IT due diligence for company sales and successions in Germany
I examine the IT of a company before it is sold or handed to a successor: the systems, the people who run them, the IT contracts and the risks a buyer takes over on the day of the closing. I have taken part in several due diligences, on the buyer's side and on the seller's side. I take on this work freelance, remote across Germany with days on site. Let's talk about your needs in a free 30-minute video call.
What I take care of for you
-
Due diligence experience
I have examined and prepared the documents that describe IT systems, teams and products, for buyers and for sellers. I read them for the customers and staff who depend on those systems after the deal.
-
The view of a CIO
As CIO of a Frankfurt fintech I was responsible for IT budgets and teams. I know which answers an IT head should have ready, and I notice when one is missing.
-
Contracts read by a technician
I have written and reviewed IT contracts, license agreements and terms of use. I check whether licenses and service contracts pass to the buyer or end with the change of owner.
-
From the rack to the cloud
I have installed servers in data centers and run AWS, Azure and Google Cloud. I can tell a documented setup from one that lives in the head of a single employee.
-
Findings in plain words
The report names each risk, what a fix would involve and who has to act. Management and lawyers can read it without an IT glossary.
-
Data protection
I have documented and put in place data protection measures under the GDPR. The review shows where personal data sits and whether the paperwork for it exists.
What an IT due diligence checks
An IT due diligence answers one question for a buyer: can the IT of this company carry the business after the deal, and what has to happen first? For a seller it answers the same question earlier, while there is still time to close gaps before a buyer finds them.
Why the IT needs its own review in a smaller deal
When a smaller company is sold or handed to a successor, the financial and legal reviews come first on the plan. Yet on the day of the closing the buyer also takes over the servers, the software licenses and the contracts with IT providers, together with the one employee or outside provider who knows how it all works. If that knowledge is not written down, the buyer pays for it later, in outages or in the price of a new provider.
IT due diligence checklist for a smaller company
These are the areas I work through, with the documents I ask for in the data room. A missing document is a finding of its own.
| Area | What I check | Documents I ask for |
|---|---|---|
| Systems | Servers, cloud accounts and software, with their age and support status | System list, network plan |
| Business software | ERP, CRM or shop: version, custom changes, vendor | License and maintenance contracts |
| Licenses | Whether the licenses cover the actual use and pass to the buyer | License list, change-of-control clauses |
| IT providers | Who runs what, notice periods, dependence on a single provider | Service contracts, service levels |
| People | Who knows which system, and what happens if that person leaves | Organization chart, handover notes |
| Documentation | Whether setup, backups and access are written down | Operating manuals |
| Security | Access rights, updates, incidents of recent years | Access lists, incident reports |
| Backups | Whether a restore has been tested, and how long an outage may last | Backup plan, log of the last restore test |
| Data protection | Where personal data sits, and whether the GDPR paperwork exists | Record of processing activities, data processing agreements |
| Own software | Who owns the code, how it is tested, who can deploy it | Repository access, rights clauses in contracts with developers |
| Costs | Running IT costs and investments that fall due soon | IT budget, invoices of the past year |
| Closing day | Which accounts, domains and contracts change hands | Domain list, list of admin accounts |
The last row is easy to forget. Domains, admin logins and cloud accounts can sit in the name of a former employee or of the owner, and they have to move to the buyer on the day of the closing.
Where my due diligence experience comes from
I have taken part in several due diligences, on the buyer’s side and on the seller’s side. My part was the documents on the quality of the IT systems, the state of the teams and the health of the products: I examined them for buyers and prepared them for sellers.
I have also written and reviewed contracts, license agreements and terms of use for business development and IT. At the Frankfurt-based company Blocksize Capital this included the terms of a market-data product and the legal framework of a partner program. As CIO there I had disciplinary responsibility for business-critical teams and was responsible for the IT budgets.
Who I am
I am Michael Wutzke from Frankfurt, and my work in IT and media goes back more than twenty years. Before the CIO role I was Head of Decentralized Finance and Node Operations at Blocksize Capital, Project Manager and Web Developer at an insurance group, and earlier IT Team Lead and Managing Director. I sit on the Product Advisory Committee of the Digital Token Identifier Foundation. Details: Publications, press and committees.
How an IT due diligence runs
-
Free video call
You tell me about the deal, which side you are on and the signing date you work toward.
-
Assessment together
We agree on the scope: which systems and contracts, which people I may talk to, and what the data room holds.
-
Quote and order
You receive a quote for the review. The work begins when you accept it, under a confidentiality agreement.
-
Documents
I work through the data room along the checklist below and write down each question the documents leave open.
-
Interviews and systems
I talk with the IT head or the outside service provider and look at the systems, on site or by screen share.
-
Report and call
You receive the findings sorted by risk, and we go through them in a call before the negotiation.
Questions companies ask
What is an IT due diligence?
An IT due diligence is the review of a company's IT before a sale, an investment or a succession. It checks whether the systems, the people and the contracts can carry the business after the deal, and what has to be fixed first.
Buy side or sell side: who orders it?
The buyer orders a buy-side review to find risks before signing. The seller orders a sell-side review to prepare the documents and close gaps before buyers see them. I have worked on both sides.
Is an IT due diligence the same as a technical due diligence?
In real estate, a technical due diligence checks a building. In company purchases the terms overlap: technical due diligence tends to mean the software and its development team, IT due diligence the whole IT including operations and contracts.
Do you review source code?
I read code and the way a team works with it: repositories, reviews, tests, deployments. A line-by-line audit of a large code base needs a specialist tool or a second reviewer, and the assessment says whether your deal needs one.
Do you give legal advice?
No. I review the technical content of contracts and data protection documents. Lawyers and tax advisers do their part of the due diligence, and my report gives them the technical facts.
Which engagements do you take on?
Freelance reviews for buyers, sellers and successors of smaller companies, remote across Germany with days on site. I live in Frankfurt.
Details on the work behind this page
-
Publications, press and committees
I write about technology in finance and real estate. The page also lists my interviews and the committees I sit on.
-
CIO and Head of DeFi at a Frankfurt fintech
Node operations, a market-data product, teams, budgets and procuration at a Frankfurt fintech.
-
Realized projects
I am using AI technologies to rapidly create MVP and production-ready applications.
-
Supporting people
How I lead teams: as a sparring partner for colleagues, and through the networks I build around a team.
Your IT due diligence consultant in Germany
I am Michael Wutzke, an IT due diligence consultant in Germany, based in Frankfurt. In a free 30-minute video call we talk about the deal and your side of it, and you learn what the review should cover before you sign.
Searches this page answers
- IT due diligence
- IT due diligence checklist
- IT due diligence meaning
- IT due diligence M&A
- IT due diligence report
- IT due diligence report example
- IT due diligence framework
- IT due diligence questionnaire
- IT due diligence questions
- M&A IT due diligence checklist
- technical due diligence
- technical due diligence consultant
- technical due diligence report
- technical due diligence checklist
- technical due diligence questionnaire
- technical due diligence for investors
- technology due diligence
- technology due diligence checklist
- technology due diligence consulting
- technology due diligence in mergers and acquisitions
- tech due diligence
- tech due diligence checklist
- software due diligence
- software due diligence checklist
- software acquisition due diligence checklist
- source code due diligence
- sell side due diligence
- sell side due diligence checklist
- buy side due diligence
- buy side due diligence checklist
- vendor due diligence vs buyer due diligence
- IT infrastructure assessment
- IT infrastructure assessment checklist
- IT infrastructure due diligence questionnaire
- due diligence for small business acquisition
- buying a business due diligence checklist
- due diligence questions when buying a business
- technical debt assessment
- cloud services due diligence checklist