Insights / Technical due diligence

Technical due diligence: what buyers actually look for

Diligence rarely fails on code quality. It fails on concentration risk, undocumented dependencies and a roadmap nobody believes.

Duncan Clapman / 9 March 2026 / 6 min

Founders preparing for investment or sale often expect the technical review to focus on the codebase. Reviewers certainly look at it, but the findings that change valuation are usually elsewhere.

Concentration risk comes first. If one person holds the architecture in their head, or one supplier holds the deployment keys, that is a discount. Documentation and shared ownership are cheap insurance and are best built long before a process starts.

Second is the gap between roadmap and capacity. A plausible plan delivered by a team that is already fully committed to support work is not a plan. Buyers model delivery capacity, not intention.

Third is data: what you hold, on what basis, and whether the platform could withstand a serious question about it. Security posture, access control and third-party processing all sit here.

The best preparation is unglamorous. Write down the architecture. Reconcile the roadmap with real capacity. Fix the two things you already know a reviewer will find. Diligence rewards businesses that are honest with themselves first.

Next step

Got something difficult to solve?

Tell us what you’re working on.