Diligence support

Systems and data room review

A data room is a collection of claims. The live systems underneath those claims tell a different story. We open the applications, run the queries, and compare what the seller has provided against what the infrastructure actually contains. The output is a list of gaps, a map of what the business really runs on, and a set of questions the seller must answer before close. We do this for buyers who need to know what they are acquiring and for sellers who want their diligence to finish without stalls.

What this work covers

The review begins with the data room index. We take every exhibit the seller has posted and check it against the live systems the business operates. If the seller provides a customer list exported from a CRM, we log into the CRM and run the same report. If the seller provides a chart of accounts, we trace it to the general ledger. If the seller provides a list of software licences, we inventory the actual SaaS subscriptions, on-premise installations, and cloud tenants. Discrepancies are common. Some are innocent, caused by stale exports or poorly maintained documentation. Others matter. We flag both and let your team decide which to pursue.

Beyond the reconciliation work, we map the full technology and data landscape of the target. This includes domain registrations, DNS configurations, SSL certificates, cloud accounts across AWS, Azure, and Google Cloud, payment processors, email sending infrastructure, developer tools, and any custom applications the business depends on. We identify who holds the root credentials, which employees have access to what, and whether any critical services are tied to personal accounts. For a buyer, this map prevents the unpleasant discovery, weeks after close, that the production database lives on a former employee's personal AWS account. For a seller, it shows you what needs to be cleaned up before a buyer's team starts asking questions.

The work also extends to data ownership and privacy obligations. We trace where customer data resides, how it flows between systems, and whether the business has the consents and contractual rights it claims. If the target operates in regulated markets, we identify the data that falls under those regulations and check that the systems handling it are configured appropriately. This is not a legal review and we do not offer legal conclusions. It is a factual inventory that your counsel can use to assess exposure.

The deliverable is a structured report with an executive summary, a detailed findings log, and a set of prioritised questions for the seller. Each finding is tied to a specific exhibit, a specific system, and a specific observation. We do not offer opinions on materiality or deal implications. We present what we found, what we could not verify, and what we recommend your team examine further.

How we read the data room against the live systems

The process starts with access. We request read-only credentials to the applications that produced the data room exhibits. If the seller will not grant direct access, we work through screen shares and recorded walkthroughs. This is slower and less thorough, so we flag the limitation early. Once we have access, we run a structured comparison. For each exhibit, we identify the source system, the query or export that generated it, the date it was produced, and the parameters used. We reproduce the export and compare row counts, column totals, date ranges, and key field values.

Discrepancies fall into several patterns. The most common is a stale export. The seller prepared the data room weeks before diligence began and the business has moved on. Another pattern is a filtered export that omitted certain records, sometimes by design, sometimes because the person pulling the data did not understand the query. A third pattern is a reconciliation failure between systems. The CRM says one thing, the billing system says another, and the data room contains only the CRM export. We document each pattern and its implications.

We also check the completeness of the data room itself. Most data rooms are missing exhibits that a thorough buyer would expect. We maintain a checklist of standard requests and flag every gap. If the target is a SaaS business, we expect to see a list of all production databases, a network diagram, a software bill of materials, a list of third-party subprocessors, and evidence of backup and disaster recovery testing. If these are absent, we note it. The checklist is not a one-size-fits-all document. We tailor it to the target's industry, size, and deal structure.

Throughout this work, we operate as an extension of your team. We attend diligence calls, we draft follow-up questions, and we update our findings as new information emerges. The goal is not to produce a report that sits on a shelf. The goal is to give your deal team the facts it needs to negotiate, to price risk, and to plan the integration or separation work that follows close.

The sell-side view

Sellers often underestimate how much friction a messy data room creates. A buyer's diligence team finds a discrepancy, asks a question, gets an incomplete answer, asks a follow-up, and the cycle repeats. Each cycle consumes time and erodes trust. The seller's management team gets distracted from running the business. The buyer starts to wonder what else is hidden. The deal timeline stretches. In the worst case, the buyer walks.

We help sellers avoid this. Our sell-side systems review is the same technical work we perform for buyers, done before the data room opens. We inventory the systems, reconcile the exports, identify the gaps, and fix what can be fixed. We draft the exhibits the buyer will expect and ensure they tie to the live systems. We prepare a list of the questions the buyer is likely to ask and help the seller prepare honest, complete answers. The result is a data room that withstands scrutiny.

This work also helps the seller understand its own business better. Many founders and management teams do not have a complete picture of their technology estate. They know the main applications but not the shadow IT, the forgotten subscriptions, the domains registered by a departed employee. Our review surfaces these items and gives the seller a chance to address them before they become deal issues.

The sell-side engagement typically takes two to three weeks, depending on the complexity of the business. We work alongside the seller's finance and operations teams, not in place of them. Our role is to bring the systems perspective that most internal teams lack. The seller's own accountants and counsel remain responsible for the financial and legal content of the data room.

What we examine

The list above is a starting point. Every business is different. A manufacturing company might have operational technology networks that a software company does not. A healthcare business will have patient data systems that require specific scrutiny. We adapt the scope to the target's industry and deal context.

For each system we examine, we document the vendor, the version, the hosting arrangement, the users with administrative access, the integration points with other systems, and the contract status. We flag any system that is end of life, unsupported, or running without a licence. We identify any system that is shared with another entity, which is a common issue in carve-out transactions. If the target is being separated from a parent company, we map every dependency on the parent's systems and estimate the effort required to sever them. This work feeds directly into the carve-out planning we describe on our technology separation page.

We also examine the data room itself as a system. Many data rooms are poorly organised, with inconsistent naming conventions, duplicate files, and missing version histories. We index the room, cross-reference the exhibits, and flag any document that appears to have been altered after its stated date. This is not a forensic document examination. It is a practical check that the data room is what it claims to be.

Forensic data analysis

Some transactions require a deeper look at the numbers. When the seller's financials raise questions, we perform the data-level analysis that supports the client's own accountants. We extract transaction-level data from accounting systems, ERP platforms, billing engines, and operational databases. We check that the totals in the data room financials reconcile to the underlying records. We look for patterns that suggest incomplete data, duplicate entries, or timing anomalies.

This work is technical, not interpretive. We do not form conclusions about the accuracy of the financial statements. We do not issue any form of professional opinion. We present the raw findings: the queries we ran, the records we extracted, the reconciliations we attempted, and the discrepancies we observed. The client's own licensed advisors review our work, interpret the findings, and form their own conclusions. Our role is to do the data work that most accounting teams do not have the systems skills to perform themselves.

We describe this work in more detail on our forensic accounting analysis page. The boundary is important. We are a technology and operations firm. We work with data and systems. When a transaction requires professional accounting judgement, we step back and let the licensed advisors lead. Our value is in the extraction, the transformation, the reconciliation, and the presentation of data that those advisors can rely on.

Technology due diligence

Systems and data room review is one component of a broader technology due diligence engagement. In a full technical diligence, we go beyond the data room and examine the target's architecture, code quality, security posture, and engineering team. We assess scalability, technical debt, and the effort required to integrate or separate the technology from the acquirer's estate. The systems and data room review feeds into that broader assessment by providing the factual baseline.

Many clients engage us for the systems and data room review first, then expand the scope to full technical diligence once the initial findings are clear. This is a natural progression. The data room review tells you what the seller claims. The technical diligence tells you whether what they have built can support the growth the deal model assumes. We describe the full scope on our technical due diligence page.

For smaller transactions, the systems and data room review may be sufficient on its own. If the target is a straightforward business with simple technology and the deal is primarily about customers or market position, a full technical diligence may be unnecessary. We are honest about this. We will not sell you work you do not need. If we think a lighter review is appropriate, we will say so.

Carve-out technology separation

When a transaction involves separating a business unit from a parent company, the systems and data room review takes on additional complexity. The target's systems are often entangled with the parent's infrastructure. Shared databases, shared authentication, shared network segments, and shared software licences are common. The data room may not reflect these dependencies because the seller has not fully mapped them.

Our review in a carve-out context focuses on identifying every point of entanglement. We trace network connections, shared services, and data flows between the target and the parent. We build an inventory of what must be separated, what can be duplicated, and what must be rebuilt. We estimate the effort and the timeline. This work is the foundation of the separation planning we describe on our carve-out technology separation page.

The sell-side version of this work is equally important. A seller who presents a clean separation plan, backed by a thorough systems inventory, reduces the buyer's perceived risk. It can shorten the diligence period and reduce the holdback or escrow the buyer demands. We help sellers prepare this inventory and draft the transition services agreement schedules that describe how the parent will support the target during the separation period.

Working with your advisors

This firm is not a CPA firm, not a law firm, and not a licensed professional services provider. We do not issue audit opinions, we do not attest to the accuracy of financial statements, and we do not provide legal, accounting, tax, or investment advice. Our systems and data room review is a factual analysis of technology and data. The conclusions drawn from our work belong to the client's own licensed advisors. We present findings. Your accountants interpret them. Your counsel acts on them.

We work best when we are embedded alongside your existing deal team. We attend diligence calls, we read the purchase agreement drafts, and we tailor our scope to the specific risks your team has identified. We communicate in plain language, not consultant jargon. We flag problems early, before they become crises. And we stay engaged through close, because the systems questions do not stop when the documents are signed.

If your team includes a technical operating partner, we report to them directly. If not, we report to the deal lead and translate the technical findings into business terms. We have done this across twenty live properties and we understand that most deal professionals do not care about database versions. They care about whether the target can scale, whether the data is clean, and whether there are any hidden costs that will surface after close.

What this work will not do

We are explicit about the limits of this work because we have seen too many diligence engagements where the scope was oversold and the deliverable underdelivered. A systems and data room review is a thorough, structured examination of what the seller has provided and what the live systems contain. It is not a guarantee. No review, no matter how thorough, can catch every issue in a business that has been operating for years with ad hoc processes and poor documentation.

The value of the review is in reducing uncertainty, not eliminating it. After our work, you will know more about the target's systems than the seller's own management team typically knows. You will have a prioritised list of risks and a clear set of questions to resolve before close. You will be able to price the deal more accurately and plan the post-close work more realistically. That is what we deliver.

What this is not

Lawless LLM is not a CPA firm, not an audit firm and not a law firm. We do not issue audit opinions and we do not provide legal, accounting, tax or investment advice. This work is data and systems analysis carried out to support your own licensed advisors, who remain responsible for the professional conclusions drawn from it.

Questions

What operating partners ask first.

How long does a systems and data room review typically take?

For a mid-market transaction with a reasonably complete data room, the review takes two to three weeks from access to final report. Complex carve-outs or targets with many systems can take four to five weeks. The timeline depends heavily on seller responsiveness. If the seller grants direct system access quickly and answers follow-up questions promptly, we move fast. If access is restricted or the seller is slow to respond, the timeline extends. We provide a detailed schedule after scoping the engagement and we update it weekly.

What does this cost?

Cost depends on the scope, the number of systems, and the complexity of the data room. A focused review of a straightforward business might run for a few weeks of work. A full review of a multi-entity, multi-system target with incomplete documentation will cost more. We price on a fixed-fee basis after scoping the engagement, so you know the cost before we start. We do not bill hourly and we do not run over budget without your prior approval. Contact us with the deal context and we will provide a proposal within two business days.

We already have a Big Four firm doing financial diligence. Why do we need you?

Financial diligence firms examine the numbers. They are skilled at assessing earnings quality, working capital, and accounting policies. They are generally not skilled at logging into a CRM, running SQL queries, tracing DNS records, or inventorying cloud accounts. Those tasks require systems skills that most accounting firms do not possess in-house. We complement their work by providing the technical fact base they need. We do not duplicate their effort. We do the systems work they cannot do, and we hand them the data they need to form their own conclusions.

What if the seller will not give you direct system access?

It happens. Some sellers are uncomfortable granting access to live systems, especially early in diligence. We can work through screen shares and recorded walkthroughs, but this is slower and less thorough. We flag the limitation in our report so your team can weigh the risk. If the seller refuses access entirely, we can still review the data room exhibits for internal consistency and completeness, but we cannot verify them against the live systems. In that case, we recommend your team press for access or price the uncertainty into the deal.

Is this just a checklist exercise, or do you actually find things that matter?

We find things that matter in nearly every engagement. Common findings include production databases running on personal credit cards, domain registrations held by former employees who have left the company, software licences that will not transfer to new ownership, customer data stored in countries the business did not disclose, and financial exports that do not reconcile to the systems that supposedly produced them. Some of these findings are deal-breakers. Most are fixable, but only if they are found before close. The checklist is the starting point. The findings come from looking past it.

Related

Read next.

Next step

Tell us the company and the outcome.

A data room is a curated set of documents designed to present a business in its best light. The systems underneath are messier. Our job is to open the hood, compare the claims to the reality, and give your deal team the unvarnished facts. We do this for buyers who need to know what they are acquiring and for sellers who want their diligence to conclude without surprises. The work is technical, the reporting is plain, and the scope is honest about what it can and cannot do. If you are preparing for a transaction or are in diligence now, contact zach@lawlessllm.com to discuss the engagement.

Start a conversation