Due Diligence · 8 min read
What PE Technical Due Diligence Should Cover Before Close
A practical PE/VC technical due diligence checklist — infrastructure risk, stack scalability, integration debt, and a clear path to post-close outcomes.
Technical due diligence is not a tool inventory. Investment committees need ranked risk, scalability against the growth thesis, and a Day-100 integration path — not a slide of logos.
This checklist is the working agenda Foundation5 uses on technical due diligence engagements for private equity, venture, and corporate development teams. Use it to scope interviews, prioritize artifacts, and leave operating partners with actions they can execute after close — the same pattern we applied when supporting Smarsh through diligence and Day-100 stack integration.
1. Growth thesis and system of record map
Start with what must be true post-close. If the thesis depends on cross-sell into an acquired install base, map whether CRM, billing, and product usage data can support that motion. If the thesis depends on geographic expansion, test whether the stack supports multi-entity accounting, tax, and local compliance without heroic spreadsheet work.
Build a one-page system-of-record diagram: which platform owns customer, product, price, entitlement, invoice, and cash application. Conflicts here are where synergy models quietly fail. Ask for the last board pack and the source queries behind each revenue chart — if finance cannot reproduce numbers without manual reconciliation, the diligence memo must say so.
Interview commercial leadership separately from IT. Sales often knows where opportunities live outside CRM; finance knows where invoices are adjusted; support knows where entitlements are wrong. Those workarounds are diligence findings, not cultural color. Capture them as process debt that will consume the first hundred days whether or not you planned for it.
2. Infrastructure, cloud cost, and single points of failure
Review cloud spend trajectories for the last four to eight quarters, reserved-instance coverage, and orphaned resources. Sudden step-changes often signal migration debt or uncontrolled experimentation. Identify single points of failure: one region without DR, one database without tested restore, one vendor whose outage stops billing or identity.
Request recent incident postmortems and backup restore tests — not policy documents alone. Ask who can declare an incident and who owns customer communication. Key-person risk often hides in infrastructure: the engineer who alone understands the VPN, the contractor who alone can deploy.
Security posture belongs in the same pass: SSO coverage, privileged access reviews, vulnerability SLA performance, and whether production access is audited. For SaaS targets, review tenant isolation claims and customer data handling against the acquirer's standards. Note any "shadow IT" SaaS with company data that never appeared on the CIO's inventory.
3. Application stack: CRM, ERP, billing, and custom code
Inventory business applications with owners, license counts, renewal dates, and known technical debt. CRM and ERP deserve extra depth because they underpin revenue recognition and customer experience. Poor Salesforce or NetSuite data quality is often the silent killer of synergy assumptions — duplicate accounts, conflicting product catalogs, and automation that no longer matches the process.
Sample data quality: duplicate rates, required-field completion on closed-won opportunities, aged open cases, and integration error queues. Walk through one order end to end: quote → order → invoice → cash → recognition. Note every system hop and every manual step. If that walk takes a war room, Day-100 integration will too.
Custom code and low-code automation (Apex, Flows, scripts, middleware maps) need an age and ownership review. Untouched automation from a prior SI engagement is a liability if nobody can explain failure modes. Prefer evidence of CI/CD, sandbox promotion discipline, and regression tests for revenue-critical paths. Our Salesforce & CRM consulting practice sees the same failure modes whether the context is diligence or a rescue engagement.
4. Integration debt and Day-100 feasibility
List integrations by criticality: identity, CRM↔billing, CRM↔support, data warehouse, marketing automation, and partner portals. For each, capture pattern (batch vs real-time), error handling, and who gets paged. MuleSoft, Boomi, or custom APIs are fine — undocumented point-to-point spreadsheets are not.
Score Day-100 feasibility honestly. Can identity be unified in ninety days? Can invoices continue without dual-running forever? What breaks if the target's Salesforce org stays separate for a year versus merge? The Smarsh engagement shows why diligence that stops at "red flags" fails operators — rankings and remediation cost ranges must connect to a sequenced cutover plan.
When the acquirer already runs Salesforce or NetSuite, compare data models early. Org merges and multi-org strategies have very different cost curves; pretending they are the same inflates deal models. Include telephony, CPQ, and customer portals in the same integration score — they are often omitted until week six after close.
5. People, vendors, and operating model
Map the technology org: full-time vs contractors, onshore vs offshore, and which vendors hold institutional knowledge. Identify roles that cannot be vacant for thirty days without revenue or compliance risk. Review SOWs for evergreen contractors who effectively run production.
Ask how change is approved today — CAB theater versus lightweight risk-based review. Post-close, you will inherit that culture. Portfolio companies that lack named system owners for CRM and billing struggle to absorb any integrator's recommendations.
Capture training and documentation reality. If runbooks live in one engineer's head, price knowledge-transfer into the hundred-day plan. Ask who owns vendor renewals and whether any material contracts auto-renew inside the lockbox period.
6. Security, privacy, and compliance obligations
Align the target's certifications and contractual commitments (SOC 2, ISO, HIPAA, PCI, GDPR/CCPA) with the acquirer's obligations to customers. Gaps are not only legal — they change product roadmap and sales cycle length.
Review access to production customer data, retention policies, and subprocessors. Voice and AI features deserve explicit review: what is recorded, where transcripts live, and whether customers consented. These questions overlap our Voice AI consulting work when targets claim AI differentiation without governance.
7. Checklist summary for the investment committee
Deliver a memo investment committees can use:
Also attach a short "what we could not see" list — systems without access, interviews declined, or data rooms that arrived late. Unknowns are findings.
Foundation5 structures diligence interviews and artifact review around these questions, and often stays through the first hundred days so findings become Salesforce, billing, and identity workstreams — not rediscoveries in month three. If you are preparing a deal or a portfolio company integration, schedule a diligence conversation.
- Red / yellow / green ratings by domain (infra, apps, data, integrations, people, security)
- Top ten issues ranked by severity and estimated remediation cost/range
- Explicit call on whether the stack supports the growth thesis in 12–24 months
- Day-100 recommended workstreams with owners (internal vs external)
- Items that should change purchase price, escrow, or close conditions
Related reading
For process and systems work that often follows close, see process mapping before automation spend and legacy migration without rip-and-replace.
8. Working sample: artifact request list
Send this list early so the data room fills with decision-useful material instead of marketing PDFs:
When artifacts are missing, record the gap. Persistent gaps after repeated requests are themselves a diligence signal about operating maturity.
- Org charts for technology, RevOps, and finance systems owners
- Architecture diagrams (even imperfect) for CRM, billing, ERP, identity, and data warehouse
- Last four quarters of cloud invoices with tagging conventions explained
- Salesforce (or CRM) storage and API usage reports; Flow/Apex inventory if available
- Integration inventory with owners and last incident dates
- Top twenty production incidents in twelve months with severity and time-to-restore
- License and renewal calendar for material vendors
- Sample of ten closed-won opportunities and ten invoices traced end to end
- Access policy, privileged account list, and latest access review evidence
- Any AI or bot features in production with permission and retention notes
9. How Foundation5 runs the engagement
Typical timelines compress into deal calendars: focused assessments in days to a few weeks depending on access. We staff senior practitioners who have implemented the platforms under review — not generalist slide producers. Findings land in investment-committee formats: executive ratings, issue register with cost ranges, and Day-100 workstreams.
When asked, we stay through integration so the memo becomes Salesforce, identity, and billing execution. That continuity is why operating partners prefer diligence teams who also deliver — fewer handoffs, fewer rediscoveries.
Cluster reading
Dive deeper with CRM/ERP data quality in diligence, Day-100 tech integration, and key-person risk.
Related reading
Due Diligence · 5 min read
CRM and ERP Data Quality in Technical Due Diligence
How duplicate accounts, conflicting catalogs, and integration error queues quietly break PE synergy models — and what to sample before close.
Due Diligence · 5 min read
Day-100 Tech Integration Plan After Acquisition
A practical hundred-day plan for identity, Salesforce, billing, and integrations — so diligence findings become operating reality.
Put these ideas to work
Schedule a consultation to discuss technical due diligence for your team.
