M&A Due Diligence: Uncovering Shadow IT and Post-Close Technology Pitfalls
Standard due diligence checks software, procurement, vendor, and utility expense line items rather than actual workflows, resulting in critical operational debt hidden behind clean spreadsheets. This brief outlines how "Shadow IT" and tribal knowledge obscure real technology liabilities when operators assume control of a new business acquisition, and provides specific diligence questions and actionable steps sponsors can use to identify these pitfalls before closing.
We participate in discussions on Searchfunder, an online community for investors. Engaging directly with lower-middle-market private equity sponsors and independent operators allows us to stay attuned to the unique challenges sponsors face during acquisitions.
Recently, a community member asked, "What surfaced in your first 90 days of ownership that you wish you had diligenced before closing?"
The thread quickly filled with similar responses: buyers had diligenced the Quality of Earnings (QoE), only to discover post-close that the business was held together by duct tape.
When due diligence happens entirely on spreadsheets, it’s easy to mistake an IT expense line item for secure, scalable systems. You can review the P&L and audit software licenses all day. But if you don't pay attention to how the work actually gets done, you are flying blind.
What we often find in the lower-middle market is that revenue is generated despite the official systems. The business relies on legacy employees who build parallel processes just to survive the workday.
The Realities of Post-Close Discovery
When we audit operations post-close, we consistently uncover the same hidden liabilities.
Here’s what it usually looks like:
Discovery 1: The Estimator's Spreadsheet
You review the tech stack during diligence and see a line item for an enterprise quoting tool or ERP. You assume the company has a standardized, scalable pricing model.
The post-close reality is that the lead estimator does all the complex math on a local Excel file saved to his desktop. He only uses the official system to generate a flattened PDF for the client. The actual intellectual property, margins, and vendor logic live exclusively in his head and spreadsheet.
The operational damage goes beyond key-person risk. Because those granular calculations never enter the core system, the production team is handed a black box. When a project goes over budget, conducting a financial post-mortem is impossible. There is no detailed breakdown to compare actuals against estimates, so you bleed margin without a way to diagnose why.
Discovery 2: The "Shadow IT" Contagion
You audit IT spending and verify that the company is paying for a secure Microsoft 365 or Google Workspace environment. Check the box.
The post-close reality is that the existing productivity suite was too slow or difficult to use, so the team bypassed it entirely. Half the staff runs client communication through free, personal Gmail accounts. Critical design files and contracts are shared via personal Dropbox folders. You don't actually own your company's data. It lives in employees' consumer-grade accounts, posing a massive security and compliance liability.
The Autopsy: 3 Reasons Operational Diligence Fails
Auditing Licenses Instead of Workflows: Checking a box that says "They pay for an ERP" tells you nothing about adoption. Software is a transaction. Enforcing its use requires governance.
The Shadow IT Blind Spot: Traditional IT diligence checks the perimeter for cybersecurity risks, but it rarely checks if employees are bypassing the secure systems to do their jobs faster.
The Tribal Knowledge Trap: Confusing a highly capable, tenured employee with a scalable operational system. If the process only works because one specific person is managing it, that person is a single point of failure.
The Prescription: The "Keystroke" Test
To uncover Shadow IT and heroics before closing, bypass the executive summary. Ask frontline operators one specific question to make the audit payoff clear:
"Don't tell me how the system works. Show me. Walk me through the exact clicks, keystrokes, and folders required to take an order from a signed contract to a shipped box."
If the answer means minimizing the main software to open a personal Dropbox folder, or switching over to a local spreadsheet that no one else has access to, you aren't buying a system. You are buying operational debt.
Financial diligence tells you what the company is worth today. Operational execution dictates what it will be worth tomorrow. That is the audit payoff: it shows where value is protected or lost.
This is why The Odd Agency becomes directly involved in business transitions. We translate tribal knowledge, eliminate Shadow IT, and transform fragmented efforts into resilient systems. Laura and I provide sponsors and founders with clear insight into operational debt and the practical steps needed to address it.