, the rights to license its records and an owner, CEO, CFO or other authorized sponsor willing to discuss it.

Keep the diligence report itself inside the deal team. It sits under the NDA and the company's control, and a referral partner never forwards it or describes record contents.

What IT due diligence means for a referral partner

An operating partner who spots the signals makes the introduction and steps back. The company's sponsor then works with SourceX on qualification, a data inventory, price and terms, buyer review, contracting and delivery. Redaction and de-identification rules are agreed before any work starts, and nothing is delivered without a signed agreement and the company's authorization. The page for private equity operating partners shows how this fits a portfolio routine, and the company fit checker gives a preliminary, non-binding read with no contact details required.

Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company. The reward becomes payable only after the buyer pays and SourceX receives its fee, and no reward is guaranteed; the explainer on paid on collection covers that trigger.

  • Minority recapitalization: minority investors also run IT diligence, but usually have less say over post-closing system changes.
  • Entrepreneurship through acquisition: search fund buyers often find systems knowledge concentrated in one or two people, so mapping systems early protects history.
  • Exit readiness: sell-side IT readiness reuses the same inventory before buyers ask for it.

Next step

Pull the IT diligence report for one portfolio company and answer the five extra questions above. If the answers point to deep, rights-clear history, register as a partner and introduce the CEO or CFO.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

How long does IT due diligence take in a private equity deal?

It usually runs inside the exclusivity period alongside financial, legal and commercial diligence, so its timetable follows the deal timetable. Scope drives the effort: a single-site services company with a handful of cloud applications is quicker to review than a carve-out with shared infrastructure, custom software and transition services. Fast access to management and documents matters more than the size of the advisory team.

Who performs IT due diligence?

Usually a specialist advisory firm or the technology practice of a consulting or accounting firm, engaged by the buyer. Larger sponsors may use an in-house technology operating partner, and smaller buyers sometimes rely on an experienced CIO or an IT services provider. The target's IT lead and its outsourced providers supply documents and sit for interviews.

Is IT due diligence the same as cybersecurity due diligence?

No. Cybersecurity due diligence is one workstream within a broader IT review, focused on controls, incidents, vulnerabilities and insurance. IT due diligence also covers systems, infrastructure, software contracts, data management, IT staff, cost and integration. Buyers of businesses that hold sensitive data often commission a deeper standalone cyber assessment on top of the general IT review.

Should a portfolio company share its IT due diligence report with SourceX?

No, and a partner should never forward it. The report belongs to the deal process and usually sits under confidentiality terms. If the company decides to explore licensing, its own team completes a separate data inventory with SourceX, listing systems, years of history and what can be exported, under terms the company agrees.

Does a clean IT report mean the company's data can be licensed?

No. A clean report shows that systems are stable and secure, not that the company owns the content or wants to license it. Licensing also depends on rights under client contracts and policies, an authorized sponsor, enough size and history, and the owner's willingness to consider an exclusive AI-training license for an agreed term.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment