Tech Guru
Resources

Acquiring a firm? Audit the technology like you audit the books.

The financials get scrutinized line by line. The technology usually gets a walkthrough and a shrug. That blind spot is where acquisition returns quietly go to die.

Two professionals shaking hands on an acquisition

When you buy an accounting firm, the deal is priced on the book of business: revenue, retention, realization. Those numbers get worked hard during diligence. The technology behind them usually gets a screen share and a verbal assurance that everything works fine.

But you are not just buying clients. You are buying every technology decision the seller made, and every one they deferred. The ten-year-old server in the closet. The tax software three versions behind. The backups nobody has ever tested. The retired partner whose login still works. All of it transfers on closing day, and none of it appears on the balance sheet.

Technology debt is a price adjustment nobody made

Deferred technology spending does not disappear in an acquisition. It changes hands. Aging hardware, unsupported operating systems, unlicensed software, on-premise servers, and undocumented systems are all bills the seller postponed, and after closing they are your bills, due in year one, exactly when the deal is supposed to start earning its return.

The direct costs are the obvious part: replacement hardware, licensing true-ups, migration work you did not budget. The indirect costs do more damage to your model. Staff at the acquired firm lose days to systems that fight them, right when you need them focused on retention. Clients feel the friction of a rough transition and start returning calls from competitors. Two firms limp along on two incompatible stacks for a year because integration was never scoped. Every one of those drags shows up as lower realization and higher churn, which is to say: a worse return on the price you already paid. A firm that looks identical to another on revenue can be worth meaningfully less once its technology liabilities are priced, and the only way to price them is to look before you sign.

The breach you cannot see is the one you are buying

Here is the diligence question that matters most and gets asked least: has this firm ever been compromised, and would they even know?

An undisclosed breach is bad. An unknown one is worse, and more common than most buyers assume. A firm with no monitoring, no managed detection, and no log retention is not a firm with a clean history. It is a firm with no history at all. Absence of a breach story is not absence of a breach; it may only be absence of the tooling that would have caught one. Threat actors who compromise a tax practice do not announce themselves. They quietly harvest taxpayer data, and the first sign is often fraudulent returns filed under your acquired clients' names, months after you took over.

If that surfaces after closing, it surfaces as your problem: your notification obligations, your remediation bill, your name in the letter that acquired clients open, and your retention numbers absorbing the fallout. The clients transferred to you; under the FTC Safeguards Rule and IRS Publication 4557, so did the duty to protect their data. The deal documents can assign liability, but they cannot reassign reputation, and depending on how the deal is structured you may inherit far more of the legal exposure than you expect. This is a conversation to have with your attorney before the letter of intent, not after the incident.

So the seller's security posture is not an IT detail. It is a core diligence item, on par with work-in-progress and receivables. Concretely, that means evidence, not assurances: whether multi-factor authentication is actually enforced on every account or merely available, whether anything has ever monitored the environment and for how long logs exist, whether staff credentials are circulating in credential dumps, whether there is a WISP and whether it resembles reality, what the cyber insurance policy covers, and what claims or incidents have already occurred. A firm that cannot answer those questions is not necessarily hiding something. But you should price it as if you cannot know, because you cannot.

One more transfer trap worth raising with counsel: consents. Tax firms rely on IRC Section 7216 consents to use and disclose return information, and consents obtained by the seller's entity may not simply carry over to yours. Discovering that in October is a very different experience than discovering it in diligence.

Make disclosure a signature, not a vibe

The fix for the unknown-breach problem is not asking nicer questions in a meeting. It is putting the questions in writing and getting the answers signed. Ask the seller to list every security incident from the past five years: breach, ransomware, business email compromise, wire fraud attempts, lost devices. Ask whether the answers on their most recent cyber insurance application were accurate. Then have someone sign an attestation that everything known has been disclosed. An undisclosed incident discovered after close becomes a dispute; a disclosed one becomes a plan. Written, signed answers are what turn "we never had a problem" from a vibe into a representation your attorney can work with.

What to actually ask

A real technology diligence pass fits into the same window as your financial review. The questionnaire below asks the seller, or their IT provider, to answer in writing across every area that turns into money after close:

  • People and organization. Headcount and work model drive licensing and hardware cost. Also: does one person hold all the IT knowledge, and do offshore staff touch client data?
  • The current IT provider and the transition. Contract penalties, whether Microsoft licenses are bought through the provider and must migrate, which security and backup tools the provider owns and will rip out with them, who controls DNS, and whether break-glass admin credentials exist at all.
  • Applications and licensing. The full stack including legacy Windows apps and how their remote access is secured, which licenses are registered to whom, and which of them transfer on a sale. Many do not.
  • Infrastructure and devices. Server operating systems still in support, firewall subscriptions, devices past end of support, BYOD, and client data sitting on local drives.
  • Identity and MFA. Enforcement system by system, not in general. Shared logins, stale accounts from departed staff, and how the firm stores its clients' own credentials.
  • Security posture and incident history. EDR coverage, tested backup restores, wire-fraud controls, cyber insurance, and the signed five-year incident history above.
  • Compliance and practice operations. The WISP against reality, Section 7216 consents including offshore coverage, and a trap specific to accounting deals: in an asset purchase the seller's EFIN does not transfer, and getting your own IRS approval takes 45 days or more. Discover that in diligence, not in January.
  • Client data and vendor costs. Every place client data lives, paper and personal cloud accounts included, plus total technology spend, seasonal peaks, and the deferred maintenance the seller already knows about.

Timing matters as much as thoroughness. Run this before or during diligence, never after closing. Findings discovered before signatures are negotiating leverage: a remediation number you can take to the table as a price adjustment, an escrow, or a seller obligation. The same findings discovered after closing are just your costs.

This is work we do for accounting firms as a standing service: a pre-acquisition technology assessment that inspects the target's stack, security posture, and integration cost before you commit, and hands you a written report you can negotiate with. If you have a deal in motion, that assessment is the fastest way to know what you are actually buying, and the questionnaire below is the actual instrument we use to run it.

This article and the questionnaire below are educational content, not legal advice. Acquisition liability, breach notification duties, and consent transfer questions depend on how your deal is structured; run them past your attorney.

Free download

Download our technology due diligence questionnaire

The Word document we use in real acquisitions: a questionnaire the selling firm or its IT provider completes, covering the areas above in fifteen detailed sections, ending with a list of documents to attach and a signed attestation that every known incident has been disclosed. Tell us who you are and the download starts immediately.

Your details go only to our team and are handled under our privacy statement.

Buying a firm? Know what you're buying.

Book a discovery call and ask about our pre-acquisition technology assessment. We inspect the target's stack and security posture before you commit.

Talk to a guru now

Not ready to talk? Score your firm's security in two minutes.

No long-term contract. No hour caps. No minimums. 60-day cancellation any time. We earn it every month.  ·  (800) 692-6096