Every IT services business has risks that don’t appear on the balance sheet. Buyers and their advisers spend significant time finding them. The founders who surface and address these risks before going to market command significantly better outcomes than those who wait for buyers to find them first.
Published by Evolution Capital | IT/Telco M&A Specialists | 25 Years | 250+ Transactions
Years in technology M&A
Transactions
In completed transactions
“Preparation doesn’t eliminate every risk. It gives you control over how that risk is presented and managed.”
Evolution Capital · From the trenches
How Buyers Assess Risk
Understand the key areas buyers scrutinise during due diligence and where hidden issues can emerge.
What Can Impact Deal Value
See how financial, contractual and operational risks can affect price, deal structure and buyer confidence.
How to Prepare Early
Learn what you can address before going to market to reduce surprises and keep your transaction on track.
Why Hidden Risks Matter in a Sale
The Risks Buyers Look For
Financial & Tax Risks
Customer & Contractual Risks
Employment & People Risks
IP, Data & Regulatory Risks
How Buyers Assess Risk
Preparing Your Business Before a Sale
How Evolution Capital Can Help
Common Questions
There is a formulation, famously said by Donald Rumsfeld from February 2002, that has always resonated with me in the context of M&A:
There are known knowns: things we know we know. There are known unknowns: things we know we don’t know. And then there are unknown unknowns: things we don’t know we don’t know.
In an IT services sale process, the known knowns are manageable. The seller is aware of them, can prepare for them, and can present them in context. The known unknowns are harder but still workable: you know the gap exists and you can try to fill it. It is the unknown unknowns that kill deals or destroy value, because they surface during diligence when it is too late to address them proactively and the only negotiating dynamic is damage limitation.
As advisers who happen to be accountants, this framework lands with particular resonance. Our job, in an M&A context, is precisely to account for the unexpected: to find the things that aren’t visible on the surface, to price the risks that don’t appear on the balance sheet, and to help sellers understand what is lurking in their business before a buyer’s team goes looking for it.
I did briefly consider calling this article “What to Expect When You’re Not Expecting It.” I couldn’t get the all-star cast together to feature, so we went with something slightly less glamorous.
What this article does, in the spirit of both Rumsfeld and our accounting instincts, is try to help you account for the unexpected: to move as many of your unknown unknowns into the known category as possible, so that when they do surface, you understand what they are, why they matter, and what you can do about them.
The deal was on track for completion. A cybersecurity services business with £9 million revenue and £1.4 million EBITDA. The buyer had completed financial and commercial due diligence. Legal documentation was being finalised.
Then the buyer’s legal team uncovered something in their review of historic correspondence. Three years earlier, the company had implemented a security solution for a financial services client that subsequently suffered a data breach. The client had threatened legal action claiming the seller’s solution was inadequate, seeking £800,000 in damages.
The seller’s position: “That was years ago. The client never actually sued. We haven’t heard from them in 18 months. It’s ancient history.”
The buyer’s position: “This is a material undisclosed contingent liability. The claim period hasn’t expired. If the client pursues this post-acquisition, we inherit the liability.”
After two weeks of tense negotiation, they settled on £450,000 in escrow for three years to cover potential claims, plus comprehensive warranty coverage for any litigation arising from pre-completion events.
The seller was furious. In his mind, this was a dead issue. In the buyer’s mind, it was precisely the type of hidden risk that diligence exists to uncover.
Evolution Capital
Every IT services business carries risks that don’t appear in the financial statements: customer disputes about service quality or billing, former employee claims, supplier disagreements, regulatory compliance gaps, tax positions that HMRC might challenge, IP ownership questions, data protection issues.
These risks are contingent: they may or may not materialise into actual liabilities. But buyers price them as if they’re real, because from their perspective, they very well might be. And crucially, they are not just priced for their direct financial exposure. They are priced for what they signal about the quality of the business and the reliability of the management.
Review your financials, contracts, people, tax position, IP and regulatory obligations to identify potential issues.
Address outstanding liabilities, documentation gaps, contractual issues and other known risks before going to market.
Make sure key agreements, records and supporting evidence are organised and ready for buyer review.
Understand which risks could affect valuation, deal structure or the protections a buyer may request.
Evolution Capital
Before covering the seven main categories of hidden risk, it is worth briefly distinguishing between contingent liabilities and off-balance sheet obligations, because they are different things that buyers treat differently.
Contingent liabilities are potential obligations that depend on uncertain future events: a customer might sue, HMRC might challenge a tax position. These may or may not appear on the balance sheet depending on how likely they are and how reliably they can be estimated.
Off-balance sheet obligations are actual commitments the business has made that are not reflected on the face of the balance sheet. Operating lease commitments disclosed only in the notes to the accounts are the classic example. Future minimum purchase commitments under supplier contracts. Guarantee obligations given to third parties. These are not contingent: they are real obligations that the buyer is inheriting, just not visible in the balance sheet headline.
Buyers address these through their own modelling and through the warranty and indemnity process rather than through the completion accounts mechanics directly, but they affect valuation, deal structure, and the protections buyers seek in the SPA. A business with £300,000 of future operating lease commitments and £200,000 of minimum purchase obligations is carrying half a million in off-balance sheet obligations that a buyer will factor into their view of the business even if they don’t appear as balance sheet line items. Understanding your off-balance sheet position, and being able to present it clearly, is part of being prepared for a sale.
Know Your Risks Before the Buyer Does
Identify and address potential issues before they become obstacles in your transaction. Evolution Capital can help you prepare your business for due diligence and navigate the risks that matter most to buyers.
Evolution Capital
Customer disputes and claims
IT services businesses live at the intersection of complex technology and demanding customers. Things go wrong. Systems fail. Projects overrun. Most of the time these issues get resolved through service credits, remediation work, or commercial negotiation. But sometimes they escalate.
Failed implementations or migrations where customers claim business disruption and financial losses. Security incidents where clients claim inadequate protection. Billing disputes where customers refuse payment and threaten legal action. SLA breaches where customers seek financial penalties. IP or confidentiality disputes where customers allege misuse of their data.
Buyers discover these through reviews of customer correspondence files, analysis of aged debtor disputes, customer reference calls, contract reviews identifying penalty clauses, and legal diligence uncovering demand letters.
Even if the seller believes a claim is entirely meritless, the buyer sees risk. Legal defence costs money. Settlement costs more. And the broader credibility signal one dispute sends about the business often matters more than the specific financial exposure.
We worked on a transaction where an MSP had a £180,000 invoice in dispute with a customer who claimed services weren’t delivered as specified. The buyer insisted on a £180,000 escrow holdback plus full indemnity. Their reasoning: “We’re not just worried about the £180,000. We’re worried that this indicates poor project management or documentation practices. What other customers might have similar disputes we haven’t found yet?”
Employment and HR liabilities
People issues create significant hidden liabilities that founders typically don’t think to flag to buyers.
Unfair dismissal or discrimination claims from former employees, even unsubstantiated ones, cost £15,000 to £40,000 in legal fees to defend. Unpaid wages or holiday pay claims can go back several years. IR35 contractor misclassification is a major risk: if individuals treated as contractors should have been classified as employees for tax purposes, retrospective tax, penalties, and interest can run to hundreds of thousands of pounds. Pension auto-enrolment failures result in compliance action from The Pensions Regulator including fines and backdated contributions.
A telecommunications business we advised had classified 12 field engineers as contractors for four years. Diligence concluded they should have been employees under IR35 rules. Retrospective tax liability: approximately £320,000 plus penalties and interest. The buyer required a full indemnity, £400,000 in escrow for three years, and immediate reclassification of all contractors to employee status post-completion.
The seller had relied on his accountant’s advice that contractor status was appropriate. But reliance on professional advice does not eliminate the liability if HMRC disagrees.
Tax exposures and uncertain positions
Tax systems are complex, and IT services businesses often take positions that seem reasonable but carry challenge risk.
R&D tax credit claims are particularly common. Many IT businesses claim credits for development work. If HMRC challenges that the work doesn’t qualify, the credits must be repaid with interest. An MSP we reviewed had claimed £280,000 in R&D tax credits over three years for development of customer portals and automation tools. The buyer’s tax advisers concluded that most of this was routine software development, not qualifying R&D under HMRC guidelines. Potential exposure: £280,000 repayment plus £60,000 to £80,000 in penalties. The buyer demanded a tax deed of indemnity and £350,000 in escrow.
VAT treatment questions, aggressive positions on allowable business expenses, employment taxes beyond IR35, and transfer pricing for businesses with related entities or offshore arrangements all carry similar risk profiles.
Beyond the challenge risk on specific positions, there is a separate cash flow dimension to tax that is worth understanding. Corporation tax is not paid at the point it is recognised in the P&L. For most companies, tax is paid in the year following the accounting period to which it relates, through a combination of a payment on account and a balancing payment. For larger companies, quarterly instalment payments apply. This timing difference means that a business that has grown its profits significantly in the most recent year may have a tax liability building that has not yet been paid and does not obviously appear in the management accounts. Buyers will identify this and treat it as a debt-like item in the net debt schedule: cash that belongs to HMRC rather than to the seller.
The practical point for sellers is to understand their current tax position clearly before going to market: what is the estimated liability for the most recent period, what payments on account have already been made, and what balance will be due at or after completion. Surprises in the tax cash position, discovered during diligence, create exactly the kind of trust erosion that makes buyers question everything else.
Regulatory and compliance gaps
IT services businesses operate in increasingly regulated environments, and compliance gaps are surprisingly common.
GDPR and data protection failures create ICO fine exposure of up to £17.5 million or 4% of global turnover. Sector-specific regulations apply to businesses serving financial services clients under FCA requirements or healthcare under NHS data security standards.
Information security certifications are a particular area of risk. A cybersecurity services business claimed ISO 27001 certification in its marketing materials and customer contracts. Diligence revealed the certification had lapsed 14 months earlier. Three major customers had contracts requiring valid ISO 27001 as a condition of ongoing service provision. The lapsed certification was a technical breach giving those customers termination rights. Potential exposure: loss of £680,000 annual revenue if customers exercised those rights, plus claims for misrepresentation. The buyer required immediate recertification before completion at a cost of £45,000, plus written confirmation from the three customers of continued engagement, plus full warranty coverage for any claims arising from the lapsed certification.
Ofcom registrations for telecommunications providers, SIA licensing for security services, and Modern Slavery Act compliance statements all carry similar potential exposure when not properly maintained.
Intellectual property risks
IT services businesses often have complex IP situations that aren’t visible until someone looks carefully.
Unclear ownership of developed IP is the most common issue. Software, tools, or methodologies developed by contractors may not be properly assigned to the company, particularly where contractors were engaged without formal IP assignment agreements. Third-party IP used without proper licensing, including open-source software with restrictive licence terms, creates related exposure.
One managed services provider had built a customer portal using a popular open-source framework licensed under GPL, which requires any derivative works to also be open-sourced. The portal contained proprietary features the seller considered competitive advantages. Enforcing GPL would require making that code publicly available, destroying the competitive value. The buyer’s options were a complete rebuild at £200,000 over eight months, commercial licensing at £80,000 plus ongoing fees, or accepting GPL obligations and open-sourcing the code. There was no cheap resolution.
Contractual commitments and onerous obligations
Hidden within supplier contracts, customer agreements, and partnership arrangements are obligations that only become visible under careful diligence.
Minimum purchase commitments with suppliers that aren’t being met. Exclusivity restrictions preventing the business from working with certain customers or offering competing services. Change-of-control provisions in supplier or partner contracts that terminate upon sale, requiring renegotiation. Price freezes in multi-year customer contracts locking in eroding margins. SLAs with heavy penalty clauses.
A telecommunications reseller had a wholesale supply agreement requiring minimum annual purchases of £400,000. Current purchases were running at £280,000 annually, a £120,000 shortfall with associated penalties. The contract also had change-of-control provisions allowing the supplier to renegotiate terms or terminate once the sale became known. The buyer’s leverage with this supplier disappeared at the point of disclosure.
Litigation and other legal disputes
Beyond customer and employment disputes: landlord disputes about dilapidations, service charges, or lease terms; shareholder disputes with minority holders about exit terms or governance; supplier claims for unpaid invoices or breach of contract; and professional negligence claims where clients allege advice caused financial losses.
Buyers conduct comprehensive legal diligence including litigation searches, review of correspondence files, and warranties requiring disclosure of all threatened or actual litigation. Undisclosed correspondence revealing past disputes, even those the seller considers resolved, is one of the most common triggers for material price adjustments or increased escrow requirements.
Evolution Capital
When contingent liabilities are identified, buyers have several responses.
For quantifiable, near-certain liabilities: reduce the price by the estimated exposure.
For uncertain but material risks, funds are held in escrow rather than paid at completion. Escrow amounts typically exceed the estimated exposure by 10 to 20% as a risk buffer.
Warranties require factual statements about the state of the business. Indemnities are promises to reimburse the buyer for specific losses if they materialise. Both provide recourse if hidden liabilities emerge post-completion.
Significant hidden risks can cause buyers to restructure from a simple cash acquisition to a lower upfront payment with earnout tied to absence of claims, a seller note allowing offset if liabilities emerge, or an asset purchase rather than share purchase to avoid inheriting liabilities.
If hidden liabilities are material enough and the seller will not adequately address them, buyers terminate.
Beyond the direct financial impact, hidden risks affect transactions in ways that matter as much as the money.
Trust destruction. If buyers discover significant undisclosed liabilities, they question everything. What else wasn’t disclosed? Are the financials accurate? Can anything the seller has represented be relied upon? The credibility damage from one unexpected finding often exceeds the financial impact of the specific issue. The unknown unknown that surfaces in week four of diligence doesn’t just cost what it costs. It costs the trust that was making everything else work.
Deal momentum collapse. Discovery of hidden liabilities stops momentum. Extended legal review, additional diligence, time to reassess the entire transaction. Deals that should close in ten weeks extend to eighteen to twenty, increasing the probability of failure from unrelated factors.
Seller frustration. Sellers genuinely believe many contingent liabilities are immaterial or resolved. “That dispute is three years old. The customer never formally sued. It’s irrelevant.” Buyers see it differently: “The statute of limitations hasn’t expired. We could be sued post-acquisition. We need protection.” This disconnect creates the friction that characterises the most difficult deal negotiations.
The known unknowns are the most frustrating category for sellers: situations they were aware of but underestimated. Getting ahead of them before diligence begins changes the entire dynamic.
Evolution Capital
The optimal time to identify contingent liabilities is twelve to eighteen months before going to market, not during buyer diligence.
Commission vendor due diligence. Engage advisers to conduct the same scrutiny buyers would apply: legal DD reviewing contracts, correspondence, and regulatory status; tax DD examining filed returns and positions taken; employment DD reviewing HR files and practices; and an IP audit assessing ownership and licensing. This surfaces issues while you still have time to address them.
Resolve known issues proactively. Settle customer disputes. Regularise employment situations. Fix compliance gaps. Renew lapsed certifications. Get tax positions settled with HMRC. Where resolution is not possible before going to market, proactive disclosure with supporting documentation is far better than buyers discovering issues and questioning what else is being concealed.
Document everything. Written contracts with clear terms, IP assignment agreements from all developers, regulatory compliance records and certifications, tax position documentation. Good documentation doesn’t eliminate risk, but it demonstrates competence and reduces buyer anxiety.
Build cash reserves for known exposures. For risks that cannot be fully resolved, plan for the escrow or indemnity arrangements they will generate. If there is a £200,000 contingent liability, plan for £250,000 to be held in escrow.
Consider warranty and indemnity insurance. For material known risks that cannot be resolved, W&I insurance can bridge the gap between what the seller is willing to indemnify and what the buyer needs as protection. The seller discloses the risk in warranties and obtains insurance covering potential claims. Cost is typically 1 to 2% of the insured amount.
Issues that seem minor during day-to-day operations can become significant during due diligence, affecting valuation, deal terms, or the buyer’s willingness to proceed.
Hidden risks are, by definition, the things that founders living and breathing the business every day have learned not to think about. The IR35 situation has been the same for four years and no one has ever challenged it. The lapsed certification slipped off someone’s to-do list. The old customer dispute felt resolved even though nothing was formally settled. They are, in Rumsfeld’s taxonomy, known unknowns at best and unknown unknowns at worst.
They surface under diligence, where someone with no prior knowledge of the business and a professional obligation to test everything is looking with fresh eyes.
EC Analytics (Virtual CFO / CFO Assist)
Many of the compliance and documentation issues that generate hidden risk at sale, IR35 assessments, regulatory certification maintenance, proper IP assignment agreements with contractors, tax position documentation, are things that a CFO-level oversight function manages as a matter of routine. EC Analytics works with IT services businesses to build this function in the period before sale, systematically reducing the inventory of hidden risks that buyers will find.
When hidden risks surface despite best preparation, we manage the response: assessing whether the buyer’s proposed price adjustment or escrow is commercially proportionate, negotiating warranties and indemnities so that they are appropriately limited, exploring W&I insurance where it is a more efficient solution than escrow, and maintaining deal momentum through what is typically the most difficult period of any transaction.
Our legal, tax, and employment due diligence work identifies exactly these issues for buyers. Across 250 transactions in IT and Telco, we know the specific categories where hidden risks most commonly emerge: IR35 and employment status, R&D tax credit claims, lapsed certifications, IP ownership in businesses that have used contractors for development, and change-of-control provisions in wholesale supplier contracts.
When we act as vendor DD adviser for a seller preparing to go to market, we bring this same forensic approach to the seller’s own business. We find what buyers will find, before they find it, while the seller still has time to resolve the issue rather than negotiating over it under time pressure.
Enterprise Value is the agreed value of the business before accounting for its financial position. Equity value, what you actually receive at completion, is derived by adjusting EV through the net cash and debt schedule, which adds cash and deducts financial debt and debt-like items, and the working capital adjustment, which is positive if completion working capital is above the agreed peg and negative if below. Understanding this bridge before going to market is essential: the adjustments frequently move the headline number by £500,000 to £2 million or more.
The Sale and Purchase Agreement is the binding legal contract governing the transaction. It defines the purchase price mechanics, including how the balance sheet feeds into the final price through either completion accounts or a locked box structure, what items are treated as cash, debt, or debt-like, and the working capital peg. The SPA is where the balance sheet stops being an accounting document and becomes a financial settlement mechanism. Understanding its terms before signing is essential.
Completion accounts is the standard structure in the UK mid-market IT services space: the price is estimated at signing and adjusted post-completion based on the actual balance sheet, with a reconciliation process typically taking 30 to 90 days after the deal closes. Locked box fixes the price based on a historical balance sheet, with no post-completion adjustment. Locked box provides price certainty but requires a very clean historical balance sheet and is rarely seen at the lower to mid end of the UK market.
Deferred revenue represents cash received for services not yet delivered and is a liability on the balance sheet. For IT services businesses with annual or multi-year contracts billed upfront, and particularly those serving customers who time spend around financial year-ends or seasonal cycles, it can be a very material number. Businesses not on accrual accounting often carry no deferred revenue on their balance sheet at all, meaning it overstates the net asset position. Buyers always restate, and the adjustment comes off your proceeds.
If a director owes the company money through a DLA and it is not repaid within nine months of the company’s accounting year-end, the company faces a Section 455 tax charge of 33.75% of the outstanding balance. This is repayable by HMRC once the loan is repaid, but it represents a real cash cost at the point of a deal, treated as a debt-like item deducted from proceeds. A £150,000 outstanding DLA creates a £50,625 s.455 charge on top of the loan balance itself.
Yes. Buyers always look at the consolidated position across all entities in the group. Holding company balance sheets that haven’t been updated for months or years are one of the most common sources of unwelcome surprises in IT services diligence. Get the consolidated position clear and current well before going to market, and identify which entities are in and out of the transaction perimeter early in the process.
Start with a strategic assessment to understand your maximum potential valuation in the current market.
About Us
Blogs
Our Location
Careers
About Us
Sell Side
Buy Side
Data Work
Faq
Client Dashboard
Support
Our Location