MSP acquisition due diligence checklist: PSA, tickets, documentation and data rights

An MSP acquisition due diligence checklist should test the PSA, ticket history, RMM and documentation platforms, client contracts and authorship of runbooks, not just MRR and churn. Those same checks pre-screen the seller for AI data licensing: years of resolved tickets an MSP has the right to license can become a separate, one-time source of proceeds.

Why an MSP diligence checklist should cover data rights

The checks you already run in IT-services diligence (PSA reporting, ticket samples, RMM coverage, client contracts) answer two questions at once: how healthy the service operation is, and whether the seller holds years of operational records it has the right to license for AI training. Adding a rights section costs one extra page on the request list, and nobody has to hand over a single ticket to answer it.

Both sides of the table benefit. A sell-side advisor can surface a possible additional source of proceeds before the business goes to market. A buy-side advisor learns whether the target's service history is an asset, a liability or both, and whether client agreements allow the MSP to reuse it at all.

The demand behind this is specific. AI developers are training agents to triage, troubleshoot and resolve IT problems, and they need real examples of that work: the alert, the ticket, the technician's notes, the time entries, the escalation and the fix. A mature MSP's PSA holds exactly that sequence, often across a decade of clients and technologies. M&A advisors who work IT services deals are well placed to notice it because the PSA reports are already in the data room.

How to use this checklist

Work through it during the data room review and the first management meeting, before the LOI narrows everyone's attention to price and terms. Every item asks for metadata, a document you would request anyway, or a yes or no answer from management. None asks for ticket contents, client names or credentials.

Tick an item only when you have seen the document or a written answer. Anything left unticked becomes a follow-up question, not an assumption.

The MSP due diligence checklist

PSA and ticket history

  • Which PSA runs service delivery (ConnectWise PSA, Autotask, HaloPSA or another), and in which year did it go live?
  • Were tickets migrated from an earlier PSA, and does the old system or a full export of it still exist?
  • Rough annual ticket volume, split between reactive tickets and alert-generated or recurring maintenance tickets.
  • Are resolution notes, internal notes and time entries completed consistently, or do many tickets close blank?
  • Are tickets linked to configurations, agreements and SLAs, so each one can be traced to an environment and a contract?
  • Do closed statuses carry meaning (resolved, escalated to vendor, duplicate, client-caused), or does everything close the same way?

RMM, documentation and security tools

  • Which RMM platform is in use, and how long does it keep alert, patch and script-run history?
  • Is there a documentation platform such as IT Glue or Hudu holding runbooks, standard operating procedures and network diagrams?
  • Who wrote the runbooks and automation scripts: employees, subcontractors or a vendor?
  • Do security tools (EDR, SIEM, backup) retain incident records that the MSP, not only the client, can access?
  • Are credentials stored in the documentation platform? They must be excluded from any data work, whatever else happens.

Client contracts and data rights

  • The standard MSA and the largest client agreements: what do the confidentiality, data use and return-of-data clauses say?
  • Does any agreement permit use of de-identified or aggregated service data, or does it limit use strictly to delivering the services?
  • Which clients sit in regulated sectors (healthcare, financial services, government) with business associate agreements or flow-down terms?
  • Is there a documented process for client data at offboarding, and has it been followed?
  • Has any part of the service history already been licensed or shared for AI training?

People, size and authorship

  • Peak full-time headcount, contractors excluded. The SourceX baseline is 50+ full-time employees at peak (contractors excluded).
  • Which share of technical delivery ran through subcontractors or offshore partners, and under what intellectual property terms?
  • Do employment agreements or the handbook state that work product belongs to the company?

Licensing pre-screen for the owner

  • Would the owner consider an exclusive AI-training license for an agreed term, paid once, separate from the sale?
  • Who would act as the authorized sponsor: the owner, CEO, CFO or another authorized representative?
  • Is there someone inside the MSP who can run exports and own a metadata inventory?

Authorship gets its own section because copyright ownership follows it. The US Copyright Office's circular on works made for hire explains that a work prepared by an employee within the scope of employment belongs to the employer, while commissioned work from an independent contractor counts as work made for hire only in listed categories and with a signed written agreement. A runbook library written by salaried engineers is a cleaner asset than scripts a subcontractor produced under a loose statement of work. This is general information, not legal, tax or financial advice. Confirm with deal counsel before relying on it.

How to read the results

ResultWhat it meansNext action
PSA live five or more years, consistent notes, contracts silent or permissive on de-identified useA well-documented service business and a credible licensing candidateRaise the licensing pre-screen with the owner before marketing or at the management meeting
Deep history, but every MSA limits use to service deliveryRights work is needed; a narrower scope or client consents may be requiredNote it in the diligence memo and involve counsel before any licensing conversation
History lost in a PSA migration, old system deletedA trend-analysis gap for the buyer and little left to licenseAsk whether backups or archived exports survive
Most delivery by subcontractors without IP assignmentsOwnership of documentation and scripts is unclearAsk counsel about assignments before going further
Peak headcount short of 50+ full-time employees (contractors excluded)Outside the SourceX baselineDrop the licensing question; the deal proceeds normally
Owner has no interestLicensing is optionalLeave it there and keep the transaction on track

The rights readiness checklist goes deeper on contract language once a seller looks promising, and who qualifies lists every baseline requirement.

Where the licensing question fits in the deal timeline

Deal stageLicensing stepWho leads
Pre-marketing (sell-side)Run the owner pre-screen; decide whether to explore a license before, during or after the saleSell-side advisor and owner
Data room buildIndex PSA reports, MSAs and documentation summaries; never upload ticket contents for licensing purposesAdvisor with the MSP's operations lead
Confirmatory diligence (buy-side)Read data-use clauses; ask whether any history is licensed or committedBuyer's counsel
Purchase agreementDisclose any existing or pending license, its scope, term and exclusivityCounsel for both sides
Post-close integrationPreserve PSA, documentation and mailbox exports before systems are retiredBuyer's integration lead

Integration is where history quietly disappears. If the platform will fold the acquired MSP into its own tenant, the Microsoft 365 tenant migration playbook covers what to keep before cutover.

Red flags that end the licensing conversation, not the deal

  • Ticket contents are mostly about client systems, every MSA forbids secondary use, and client consent is unrealistic.
  • Many clients are healthcare providers and tickets routinely contain patient information.
  • The PSA was purged, or a migration brought over only open tickets.
  • The history has already been licensed for AI training.
  • Nobody at the MSP can export the PSA or the documentation platform.
  • A lender, receiver or trustee controls the assets and has not been involved.
  • Records were generated or padded with AI to look larger.

How an advisor makes the introduction

  1. Ask the owner whether they want to explore licensing at all, and how it should sit alongside the sale process.
  2. Register as a partner, then send your referral link or submit the MSP through the referral form.
  3. SourceX checks headcount, operating history, the spread of systems and rights directly with the owner or another authorized sponsor.
  4. The MSP lists its PSA, RMM, documentation and email systems as metadata, for example with the data inventory builder; no records change hands at this stage.
  5. Price and terms are agreed with the MSP, as one all-in price, before AI labs and data buyers review the opportunity.
  6. Once an agreement is signed, the MSP delivers data under the redaction rules agreed at the start and receives a one-time payment.

Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company, and the reward is paid only after the buyer pays and SourceX receives its fee. No reward is guaranteed, and it is never deducted from what the company receives. If a seller already pays you a success fee, tell them about the referral relationship and check your engagement letter and firm policy before you register.

Next step

Add the licensing pre-screen items to your next IT-services request list. When a seller passes, register as a partner and introduce the owner, or have them apply directly at sourcex.si/apply using your referral link.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

Does adding data rights questions slow down MSP due diligence?

Not in practice. Most items reuse documents already on an IT-services request list: PSA reports, the standard MSA, the largest client agreements and headcount data. The licensing pre-screen is a short conversation with the owner. Nothing requires ticket contents or credentials, so it adds questions rather than data handling, and it can run alongside the quality of earnings work.

Can an MSP license ticket history that describes its clients' systems?

Sometimes. It depends on what the MSAs say about confidentiality and data use, whether the material can be de-identified, and whether clients need to consent. Tickets that mostly describe the MSP's own methods and resolutions are easier than tickets full of client-specific details. Counsel should review the agreements, and redaction rules are agreed before any work begins.

Should a seller license data before or after selling the MSP?

Either can work, and the owner decides with the deal team. A license signed before the sale must be disclosed, and its exclusivity and term will matter to buyers. Some owners prefer to finish the sale first and let the new owner decide. What matters is that the license and the transaction are coordinated rather than run in isolation.

Will a buyer treat an existing data license as a problem?

A buyer will want to see its scope, term, exclusivity, which records were included, whether any client information was involved and whether it restricts how the business can use its own data. A clean, well-documented license with de-identified records is easier to diligence than an informal data-sharing arrangement. Disclose it early and let counsel on both sides review it.

Does the advisor ever see or handle the MSP's ticket data?

No. The advisor makes the introduction and shares basic fit information such as headcount, years on the PSA and the systems in use. The MSP works directly with SourceX on the inventory, rights review, pricing and redaction rules, and data moves only after an executed agreement and the MSP's own authorization.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment