The Dispatch

Inside the Quality of Earnings Conversation: Where IT Risk Hides

Written by Jason Lee | 8/14/26, 12:15 PM

 

When a business goes to market, the first question every serious buyer asks is: are these numbers real?

A Quality of Earnings report answers that question. Commissioned by buyers, sellers preparing for sale, or their private equity sponsors, a QoE is a deep-dive financial analysis that evaluates whether a company's reported EBITDA reflects its true, recurring, and sustainable earnings. It normalizes one-time expenses, identifies owner add-backs, flags revenue concentration risks, and establishes what the business would actually generate under new ownership.

In middle-market deals, a QoE report has become standard practice. The findings shape the purchase price, the indemnity structure, and in some cases, whether the deal closes at all.

What the QoE process does not typically address is technology.

Why IT Stays Outside the QoE Conversation

Financial analysts running a QoE engagement are accountants. They are looking for accounting policy inconsistencies, working capital manipulation, and non-recurring items buried in operating expenses. They are not evaluating whether the company's firewall has been patched in eighteen months, whether its ERP license expires in sixty days, or whether a critical server is running end-of-life hardware.

That gap is expensive.

The financial statements might look clean. But underneath them, the technology infrastructure often tells a different story.

Where IT Risk Actually Hides in a QoE

Deferred Technology Investment

One of the most common ways sellers inflate EBITDA is by deferring capital expenditures on technology. Hardware that should be refreshed every three to five years runs another cycle. Security tools go un-upgraded. Software development slows. Support contracts lapse.

None of this shows up as a red flag on the income statement. In fact, it makes the business look more profitable. But a buyer who acquires that company inherits the catch-up bill on day one.

When a technology advisor maps the true normalized IT spend against what the seller has been reporting, the delta can be substantial. On software-heavy acquisitions, that recalibration alone can move the purchase price by hundreds of thousands of dollars.

Software Licensing and Vendor Contract Exposure

Licensing audits are rarely part of a standard QoE. But they should be.

Unlicensed software, expired maintenance agreements, and vendor contracts with change-of-control clauses are common findings in IT due diligence. A change-of-control clause can require a seller to notify a vendor of the transaction, triggering a renegotiation or an immediate renewal demand from a vendor who now knows a deal is in progress.

These are not hypothetical risks. They are the kind of discoveries that show up in the first ninety days post-close and become the subject of earnout disputes and escrow claims.

Cybersecurity Posture and Undisclosed Incidents

This is where the financial exposure concentrates most dramatically.

When Verizon acquired Yahoo in 2017, two undisclosed security breaches emerged after the deal was signed. The purchase price was reduced by $350 million as a result. That is not an edge case anymore. It is a playbook that buyers and their advisors now follow closely.

According to IBM's Cost of a Data Breach Report, the average cost of a data breach globally is $4.88 million.1 An acquirer who inherits an undisclosed incident inherits that liability along with it.

Missing compliance certifications carry their own price tags. A company without a current SOC 2 Type II report typically triggers a 5 to 10 percent purchase price reduction, because the buyer must fund the 12 to 18 month audit process after close.2 Unreported security incidents discovered during diligence can result in a 10 to 25 percent purchase price holdback held in escrow.2

Shadow IT and Undocumented Systems

In many businesses, especially those that have grown quickly, the IT landscape employees actually use diverges significantly from what appears in the financials. Departments have stood up their own SaaS subscriptions. A critical workflow runs on a spreadsheet three people maintain. An integration between the CRM and the billing system was built by a contractor three years ago and nobody knows how it works.

Shadow IT creates two kinds of risk. First, costs are underreported, which makes margins look better than they are. Second, the operational complexity is invisible until an acquirer tries to integrate it, at which point timelines and budgets both expand.

How IT Risk Translates to Purchase Price Impact

Technology due diligence re-trades 30 to 40 percent of software-heavy M&A deals. When material findings emerge, purchase price reductions typically run between 5 and 25 percent of deal value.2 On a $50 million acquisition, a single security vulnerability combined with an open-source licensing issue can produce $2 to $4 million in adjusted purchase price, plus an 18 to 36 month indemnity escrow.2

For deals outside the software sector, the dynamic is different but not absent. Any business that depends on technology to deliver its product or service, which is most businesses today, carries technology risk that belongs in the earnings conversation.

What Buyers and Sellers Should Do Before the QoE Begins

The QoE engagement is not the right place to discover IT problems for the first time. By then, the financial model is already built, the letter of intent is already signed, and any finding becomes an adversarial negotiation rather than a clean correction.

Both buyers and sellers benefit from running a parallel technology assessment before the QoE kicks off.

For sellers, this means getting ahead of the narrative. A pre-sale IT assessment surfaces the vulnerabilities before a buyer's team does, giving management time to remediate what is fixable and explain what is not. A company that walks into a deal with a current SOC 2 report, a clean licensing inventory, and a documented IT roadmap negotiates from strength, not from the defensive crouch of unexpected findings.

For buyers, it means not relying on a financial due diligence team to catch risks they are not trained to find. An independent technology advisor who speaks the language of both IT and deal economics is not a nice-to-have on a complex acquisition. It is the difference between buying what you think you are buying and finding out what you actually bought.

Related reading: Before You Sign: The Technology Assessment Many M&A Teams Miss | Comprehensive IT Due Diligence Checklist for M&A | Risks of Neglecting IT Due Diligence in M&A Deals

Ready to Know What Your Deal Is Actually Worth?

Sentry Technology Solutions works with business buyers, sellers, and their advisors to evaluate IT environments ahead of and during the M&A process. Our team assesses infrastructure health, cybersecurity posture, licensing compliance, and technology debt in terms that translate directly into the deal conversation.

If you are preparing a business for sale or evaluating an acquisition target, a technology assessment should run alongside your financial due diligence.

Frequently Asked Questions

Is IT due diligence the same as a Quality of Earnings report?

No. A QoE is a financial analysis conducted by accountants to assess earnings quality and normalize EBITDA. IT due diligence is a separate technical assessment of the company's technology infrastructure, cybersecurity posture, and operational systems. The two workstreams should run in parallel, with findings coordinated before the purchase price is finalized.

Who commissions the technology assessment in an M&A deal?

Either party can commission it. Buyers commission IT diligence to protect themselves before close. Sellers increasingly commission pre-sale technology assessments to identify and remediate issues before they become deal leverage for a buyer.

Can undiscovered IT issues really affect the purchase price?

Yes, significantly. Industry data shows technology findings re-trade 30 to 40 percent of software-heavy deals, with price reductions commonly ranging from 5 to 25 percent of deal value.2 Cybersecurity findings, missing certifications, and undisclosed incidents can each trigger additional holdbacks or escrow requirements.

What does Sentry look at in a technology assessment for M&A?

We evaluate infrastructure health and age, software licensing compliance, cybersecurity posture, compliance certifications (such as SOC 2 Type II), vendor contracts with change-of-control provisions, cloud and SaaS spend, and technology debt that would require capital investment post-close.

How early in the process should a technology assessment happen?

Ideally before the letter of intent is signed. For sellers, that means ahead of going to market. For buyers, it means in parallel with the financial quality of earnings engagement, not after. Finding issues late creates leverage for the other side. Finding them early gives both parties room to price them correctly.

1 IBM Security. Cost of a Data Breach Report 2024.
2 CT Acquisitions. "Technology Due Diligence in Mergers and Acquisitions." ctacquisitions.com, 2026.