IT due diligence checklist: the standard scope plus four data licensability questions

An IT due diligence checklist reviews a target's infrastructure, applications, security, IT team, vendors and integration costs. Add four data questions: how many systems hold how many years of history, whether contracts and privacy promises allow licensing, whether complete exports are possible, and whether any data is already licensed for AI training.

What IT due diligence covers, and the question it usually skips

IT due diligence tests whether a target's technology can support the investment thesis: what it runs, what it costs, how secure it is, who keeps it running and what integration will take. Most checklists stop there. They rarely ask whether the target's operational records are an asset in their own right, licensable to AI developers through SourceX, or whether the integration plan is about to destroy them.

Four extra questions close that gap. The answers tell the deal team whether a post-close introduction is worth planning and which systems the 100-day plan must not retire blindly.

The checklist

Infrastructure and architecture

  • Network diagram, hosting model (on-premises, colocation or cloud) and the age of core hardware.
  • Cloud accounts and subscriptions, and which entity holds each billing relationship.
  • Backup scope, frequency, restore testing and offsite copies.
  • Disaster recovery plan and the date it was last tested.

Applications and systems inventory

  • Every business system: ERP, CRM, helpdesk, WMS or TMS, PSA, HR and payroll, document management, collaboration.
  • For each system: go-live date, earlier systems it replaced, hosting, license terms and renewal date.
  • Customizations, integrations and middleware that would break in a migration.
  • Shadow IT and departmental tools found through expense reports or single sign-on logs.

Security and compliance

  • Identity and access management, MFA coverage and privileged account controls.
  • Incident history, open findings from penetration tests and audits, and cyber insurance terms.
  • Frameworks in scope, such as SOC 2, PCI DSS, HIPAA or CMMC, and the evidence behind them.
  • Privacy notices, data processing agreements and the log of consumer requests.

IT organization, vendors and cost

  • IT headcount, key-person dependencies, and MSP or outsourcer contracts.
  • Run-rate IT spend against budget, and one-off costs deferred until after close.
  • Vendor contracts with change-of-control, assignment or termination clauses.
  • Technical debt and end-of-life systems that need investment during the hold.

Data rights and licensability: the four added questions

  • Depth: how many systems hold the company's own operational records, and how many years does each go back, including archived and retired platforms?
  • Rights: do customer contracts, privacy policies and terms of service restrict how records may be used, and does the company own what employees and contractors created?
  • Export: can each system produce a complete export, including attachments, comments, audit history and metadata, and who can run it?
  • Prior licenses: has the company already licensed any data for AI training, and does any agreement grant exclusivity?

How to answer the rights question

Two issues come up in most targets. The first is ownership of work product. Under US copyright law, material employees create within the scope of their jobs is generally a work made for hire owned by the employer, while content from independent contractors may not belong to the company unless it qualifies as a commissioned work made for hire under a signed written agreement or the rights were assigned in writing, as the Copyright Office's Circular 30 explains. Ask for contractor agreements with IP assignment clauses, especially for engineering and documentation work.

The second is what the company promised its customers. FTC staff have stated that a company's commitments not to use customer data for undisclosed purposes, such as training models, are enforceable whether they appear in privacy policies, terms of service or marketing materials. Read what the target promised before assuming any customer-facing records can be licensed. This is general information, not legal, tax or financial advice. Confirm with deal counsel before acting.

Sector notes for common targets

Target typeWhere the history livesRights issue to probe
3PL and warehousingWMS, TMS, EDI logs, claims files and carrier emailCustomer-owned inventory and shipment data under service agreements
DistributorERP order history, pricing exceptions, RMAs, supplier portalsSupplier pricing confidentiality and customer contract terms
SaaS companySupport tickets, engineering repositories, CRMCustomer data inside the product is governed by customer agreements and typically belongs to the customer
MSP or IT servicesPSA tickets, runbooks, RMM scriptsClient environment data and credentials are out of scope
Professional servicesDocument management, time and billing, emailClient deliverables and engagement confidentiality

For targets with a heavy Microsoft 365 estate, a recent Copilot readiness assessment may already contain a map of SharePoint, OneDrive and Teams history. For the full rights review after close, use the rights readiness checklist.

How to use the results

FindingWhat it meansAction for the deal team
Many systems, long histories, clean rights, exports possibleA possible value-creation leverNote it in the IT DD report and plan a post-close introduction in the 100-day plan
Long histories but customer contracts restrict useRights narrow the scope without necessarily ending itAsk counsel to scope which record sets are affected
Integration plan retires systems in year oneYour own plan may destroy the assetRequire a full export and an owner decision before decommission
Prior AI-training license with exclusivityOverlapping records cannot be licensed again during the termReview the contract and record the constraint
Few systems or a short historyUnlikely to qualifyNo action beyond standard retention
Target never reached 50+ full-time employees at peak (contractors excluded)Below the baselineNo action

When to introduce the owner after close

The introduction belongs after close, once the new owner controls the company and an authorized sponsor, such as the CEO or CFO, can sign. Raise it during the 100-day plan, before any system on the retirement list is switched off. For add-on acquisitions, line it up with the buy-and-build IT integration sequence so legacy platforms are not retired before their history is assessed, and keep servers out of the ITAD destruction queue until exports are verified.

During exclusivity and before signing, do not approach the seller about licensing on your own; coordinate through the deal lead.

Red flags in the data rights answers

  • Most records belong to the target's clients, as with many agencies and outsourcers.
  • The data is mainly protected health information or consumer personal data.
  • Archives were deleted, or a vendor holds the only copy and will not export it.
  • The target cannot say who created its engineering or documentation work.
  • Nobody at the target can run a complete export.

Next step

Add the four questions to your next IT DD request list. If a company you diligenced fits after close, register as a partner and introduce it; the network opportunity finder helps you list past targets worth revisiting, and who qualifies has the full baseline. Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company, payable only after the buyer pays and SourceX receives its fee; rewards are not guaranteed.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

Who should answer the data licensability questions during diligence?

Usually the target's CIO or IT manager for depth and export, and its general counsel or outside counsel for rights and prior licenses. The deal team should ask for metadata only, such as system names, date ranges and contract terms, never samples of the records themselves. Any content review happens later between the company and SourceX under an executed agreement.

Should a data licensing opportunity change the valuation model?

Keep it outside the base case. Any license would be a one-time payment negotiated after close, and it depends on rights, buyer demand and the owner's decision, so it may never happen. Record it in the IT DD report as a potential value-creation lever with its conditions, rather than as revenue in the model.

What if the target's MSP holds the admin credentials and the history?

Confirm in diligence that the MSP contract gives the company full access to its own data and a right to complete exports on termination. An MSP transition after close is a point where tenant history, tickets and backups can get lost. Make export rights and handover duties a closing condition or an early item in the 100-day plan.

Is a prior data license with an AI developer a red flag?

Not by itself, but it matters. If the target already licensed records for AI training, those records generally cannot be licensed again for that use while any exclusivity runs, and the contract may carry obligations the new owner inherits. Ask for the agreement and review its scope, term, exclusivity, delivery obligations and payment status.

Can the four questions be used in carve-out diligence?

Yes, with one addition: which entity owns the records after separation. In a carve-out, shared systems and a transition services agreement can leave the divested business without its own history when the TSA ends. Confirm what data transfers, in what format and by when, before signing, and treat the export plan as part of separation scope.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment