Successful mergers and acquisitions have one thing in common: a fanatical focus
on due diligence. It makes sense. An acquiring organisation wants to know
precisely what it is buying — the good, which is assets, and the bad, which is
liabilities.
It is surprising, then, how rarely much attention is paid to the state of either
side’s technology assets. Deployed hardware, software consumption, licence
entitlement, subscriptions and cloud accounts routinely go unexamined in a
process that scrutinises almost everything else.
Why the acquirer’s own position matters first
Beyond acquiring staff, customers, new sectors or territories and perhaps some
valuable intellectual property, most acquirers want economies of scale and
rationalised costs out of a deal.
That might mean consolidating functions such as HR and finance. It might mean
combining regional offices. It might mean rationalising vendor contracts. It
will almost certainly include finding savings in IT costs and operations.
Every one of those drivers lands on IT. And if you do not know your own current
costs, where your assets are, how old they are and what software runs on them,
you cannot plan any of it with confidence.
So part of the acquirer’s planning has to be understanding its own environment
as it stands before the transaction. Only then can you establish whether you are
ready to absorb the target and its technology. Specifically, you need to know:
- What is deployed and what is running on it. Will operating systems,
applications, virtualisation platforms, databases and user management be
compatible across the combined organisation on day one, or will alignment
need significant planning?
- What your key software contracts say, and where they stand. Can you add
users to existing agreements, or extend mission-critical systems into new
environments and geographies, without renegotiating?
- Where your current licensing risk sits. Acquisition activity is watched
closely by publishers, and audits during or shortly after a deal are
commonplace.
This is SAM fundamentals. It simply matters far more during organisational
change.
Why effective SAM at the target matters
Due diligence should surface the target’s known assets and liabilities. If that
organisation has no effective software asset management practice or technology,
the probability of unknown risk rises considerably.
Without a true picture of the target’s hardware and software consumption, how do
you know whether:
- The IT assets you are buying are fit for purpose, or will need expensive
replacement within months of completion?
- The target carries a sizeable undocumented compliance exposure with one or
more publishers? Perhaps they stopped buying licences to flatter the balance
sheet. Perhaps free editions are being used commercially. Perhaps development
licences are running in production.
- The contracts in place at the target can continue to be used after the
acquisition at all — are they bound to a legal entity that is about to cease
to exist, or a location that prevents wider geographic use?
The third of those is the one people forget, and it is the one that converts a
compliant target into a non-compliant subsidiary on the day the deal completes.
Add the subscriptions and the cloud accounts
The 2019 version of this article stopped at hardware and installed software.
That is no longer a complete list, and in many deals it is not even the largest
part.
A target organisation of any size will be carrying SaaS subscriptions bought on
departmental cards, outside procurement, invisible to the finance system beyond
a line item that says the name of a card processor. It will be carrying cloud
accounts opened by engineers. It will be carrying AI tools nobody has formally
approved, holding access to data that is about to become your data.
Each of those raises the same three questions as a software contract — what is
it, who uses it, and does it survive the transaction — and none of them is
answered by a network scan.
CerteroX SaaS Management addresses this with three converging signals rather
than one: identity provider sync from Entra ID and Okta, authoritative user and
licence lists pulled through 47 vendor connectors, and a browser extension that
detects SaaS domains and attributes time-on-app per user. Applications resolve
against a catalogue of more than 35,000, so what comes back is a named
application with an owner, not an unexplained domain. OAuth grants consented to
third-party applications are discovered and scored on data sensitivity, scope
breadth, consent age and dormancy — which is the shape of the question you
should be asking about a company you are about to own.
Why acquisitions and audits go together
It is perhaps unfair to draw analogies about circling sharks, but the fact
remains that publishers have teams watching acquisition activity, because
experience has taught them it is productive ground. There is an inevitable
period of flux — sometimes outright chaos — during and after a deal, and flux
breeds both confusion and risk.
The auditors know licensing is often left out of due diligence. They know the
target is more likely than average to have compliance issues. They know the
acquirer may be about to break entitlement restrictions without realising it.
That is precisely the environment a seasoned auditor knows how to turn to
advantage. If you are not in control of the position, the acquisition can become
considerably more expensive than modelled.
What to do when there is no SAM programme
If you are the acquirer and you do not have software asset management in place,
now is the time. You are about to become larger, more complex and more
diversified than you have ever been, which is a recipe for losing control
entirely.
If the target has no SAM in place but you do, one option is to extend your own
practice to the target for a defined period as part of due diligence. That may
or may not be acceptable to the organisation you are buying.
If it is not — or if you lack the staff or technology to run a programme outside
your own network, in which case this is probably the better route regardless —
the alternative is an acquisition-specific SAM programme at the target, run by
an independent SAM technology and services provider.
As a quick guide, that programme should tell you:
- What is deployed across the target. Laptops, desktops and servers as a
minimum; network devices, virtual infrastructure and cloud instances where
they matter.
- What software is actually being consumed by employees. Including whether
it is current, supported, and free of known security exposure.
- Whether that software is correctly licensed. Usage reconciled against
contracts and entitlement, not an install count compared to a purchase order.
- What the main risks and expected costs are. Refreshes, mandatory
upgrades, and any compliance shortfall.
- What the main opportunities are. Which contracts can carry the combined
organisation, which should be cancelled or allowed to lapse, and which
publishers should be approached about consolidating into a single larger
agreement.
Points three and four are where publisher depth stops being a procurement
checkbox. A generic tool will tell you the target has four hundred installs of a
database. It will not tell you which options are enabled, which cores are
licensable under which core factor, or which hosts are covered down by an
Enterprise Edition pool. CerteroX SAM runs dedicated engines for Microsoft,
Oracle, IBM, SAP, Adobe and Salesforce and computes an effective licence
position continuously — purchased, used, available, required, variance and
exposure — which is the difference between a due-diligence finding you can price
and one you discover afterwards.
Make it part of the diligence
There is good reason so much effort goes into due diligence on an acquisition.
The target’s use of technology — and your own — belongs inside that effort, not
in the integration plan drawn up after the money has moved.
If you are in acquisition mode and lacking the licensing skills to be confident
you are not buying a large undisclosed risk, talk to us about a
full or partial SAM managed service, or about CerteroX SAM.