Mergers & Acquisitions Due Diligence Checklist

Home/Mergers & Acquisitions Due Diligence Checklist

M&A DUE DILIGENCE CHECKLIST

The Scorecard Review during M&A due diligence typically examines nine areas of code integrity, with two optional topics:

  • Source Code Correctness
    • We identify violations of the governing language adopted standard.
    • Source code incorrectly written, even if it compiles successfully, is flagged.
  • Adherence to Best Practices
    • Industry standards and best practices are verified by sampling code of a statistically relevant size.
    • Coding practices are checked for secondary side-effects of non-standard coding practices.
  • Suitability of the Technology for the Purpose
    • Technology choices, programming languages, technology stacks, frameworks, and third-party libraries are investigated principally for proper use for the chosen purpose.
  • Exception Handling Practices
    • Exception handling statements and control structures (e.g. try blocks and catch blocks) are analyzed for subtle design flaws leading to a slowdown, crash, or unexpected behavior.
  • Multithreading Techniques
    • We inspect the source code for proper and adequate use of multithreading features.
  • Performance Factors
    • M&A review identifies programming patterns, unnecessary code, or configuration settings known to produce adverse performance.
  • Evaluation of Testing and Logging
    • Evidence of source code testing and the extent of such testing will be examined during our M&A due diligence checklist review.
    • We will check for logging capabilities and usefulness of those capabilities in identifying and fixing anomalies and errors.
  • Maintainability Assessed
    • We opine on the successful ability to continue maintaining and expanding upon the source code in the future.
  • Scalability Appraised
    • We consider the design of the software and its likelihood to successfully scale to higher system loads.
  • Database Analysis (optional)
    • We inspect the database schema for the use of normal forms, proper and reasonable design approaches, and proper and secure calls into database systems from the source code.
  • Security Analysis (optional)
    • We analyze the source code using both manual and automated approaches in search of violations of the OWASP Top 10, or any other violations of security best practices.

Prolifogy will examine the code to find strengths and weaknesses in each of the topic areas mentioned above.  Whether the software was written in PHP, Java, Python, JavaScript, C, C#, C++, Ruby, some combination of these, or even something more obscure, the skills of the Prolifogy group performing the M&A Review will always be seamlessly aligned with the technical requirements of the project.

Whether your company is on the selling or buying end of a merger or acquisition, you need to be properly informed and well-prepared for the magnitude of risk at hand. The investigative stage of due diligence often occurs after a letter of intent has been issued and is possibly the most important phase for the buyer. That is when the purchasing company takes detailed measures in sifting through the selling company’s assets and data. The idea is to collect any and all information that helps the buyer determine whether the benefits of closing the deal ultimately outweigh the risks. This gives the buying company a chance to decide upon the fairness of the final offer, and supports the ability for price negotiation based on concrete technical findings.