Guide

IT consulting firm / MSP due diligence

Due diligence on an IT consulting firm or MSP means independently verifying that the client contracts are genuinely recurring and assignable, reviewing the business’s cybersecurity and data-privacy exposure directly, confirming vendor partner-tier status with the vendor itself, and checking what is actually documented versus dependent on one person’s memory.

Reviewed

Diligence on an MSP is largely about testing two things independently of the seller’s narrative: whether the recurring revenue is really recurring, and whether the client environments the business supports carry hidden security or technical-debt risk that becomes the buyer’s problem the moment ownership changes. Neither is something a summary spreadsheet can reliably answer on its own, and a buyer who works through both methodically, with a lawyer and a technical reviewer alongside them, ends up in a materially different position at closing than one who took the seller’s summary at face value.

Testing whether "recurring" really means recurring

Pull the actual signed agreements, not a revenue summary the seller has prepared, and check the notice period, auto-renewal terms and — critically — whether each contract is genuinely assignable on a change of ownership. A contract that requires client consent to assign is not a problem by itself, but a buyer needs to know which contracts fall into that category before relying on the revenue they represent. Reconcile the total against the seller’s own summary line by line, and treat any contract you cannot locate, or any client the seller describes verbally rather than in writing, as unverified revenue until proven otherwise.

The cybersecurity and data-privacy review is not optional

An MSP typically holds privileged access to many clients’ systems and data, so a single undisclosed security incident anywhere in the client base can become the deal’s single biggest liability. Request incident history directly, and review how the seller’s own obligations under federal privacy law, and any sector-specific requirements that flow through from regulated clients such as health or finance, are actually built into the seller’s client contracts rather than assumed. This review is specialized enough that it is normally worth engaging counsel with genuine cybersecurity and data-privacy experience, rather than treating it as a subset of general contract review.

Verifying vendor partner-tier status directly with the vendor

Do not rely on the seller’s representation of partner-tier status alone. Confirm directly with each relevant vendor what re-qualification the buyer will need to complete, and whether existing rebates or pricing tiers are realistically likely to survive the change of ownership, since this can materially change post-acquisition margin.

Testing client concentration and dependency directly

Work from the actual contract list to calculate what proportion of revenue sits with the largest few clients, rather than relying on the seller’s characterization of the client base as diversified. Cross-check that figure against anything stated during negotiation, and treat a meaningful gap between the two as a reason to look harder elsewhere, not as an isolated rounding error.

Reviewing insurance and liability history

Ask whether the business carries cyber-liability and errors-and-omissions coverage, review the claims history if any exists, and confirm whether that coverage is expected to continue after the sale or whether a new policy will need to be in place from day one. Given how much access an MSP holds into its clients’ systems, a gap in coverage during the transition period is a real exposure, not a technicality to sort out later.

Checking what’s actually documented versus what lives in someone’s head

Request runbooks and client environment documentation, and, with appropriate permission, speak with key technicians about what institutional knowledge is not written down anywhere. Any proprietary scripts, tools or automation the firm has built internally should also be reviewed for what actually belongs to the business rather than to an individual, including who holds the credentials and licences those tools depend on. Treat heavy reliance on one or two people’s memory as a real, priceable risk rather than a minor gap to note and move past, and factor the cost of documenting it properly into your offer if it is missing.

Standard corporate checks still apply

The same baseline diligence that applies to any acquisition still matters here — confirming corporate status and good standing, and running an execution and judgment search against the corporation and, where relevant, the owner personally, before you sign anything final. None of this is specific to IT services, but it is easy to deprioritize in a sector where the technical review feels like the more interesting work, and skipping it exposes a buyer to risks that have nothing to do with the client base at all.

What a finding actually means

Not every finding is fatal. Undocumented runbooks or a lapsed certification are usually fixable with time and cost that can be negotiated into the price. An undisclosed security incident, a client base that turns out to be mostly month-to-month despite being represented otherwise, or a vendor unwilling to requalify the buyer at all, are the kinds of findings that genuinely change whether the deal should proceed as structured.

Sources

Every requirement and figure referenced in this guide traces to a primary source. Links were last confirmed on the dates shown.

  1. 01
    Treadstone LawLegal commentary
    Cybersecurity and Data Privacy Due Diligence When Buying a Business in Ontario
    treadstonelaw.ca·Checked Aug 14, 2026
  2. 02
    Treadstone LawLegal commentary
    Are Your Contracts Assignable?
    treadstonelaw.ca·Checked Aug 14, 2026
  3. 03
    Treadstone LawLegal commentary
    Intellectual Property Due Diligence When Buying a Business in Ontario
    treadstonelaw.ca·Checked Aug 14, 2026
  4. 04
    Treadstone LawLegal commentary
    Checking Corporate Status and Good Standing Before Buying an Ontario Business
    treadstonelaw.ca·Checked Aug 14, 2026
  5. 05
    Office of the Privacy Commissioner of CanadaGovernment
    The Personal Information Protection and Electronic Documents Act (PIPEDA)
    priv.gc.ca·Checked Aug 14, 2026

Deavo is an advertising and listings platform, not a brokerage, law firm or valuation firm. This page is general information, not legal, tax, accounting or valuation advice, and rules differ by province. Confirm anything you rely on with a qualified professional before you act on it.