Independent technology diligence on deal timescales

Technology Due Diligence for Private Equity and Acquirers

Technology due diligence is the independent assessment of a target business's technology before an investment or acquisition completes. It covers architecture and scalability, cyber security, technical debt, software delivery capability, key-person and third-party risk, licensing, data protection, and the real cost of the technology roadmap the deal is priced on.

Intology carries out technology due diligence for UK private equity sponsors and corporate acquirers, buy-side and sell-side. The review is led by an operator who has run the systems, integrations and recoveries that diligence is meant to predict, and the output is a position on risk and cost that an investment committee can use.

Intology does not sell technology, integration or remediation work, so nothing in the report is a sales pipeline.

Independent of vendors and integrators Findings quantified in £ Written for investment committee

What technology due diligence covers

The scope is set by the investment thesis, but a complete review addresses all of these:

  • Architecture and scalability: whether the platform can carry the growth in the plan or is already at its limits
  • Cyber security posture: controls, breach history, incident response and the exposure that transfers on completion
  • Technical debt: what it is, what it costs to carry, and the capex required to reach the roadmap
  • Software delivery capability: the team, tooling, release cadence and quality behind the product
  • Key-person and founder dependency: which capabilities leave if one person does
  • Third-party, licensing and contract exposure, including change-of-control clauses and TSA dependencies
  • Data protection and regulatory obligations, including UK GDPR and, where relevant, DORA and operational resilience
  • The ERP and data estate: whether the business can produce the management information a new owner will need

Buy-side and sell-side

Buy-side technology due diligence

Before you commit capital, an independent view of what you are buying, what it will cost to own and fix, and whether that cost supports the thesis. Findings feed the price, the SPA and the 100-day plan.

Sell-side and vendor readiness

Before a process starts, the technology estate and the evidence base are prepared so the asset stands up to a buyer's diligence and value is not eroded at exclusivity. See the guide to vendor due diligence.

Three levels of review

Not every deal needs the same depth at the same moment.

Red-flag review

A fixed-fee, pre-LOI read on the five areas most likely to move price or plan, delivered as a one-page RAG memo with a verdict on whether full diligence is warranted.

About the red-flag review

Full technology due diligence

The complete review above, scoped to the investment thesis and the information available, typically completed in two to four weeks depending on access to management and the data room.

Focused deep-dives

Cyber security, software and codebase, or ERP and data, where the thesis depends on one area or a red-flag review has raised a specific concern.

How Intology runs a technology due diligence

Step 1

Scope against the thesis

What has to be true about the technology for the deal to work, and what would change the price.

Step 2

Data room and request list

A targeted information request rather than a generic questionnaire, so management time goes on the questions that matter.

Step 3

Management sessions

Structured sessions with the technology leadership and the people who actually run the estate.

Step 4

Evidence testing

Claims tested against contracts, cost data, incident records, architecture and, where the deal warrants it, the code.

Step 5

Quantified findings

Each finding rated, costed in £ where the evidence allows, and mapped to price, SPA protection or the 100-day plan.

Step 6

Investment committee read-out

A report written for the investment committee and a read-out to the deal team, with the detail available to the operating team.

What you receive

  • A one-page RAG summary for the investment committee
  • A risk register with £ exposure where evidence exists
  • A technical debt position and the capex required to reach the roadmap
  • A cyber security assessment with remediation cost and timing
  • A key-person and third-party dependency map
  • Input to SPA warranties, indemnities and conditions
  • Integration or separation implications, including TSA scope where relevant
  • A technology 100-day plan the new owner can start on day one

Independence, and why it changes the findings

Many technology due diligence providers also sell the remediation, the integration or the managed service that follows. That does not make their findings wrong, but it does mean the size of the problem and the size of the follow-on work are connected.

Intology holds no reseller agreements, no vendor partnerships and no implementation revenue, and does not bid for the remediation work its diligence identifies. The finding that a platform is fine, or that a problem is cheaper to fix than the target's own plan suggests, costs Intology nothing.

Technology due diligence, M&A advisory or an IT audit?

Three different pieces of work that are often confused.

Technology due diligence

A deal-focused assessment of technology risk and cost against an investment thesis, on deal timescales. That is this page.

M&A advisory

Operational due diligence, carve-out and post-merger integration across the whole business. See M&A advisory.

IT audit

A control-focused review against a standard, usually for compliance. It answers whether controls exist, not what the technology will cost a new owner.

For a structured list of what to check, see the IT due diligence checklist. For mid-market practice, see how to conduct technology due diligence in mid-market deals.

After completion

Diligence is where the value creation plan starts. Intology also leads the technology parts of the 100-day plan, post-merger integration, carve-outs and TSA exits, and exit readiness, often through a fractional or interim CIO. The operator who finds the risks can help remove them.

Who leads the review

Technology due diligence at Intology is led by Richard Keenlyside, Intology's founder. He has led technology due diligence and 100-day plans on private equity transactions up to £1.7bn enterprise value, with integration and carve-out work across 36 countries. See his M&A experience and technology diligence work for PE portfolio companies.

Frequently asked questions

The questions deal partners, operating partners and corporate development teams ask most often.

What does technology due diligence involve?+
An independent assessment of a target's technology before an investment completes: architecture, cyber security, technical debt, delivery capability, key-person and third-party risk, licensing, data protection and the cost of the roadmap. The output is a position on risk and cost mapped to the investment thesis.
How long does technology due diligence take?+
A red-flag review is fast and fixed in scope. A full technology due diligence typically takes two to four weeks, depending on the depth required and access to management and the data room.
When should technology due diligence be commissioned?+
Ideally before LOI for a red-flag view, and before exclusivity ends for the full review, so findings can still influence price, the SPA and the 100-day plan.
What red flags does technology due diligence surface?+
Most often: a platform that will not scale to the plan, technical debt that understates capex, cyber exposure that transfers on completion, key-person dependency, restrictive licences or change-of-control clauses, and finance systems that cannot produce the information a new owner needs.
How is technology due diligence different from an IT audit?+
An IT audit tests controls against a standard. Technology due diligence asks what the technology will cost to own, operate and fix, and whether that supports the deal.
Is cyber security due diligence included?+
Yes. Security posture, breach history, incident response and regulatory exposure are assessed in every review, because liability and remediation cost transfer with ownership.
Do you carry out sell-side technology due diligence?+
Yes. Sell-side work prepares the estate and the evidence base before a process starts, so the asset stands up to a buyer's diligence.
What does it cost?+
The red-flag review has a published fixed fee. Full technology due diligence is quoted as a fixed fee per deal once the scope is agreed.
Is Intology independent of technology vendors and integrators?+
Yes. Intology holds no reseller agreements, vendor partnerships or implementation revenue, and does not bid for the remediation work its diligence identifies.

Working on a live deal?

Tell us where the deal is and what the thesis depends on. We will tell you whether a red-flag review, a full technology due diligence or a focused deep-dive is the right call. Conversations are confidential and an NDA can be in place within 24 hours.