Technology due diligence · Tech DD for investors · Vendor due diligence

Technology due diligence · for investments, acquisitions and exits, led by a senior CTO

Technology due diligence is a senior review of a company’s technology before an investment, acquisition or exit: architecture and scalability, code quality and IP ownership, security, data protection, the team and key-person risk, technical debt and running costs. It tells an investor or buyer what they are paying for, and a seller what to fix first.

We deliver it by placing a senior practitioner, usually an interim or fractional CTO, who runs the review and writes the report. To hire an interim CTO for a deal, brief us: we send a shortlist of 3–5, each with day rate, availability and IR35 position set out, after five-stage vetting.

How a brief runswhat we undertake

  1. 01Brief30-MINUTE SCOPING CALLDay 0
  2. 02Shortlist of 3–5VETTED · RATE BENCHMARK · IR35After the brief
  3. 03InterviewsYOU MEET THE SHORTLISTYour diary
  4. 04Scoped startFIRST-MONTH OUTCOMES AGREEDYou set the date
  5. 05Fractional, interim and permanentIR35 POSITION SET OUTOn every brief

Shortlist3–5

3–5
Shortlist · with day rate, availability and IR35 set out
5
Vetting · stages before a practitioner reaches you

15 minutes · video or phone

Book 15 minutes to hire an interim or fractional CTO

Tell us the scope and the days a week. We come back with CTO candidates, their day rates and availability.

  1. 0115 minutes, video or phone
  2. 02We scope the role and the days a week
  3. 03A shortlist of 3–5 after the call
  4. 04Fractional, interim and permanent briefs
Prefer email? Use the booking page →

Pick a day that suits · live availability

Live CTO, CIO and CISO roles

Fractional Quest is a fractional recruitment agency: send a CTO brief and we come back with a shortlist of three to five vetted candidates.

01/ the role

Technology due diligence: what is assessed

Technology due diligence answers one question for the people putting money in: does the technology support the plan the valuation assumes? It sits alongside financial and legal due diligence, and it is best run by someone who has been a CTO, because the risks that matter are rarely the ones a checklist finds.

Architecture and scalability

Whether the product can carry the growth in the business plan, what has to be rebuilt to get there, and which parts depend on a single supplier or a single person.

Code quality and IP ownership

How the code is written, tested and released, and who owns it. Copyright in code written by an employee in the course of employment usually belongs to the employer; code written by a contractor or agency usually stays with its author unless a written agreement says otherwise, as the Intellectual Property Office’s guide to ownership of copyright works explains. The review lists who wrote the core product and checks the contracts. Open-source licences are checked too.

Security

Access, patching, past incidents and how the company would respond to one. ICAEW’s guide Cyber Security in Corporate Finance notes that an acquirer can inherit a breach the business does not know about, and that a transaction itself draws attackers. The NCSC’s Cyber Security Toolkit for Boards gives the questions a board should be able to answer.

Data protection

What personal data the company holds, on what lawful basis, and whether it can show its compliance, as the ICO’s guide to accountability and governance requires. On an acquisition, the ICO’s code on due diligence when sharing data following mergers and acquisitions says the buyer must consider data sharing as part of its due diligence, including the purposes the data was first collected for.

Team and key-person risk

Who holds knowledge nobody else has, whether they are staying after the deal, and whether the team can deliver the roadmap. A company where one founder is the only person who understands the platform is a different investment from one with a documented system and a second in command.

Technical debt and costs

The shortcuts that will have to be paid back, what they will cost in time and people, and what the technology costs to run today. The review separates debt that limits growth from debt that is merely untidy.

Sensitive sectors

Some acquisitions must be notified to the government before they complete under the National Security and Investment Act; GOV.UK says a notifiable acquisition completed without approval is void. Qualifying assets can include intellectual property. Whether a deal is caught is a legal question, but the technical reviewer is often the person who can say plainly what the target’s technology does.

02/ scope

Tech due diligence for investors: the buy-side view

Tech due diligence for investors is commissioned by the buyer or the fund. Its job is to test the story in the information memorandum and the data room against what the practitioner finds when they read the code, walk the systems and talk to the team.

Scope it from the investment case

Start from what the deal assumes: the growth rate the platform must carry, the markets it must enter, the products it must add. Every question the review asks should trace back to one of those assumptions.

Read, walk and talk

Documents in the data room, access to the code and the cloud accounts, and interviews with the CTO, the engineers and the key suppliers. The interviews usually tell the practitioner more than the documents do.

Turn findings into terms

Each finding should say what it means for the deal: a price adjustment, a warranty, a condition before completion, or an item for the first months after it. ICAEW’s guide notes that due diligence findings can guide the cyber security work after completion. For an early-stage round, UK Private Capital (formerly the BVCA) publishes model documents for Series A investments, including a subscription agreement and a summary of terms, as an industry starting point.

Who runs it

We place the practitioner who runs it. Every candidate goes through our five-stage vetting first: qualification, mandate fit, references, shortlist and kick-off. IR35 status is decided by how the engagement runs, and a medium or large client makes the determination; our IR35 guide sets out the tests.

03/ comparison

Buy-side due diligence vs vendor due diligence

The same ground, read from opposite sides of the table.

Buy-side (investor or acquirer)Vendor (seller or company raising)
Commissioned byThe investor, fund or buyerThe company, before it goes to market
PurposeTest the investment case and find risk that affects price or termsFind and fix issues first, and give bidders a report to rely on
Usually led byAn interim or fractional CTO acting for the buyerAn interim or fractional CTO working inside the company
OutputFindings mapped to price, warranties, conditions and post-deal planA readiness report, fixes made, and a data room that answers the questions

04/ vetting

How we vet interim and fractional CTOs

What we undertake on every brief, before a candidate reaches you.

  1. 01

    Qualification screen

    Verify CTO tenure, sector context and stage fit.

    SOURCING
  2. 02

    Mandate fit

    Match to your situation — stage, board dynamics, timing.

    MATCHING
  3. 03

    Reference deep-dive

    We take references ourselves, from recent past clients — real outcomes, not titles.

    VERIFY
  4. 04

    Shortlist

    Three to five candidates with day rate, availability and IR35 position set out.

    SHORTLIST OF 3–5

05/ vendor due diligence

Vendor due diligence: getting ready for a raise or a sale

Vendor due diligence is the same review, commissioned by the company before investors or buyers arrive. It finds the issues while there is still time to fix them, so the first time a bidder sees a problem is not in the middle of negotiating the price.

ICAEW’s Cyber Security in Corporate Finance describes a vendor report as covering the matters an acquirer would expect in its own review, with the vendor able to take remedial action on what it finds. The British Business Bank’s Are you ready for finance? checklist makes a related point for founders: from tax planning to not owning your own IP, knowing the sticking points up front helps the negotiation and shows you are being transparent.

Getting ready usually means: confirming the company owns its code, with assignments from contractors where needed; documenting the architecture; closing obvious security gaps; putting the data protection records in order; and making sure the platform does not depend on one person. Before sensitive information goes to a fund, the British Business Bank’s private equity checklist suggests a non-disclosure agreement to protect IP and commercially sensitive data. If you want a wider review first, start with a technology audit.

06/ hire an interim or fractional CTO

Hire an interim or fractional CTO for a deal

A deal needs a CTO’s judgement for a set period. Hire an interim CTO for a full-time push: running vendor due diligence, preparing the data room and answering bidders’ questions, or taking the seat after completion while a permanent hire is found. Hire a fractional CTO for part-week work: a buy-side review for a fund, or preparing a company over several months for a raise.

After the deal, the findings often point to a permanent technology leader. Our CTO headhunter page covers that route, and we recruit fractional, interim and permanent CTOs, and non-executive directors.

Whichever route you choose, we send a shortlist of 3–5, each with day rate, availability and IR35 position set out.

07/ questions

Technology due diligence FAQ

The questions people ask before bringing in an interim or fractional CTO.

A senior review of a company’s technology before an investment, acquisition or exit: architecture and scalability, code quality and IP ownership, security, data protection, the team and key-person risk, technical debt and running costs. It tells a buyer what they are paying for and a seller what to fix first.

Whether the technology supports the plan the valuation assumes. The practitioner reads the data room, reviews the code and the cloud accounts, and interviews the team, then maps each finding to the deal: price, warranties, conditions or the plan for the months after completion.

The same review, commissioned by the company before it raises or sells. It finds issues while there is time to fix them and gives bidders a report to rely on. If you want a wider review first, start with a technology audit.

Decide which side you are on, what the review must answer and how much of the week it needs. Then brief us: we send a shortlist of 3–5, each with day rate, availability and IR35 position set out. See the hubs for an interim CTO or a fractional CTO.

It depends on the size of the company, the depth of the review and the practitioner’s day rate. We set out each candidate’s day rate on the shortlist, and our rate calculator multiplies a day rate by the days you need.

Usually the employer owns code its employees wrote in the course of their employment, while a contractor or agency keeps the copyright in its work unless a written agreement assigns it (Intellectual Property Office). Due diligence checks the contracts for the people who wrote the core product.

It can. Some acquisitions in sensitive areas of the economy must be notified to the government before completion, and qualifying assets can include intellectual property (GOV.UK). Take legal advice; the technical review helps by describing plainly what the target’s technology does.

They cover similar ground. Due diligence is read by an investor or buyer and asks what could affect the deal. An audit is for the business itself and asks what to fix and in what order. See technology audit.

Neither by default. Status is decided by how the engagement runs, contract by contract. If they work through their own company, a medium or large client makes the determination. Our IR35 guide sets out the tests.

Book 15 minutes · shortlist of 3–5

Bring the brief. We architect the team.

A shortlist of 3–5 with day rate, availability and IR35 position set out, after five-stage vetting.

Fractional Quest logo — how to hire an interim CTO, technology due diligence