Skip to content

The Role of IT and Software Asset Management in Mergers and Acquisitions

Due diligence covers the balance sheet and rarely covers the licence position — which is exactly why publishers watch acquisitions closely. What both sides need to know before the deal closes, and what to do when neither has a SAM programme.

Successful mergers and acquisitions have one thing in common: a fanatical focus on due diligence. It makes sense. An acquiring organisation wants to know precisely what it is buying — the good, which is assets, and the bad, which is liabilities.

It is surprising, then, how rarely much attention is paid to the state of either side’s technology assets. Deployed hardware, software consumption, licence entitlement, subscriptions and cloud accounts routinely go unexamined in a process that scrutinises almost everything else.

Why the acquirer’s own position matters first

Beyond acquiring staff, customers, new sectors or territories and perhaps some valuable intellectual property, most acquirers want economies of scale and rationalised costs out of a deal.

That might mean consolidating functions such as HR and finance. It might mean combining regional offices. It might mean rationalising vendor contracts. It will almost certainly include finding savings in IT costs and operations.

Every one of those drivers lands on IT. And if you do not know your own current costs, where your assets are, how old they are and what software runs on them, you cannot plan any of it with confidence.

So part of the acquirer’s planning has to be understanding its own environment as it stands before the transaction. Only then can you establish whether you are ready to absorb the target and its technology. Specifically, you need to know:

  1. What is deployed and what is running on it. Will operating systems, applications, virtualisation platforms, databases and user management be compatible across the combined organisation on day one, or will alignment need significant planning?
  2. What your key software contracts say, and where they stand. Can you add users to existing agreements, or extend mission-critical systems into new environments and geographies, without renegotiating?
  3. Where your current licensing risk sits. Acquisition activity is watched closely by publishers, and audits during or shortly after a deal are commonplace.

This is SAM fundamentals. It simply matters far more during organisational change.

Why effective SAM at the target matters

Due diligence should surface the target’s known assets and liabilities. If that organisation has no effective software asset management practice or technology, the probability of unknown risk rises considerably.

Without a true picture of the target’s hardware and software consumption, how do you know whether:

  1. The IT assets you are buying are fit for purpose, or will need expensive replacement within months of completion?
  2. The target carries a sizeable undocumented compliance exposure with one or more publishers? Perhaps they stopped buying licences to flatter the balance sheet. Perhaps free editions are being used commercially. Perhaps development licences are running in production.
  3. The contracts in place at the target can continue to be used after the acquisition at all — are they bound to a legal entity that is about to cease to exist, or a location that prevents wider geographic use?

The third of those is the one people forget, and it is the one that converts a compliant target into a non-compliant subsidiary on the day the deal completes.

Add the subscriptions and the cloud accounts

The 2019 version of this article stopped at hardware and installed software. That is no longer a complete list, and in many deals it is not even the largest part.

A target organisation of any size will be carrying SaaS subscriptions bought on departmental cards, outside procurement, invisible to the finance system beyond a line item that says the name of a card processor. It will be carrying cloud accounts opened by engineers. It will be carrying AI tools nobody has formally approved, holding access to data that is about to become your data.

Each of those raises the same three questions as a software contract — what is it, who uses it, and does it survive the transaction — and none of them is answered by a network scan.

CerteroX SaaS Management addresses this with three converging signals rather than one: identity provider sync from Entra ID and Okta, authoritative user and licence lists pulled through 47 vendor connectors, and a browser extension that detects SaaS domains and attributes time-on-app per user. Applications resolve against a catalogue of more than 35,000, so what comes back is a named application with an owner, not an unexplained domain. OAuth grants consented to third-party applications are discovered and scored on data sensitivity, scope breadth, consent age and dormancy — which is the shape of the question you should be asking about a company you are about to own.

Why acquisitions and audits go together

It is perhaps unfair to draw analogies about circling sharks, but the fact remains that publishers have teams watching acquisition activity, because experience has taught them it is productive ground. There is an inevitable period of flux — sometimes outright chaos — during and after a deal, and flux breeds both confusion and risk.

The auditors know licensing is often left out of due diligence. They know the target is more likely than average to have compliance issues. They know the acquirer may be about to break entitlement restrictions without realising it.

That is precisely the environment a seasoned auditor knows how to turn to advantage. If you are not in control of the position, the acquisition can become considerably more expensive than modelled.

What to do when there is no SAM programme

If you are the acquirer and you do not have software asset management in place, now is the time. You are about to become larger, more complex and more diversified than you have ever been, which is a recipe for losing control entirely.

If the target has no SAM in place but you do, one option is to extend your own practice to the target for a defined period as part of due diligence. That may or may not be acceptable to the organisation you are buying.

If it is not — or if you lack the staff or technology to run a programme outside your own network, in which case this is probably the better route regardless — the alternative is an acquisition-specific SAM programme at the target, run by an independent SAM technology and services provider.

As a quick guide, that programme should tell you:

  1. What is deployed across the target. Laptops, desktops and servers as a minimum; network devices, virtual infrastructure and cloud instances where they matter.
  2. What software is actually being consumed by employees. Including whether it is current, supported, and free of known security exposure.
  3. Whether that software is correctly licensed. Usage reconciled against contracts and entitlement, not an install count compared to a purchase order.
  4. What the main risks and expected costs are. Refreshes, mandatory upgrades, and any compliance shortfall.
  5. What the main opportunities are. Which contracts can carry the combined organisation, which should be cancelled or allowed to lapse, and which publishers should be approached about consolidating into a single larger agreement.

Points three and four are where publisher depth stops being a procurement checkbox. A generic tool will tell you the target has four hundred installs of a database. It will not tell you which options are enabled, which cores are licensable under which core factor, or which hosts are covered down by an Enterprise Edition pool. CerteroX SAM runs dedicated engines for Microsoft, Oracle, IBM, SAP, Adobe and Salesforce and computes an effective licence position continuously — purchased, used, available, required, variance and exposure — which is the difference between a due-diligence finding you can price and one you discover afterwards.

Make it part of the diligence

There is good reason so much effort goes into due diligence on an acquisition. The target’s use of technology — and your own — belongs inside that effort, not in the integration plan drawn up after the money has moved.

If you are in acquisition mode and lacking the licensing skills to be confident you are not buying a large undisclosed risk, talk to us about a full or partial SAM managed service, or about CerteroX SAM.

Related reading

Other posts covering the same ground.

  • Certero Insider Newsletter – July 2025

    The licensing changes that mattered in June and July 2025 — Microsoft Product Terms, the return of the SAMOSA Act, the end of the Microsoft 365 nonprofit grant, Adobe's AI credit cuts, a Dutch ruling against Broadcom, and rising Oracle Java audit activity.

    • ITAM
    • SAM
    • SaaS
    • Governance
    10 min
  • Software Asset Management Plan

    A six-step plan for building a SAM programme that covers on-premises, SaaS and cloud as one problem rather than two — scope, maturity, people and technology, accountability, and what to do first.

    • ITAM
    • SAM
    • SaaS
    • Governance
    8 min
From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.