We’ve sat on your side of the table
Our leadership brings board-level technology ownership in an S&P 100 group. We speak the language of the boardroom and the deal room.
ICAN Consultancy · Executive Field Guide
M&A Technology Advisory & Digital Divestments
A practical playbook for acquirers, investors and divesting leadership: how to see inside a target's technology before you sign, cost the integration honestly, and cut over cleanly — including the hidden risks no data room will show you.
Proper technology diligence looks through every lens below — and scores what it finds against evidence, not against what management presented.
| Lens | The questions that price the deal |
|---|---|
| 1 · Architecture & scalability | Can the platform carry the growth the deal model assumes? What breaks first, and what does fixing it cost? |
| 2 · Code quality & delivery | Automated codebase scans: technical debt, test coverage, deployment maturity. How fast can this team actually ship? |
| 3 · Team & key-person risk | Who really keeps this running? What leaves when they leave — and would you know before they resigned? |
| 4 · Security & compliance | DevSecOps posture, vulnerability exposure, incident history, regulatory readiness. Audits find high-risk vulnerabilities in most acquired codebases — assume you’re not the exception. |
| 5 · IP & open-source exposure | Licence obligations that can poison proprietary claims; provenance of everything the valuation calls “owned”. |
| 6 · Data & AI exposure | Data handling, residency and consent; for AI features — model provenance, training data rights, third-party model dependencies. |
| 7 · Roadmap credibility | Is the roadmap engineering reality or investor fiction? Does delivery history support the promises the price assumes? |
Codebase scanning gives you objective, comparable, fast coverage of lenses 1–2 and 4–5 across the whole estate — no reliance on the target’s self-assessment, no cherry-picked demos.
Lenses 3 and 7 — the ones that most often kill post-close value — are invisible to scanners and spreadsheets. They require a fundamentally different method: embedded, behavioural observation.
The riskiest part of a deal is never in the data room. It’s in how the target actually works when nobody is presenting.
Seven engineers, healthy commit volume across the board — by every mechanical measure, a balanced, productive team. Then we joined their sprints and watched the work happen. The commit graph showed seven contributors; the sprint showed one engine.
Read the full story — and what it changed in the dealEvery one of these has sunk real deals. None of them appears in a data room. All of them have tells — if you know where to sit.
| Red flag | What it looks like from outside | The tell |
|---|---|---|
| The hidden engine | A “balanced team” where one person quietly carries the architecture, the reviews and the hard problems. | In sprint ceremonies, every difficult question routes to the same person — whatever the org chart says. |
| Demo-ware | A product that performs beautifully in exactly the scenarios management shows you. | Ask to watch a real customer onboarding end-to-end, unscripted. Watch what gets worked around by hand. |
| Licence time-bombs | Proprietary product claims sitting on copyleft open-source components or unlicensed code. | Automated provenance scans against the full dependency tree — never the target’s own inventory. |
| Security theatre | Certifications on the wall, policies in the wiki — and credentials in the codebase. | Scan results vs. paperwork. Ask when the last real incident drill ran and what it found. |
| Roadmap fiction | An 18-month roadmap that justifies the price, promising 3× historical delivery pace. | Compare promised velocity with the last year of actual delivery. Ask the engineers — in private — what they believe ships. |
Every tell requires either objective scanning or embedded observation. None can be caught by questionnaire — which is why questionnaire-driven diligence keeps certifying deals that fail.
If your diligence provider’s report could have been written without ever watching the target’s team work, what exactly did it de-risk?
Anyone can count commits. The question is who is actually carrying the company — and whether they’ll still be there a year after you buy it.
We led the carve-out and divestment of a $40M technology estate — repositioning a loss-making product company into a profitable professional-services firm within twelve months, while cutting employee churn from 15% to 5%. And as primary technical authority for a global BioPharma group’s M&A, we assessed targets’ DevSecOps, cloud readiness and open-source risk with automated codebase scans — fast, objective, evidence-based reads before the price was set.
Delivered by ICAN’s leadership in prior engagements and senior roles.
Read the divestment case studyThe full deal lifecycle, the behavioural diligence method, integration costing, carve-out principles, TSA exit discipline and the phase-by-phase checklist — the full 12-page guide, free to read and share.
You are welcome to share this guide in full, with attribution.
Our leadership brings board-level technology ownership in an S&P 100 group. We speak the language of the boardroom and the deal room.
The same engineers who advise on the deal run the codebase scans, sit in the sprints, untangle the infrastructure and execute the cutover. Diligence grounded in delivery.
Hidden risks and unspoken dynamics — key-person dependencies, shadow hierarchies, roadmap fiction — surfaced by embedded observation, not questionnaires.
Assessing a target, planning an integration, or untangling a carve-out — we’ll come back with a clear, evidence-based view of the technology risk and the path to delivery.