Figure 1: The M&A operational risk assessment model
Figure 1: The M&A operational risk assessment model
Financial and legal due diligence can tell you what a company owns and owes. It may not tell you whether its technology, security controls, suppliers, data practices and operating model can survive integration.
Original article date: 26 February 2024
Article type: Risk management / M&A due diligence
Mergers and acquisitions are often assessed through financial, legal and commercial lenses. Those are essential, but they can leave a significant blind spot: operational technology risk.
A target company may look attractive while carrying hidden liabilities in its applications, infrastructure, information-security maturity, third-party dependencies, data handling, resilience, technical debt or organisational capability.
These risks matter because they do not disappear when the transaction closes. They become the acquirer's risks.
This article sets out a practical pre-acquisition assessment model covering five areas:
information-security maturity and compliance;
sensitive data and privacy exposure;
third-party and supplier risk;
IT architecture, technical debt and integration risk;
resilience, people and organisational capability.
Traditional due diligence is very good at examining financial statements, contracts, ownership, liabilities and regulatory exposure.
But modern companies are increasingly software-dependent. Their value may rely on cloud platforms, custom applications, outsourced development teams, data pipelines, external APIs, SaaS platforms and a complex web of suppliers.
A transaction can therefore introduce risks that are difficult to see in a balance sheet:
unsupported or obsolete systems;
weak identity and access controls;
poor change management;
undocumented applications;
insecure software-development practices;
unknown stores of personal or sensitive data;
supplier lock-in;
weak disaster recovery;
unresolved vulnerabilities;
dependence on a small number of key employees; and
architectures that cannot be integrated economically with the acquiring organisation.
The important question is not simply "Does the target have an information-security policy?" It is: Does the organisation operate in a controlled, observable and resilient way?
The first assessment area is the maturity of the target's security-management system.
Useful questions include:
Is there an active Information Security Management System or equivalent governance framework?
Are security roles and responsibilities clearly defined?
Is there executive or board-level sponsorship?
Are policies current, accessible and reflected in actual practice?
Is formal change control used for important systems?
Are vulnerabilities identified, prioritised and remediated systematically?
Are independent security reviews or penetration tests performed where appropriate?
Are security objectives measured and reviewed?
Are incidents recorded, investigated and used to improve controls?
Are recognised standards or certifications relevant to the business maintained where required?
The purpose is not to collect certificates. It is to determine whether security is an operational capability or merely a set of documents.
A buyer should understand the target's data landscape before inheriting it.
That includes identifying:
personal information;
customer and employee records;
payment information;
authentication data;
intellectual property;
commercially sensitive information; and
regulated or contractually restricted datasets.
Key questions include:
What sensitive data does the company collect?
Why is it collected?
Where is it stored?
Through which systems and countries does it move?
Who can access it?
How long is it retained?
Which third parties process it?
Which legal and contractual requirements apply?
Can the company actually delete, export or segregate the data when required?
Unknown data is unmanageable data. A transaction can expose the acquirer to inherited privacy, retention and breach risk if the data estate is poorly understood.
Many modern businesses are only as resilient as their suppliers.
An acquisition assessment should therefore examine critical vendors, cloud providers, outsourced developers, payment providers, hosting companies and specialist service providers.
Questions should include:
Is procurement governed by a documented process?
Do security and legal specialists review high-risk suppliers?
Are critical supplier contracts and service levels documented?
Are concentration risks understood?
Is there technology, vendor or resource lock-in?
Can the organisation migrate away from a supplier?
Are exit plans realistic and tested?
Does the business know which suppliers can access sensitive data?
Are subcontractors visible?
What happens if a key supplier fails immediately after acquisition?
A low-cost outsourced service can become a very expensive acquisition liability if nobody knows how to replace it.
The target's technology estate should be examined as an operating system for the business, not merely as a list of assets.
Areas to assess include:
application architecture;
cloud and hosting models;
databases and data flows;
supported versus unsupported technology;
software-development lifecycle maturity;
deployment and release processes;
observability and logging;
shadow IT;
duplicated systems;
integration dependencies;
source-code ownership;
licensing obligations;
documentation quality; and
the portability of systems and data.
One of the most important questions is: How difficult will this environment be to integrate, operate or separate?
A business may be profitable while carrying years of technical debt that becomes visible only when an acquirer attempts to integrate it.
A company should be able to continue operating when systems fail, suppliers disappear or cyber incidents occur.
Useful evidence includes:
documented incident-response procedures;
business-impact analysis;
disaster-recovery plans;
tested backups;
recovery objectives;
crisis communications;
dependency maps;
security awareness; and
evidence that exercises have actually been performed.
The key distinction is between a plan that exists and a capability that has been tested.
Technology risk is also people risk.
A target may depend heavily on a handful of developers, architects, security specialists or operational experts whose knowledge is poorly documented.
Due diligence should therefore examine:
key-person dependencies;
employee turnover in critical functions;
succession planning;
access termination and joiner/mover/leaver controls;
the availability of technical documentation;
retention risk during an acquisition;
the maturity of performance and management processes; and
whether outsourced teams have left the company with sufficient internal knowledge to govern them.
The question is not whether the culture is "good" or "bad." It is whether the organisation can retain the capability needed to operate securely through a period of major change.
The Musmato M&A Operational Risk model converts these areas into a structured set of questions that can be assessed before acquisition.
The objective is to make hidden risk visible early enough to influence:
valuation;
contractual warranties;
remediation commitments;
integration planning;
insurance;
post-deal investment; and
ultimately the decision to proceed.
The model can be used as a structured discovery tool rather than a binary pass/fail checklist. A "no" answer is not automatically fatal; it identifies an area requiring investigation, remediation, pricing or acceptance.
A useful technology-risk assessment should leave the acquiring organisation with:
a clear view of the target's most material operational technology risks;
evidence supporting those findings;
an understanding of the likely business impact;
a prioritised remediation plan;
known integration constraints; and
explicit risk-acceptance decisions where remediation is not immediately practical.
The technology estate of an acquired company becomes part of the transaction whether it was examined properly or not.
A security breach, unsupported application, undocumented supplier dependency or brittle integration can turn into a material financial issue after closing.
That is why M&A due diligence should not treat information security and technology as a narrow technical workstream. They are part of the value, continuity and risk profile of the business itself.
Musmato's M&A Operational Risk model is designed to help buyers ask those questions before the risks become theirs.