A deal team spends three months on financial diligence. Audited statements, a quality-of-earnings study, working capital analysis, customer concentration. They retain a Big Four firm and build a model that knows revenue to four decimal places, interrogating every assumption behind the number until it holds.
Then they spend two weeks on the technology. They interview the CTO for an hour, run a handful of automated scans, and receive a red-yellow-green report that comes back mostly green. The check clears.
The financial statement they reviewed was audited. The codebase they just bought was not.
That asymmetry is the most expensive habit in technology M&A, and it is getting worse. The technology layer is a large and growing share of what acquirers pay for, and it is the part of the deal that gets the least independent verification. We have sat on the buyer's side of that gap. Its consequences do not show up in the data room. They show up after close.
The Numbers Behind the Gap
Start with the failure rate, because it is worse than most deal teams assume. Roughly 70% of technology investments fail to hit their value creation targets, and the failures concentrate in issues that were discoverable during diligence rather than in market timing or integration luck.1 Decades of M&A research put the broad failure rate for acquisitions at 70% to 90%, with technology among the most failure-prone categories of all.2 Technology integration problems alone account for close to 30% of failed mergers.1
Now set that against how the work is resourced. Only about one in four CEOs report conducting technology due diligence on most of their deals, even as a large majority call technology a core growth enabler.3 Among deal participants, 45% identify the technology review as the most expensive and arduous part of diligence, and it is still under-resourced relative to the risk it exists to price.3 Tech diligence rarely gets skipped. It gets under-built. A two-week scan is asked to carry the weight that three months of audited financial work carries on the other side of the ledger, and it cannot.
The cost of that imbalance is quantifiable. Technical debt discovered after close runs three to five times more expensive to remediate than the same debt identified before the wire goes out, turning a $500K finding in the data room into a $1.5M to $2.5M problem six months later.1 And the underlying condition is not rare. Recent audits of nearly a thousand commercial codebases found that 86% contained known open-source vulnerabilities, 81% contained high or critical-risk vulnerabilities, and 56% carried license conflicts that can threaten clean IP ownership at transfer.4 Ninety-one percent contained a component with no development activity in the prior two years, which is to say a large share of the typical target runs on code no one is maintaining.4
Every one of these findings is a price chip. Material technical issues routinely move the number by 5% to 15% for moderate problems and 15% to 30% for serious ones.5 The mechanism is familiar at the largest scale: when undisclosed security breaches surfaced during Verizon's acquisition of Yahoo, the parties cut the price by $350 million.6 It runs the same way down in the lower middle market, where one diligence process that turned up unpatched critical vulnerabilities and compliance gaps supported a $2.1 million reduction and a seller-funded remediation escrow.5 The findings were always there. The only variable was whether the buyer looked.
AI-Washing Changes the Stakes
There is a new dimension to this in 2025 and 2026, and it is the one most diligence playbooks are least equipped to handle. Every software company in the lower and middle market now describes itself as AI-enabled, AI-powered, or AI-native. Most are not, in any sense that survives contact with the architecture. The distinction is not a marketing question a management presentation can settle. It is an architecture question, which is exactly the question a two-week review tends not to reach.
It helps to hold three tiers in mind, because the spread between them is enormous. AI-native platforms, where the AI is the product and runs on proprietary data and trained models, have commanded 25x to 30x EV/revenue.7 AI-integrated businesses, ordinary software with genuine and measurable AI inside, trade in the single-digit SaaS range. AI-washed businesses reprice, once the architecture is examined, to whatever their underlying non-AI economics support. The distance between AI-native and AI-washed is the valuation risk that thin diligence quietly transfers from the seller to the buyer.
We have opened a system like this. A target presented its "AI-driven risk engine" as the core differentiator and priced accordingly. Inside, the engine was a set of manually maintained rules tables, the same architecture the company had run since the 1990s, with a general-purpose chatbot bolted on top that accounted for a low single-digit share of what the platform actually did. The valuation had been built on a capability that was not there. We have seen versions of it more than once.
The regulatory signal is worth naming, carefully. In March 2024 the SEC brought its first enforcement actions over AI-washing, charging two investment advisers, Delphia and Global Predictions, for false and misleading statements about their use of artificial intelligence.8 That was a securities matter, not an M&A precedent. But the directional point stands: unsubstantiated AI claims now carry legal consequence and not merely reputational risk. AI representations in a CIM or management deck that fail technical scrutiny expose a seller to indemnity claims and a buyer to paying for an asset that reprices the moment someone competent reads the code.9
What Good Technical Diligence Actually Looks Like
None of this argues that technical diligence is easy or can be done on the cheap. The point is the opposite. Done properly it is a specialized discipline, and in 2026 it covers seven areas, six that are familiar in shape if not always in practice, and a seventh that has become standard at leading firms:
- Code quality and architecture: whether a team that did not build the system can actually operate it.
- IP ownership and transferability: whether contractor assignments and open-source licenses permit the IP to move cleanly to the buyer.
- Scalability under real load.
- Data security and tenant isolation.
- Portability: whether the system can move to the acquirer's infrastructure without a rebuild.
- Technical debt, quantified in dollars rather than represented as a color on a slide.
- AI architecture verification: not whether the target uses AI, but what it owns that a competitor cannot replicate by calling the same API tomorrow.10
Genuine AI capability produces durable intangible assets: proprietary training data with clean provenance, owned rather than rented model weights, institutional machine learning expertise embedded in the system, and experimentation infrastructure that compounds. A wrapper around a third-party model produces none of these. One is a moat. The other is a feature any competitor can stand up in a weekend.
This matters to a deal team rather than an engineering team because each finding is a negotiation instrument. A quantified technical debt assessment supports a specific price adjustment. An undisclosed vulnerability supports an escrow. An AI architecture that does not match the marketing supports a retrade, or an earnout tied to demonstrated performance rather than claimed. We have told a client to walk on the strength of a code review, and we have told one to pay up because the moat was real. The findings tell you which conversation you are in.
No CFO would sign a transaction on the strength of unaudited financials. The technical equivalent is a codebase that has been described but not examined, and in most deals that is exactly what changes hands. The acquisitions that underperform their thesis are seldom the ones where the market turned or the integration ran hot. They are the ones where what got bought was not what got presented. An hour with the CTO and a clean automated scan is not an audit, and treating it like one does not make the repricing go away. It just moves it past the close, onto the buyer's side of the table, where it costs three to five times more to fix.
Prepared June 2026. All figures validated against the live sources cited below.
Notes
- Human Renaissance, "2025 M&A Technology Due Diligence Benchmarks," January 2026. humanr.ai
- Clayton Christensen et al., "The Big Idea: The New M&A Playbook," Harvard Business Review. hbr.org
- SRS Acquiom, "M&A Due Diligence Study: 2025 Insights and Trends." srsacquiom.com; West Monroe Partners technology due diligence survey data. westmonroe.com
- Black Duck (formerly Synopsys Software Integrity Group), "2025 Open Source Security and Risk Analysis Report," February 2025. blackduck.com
- Acquisition Stars, "M&A Failure Rate"; Blaze InfoSec, "M&A Cybersecurity Due Diligence: A Guide for Buyers and Sellers." acquisitionstars.com; blazeinfosec.com
- "After data breaches, Verizon knocks $350M off Yahoo sale," TechCrunch, February 21, 2017. techcrunch.com
- Windsor Drake, "SaaS Valuation Multiples 2026," February 2026. windsordrake.com
- U.S. Securities and Exchange Commission, "SEC Charges Two Investment Advisers with Making False and Misleading Statements About Their Use of Artificial Intelligence," Press Release 2024-36, March 18, 2024. sec.gov
- Skadden, "M&A in the AI Era: What Buyers Can Do to Confirm and Protect Value," 2026 Insights. skadden.com
- EY, "Software M&A: Tech Due Diligence for Future-Proof Deals"; West Monroe Partners, "Technology Due Diligence Best Practices"; Dextra Labs, "Software M&A Technical Due Diligence in 2026." ey.com; dextralabs.com