# IT Due Diligence 2027: What Private Equity should focus on now

The questions that decide the deal in an IT Due Diligence today: post-closing costs, security, dependencies and AI.

A good IT Due Diligence answers one question: what does IT really cost after closing, one-off and recurring, and which risks can derail the plan? Everything else is supporting material.

## Costs: separate run-rate from catch-up investment

The IT budget in the data room rarely shows the catch-up need. Outdated systems, expiring support and missing security measures belong in a separate model as one-off investment.

## Security: evidence instead of self-assessment

Ask for penetration tests, backup restore tests and access concepts, each with a date. A signed self-assessment is no substitute for evidence.

## Dependencies: group, service providers, key people

Systems shared with the seller, a single service provider without backup, or one person who knows everything: these are the points that cost money after closing.

## AI: opportunity and risk at once

- Which AI functions are in the product, and on which models and contracts are they based?
- Was software built with AI tools, and are there review and security processes for it?
- Where can AI reduce process costs after closing, and who will implement it?

## Questions to the seller: short and one at a time

Bundled questions produce bundled answers. One clear question per line, context as a short note underneath, and the data room fills faster and more precisely.

> **In short:** Post-closing costs, security evidence, dependencies and AI are the four areas an IT Due Diligence must answer in 2027.