IT due diligence checklist: the systems the business runs on, which is not the product it sells

An IT due diligence checklist and a technology due diligence checklist get used interchangeably and cover different things. IT is the estate the business runs on: laptops, networks, the ERP, the licences, the contracts and the people who keep them working. Technology is the product being bought. On a carve out the IT list matters more than either side expects, because most of it belongs to the parent. This page sets out the five areas.

The application estate and who owns each contract

Every system in use, what it costs, when the contract renews and whose name is on it. On a carve out this list is the first draft of the TSA, because anything the parent contracts for is either being novated, replaced or rented back. Producing it before going to market saves a negotiation later.

Licences, and whether they survive the deal

Seat counts against actual users, and assignment or change-of-control clauses in the licence terms. Under-licensing is a real liability that surfaces at the worst time, and a licence that cannot be assigned is a cost the buyer has to carry on day one rather than a negotiating point.

Infrastructure, hosting and the exit from it

Where things run, under whose account, and what it would take to move. Cloud accounts owned by the parent are the carve-out version of this problem and they show up as a TSA line: on this site's worked example, seven services at $4,200 a month with an 8% markup is $381,024 across a year.

The people, and the two who know everything

Most small IT estates depend on one or two people who have never written any of it down. Identifying them early and deciding whether they transfer is worth more than any documentation the process can produce, and it is the question a checklist tends not to ask.

Security posture, briefly

Enough to know whether there is an incident history and whether the basics exist. A full security review is its own exercise and belongs on the cybersecurity list rather than here; conflating them produces an IT review that is long on policy documents and short on the contracts that actually cost money.

Questions people ask about it due diligence checklist

How is IT diligence different from technology diligence?

IT is the estate the business runs on; technology is the product it sells. On a carve out the IT list is the first draft of the TSA.

What is most often missed?

Licence assignment and change-of-control terms, and the one or two people who know how everything works and have written none of it down.

Should security be in the IT list?

Only briefly. A full review is its own exercise, and merging them produces a list long on policy and short on contracts.

Sources

Related answers

Keep this mandate: start Mandatzo ProStop rebuilding the buyer list: start Pro