All Services
M&A & Transactions

IT Due Diligence

Buyer-side M&A due diligence before acquisition close.

1–2 weeksBuyer-side M&A

A red-flag-first M&A assessment for buyers and investors, covering technology debt, security exposure, integration effort, key-person risk, and inherited vendor commitments inside the deal window.

Led directly by SvenIndependent recommendationsScope agreed before delivery

Runs on the Galactus assessment platform: anchored questions, evidence-based scoring, and red flags that override averages. Probe depth scales with the access your deal allows. See how our assessments work

50 anchored questions · 7 scored domains · priority mode for compressed DD windows

We run both sides of the table: buyer-side IT Due Diligence and seller-side Exit Readiness, on the same instrument. See Exit Readiness

How this engagement stays controlledA senior mandate should make the decision, evidence, and accountability easier to control.

Decision first

The mandate starts with the decision, owner, time window, and evidence that could change the answer.

Evidence and boundaries

Scope, exclusions, evidence access, and uncertainty are made explicit before conclusions are presented.

Accountable handover

Sven leads the work directly and closes with clear ownership, decisions, and next actions.

Protect the deal window

How IT findings become transaction decisions

Technology debt, exposure, integration effort, and inherited commitments are translated into consequences the deal team can act on before close.

Deal question

What IT due diligence must answer before close

The review starts with the investment thesis and the deal questions that technology can materially change: continuity, scalability, integration or separation effort, security exposure, key-person dependency, and the reliability of the cost base.

Red flags

Red flags need deal consequences

A technical weakness matters when it affects valuation, warranties, escrow, conditions to close, day-one continuity, or the first 100 days. Findings are therefore framed by consequence and evidence strength, not by severity labels alone.

Value impact

Integration effort belongs in the valuation

Applications, data, identity, infrastructure, vendors, licenses, operating capability, and technical debt are tested against the proposed integration or separation model. Where evidence allows, the review exposes likely cost, timing, and dependency implications.

Deal action

Findings shaped for the deal team

The output separates confirmed red flags, open questions, assumptions, and post-close actions so investors, legal advisers, management, and integration owners can use the same evidence without receiving a generic technology report.

Decision dossier

What this mandate decides, includes, and hands back.

The useful boundary is visible before the work begins: the decision, the evidence, what is excluded, and what happens next.

Decision

The decision this supports

Whether the target's IT changes valuation, deal protections, integration assumptions, the day-one plan, or the investment thesis.

Included

In scope

Technology debt, architecture, security and continuity exposure, applications and data, team and key-person risk, vendors and licenses, integration or separation implications, cost, and evidence coverage.

Boundary

Out of scope

Legal, financial, tax, or cyber-forensic opinions; code-level product diligence unless specifically added; and post-close integration delivery.

Evidence

Evidence required

Data-room material, contracts, architecture and asset records, security and incident evidence, cost and staffing data, project information, and management interviews within the access allowed by the deal.

Handover

What happens next

The deal team receives a concise red-flag chapter, quantified implications where evidence allows, open questions, and actions for terms, day one, and the first 100 days.

How the mandate is set up

Timing

1–2 weeks

Delivery owner

Every mandate is led directly by Sven Van Roosenbroek. Specialist involvement, when needed, is made explicit in scope.

Commercial model

Fixed fee shaped by deal window, target complexity, and available access.

What you receive

  • A clear-eyed view of tech debt and the real cost to remediate it
  • Integration effort and timeline estimated, not guessed
  • Security and compliance exposure surfaced before it becomes your liability
  • Key-person and single-point-of-failure risk identified
  • Findings translated into price, escrow or warranty leverage
  • One concise report your deal team can act on - no 80-page filler

Use this when

  • Acquirers evaluating a target's technology before close
  • PE firms screening platform or bolt-on investments
  • Corporate development teams without in-house IT diligence capacity
  • Deals where IT is material to valuation or integration risk

Bring the decision to a direct conversation.

Thirty minutes is enough to establish fit, the right depth, and the next responsible step.