Technology Due Diligence for Private Equity: NetSuite and ERP Targets
AI static analysis of the target ERP in 48-72 hours prices script debt, permission risk and margin leaks before capital is wired, so the finding moves into the purchase agreement instead of surfacing after close. See the 100x ledger for the rows behind this lever.
What should a technology due diligence report contain?
Most technology diligence deliverables are narrative documents that restate what is already on the vendor invoice. A report that actually informs a purchase price has to answer six mechanical questions, each with a number attached.
- Customization inventory. Every script deployment, custom record, workflow and saved search in the target instance, with owner, last-modified date and execution frequency.
- Deprecation exposure. Which customizations depend on sunsetting platform versions, and what the refactor costs in engineering weeks and dollars.
- Permission and segregation-of-duties risk. Every role scored on a 0-4 index against the org chart, with shared logins and unsegregated approval paths called out by name.
- Integration topology. Every inbound and outbound interface, the middleware it runs on, and the recurring subscription cost that transfers to the buyer at close.
- Data readiness for consolidation. Chart of accounts structure, subsidiary configuration, item and customer master duplication, and what has to be true before the target can be folded into a platform close.
- A costed Day 1 and 100-day remediation plan. Not recommendations. A sequenced plan with a price, so the number can move into the purchase agreement.
Which ERP red flags should change your offer price?
These are the findings that have repeatedly justified a price adjustment or a specific indemnity in deals we have read.
- Order-to-cash depending on unmaintained legacy scripts written by someone who has left the company.
- Synchronous user event scripts that deadlock records under concurrent load, capping transaction throughput.
- Shared administrator logins, or finance roles with full create-and-approve authority over the same transaction type.
- A shadow spreadsheet or desktop database performing a step the ERP is supposed to perform, such as job costing or inventory reconciliation.
- Middleware subscriptions carrying material annual cost for interfaces that could run natively.
- Two or more charts of accounts across entities that management reports as if consolidated.
- A period close longer than ten business days, which usually means the numbers under diligence are themselves estimates.
The 0-4 Role Risk Index
We score every permission record on a fixed five-point scale so that access risk becomes a number a deal team can compare across targets rather than a paragraph of narrative.
| Score | Level | What it means | Diligence concern |
|---|---|---|---|
| 0 | None | Access prohibited | Baseline. No exposure. |
| 1 | View | Read-only | Data exfiltration risk only. |
| 2 | Create | Can originate records | Acceptable when approval is separated. |
| 3 | Edit | Can alter existing records | Requires audit trail review. |
| 4 | Full | Create, edit, approve, delete | Segregation-of-duties failure if held by a single finance role. |
Why 48-72 hours instead of four to six weeks?
Conventional diligence timelines are set by the calendar of stakeholder interviews, not by the difficulty of the analysis. The configuration and the codebase already contain the answer. We run automated static analysis against them and spend our human hours on interpretation rather than scheduling.
| Workstream | Conventional baseline | DataOngoing | Multiple |
|---|---|---|---|
| Technology diligence report | 4-6 weeks | 48-72 hours | 14-21x |
| Source-system API integration | 6-12 weeks | Same or next day | 30-60x |
| Script and permission inventory | 2-3 weeks of manual review | Automated static analysis, hours | 40x+ |
| Multi-entity period close | 21 business days | 3 business days | 7x |
| Shop-floor device integration | 3-6 months via WMS project | 2-3 week sprint | 6-12x |
What we need from the target
- Read-only access to the ERP instance, or a metadata export if access is restricted pre-LOI.
- The customization repository, if one exists under source control.
- A current role and user listing.
- The last three period close calendars.
- A list of connected systems and their contracts.
Deliverables
- Board-ready risk matrix, scored and prioritized.
- Customization and integration inventory with deprecation exposure.
- 0-4 role risk scoring against the org chart.
- Quantified remediation cost, sequenced across Day 1 and the first 100 days.
- A one-page summary written for the investment committee, not for IT.
Frequently asked questions
How can you audit an ERP in 48-72 hours when a larger firm quoted four weeks?
Because we do not interview twenty people about their opinion of the software. We run static analysis directly against the codebase and metadata: script deployments, custom record dependencies, deprecation liabilities and role permission tables. The configuration tells the truth immediately. We spend the time on interpretation instead of scheduling.
Can you work pre-LOI with limited access?
Yes. With a metadata export and a role listing we can produce most of the customization and permission analysis. Full codebase access sharpens the refactor cost estimate but is not required to flag the material risks.
Do you handle non-NetSuite targets?
Our deepest instrumentation is NetSuite. We routinely assess targets running QuickBooks, Sage, Dynamics and bespoke systems in the context of whether and how they can be consolidated into a platform ERP.
Is the output usable in the purchase agreement?
That is the point of quantifying remediation. The output is a costed plan, so the number can be negotiated as a price adjustment, an indemnity, or a post-close budget line.
Related research
Technical Arbitrage and Multiple Expansion
Why bolt-on acquisitions fail to achieve multiple expansion when technology integration is deferred, and how a 48-72 hour NetSuite diligence read protects fund returns across SuiteScript 1.0 liabilities and role permission sprawl.
CTO Dialogue: SuiteScript 1.0 and the Single Entry Point
A deep architectural debate on why dozens of ad-hoc User Event scripts lock database rows, how AST static analysis catches SuiteScript 1.0 sunset risk, and how a Single Entry Point router stabilizes high-throughput ledgers.
Executive Roundtable: The Governed Process Experience
A six-stakeholder retrospective contrasting conventional consulting engagements with 14-day production sprints, the hard financial outcomes, and why disciplined systems engineering beats billable-hour discovery.
Talk to the architect, not a salesperson
AI automation for private-equity portfolios, measured in basis points: a few hours of operating-partner time in, hundreds of engineering hours and margin out, delivered as working code in two-week sprints.