Tips / Tip

The one question that exposes an acquisition's real IT risk

10 September 2026 · Leadership & Management

Every acquisition due-diligence pack has an asset register, a licence list and an org chart. None of them tell you the thing that actually bites you three months after completion: who still has access, and why.

The question to ask, on day one, before anything else: "Give me a full list of everyone with admin rights across your systems, and for each one, tell me why they have it."

What this actually surfaces:

  • The former IT contractor who left two years ago and still has a Global Admin account nobody thought to disable, because the person who'd have remembered to also left.
  • Shared logins - one account, several people, no way to know who actually did what, which becomes your problem the day something needs investigating.
  • "Temporary" access from a project that finished 18 months ago, granted for a migration or an integration, never revoked because revoking it wasn't anyone's job once the project closed.
  • Whether they can even answer the question at all. An org that can produce this list in an afternoon has actual identity governance. An org that needs three weeks and still isn't confident in the answer is telling you exactly how much of their IT estate you're about to inherit blind.

You're not just buying their systems. You're buying every access decision anyone ever made and never revisited - ask for the answer before completion, not after you've already signed.

← All tips