IT and finance due diligence request list items that reveal licensable records
An IT due diligence request list already asks for most of what shows whether a company's records could be licensed: the systems inventory, retention settings, retired platforms, privacy notices and data processing terms. Read each answer twice, once for risk and once for value, and never request the records themselves for licensing purposes.
Why read a diligence request list for data value?
A standard IT and finance diligence request list already asks for the documents that show whether a company's records could be licensed: the application inventory, retention and deletion settings, the list of retired platforms, privacy notices and data processing terms. The annotations below show how to read each answer twice, once for risk and once for value, without adding a single request for actual records.
For transaction advisors this is a cheap second use of work already in the plan. A company being sold, recapitalized or refinanced can hold years of operational history nobody has priced. On the sell side, spotting it early gives the owner an additional source of proceeds to pursue on its own timetable. On the buy side, the same answers tell the acquirer whether a value creation lever exists after closing.
The annotated request list
Each item is an ordinary diligence request. The note after it says what the answer reveals about licensing fit.
Systems and architecture
- Application inventory with owners, start dates and user counts. Companies with strong records often run 10-15+ systems, and start dates show how far back the history goes.
- Retired, replaced or archived systems, and where their data now sits. Archived platforms can add years of history, provided an export survived.
- Integration and data flow map. Connected systems, such as CRM feeding ERP feeding the support desk, let records be linked into complete workflows.
- Email and collaboration tenancy details with retention settings. These show whether years of email and chat still exist or are purged on a schedule.
- Admin roles for each major system. Someone inside the company must be able to run exports; if nobody can, licensing stops there.
Records management and retention
- Records retention schedule and deletion policy. Short auto-delete windows cap the history available.
- Legal holds currently in force. Held records are preserved but may be off-limits for other uses until the hold lifts.
- Backup and archive policy, including the oldest restorable backup. Shows whether gaps in live systems could be filled.
Contracts, privacy and rights
- Customer contract templates and material contracts, especially data and confidentiality clauses. If clients own the deliverables or the records, the company may not be able to license them.
- Vendor and SaaS terms, including data export rights on termination. Confirms the company can get its own history out.
- Current and prior privacy policies and terms of service, with change dates. What the company promised about data use governs what it can license.
- Employee and contractor IP assignment agreements. Shows who owns material created by people who were not employees.
- Call recording notices and consent practices. Recordings are usable only where proper notice was given.
- Existing data licensing or data sharing agreements, especially for AI training. A prior AI-training license on the same records is a conflict.
Finance and operations
- ERP migration history: what moved to the new system and what stayed behind. Left-behind detail is often the deepest record of how the business ran.
- Audit PBC lists and response histories for recent years. The note on audit PBC request lists and response histories explains why these finance workflows have value in their own right.
- Headcount by year, with full-time staff and contractors shown separately. The licensing baseline counts full-time employees at peak, not contractors.
- Ticketing, project and CRM volumes by year. Volume plus outcome fields (resolved, escalated, won, lost) indicate depth.
The privacy item deserves a closer read. FTC staff have said that companies' promises not to use customer data for undisclosed purposes, such as training models, are enforceable wherever they were made (FTC staff, January 2024), and that adopting more permissive data practices through a quiet, retroactive change to terms or privacy policies may be unfair or deceptive (FTC staff, February 2024). Both are staff guidance, not rules, but they explain why the history of a company's privacy promises matters as much as the current version.
This is general information, not legal, tax or financial advice. Confirm with your own counsel, tax adviser or professional body before acting.
What should you never request for licensing purposes?
Diligence exists for the transaction. Keep licensing out of the data room.
- Do not ask for sample records, exports or extracts to judge licensing value. Any licensing review happens later, between the company and SourceX, under its own agreement.
- Do not repurpose data-room material. Information shared under a deal NDA is usually limited to evaluating the transaction; raise licensing only with your client's permission and through the company's leadership.
- Do not describe the target's records to anyone outside the deal team.
- Do not let licensing questions slow the deal. One note in the cover memo is enough.
A referral partner's job ends at the introduction and a few basic fit facts. De-identification and redaction rules are agreed with the company before any work starts, and nothing is delivered without an executed agreement and the company's authorization. The CFO-side companion, due diligence questions to ask a data licensing platform, covers what the company should ask SourceX.
How do you use the results?
| Result | What it means | Next action |
|---|---|---|
| Many connected systems, 5-10+ years of history, exports possible | Strong licensing fit signal | Note it in the cover memo and suggest the owner try the company fit checker |
| Good history, but key archives were deleted | Fit depends on what survives | Check backups and archived exports before drawing a conclusion |
| Records mainly owned by the company's clients | Weak fit unless clients consent | Leave licensing out of the recommendations |
| Privacy promises restrict secondary use | Consumer data is likely out of scope | Focus on business-process records, with counsel's view |
| Prior AI-training license on the same records | Not a fit for those records | Record it as a contract item, not an opportunity |
| Never reached 50+ full-time employees at peak (contractors excluded) | Below the baseline | No licensing note needed |
The who qualifies page sets out the full baseline. When a CFO objects mid-deal that the team has no capacity, the page on finance team bandwidth for a licensing project is the one to share.
Red flags to record
- A court, trustee or assignee controls the assets and has not been involved.
- Records were generated with AI in order to sell them.
- Nobody inside the company can export the data.
- The owner will not consider an exclusive license for an agreed term; the page on exclusive license opportunity cost explains why that matters.
- The data is mainly protected health information, such as medical records or claims, with no authorization or de-identification in place.
When should licensing come up in the deal timeline?
| Deal stage | What to do |
|---|---|
| Sell-side readiness, before marketing | Raise the question with the owner; a license can be scoped or completed before the process starts |
| Diligence | Note signals only; do not open a parallel workstream |
| First 100 days after closing | Hand the note to the new owner's operating team |
If you hold a securities registration or a professional license, check its rules on referral compensation and disclosure with your compliance team before taking part.
Next step
Add these annotations to your next request list template. When a target or client shows strong signals and the owner is interested, register as a partner and introduce the company's owner, who can also apply at sourcex.si/apply through your referral link. Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company, paid only after the buyer pays and SourceX receives its fee.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Should licensing signals go in the formal diligence report?
Keep them out of the main findings unless your client asks for them. A short note in the cover memo or a separate letter to the client is enough: which systems exist, how much history survives and whether rights look clean. The licensing decision belongs to the company's owner and is made later, outside the transaction workstream.
Can findings from a data room be used to start a licensing conversation?
Only through your own client and with the company's leadership involved. Data-room information is usually covered by a confidentiality agreement limited to evaluating the deal, so it should not be shared or repurposed. The safe path is to note the signal for your client, then let the company's owner decide whether to explore licensing on their own timetable.
What if the target has already licensed data for AI training?
Treat it as a contract diligence item. Ask for the agreement, its scope, term and exclusivity, and whether it restricts other uses of the same records. A prior AI-training license on the same records rules those records out of a new license, although other datasets the company holds may still be available if the existing agreement allows it.
Which request list items carry the strongest licensing signals?
Three answers carry most of the signal: the application inventory with start dates, the list of retired systems showing where their data went, and the retention settings for email and collaboration tools. Together they show how many systems hold history, how far back it goes and whether it still exists. Contract and privacy items then show whether it can be licensed.
Does raising data licensing affect an advisor's independence on the deal?
It can if you stand to be paid for an introduction connected to a client or a target. Disclose any referral arrangement to your client in writing, follow your firm's conflicts policy, and if you hold a professional license or securities registration, check its rules on referral compensation with your compliance team before registering as a partner.
Related pages
- Audit PBC lists: what they contain and why the response history has value
- Vendor due diligence questionnaire: what to ask a data licensing platform
- Check Company Fit for Data Licensing
- Which US businesses are a fit for a SourceX data licensing introduction
- Our finance team has no bandwidth: how much time does data licensing take?
- What is the opportunity cost of granting an exclusive data license?
Free resources
- Working capital calculator — Net working capital, current ratio and quick ratio.
- Due diligence checklist generator — A tailored document request list by deal type.
- Cash flow calculator — A 12-month cash forecast with shortfalls highlighted.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment