← M&A Integration Suite Integration Extract · Artifact 7 · how to read this suite

Due Diligence Findings

Download Word

This is the integration extract of due diligence: the fourteen findings that generate integration work, each with its severity, how the transaction dealt with it, what the program must now do about it, and who owns that. It deliberately excludes findings that were purely valuation matters and are now settled. It also carries a second register — the matters diligence could not assess — which is the shorter list and the more consequential one. Issued to the Steering Committee and all workstream leads on March 13, 2023.

The distinction this document exists to enforce: a finding that was priced is not a finding that was fixed. Diligence asks whether to buy and at what price. Integration asks what must now be done. When the deal team negotiates a purchase price reduction for an aging platform, the money moves to the buyer's side of the ledger and the platform is exactly as old as it was before. The commercial question closed; the work did not start. Every row in Section 3 that shows a deal treatment still shows an integration action, and that is the point of laying them side by side.

Table of Contents

Part I — Scope and Limits
  1. What Diligence Covered
  2. Deal Treatment Categories
Part II — The Findings
  1. Findings Register
  2. The Four That Shape the Program
Part III — What Is Not Here
  1. Register of Matters Not Assessable Before Closing
  2. Handoff to Risk Register and Disposition Matrices
Part I — Scope and Limits

1. What Diligence Covered

Diligence ran from October 2022 through signing on February 13, 2023, across financial, actuarial, legal, regulatory, technology, human resources and compliance workstreams, supported by external advisors. It examined contracts, statutory filings, system inventories, architecture documentation, organizational data, audit reports and management representations.

1.1 The limits, stated once

Diligence could not examine member-level enrollment or claims data, could not test Cumberland Valley records against ACME's, and could not access competitively sensitive pricing or provider rate detail except through the Clean Team in aggregated form. These are legal constraints, not omissions, and they are described in full in the Clean Team Protocol. Their consequence for this document is Section 5.

2. Deal Treatment Categories

TreatmentMeaning — and what it does not mean
PricedReflected in the consideration. The buyer paid less. No work was performed and no obligation was created.
EscrowFunds held back against a defined contingency for a defined period. Recovers money if the contingency materializes; does not prevent it.
IndemnitySeller bears specified losses. Requires the buyer to identify, quantify and claim — which is work.
Rep & warrantySeller states a fact is true. Remedy is a claim after the fact, subject to survival periods and caps.
AcceptedKnown, quantified, and taken as it stands. The most honest category, and often the correct one.
None of these five categories does integration work. Four of them move money and one of them moves nothing at all. That is not a criticism of the deal team — pricing risk is exactly their job, and they did it. It is a warning about how the finding register is read downstream. A workstream lead who sees "priced" and concludes the matter is closed has misread a commercial disposition as an operational one.
Part II — The Findings

3. Findings Register

Ref Finding Severity Deal treatment Integration action Owner
DD-01Core administration platform is a heavily customized legacy system; the vendor's support for the installed release ends within the integration windowHighPricedConfirms the absorb decision in the Application Disposition Matrix. Platform must be retired, not maintained. Sets the outer bound on the migration schedule.W. Ferriday
DD-02Enrollment records show inconsistent name and address formatting and an internal duplicate rate above sector normsHighRep & warranty⚠ Scale unverifiable pre-close — see Section 5. Profiling scheduled as the first substantive post-close activity. Drives the EMPI approach and the steward staffing model.Dr. A. Ravindran
DD-03Twelve material vendor agreements contain change-of-control provisions; three confer termination rights on the counterpartyHighRep & warrantyPre-close contract sweep. Consents and novations drafted for immediate post-close execution. The three termination rights are a Day 1 threat and are tracked individually.M. Rousseau
DD-04Business Associate Agreements with several PHI-handling vendors name Cumberland Valley as the covered entityHighAcceptedEvery BAA re-executed for the surviving entity. Tracked to completion as a Day 1 gate condition — a miss is a privacy exposure, not an administrative one.L. Braithwaite
DD-05Target has no production cloud footprint; all workloads on owned infrastructure in a single leased data centerMediumAcceptedReinforces the rehost-first migration posture. Data center lease term becomes a schedule dependency for the wave plan.B. Trammell
DD-06Interfaces between core admin and downstream systems are predominantly scheduled batch; limited real-time capabilityMediumAcceptedConstrains the integration architecture. Coexistence design assumes batch and EDI as the primary mechanisms rather than APIs.R. Delacroix
DD-07Prior state market conduct examination produced findings on claims timeliness; corrective action plan closed but recentMediumIndemnityClaims timeliness metrics monitored through cutover. Any Day 1 degradation is a regulatory matter, not only a service matter.R. Cadwallader
DD-08Concentration of institutional knowledge in a small number of long-tenured technical staff, with no documented successionHighAcceptedThese roles anchor the retention plan. Knowledge transfer is a tracked deliverable with acceptance criteria, not an assumed by-product of the TSA.D. Marchbanks
DD-09Provider contracts include a mix of evergreen and fixed-term arrangements with staggered renewal datesMediumAcceptedNetwork rationalization sequenced against renewal calendar rather than program convenience. Constrains the timing of a $19,000,000 synergy source.J. Kirkendall
DD-10Care management platform is a third-party tool under a subscription that overlaps ACME's own toolingMediumAccepted⚠ Tension with the preserve decision: the capability is retained, so the tool cannot simply be terminated for its subscription saving. Disposition resolved in the matrix, not by default.Dr. M. Ellsworth
DD-11Reserve setting methodology differs from ACME's in assumptions and development factorsMediumEscrowMethodology alignment required for combined statutory reporting. Actuarial workplan; not a program deliverable but a program dependency.E. Wetherby
DD-12Identity and access management is directory-based with limited role-based provisioning and periodic manual recertificationMediumAcceptedAccess model must be reconciled before any cross-entity system access is granted. Prerequisite to the landing zone identity design.A. Quintanilla
DD-13Two office leases and the data center lease expire inside the integration windowLowAcceptedLease decisions sequenced against migration waves. Renewing the data center for a year is cheaper than a migration compressed to meet a lease date.W. Pickering
DD-14Clearinghouse relationship differs from ACME's, with a distinct trading partner configuration for X12 transactionsMediumAcceptedConsolidation is a high-confidence vendor synergy, but sequencing is constrained — the target's clearinghouse cannot be dropped while a TSA still depends on it.H. Castellow

4. The Four That Shape the Program

4.1 DD-01 — the platform decision was made by the vendor, not by us

Support for the installed release ends inside the integration window. That removes the option of running the target's platform indefinitely and converts "absorb" from a preference into a constraint. It is a useful thing to be able to say in a disposition debate: the alternative to migrating is not "keep it," it is "run an unsupported claims platform for two million members," which is not an alternative.

4.2 DD-04 — the finding with the worst ratio of effort to consequence

Re-executing Business Associate Agreements is clerical work with catastrophic failure modes. Each one is a document, a signature and a tracking row. Miss one, and on Day 1 a vendor is handling protected health information for a covered entity it has no agreement with — which is a HIPAA exposure that no amount of good integration work offsets, discovered by an auditor rather than by you. This is why it is a Day 1 gate condition rather than a Day 100 task: the only defensible position is that every one of them is done before the entity changes.

4.3 DD-08 — the retention problem is a knowledge problem

A small number of long-tenured staff understand how the target's systems actually work, as distinct from how the documentation says they work. They are also the staff most able to leave, because their skills are marketable and their futures are least certain. The program's exposure is not headcount; it is that the TSA assumes those individuals are available to run services and transfer knowledge for twelve months.

The mitigation that programs get wrong here is treating knowledge transfer as something the TSA delivers automatically. It does not. A TSA obliges the seller to provide a service, not to make the buyer capable of providing it themselves. Unless transfer is specified as a deliverable with named receivers and acceptance criteria, twelve months of TSA can pass with the service running perfectly and the receiving organization no better able to run it on the last day than the first.

4.4 DD-10 — the finding that contradicts a default

The care management platform overlaps ACME's tooling, which in isolation reads as a vendor consolidation opportunity. But the investment thesis preserves care management precisely because the target's program outperforms — and the tool is part of how it performs. Terminating the subscription to book the saving would take value out of the thing the transaction was partly undertaken to acquire.

This row is here because it is the one where a synergy-driven default and the investment thesis point in opposite directions. The resolution belongs in the Application Disposition Matrix, argued explicitly, rather than being settled by whichever workstream acts first. Findings registers are full of rows like this, and they are the rows worth reading twice: a saving that is available is not automatically a saving that should be taken.
Part III — What Is Not Here

5. Register of Matters Not Assessable Before Closing

This register is shorter than the findings list and carries more risk. Each entry is a matter the program knows it does not know, with the date by which it will know.

Not assessableWhy notResolvesProgram posture in the meantime
Cross-entity member overlap and true duplicate rateRequires member-level data from both parties in one place — barred by the information barrierPost-close profiling⚠ Plan on the deal-model assumption while treating it as the program's largest single uncertainty. Contingency sized accordingly.
Actual condition of address, identifier and demographic fieldsSame barrier; only aggregate quality indicators were releasedPost-close profilingEMPI design assumes a wide clerical review band rather than a narrow one
Provider reimbursement detail sufficient to model rationalizationCompetitively sensitive; released only as directional variancePost-close contract reviewNetwork synergy timing modeled on renewal calendar, not on rate analysis
Employer-group-level renewal exposureNamed account detail not releasablePost-closeMember Services retention planning uses seasonality, not account lists
Production behavior of the core platform under combined volumeNo access to production environments before closingPost-close load analysisAbsorb decision assumes headroom; assumption logged and owned
The first row is the program's defining condition, and it deserves to be understood rather than glossed. ACME committed $1,200,000,000 to a transaction whose integration cost turns substantially on a number nobody was permitted to calculate. That is not a failure of diligence — diligence did everything the law allowed. It is a structural feature of acquiring a competitor: the information most relevant to the cost of combining is the information least available before you are allowed to combine. The correct response is not to pretend the number is known. It is to schedule its discovery first, budget for the range, and tell the Steering Committee plainly which decisions are resting on it.

6. Handoff to Risk Register and Disposition Matrices

FindingBecomesWhere it lives from here
DD-02 — enrollment data qualityRisk: identity resolution materially harder than modeledRisk Register; Data Migration & EMPI Strategy
DD-03 — change-of-control provisionsRisk: critical vendor exercises termination rightRisk Register; Vendor & Contract Disposition Matrix
DD-04 — BAA re-executionDay 1 gate conditionDay 1 Readiness Plan; Go/No-Go criteria
DD-05, DD-06 — infrastructure and interfacesDesign constraintsCloud Migration Strategy; Integration Architecture Plan
DD-08 — knowledge concentrationRisk: attrition before TSA exitRisk Register; Retention & Key Talent Plan
DD-01, DD-10 — platform and tooling dispositionDecisions requiring argumentApplication Disposition Matrix
DD-09, DD-14 — contract timingSynergy sequencing constraintsSynergy Realization Plan; TSA Schedule & Exit Plan
All Section 5 entriesAssumptions with owners and test datesIntegration Management Plan; Risk Register
What makes this a useful document rather than an archive is that every row leaves it. A diligence report that terminates in a filing cabinet has done half a job; the value is in the routing. By the time the Integration Management Plan is approved, none of these findings should exist only here — each should be a risk with an owner, a design constraint in a strategy, a row in a disposition matrix, or a gate condition on Day 1. Anything still sitting only in this document at that point is something nobody picked up.

Related artifacts: 1 — Integration Charter · 2 — Deal Summary & Investment Thesis · 5 — Clean Team Protocol · 20 — Application Disposition Matrix · 21 — Vendor & Contract Disposition Matrix · 28 — Risk Register