Skip to main content
Cayley | Independent Technology Assurance & Advisory

Assurance for transactions and investment

Technology due diligence

A Technology Due Diligence engagement identifies the material risks in a target's software, architecture, team, security, scalability and technical debt before an investment or transaction decision.

Who uses this service

Investors and acquirers
An independent view of the platform, team and downside exposure before capital is committed.
Accountants and transaction advisers
The technical debt, required investment and dependency risk that affect transaction terms and valuation inputs.
Boards
A defensible basis for approving an acquisition or investment, with material risks stated and rated.

When to commission it

  • A buy-side acquisition where the target's technology is central to the value being paid for.
  • A funding round where an investor needs an independent view of the platform and engineering team.
  • Sell-side preparation, to find and address issues before buyers raise them.
  • A pre-exit review ahead of a trade sale or listing.
  • A decision that turns on whether the platform can scale to a committed growth plan.

Questions the review answers

  • Does the target own the code it ships, and which third-party components does it depend on?

  • Will the architecture support the expected growth in users, data and transactions?

  • What is the security posture, and are there known exposures that remain unremediated?

  • How much technical debt exists, and what investment is required to address it?

  • Is the business exposed to key-person risk in its engineering team?

Evidence normally requested

We request the evidence needed to test the technical position. The exact list depends on the matter.

  • Source repositories and commit history
  • Architecture and data-flow diagrams
  • Cloud accounts and infrastructure configuration
  • Incident and outage records
  • Product roadmap and engineering backlog
  • Engineering metrics, including deployment frequency and defect data
  • Employment and contractor records for the engineering team
  • Software licence register and third-party dependencies
  • Security policies, audit results and test reports

Method

  1. Define the question

    We agree the decision the engagement supports and the questions that must be answered, then fix the scope in writing before work starts.

  2. Preserve and collect evidence

    We request access to repositories, cloud accounts, records and metrics, and note what was provided and what was withheld.

  3. Test the technical position

    We examine the code, architecture, security posture, engineering practice and team structure against the claims made about them.

  4. Rate risk and confidence

    We classify each finding by materiality and assign a confidence rating based on the evidence reviewed.

  5. State the next action

    We set out the practical next step for each material finding, including its likely effect on price, terms or completion conditions.

What you receive

Document
Diligence report
Intended reader
The investment committee, acquirer or board named in the engagement letter
Risk classification
Each finding is rated by materiality, from material risk to informational, with the basis for the rating stated.
Confidence classification
Each finding carries a confidence rating of Confirmed, Supported, Indicative or Unknown.
Includes
  • An executive summary written for a non-technical decision-maker
  • Findings in a consistent evidence, impact, confidence and recommendation format
  • An evidence appendix listing what was reviewed and what was withheld
  • A prioritised action plan with the likely effect on price, terms or completion
Verbal briefing
A verbal briefing to the deal team or board is included, so questions can be put to the reviewer directly.

Typical timing

Typically 2 to 4 weeks, depending on the size of the codebase and the access provided

Commonly excluded from this matter

Potential add-ons

The review covers the full agreed scope; it is bounded by the evidence made available and does not warrant that every defect will be found. Where the transaction needs more, the engagement can extend to include:

  • Penetration testing and deeper security assessment
  • Code-level IP and provenance review, including open-source licence exposure
  • Subscription and revenue reconciliation against production data
  • Extended reliance for additional named parties

Definition

Buyers sometimes call this a technology audit. The engagement is an independent technical review. It does not provide a statutory audit opinion, a financial valuation or a legal opinion.

From findings to execution

Where a technology audit or due diligence already exists, or the findings call for action, our Fractional CTO / CISO advisory carries the work forward: senior technology leadership, direction for onshore and offshore development teams, and the change management to bring a program back on track or restructure the software function.

Advisory work stays separate from the assurance engagement, so the review remains independent of the outcome.

Read about Fractional CTO / CISO

Independence and reliance

We are engaged for the review only. We do not build, sell or resell the systems we examine, and we do not take commission from vendors named in a finding.

The diligence report is prepared for the party named in the engagement letter. Reliance by any other party is not granted unless we agree it in writing beforehand.

Where we later provide advisory work, we keep it separate from any matter we have assured, so the review remains independent of the outcome.

Read how we maintain independence and reliance

Related services and reading

SaaS Scale & Data Integrity Review

An assessment of architecture, resilience, security boundaries and whether reported subscription and revenue figures reconcile with the systems.

Methodology

How we scope an engagement, handle evidence and assign a confidence rating to each finding.

Independence

Our engagement terms, conflict checks and reliance position for a diligence report.

Discuss a matter

Provide a short outline of the decision, transaction or dispute. Do not submit confidential source code, credentials or personal information through the form.