Private Equity3 min read

Twelve Months After Diligence, the IT Findings Are Still a Slide

Technology diligence produces a list of risks. Converting that list into a funded, sequenced plan with owners is a different job, and it is the one that usually goes unassigned.

The IT diligence report came in before close. It flagged an ageing ERP, thin security controls, key person dependency in the finance systems, and integration debt from the last two add-ons. It was accurate and it was useful.

A year later, at a portfolio review, somebody pulls up the same slide. Nothing on it has moved.

This is the most common technology failure in the portfolio, and it is not a technology failure. It is an ownership one.

Why the findings stall

Diligence is a diagnostic exercise performed by an outside party under time pressure, and it ends when the deal closes. That is the correct scope, but it leaves a specific gap.

The report tells you what is wrong. It does not tell you what to do first, what each remedy costs, who inside the company owns it, or what happens to the value creation plan if it slips. Those are operating questions, and the operating team that inherits them has a CEO focused on commercial delivery, a CFO focused on reporting, and no technology executive at all.

So the findings sit. Not because anybody disagrees with them, but because converting a risk list into a funded programme is a job, and nobody has it.

What conversion actually requires

A cost and a date against every finding. "Legacy ERP presents operational risk" is not actionable. "ERP is unsupported from March; upgrade in place is $340k over five months, replacement is $1.9m over sixteen, doing nothing carries these three specific exposures" is a decision a board can take.

Sequencing by value and by dependency, not by severity. The highest-risk item is often not the first thing to do, because it depends on something duller. Identity consolidation is rarely the most alarming finding and is frequently the one that has to come first.

A named owner inside the business for each item. Not the sponsor, not the advisor. Someone whose performance conversation includes it.

A review cadence that survives a busy quarter. Findings die between meetings. A register that comes back with a date attached is what stops it.

An explicit link to the value creation plan. Every item should answer: which part of the thesis does this protect or enable? Items that cannot answer that question are candidates for accepting rather than fixing, and accepting a risk deliberately is a legitimate outcome that should be recorded as a decision.

The reporting problem underneath

There is usually a second finding hiding under the first. Board reporting is assembled by hand each month from systems that do not talk to each other, which means it is slow, fragile, and unverifiable.

That matters beyond convenience. If the numbers take three weeks and cannot be traced to source, the sponsor is steering on stale information, and every technology investment argument is being made without the data to support it.

Fixing reporting early makes everything after it easier to justify.

Portfolio companies rarely need a full-time CIO

The obvious answer to an ownership gap is to hire an executive, and for a company of two hundred people with a five-year hold, a $250,000 fully loaded CIO is usually the wrong instrument. The work is real but it is a few days a month, and it needs somebody who moves at deal speed and can speak to both an operator and an investment committee.

That is precisely the shape a fractional mandate fits.