Call NowFree Quote
Managed IT

IT Due Diligence When Buying a Perth Business

Most business buyers scrutinise financials, leases, and staff contracts. IT gets treated as an afterthought - until the new owner discovers the server is out of support, the software licences don't transfer, or the whole business runs on the previous owner's personal accounts. Here's what a proper IT due diligence review covers.

Why IT due diligence matters

The IT environment of a business you're buying can contain significant hidden liabilities - end-of-life hardware that needs immediate replacement, software subscriptions that can't be transferred, compliance gaps that expose you to regulatory fines, or security vulnerabilities that could result in a breach shortly after settlement. These costs don't show up on a balance sheet but can run into tens of thousands of dollars.

A pre-purchase IT review typically costs a few hundred to a couple of thousand dollars depending on complexity. It can save multiples of that - and is a legitimate item to negotiate into the purchase price if significant remediation is required.

1. Hardware inventory and age

Request a complete hardware register including:

  • All PCs, laptops, and workstations - make, model, age, and operating system
  • Servers - on-premise or hosted, hardware age, operating system, support status
  • Network equipment - routers, switches, wireless access points, firewalls
  • Printers, scanners, and other peripherals
  • Any specialised industry hardware (POS terminals, EFTPOS, medical devices)

Hardware older than 4–5 years is often approaching or past its useful life. Servers running Windows Server 2012 or older are end-of-life and a security liability. Factor replacement costs into your purchase valuation.

2. Software licences and subscriptions

This is where many buyers get caught. Key questions:

  • Is software licenced to the business entity, or to an individual (often the previous owner)?
  • Are licences perpetual (one-time purchase) or subscription? What happens to subscriptions at settlement?
  • Is the software properly licenced, or are there unlicensed copies in use?
  • Are there industry-specific platforms (practice management, accounting, ERP) and what are their transfer or re-licensing costs?
  • What SaaS tools are in use (CRM, project management, marketing)? Who holds the accounts?

Microsoft 365 and Google Workspace licences typically stay with the tenant domain, but the tenant admin account must transfer correctly. If the previous owner used a personal Microsoft account to set everything up, this can cause significant complications.

3. Domain names, email, and hosting

Confirm ownership and transferability of:

  • The business domain name (who is the registrant? Is it the business or an individual?)
  • Email hosting and email accounts
  • Website hosting and CMS access
  • Any other web properties associated with the business

Domain names registered in someone's personal name rather than the business can be a problem at settlement. The same applies to Google Workspace or Microsoft 365 tenants set up with personal email addresses. Get written confirmation of all credentials and transfer arrangements before settlement.

4. Data, backups, and compliance

Understand what data the business holds and how it is managed:

  • Where is business data stored - local servers, cloud storage, individual laptops?
  • Is there an active, tested backup in place?
  • Does the business handle personal or health information subject to the Privacy Act or other regulations?
  • Has any data breach occurred? Was it reported to the OAIC?
  • Are there data retention requirements you'll inherit (legal, accounting, industry-specific)?

If the business holds personal information under the Privacy Act and has had a breach they didn't report, you could be inheriting a compliance liability. This is worth a direct question in writing as part of vendor warranties.

5. Security posture

A basic security review should check:

  • Is MFA enabled on all accounts, or at minimum on admin and email accounts?
  • Are endpoint protection tools (antivirus/EDR) in place and up to date?
  • Has there been any malware infection, phishing compromise, or ransomware incident?
  • Are there any obvious vulnerabilities - unpatched systems, default router passwords, no firewall?
  • Who has admin-level access, and is there a process to revoke it at settlement?

A business that has experienced a recent ransomware attack may have residual issues - dormant malware, compromised credentials still in circulation on the dark web, or damaged reputation with customers. Dark web credential monitoring can surface if the business email domain has appeared in known data breaches.

6. IT contracts and support arrangements

Review all existing IT contracts:

  • Is there a managed IT provider? What are the contract terms, length, and exit provisions?
  • Are there hardware leases or finance agreements that transfer with the business?
  • Are there telecommunications contracts (NBN, mobile, VoIP) with remaining terms?
  • Are there software maintenance and support contracts, and do they transfer?

Managed IT contracts with remaining terms are often transferable, but confirm before settlement. Similarly, NBN business contracts typically have 24–36 month terms with early exit fees.

7. Access and credentials handover

At settlement, you need working access to everything that runs the business. This list is often incomplete in practice:

  • Domain registrar login
  • Microsoft 365 or Google Workspace global admin credentials
  • Website CMS and hosting panel
  • Server and network device admin credentials
  • All line-of-business application admin accounts
  • Social media accounts linked to the business
  • Google Business Profile ownership

We recommend a structured IT handover checklist be made a condition of settlement, with a pre-settlement walkthrough where each item is confirmed live before funds transfer.

Our IT consulting service provides independent, pre-purchase IT assessments Perth buyers can use in negotiations.

IT Consulting →

Getting a professional IT review

An independent IT assessment before purchasing a Perth business typically takes half a day on-site and produces a written report covering hardware condition, software licence status, security posture, and remediation costs. It's a small investment relative to the purchase price and can provide meaningful negotiating leverage if issues are found.

Frequently Asked Questions

What's the most commonly missed item in IT due diligence when buying a Perth business?

Domain names, Microsoft 365 or Google Workspace admin accounts, and software licences registered to the previous owner personally rather than the business entity. These can be genuinely difficult to untangle after settlement, so it's worth confirming ownership and getting written transfer arrangements in writing before you sign.

Can I negotiate the purchase price based on IT problems I find?

Often, yes. Issues like end-of-life hardware, unlicensed software, or security gaps that need remediation are legitimate items to raise in negotiations or to build into vendor warranties. A written IT assessment report gives you something concrete to point to rather than a vague concern.

Do I inherit compliance risk if the business I'm buying has had a data breach?

Potentially, yes, particularly if personal information was involved and the breach wasn't properly reported. This is worth raising as a direct written question with the vendor as part of due diligence, and it's the kind of thing worth confirming with a compliance adviser or lawyer rather than assuming either way.

How long does a pre-purchase IT assessment take?

A typical on-site review takes about half a day, with a written report covering hardware condition, software licensing, security posture, and estimated remediation costs following shortly after. It's a small time and cost investment relative to the size of most business purchases.

IT due diligence for your Perth business purchase

We provide independent IT assessments for buyers of Perth businesses - covering hardware, software, security, and compliance. Reports are suitable for use in purchase negotiations.

For related reading, see our guides to IT Strategy vs Managed IT: Which Does Your Business Need? and IT Consulting for Perth Small Businesses.

Share this article