Adapted from Chapter 3, "The Inner Circle" of Make IT Work: An IT Playbook for Mergers and Acquisitions.
Mergers and acquisitions live or die on due diligence. For CIOs, much of that work starts in the data room. This is where IT gets its first real look at what they may be inheriting, and where the risks that shape the next twelve months either get spotted early or get missed completely. If you're a CIO or IT leader heading into your first deal, understanding how to work in a data room is one of the most useful skills you can bring to the table.
I have spent countless hours in data rooms. Most of that time falls somewhere between mildly tedious and soul-crushingly boring. But the data room is also where a deal's real risks either get caught or get missed. After nearly two dozen acquisitions, I've landed on a few rules that keep the process from eating my entire quarter.
First, ask for a data room index before you begin your due diligence. Most data rooms have some kind of folder structure. That structure is often organized around the seller's logic, not necessarily by what IT actually needs. A good index helps you find the IT-relevant documents quickly and, just as importantly, see what may be missing. An index helps you quickly identify where the IT-relevant documents are and what might be missing.
Second, work in pairs. Have two people (who have been disclosed on the deal) review the data room independently and then compare notes. One person might catch a contract clause or a security risk that the other missed. It also helps maintain focus as data room review is monotonous work, and attention drops after about three hours of continuous reading.
Third, keep a running list of questions as you review the data room. Organize the questions by data room folder structure. Send the questions in a single document when possible. Sending 50 separate emails with one question each will frustrate the other party and slow down the process. One well-structured list of questions shows professionalism and respect for the other side as well as the process.
Fourth, download everything related to IT from the data room as soon as you are allowed. This gives you faster access and lets you organize the material in a way that matches how you and your team work. Create your own folder structure, such as Contracts, Licensing, Network, Security, Applications, HR/Org Charts, and Financials. Keep track of the original data room folder names in case you need to reference them later or if the deal team references a specific section or folder from the data room.
Finally, set a deadline for the data room review. Due diligence will expand to fill whatever time you give it. Two weeks is usually enough to surface any major issues and land on a focused list of follow-ups. If I'm still finding fundamental new problems after week three, either the data room is exceptionally disorganized, has incomplete data, or I need to rethink my own review process.
All of this matters beyond simple organization. I once worked on a deal where a SaaS vendor's contract had a change-of-control clause that got missed in diligence. Once we closed, the vendor invoked it and pushed through a 25% price increase, wiping out the synergy case we'd built around consolidating onto that platform. Being organized can separate a clean integration from one that misses the budget projections in the first month. Before the deal closes, work with legal to review every technology contract for change-of-control provisions.
A data room review is not just a box to check before closing. Treat it like the last real chance to find the landmines before they become yours to defuse. Move efficiently, but do not rush past the fine print, especially the contract language no one thinks to double-check until it is too late.
Jason James is Chief Information Officer (CIO) at Aptos, a leader in retail technology solutions, where he oversees the company's ever-evolving digital landscape and translates the company’s vision into an actionable IT roadmap. He has over two decades of leadership experience in SaaS, cybersecurity, IT infrastructure, and digital transformation. Before joining Aptos, Jason was CIO at several high-growth software and data analytics organizations within the healthcare sector. Earlier in his career, Jason held executive-level IT roles at the supply chain optimization provider, Servigistics (now PTC), the data intelligence firm PRGX, and internet service provider EarthLink. He is the author of Make IT Work: An IT Playbook for Mergers and Acquisitions.