Most technology findings do not change a price. Old code, an unfashionable stack, a team that wants to rewrite everything, a security backlog — these appear in nearly every diligence and are priced into how the market already values these assets.
What moves a number is narrower: a finding that creates spend the buyer cannot avoid, or that removes a line from the investment case. Here are the ten that do it most often.
1. Two people hold the system
One engineer can explain pricing, another understands the integration layer, nobody else can. Documentation projects do not fix this before close, and retention packages only postpone it. Price the replacement cost and the eight months of reduced velocity, and make the retention of those two a condition rather than a hope.
2. Deferred maintenance sold as margin
Support contracts allowed to lapse, upgrades skipped, vacancies left unfilled through the process. The EBITDA looks better and the buyer inherits the catch-up. This one is worth checking against three years of technology spend rather than one, because the pattern only shows across the longer window.
3. A capability the plan needs and the platform does not have
The model shows recurring revenue from year two and there is no billing, entitlement or usage metering anywhere in the estate. Or international expansion with no multi-currency, no tax engine, no localisation. This is not a feature request; it is a team and a year. When it appears, the question stops being price and becomes whether the plan is the right plan.
4. Integration cost missing from a buy-and-build
The thesis assumes six bolt-ons onto one platform, and nobody has costed what integrating the sixth looks like. Integration cost is not linear — the second acquisition is manageable and the fifth is where programmes die. Ask for the cost of the first one in detail, then be sceptical of any extrapolation that assumes it gets cheaper.
5. AI that is a supplier relationship
The company describes AI as a differentiator. In practice it calls a third-party model, pays per token, and has no proprietary data loop improving anything. That is a viable business, but it is a reseller margin with a supplier concentration risk and a price that the supplier controls. It should not be valued as intellectual property, and the diligence should say so plainly.
6. Cloud spend growing faster than revenue
A reliable signal that the architecture does not scale economically. Growth is being bought rather than engineered, and the gross margin curve in the model will not happen. Get twenty-four months of cloud billing at service level, not the summary.
7. Customer data that cannot be separated
Common in carve-outs and in companies built through acquisition. Data sits in a shared estate, entangled with the parent or with a sibling business, and unpicking it needs a transitional services agreement that runs longer than anyone wants. The cost is real and it is usually borne twice: once to run the TSA, once to exit it.
8. Certifications that are not current
A company claims SOC 2 or ISO 27001 and the certificate has lapsed, covers a narrow scope, or belongs to a subsidiary. This matters less as a security question than as a commercial one: enterprise renewals and new logos often depend on it, which makes it a revenue finding rather than a compliance finding.
9. A single customer inside the architecture
One large client has a bespoke deployment, custom integrations and contractual influence over the roadmap. The technology risk and the customer concentration risk compound: losing them removes revenue and leaves an unmaintained branch of the product behind.
10. A CTO who cannot describe the next twelve months in money
Ask what the technology function will spend next year and what the business gets for it. A leader who answers in initiatives rather than in numbers has not been asked to think that way, which is usually a governance finding about the seller rather than a competence finding about the individual. It still predicts how the first year post-close will go.
What does not move a price
Worth stating, because reports pad with these. An older language or framework, when the team is productive in it. A monolith, in a business whose shape is not changing. Absence of automated testing on a stable, low-change product. An engineering team that dislikes the architecture — engineering teams almost always dislike the architecture. Each of these belongs in the appendix, and treating them as headline findings costs the adviser credibility on the items that matter.
Turning the flags into a position
The discipline that makes this useful is forcing every red flag through three questions. What does it cost to leave alone for the holding period? What does it cost to fix? And which line of the investment case does it block?
A finding that survives all three belongs on the first page, with a number attached and a recommendation on whether it is a price adjustment, a condition precedent, or simply the first item in the hundred-day plan.