Technology Due Diligence

The same discipline as every assessment here, pointed at an asset you do not own yet. AI claims tested by someone who builds these systems, deferred capex surfaced before it becomes your capex, and security gaps found before completion rather than six weeks after. From a CTO who has lived with the consequences of diligence reports, not just written them.

UK  |  Ireland  |  Europe  |  North America

The buying moment

Diligence has a clock that no other assessment has. Exclusivity is running, the IC date is set, and the question is not whether the technology is perfect but whether anything in it should change the price, the structure, or your appetite.

Four situations bring a fund or an acquirer to this conversation.

The LOI is signed and the clock is running

Confirmatory diligence inside an exclusivity window. Financial and legal workstreams are staffed; the technology workstream is where deal-changing findings most often hide, and where generalist reviewers most often miss them.

The CIM says AI and the multiple assumes it is true

AI capability now carries valuation weight, and many targets overstate it. A claim that survives a management presentation may not survive an hour with the codebase and the person who built it. Knowing which is which before you sign is considerably cheaper than finding out after.

The thesis is buy-and-build

The platform investment only works if the next three acquisitions can actually be integrated. That is an architecture and team question, not a slideware question, and it is answerable before the first close rather than during the second.

You are selling, and the buyer's advisers are coming

Sell-side readiness. The same review, run early on your own asset, so the findings surface on your timeline with time to fix or frame them, rather than in the buyer's report with a number attached.

What generalist diligence misses

Most technology diligence is performed by people who have reviewed many companies and run none. The report covers the stack, the licences and the org chart, and it reads competently. What it tends to miss is the things that only show up when you have owned the consequences.

Deferred capital expenditure is the classic. Years of postponed server refresh, network upgrades and security tooling do not appear on the balance sheet; they appear eighteen months after close, as your invoice. A team that looks adequate on an org chart can conceal key-person concentration that makes the platform un-runnable if two people resign. Security posture that passes a questionnaire can fail the first enterprise customer audit after close, which is when it reprices the asset. And AI claims are the newest gap: a reviewer who has never taken a model to production cannot tell a working system from a well-rehearsed demo, and the difference can be a full turn of the multiple.

The distance between a diligence report and the first year of ownership is where acquirers lose money. I have spent much of my career on the ownership side of that distance.

Reviewing an asset and having run one are different things

Over twenty-plus acquisition integrations, including as group CTO of a PE-backed platform built through acquisition, I have been the person who inherits the diligence report and then lives with what it missed: the migration that was priced as a quarter and took a year, the platform that could not absorb the next acquisition, the security gap that surfaced in the first customer audit after close.

That experience changes what gets checked. Architecture is assessed for whether the next acquisition can land on it, not just whether it is tidy. The team review looks for the two people the platform cannot lose. Spend analysis normalises capex against what should have been invested, not what was. And because I design and build production AI systems, AI claims are tested at the level where they are true or false: the data, the grounding, the evaluation, and the cost per transaction, not the demo.

How the work runs

The method is the same as every engagement here, compressed to the deal's timeline: scope and fee agreed before anything starts, evidence over representation, findings written against that evidence. Diligence adds two constraints: access is negotiated rather than given, and the report is written for an investment committee rather than a board.

Scope to the thesis

We agree what the deal needs to be true, what access the process allows, and the date the IC needs answers. The scope follows the thesis: a buy-and-build platform gets an integration-readiness weighting; an AI-premium deal gets the claims tested first.

Evidence

Management sessions with the technology leadership; architecture, codebase and data review to the depth access permits; spend and capex analysis; security and compliance posture; team structure, tenure and key-person exposure. Where access is limited, an outside-in review is run and labelled as such.

Findings, weighted by deal impact

Every finding is classified by what it means for the transaction: price, structure, condition to close, or post-close plan. A red flag without a deal consequence attached is an observation, not a finding.

IC-ready report

Written for the people making the investment decision: what is sound, what reprices, what to condition, and what the first hundred days need to fix. Delivered on the committed date.

What you get

  • A red-flag register, each item weighted by deal impact: price, structure, condition, or post-close action
  • Technology capex normalisation: what has been deferred, what it costs to catch up, and when it lands
  • AI claims verification: which claims survive technical review, which do not, and what the real capability is worth
  • Security and compliance exposure, framed by what an enterprise customer audit or insurer will find after close
  • Key-person and team risk: who the platform cannot lose, and what retention needs to cover
  • Architecture and integration readiness against the investment thesis
  • A first-hundred-days technology view: what must happen post-close, in what order, at what cost
  • An IC-ready report and a walkthrough with the deal team, on the committed date

Both sides of the table

Buy-side, this work protects the price. Sell-side, it protects the timeline: an issue you find three months before the process starts is a fix; the same issue found by the buyer's advisers is a chip. The review is identical; only the beneficiary of the timing changes.

When this is worth doing

This work earns its fee when a transaction is real: an LOI in negotiation or signed, a process launching inside six months, or a platform thesis that depends on integration. Earlier than that, a lighter outside-in screen answers most questions at a fraction of the cost, and if that is the honest recommendation, that is the recommendation. Diligence sold to the merely curious is a document nobody reads.

After the deal

Findings are only worth what happens to them post-close. Where the first hundred days need senior technology leadership, I take that work directly: integration oversight, the interim CTO seat, or advisory support to the portfolio company's own team. Agreed after the report, never sold inside it.

Fixed fee, agreed in advance, with the delivery date committed in the proposal. Deal timelines are honoured or the engagement is declined.

If there is a transaction on your desk and the technology story is carrying weight in the price, the first step is a conversation about the thesis and the clock.

Book a call