Using MCP for Customer Concentration Analysis in M&A Due Diligence
Model Context Protocol (MCP) lets an AI assistant securely query a company's live CRM and billing systems to reconcile customer identities and accurately calculate revenue concentration, providing sell-side M&A advisors with verifiable answers for due diligence.
Model Context Protocol (MCP) provides a secure, auditable way for AI assistants to answer questions using a company's live business data. For sell-side M&A advisors, this means you can rapidly and accurately analyze customer concentration by querying your client's ERP and CRM systems simultaneously. This allows you to identify and consolidate revenue from different subsidiaries of the same parent company, pre-empting a major buyer concern with verifiable, source-linked evidence.
The problem: Hidden customer concentration risk
Customer concentration is a critical point of scrutiny in any M&A due diligence process. Buyers want to understand the risk of a single customer relationship having an outsized impact on revenue. A common sell-side challenge is that a client's billing system and CRM may not present a unified view. For instance, a single large enterprise customer might make purchases through multiple legal entities, divisions, or regional offices, each recorded as a separate account.
Manually reconciling these disparate identities across spreadsheets is time-consuming, prone to error, and creates significant data security risks. Exporting sensitive sales data into static files makes it difficult to trace findings back to the source, and the data becomes instantly stale. Answering follow-up questions from the buy-side often requires rerunning the entire analysis. Advisors need a way to get a true, consolidated view of customer revenue that is both fast and defensible. Answering these questions is a core part of effective M&A due diligence.
A realistic workflow for reconciling concentration
Illustrative example: You are an M&A advisor representing a mid-market SaaS company, "ClientCo," in a sale process. ClientCo uses NetSuite for billing and Salesforce for sales and account management. A prospective buyer has flagged customer concentration as a key area for diligence.
Instead of requesting CSV exports, you use an AI assistant like Claude, which has been granted permissioned, read-only access to ClientCo’s systems via an MCP server.
- Initial Query: You ask the assistant, `"From NetSuite, list the top 20 customers by recognized revenue for the trailing twelve months. Show the total revenue for each."` The AI returns a table with customer names and revenue figures, sourced directly from the ledger.
- Cross-System Lookup: You follow up: `"For each customer in that list, find the corresponding Account record in Salesforce. Flag any names that do not have an obvious match."` The AI now queries the second system to link billing entities to relationship records.
- Identify Parent Accounts: Your next prompt is: `"For the matched Salesforce Accounts, check the 'Parent Account' field. Create a table showing the billing entity, the Salesforce Account, and the Ultimate Parent Account."` This step is crucial for discovering that "Global Tech Inc," "GTI Solutions," and "Globaltech Federal" are all subsidiaries of "Global Technology Holdings Corp."
- Consolidate Revenue: You give the final instruction: `"Recalculate the TTM revenue, but this time, consolidate the totals under each Ultimate Parent Account. Show the consolidated revenue and what percentage of total company TTM revenue it represents."`
Within minutes, the AI produces a verified, consolidated list that shows the true concentration is 18% from Global Technology Holdings Corp, not 7%, 6%, and 5% from three seemingly separate customers. Each number is traceable back to the live data in NetSuite and Salesforce, providing an auditable answer for the data room.
Customer concentration reconciliation worksheet
An AI assistant using MCP can populate a worksheet like the one below, providing a clear and reconciled view for a buyer. The key is its ability to perform the a CRM and ERP integration at the query level, without requiring a complex data warehousing project.
| Customer (Billing System) | Customer (CRM) | Ultimate Parent | TTM Revenue ($) | Consolidated Parent TTM Revenue ($) | % of Total Revenue (Consolidated) | Notes / Flags |
|---|---|---|---|---|---|---|
| :--- | :--- | :--- | :---: | :---: | :---: | :--- |
| Global Tech Inc | Global Tech Inc | Global Technology Holdings | 1,450,000 | |||
| GTI Solutions | GTI Solutions LLC | Global Technology Holdings | 1,220,000 | |||
| Globaltech Federal | Globaltech - Federal Sales | Global Technology Holdings | 1,050,000 | 3,720,000 | 18.6% | Consolidated |
| Innovate Corp | Innovate Corp | Innovate Corp | 1,800,000 | 1,800,000 | 9.0% | |
| Acme Industries | No Match Found | Unknown | 950,000 | 950,000 | 4.8% | FLAG: No CRM record found |
| ... | ... | ... | ... | ... | ... |
Prerequisites and limitations
While powerful, using MCP for diligence requires understanding its scope.
- Prerequisites: The client company must authorize access to its systems. An MCP server that is compatible with their specific ERP and CRM versions must be configured, typically for read-only access. Your team and authorized buy-side users will need credentials to query the assistant.
- Data Quality is Paramount: MCP provides access to data as it exists. If the client's Salesforce records are missing parent account information or contain inconsistent naming conventions, the AI's ability to consolidate accurately will be limited. The process will, however, rapidly highlight these data quality issues.
- Identity Matching Requires Oversight: An AI can intelligently match similar names (e.g., "Innovate Corp" and "Innovate Corporation"), but human review is essential to confirm its findings and resolve ambiguities.
- Licensed Data Has Restrictions: You can connect an AI to licensed research platforms like PitchBook or AlphaSense to help identify corporate parentage. However, MCP respects the entitlements of those services. The research data is for your team's analytical use and cannot be distributed, resold, or placed in a virtual data room for the buyer.
- Access Is Not Ownership: Giving an AI access to your client's operational data via MCP is for analysis, not for creating a data product. The process of analyzing data for diligence is entirely separate from assessing its value for licensing. For more on this distinction, see our guide on MCP and data asset due diligence.
Questions to ask your software provider or implementation team
- How do you establish simultaneous, read-only connections to a client's ERP (e.g., NetSuite, Dynamics 365) and CRM (e.g., Salesforce, HubSpot) for cross-system queries?
- What specific audit logs are created for every question an analyst asks? Can these logs be exported and included in the final deal file for compliance?
- How does the system trace a final, consolidated number (e.g., total revenue for a parent company) back to the specific source records in each underlying system?
- How are user permissions managed and, critically, revoked for different user groups (e.g., your deal team, external accountants, the buy-side team) after a specific diligence phase or at the close of the deal?
- What security measures are in place within the MCP server and AI assistant to prevent prompt injection, data exfiltration, or unauthorized access to the client's live systems?
Next step with SourceX
Incorporating data-readiness conversations early in your client relationships can streamline future M&A events. A company with well-structured, auditable data is not only easier to diligence but may also possess valuable data assets sought by AI labs and data buyers.
As you advise your clients, consider which ones have unique, high-quality operational datasets. You can run a quick, preliminary screen using our /tools/company-fit-checker. For clients that appear to be a good fit, a permissioned introduction to SourceX could create a new revenue stream for both your client and your firm. SourceX partners receive a reward of 25% of the platform fees SourceX collects, up to $100,000 per referred company, for successful referrals. This payment is your firm's share and is entirely separate from the licensing proceeds your client receives.
Related MCP guides
- MCP for Quality of Earnings Support: Reconciliation and Review
- MCP for M&A Contract Review: Clause Extraction, Source Evidence, and Key Limitations
- MCP and Data-Asset Due Diligence: A Guide for Sell-Side M&A Advisors
- A Sell-Side Advisor's MCP Due Diligence Preparation Checklist
- All MCP resources
Sources
- Anthropic finance agents (May 5 2026)
- Intralinks confidential deal data (Current guide)
- AlphaSense MCP overview (Current beta docs)
- PitchBook data in Claude (October 28 2025)
Vendor capabilities change. Check current official documentation before relying on any product detail.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Can MCP fix inconsistent customer names between my client's billing system and CRM?
No, MCP provides access to the data as-is. However, an AI assistant using MCP can help identify and flag these inconsistencies across systems far more quickly than a manual review, allowing your team to focus on the necessary cleanup or explanations.
Is using an AI assistant with MCP for due diligence secure?
Security depends on the specific MCP server's implementation. A properly configured, enterprise-grade server uses read-only access, enforces strict user permissions, and maintains detailed audit logs of every query. This can be significantly more secure than emailing spreadsheets or granting direct system access.
Can I use MCP to pull research from PitchBook to find a customer's ultimate parent?
Yes, if your firm has the appropriate license for a platform like PitchBook or AlphaSense that offers an MCP connection. The AI can query these sources for you, but the results are for your internal analysis only and are subject to the provider's terms. You cannot redistribute this licensed research in a data room.
What's the difference between this and giving a buyer analyst a login to the ERP?
MCP enables controlled, query-based access through an AI assistant, rather than direct UI access. This prevents users from browsing records indiscriminately, limits the potential for bulk data exfiltration, and creates a clear, auditable trail of exactly what information was requested and provided.
Does MCP create a new 'source of truth' database?
No, MCP queries the existing systems of record (like an ERP or CRM) in real-time. It does not create a separate data warehouse. This is a key advantage during a live deal, as it avoids problems with data staleness and eliminates the need for complex data synchronization projects.
Related pages
- MCP for M&A Due Diligence: Connecting AI to Live Deal Data
- MCP Across CRM and ERP: Reconciling Pipeline With Reported Revenue
- MCP and Virtual Data Rooms: A Guide for Secure AI-Powered Due Diligence
- MCP and Data-Asset Due Diligence: A Guide for Sell-Side M&A Advisors
- Check Company Fit for Data Licensing
- MCP for Quality of Earnings Support: Reconciliation and Review
Free resources
- NPV calculator — Net present value with a discounted cash flow table.
- Time value of money calculator — Future and present value with optional regular payments.
- Business DSCR calculator — Debt service coverage from cash flow and loan terms.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Facts checked 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment