Skip to content
CorpDev Wiki
8 min read

Issue & Risk Management in M&A

A deal risk register tells the team what could change the investment decision and what must happen next. It links each real uncertainty and confirmed problem to its evidence, its effect on value, the contract response, the operating action, and the person who decides.

The register matters most when several functions see different parts of one problem. A customer dependency can appear in commercial diligence, a contract review, the revenue forecast, and the integration plan. One shared record stops four teams from treating it as four separate items, or from each assuming another team owns it.

Explore the illustration Select an element to go deeper

Label each entry by what it is

Different kinds of entries need different handling. A risk needs a response, an assumption needs evidence, and a decision needs an authority.

Type What it is Example
Risk Something that might happen, with a consequence if it does A customer may buy less after a product change
Issue A problem already observed that needs a decision or action A critical system has no supported migration path
Assumption Something the case relies on that still needs proof Existing infrastructure can support the acquired product
Dependency Something that must happen before another action or outcome Customer migration depends on product compatibility
Decision An approved choice, with its reasons and conditions Keep the target's platform while a replacement is assessed
Opportunity Possible upside that needs evidence and effort Sell through the buyer's distribution channel

If you use the RAID label, define its letters, because organizations use it in different ways. The labels matter less than consistently separating fact, uncertainty, action, and approval.

Write each entry as a business consequence

"IT risk" tells nobody what to do. "The target's billing platform cannot support our planned bundled offer without a replacement project" names a business consequence and points to who should investigate.

A useful entry includes:

  • A stable ID and a short statement of the condition and its consequence
  • Evidence source, date, population affected, and confidence or limits
  • The thesis assumption, model line, contract clause, or integration milestone it touches
  • Exposure before any response, existing controls, the proposed response, and the exposure left after it
  • A named owner, action deadline, and escalation route
  • Status, next decision, approving authority, and proof of completion
  • Links to related issues and dependencies, so nothing is handled twice

Keep exposure estimates separate from accounting conclusions and legal advice. Name the specialist who makes those judgments and the basis used in the investment case.

Rank items by what the next commitment needs

Weigh each item on strategic impact, financial exposure, timing, reversibility, and how well you can detect or control it. An uncertain issue that could break the thesis deserves early work even when nobody can put a precise probability on it.

A heat map helps with triage, but its scores are rankings, not measurements. "Likelihood 4" multiplied by "impact 5" is not an expected loss. When a number is useful, show the scenarios, the amounts, probabilities where you can defend them, and the dependencies.

Set priorities by the next decision. A question that must be answered before signing cannot move to after closing because other tasks are easier. Separate the evidence deadline from the fix deadline: you may need to understand a problem now even if the fix comes later.

Pick a response that fixes the actual problem

There are six responses, and more than one can apply:

  • Investigate: get the evidence to size it.
  • Avoid: change the deal so the exposure does not arise.
  • Reduce: act to lower the likelihood or the impact.
  • Transfer or allocate: shift it to the seller, an insurer, or another party.
  • Accept: take it on knowingly, with authority.
  • Monitor: watch a defined trigger.

"Discuss with seller" is a step toward a response, not a response.

For each action, ask what exposure it removes and what remains. A price cut can improve the economics without fixing an operating dependency. A contract clause can assign responsibility without guaranteeing full or timely recovery. Assess insurance or a seller commitment with the relevant specialists for what it actually covers.

Accepting a risk means naming the authority, the reason, the exposure left, and what will be monitored. A senior person having seen an item is different from an explicit, authorized decision to accept it.

Tie the register to the investment case

Finance reconciles each important item to the forecast and valuation, and labels where it sits: the base case, the downside case, the price, a separate contingency, or elsewhere. Never count a cost in the operating forecast and then deduct it again from value.

Integration owners accept the actions that need resources. Counsel ties agreed contract responses to the right documents. CorpDev makes sure the committee sees unresolved issues, significant changes, and exceptions to earlier approvals.

Treat opportunities with the same discipline. Record the baseline, action, owner, cost, timing, and evidence before counting one in the value case. Never offset a concrete downside with speculative upside just to keep the original recommendation.

Example: one issue from diligence to integration

This example is hypothetical.

During diligence, operations discovers that a carve-out depends on its parent's warehouse system. The seller's estimate assumes the business keeps access, but the separation plan has no defined end state.

The issue links to the standalone cost model and to Day 1 readiness. Four teams pick it up:

  • Operations scopes the service the business needs.
  • Technology evaluates replacement options.
  • Counsel develops the contract approach.
  • Finance models setup cost, running cost, and delay scenarios.

The investment decision might approve a defined transition service and a funded replacement program. The issue then stays open as an integration dependency until the receiving business confirms the replacement works and the transition service can end. Signing the service agreement changes the status. It does not prove the operating risk has gone.

Hunt for contradictions between workstream reports

Each workstream report is consistent on its own. The dangerous findings sit between reports. Commercial diligence assumes the top customers renew on current terms, while legal has found that their contracts allow termination on a change of control. The synergy case assumes customers move to the buyer's platform in year one, while technology reports that migration needs a rebuild. Each lead owns only their own report, so nobody reads them against each other, and the register never sees the conflict.

So make it someone's job. A contradiction hunt reads every workstream report against the others and lists the statements that cannot all be true. The task is narrow and easy to check, because every conflict must quote two sources that a person can open.

A hypothetical example:

Statement A Statement B Why both cannot hold Register
Commercial, p. 12: the top ten customers are assumed to renew on current terms Legal, p. 31: six of the top ten contracts allow termination on change of control The renewal assumption ignores a termination right Not logged
Synergy case: customers move to the buyer's platform within year one Technology, p. 8: migration needs a billing rebuild of about 18 months Revenue benefits start before migration can finish R-014, logged only as "IT risk"
Finance: standalone costs assume the parent's warehouse system at no charge Operations, p. 5: parent access ends at closing, and no transition service is drafted Standalone costs omit a replacement or a service fee I-007

Each conflict becomes a new entry or an update, with both workstream leads named until it is resolved. Some pairs will dissolve once a lead explains the context; record that explanation too. The check that matters is merging. Never combine two entries because they sound alike: a contract renewal and the product milestone the renewal depends on are linked issues with different owners. Closing an entry or accepting a risk still needs the owner's evidence and authority.

Escalate early and review on a rhythm

Use the working review for new evidence, overdue actions, changed exposure, and conflicts between functions. Escalate at once when an issue threatens the thesis, a critical date, an approval condition, or the risk tolerance leadership has approved. Never wait for a scheduled meeting to raise a finding that affects a commitment.

A leadership summary states the decision needed, the recommendation, the alternative, the cost of delay, and the owner. Keep significant dissent on record, and say whether it concerns facts, estimates, or appetite for risk.

Close entries only with evidence, then hand them over

Use statuses that separate the stages: being assessed, response approved, being implemented, being validated, residual risk accepted, and closed. An action marked complete needs evidence and, where appropriate, confirmation from the function affected.

Before closing the deal, reconcile the register to the final approval and documents. Hand open items to named operating owners with due dates, budgets, monitoring needs, and evidence. Confirm that they accept them, and review the items in the integration or business forum.

Keep the decision history after items are resolved. It shows which assumptions, control failures, and dependencies recur across deals. Deleting difficult entries to tidy the dashboard throws that lesson away.

Continue with due diligence, approval gates, and integration.