
How to run an AI audit on a newly acquired business
You have just closed a deal. The data room told you about revenue, margins and customer concentration. It almost certainly told you very little about the target's actual AI and data capability - or the technical debt sitting underneath it. That gap is now your problem.
Most PE operating partners approach post-acquisition technology review the same way they approach IT infrastructure: tick the boxes, note the risks, move on. That approach made sense when software was a support function. It does not make sense when AI capability is increasingly the difference between a business that can scale and one that cannot. Miss this and you are not just leaving value on the table - you are inheriting liabilities you have not priced.
This article gives you a practical framework for running an AI audit on a newly acquired business: what to assess, in what order, and how to distinguish genuine capability from surface-level tooling that looks good in a board deck but delivers nothing at exit.
Why the standard tech due diligence misses the point
Traditional technology due diligence asks whether the systems work and whether they are secure. Those are necessary questions. They are not sufficient.
The question that matters for value creation is different: does this business have the data and AI infrastructure to support the operating thesis you have already committed to? If your thesis depends on pricing optimisation, customer retention improvement or operational efficiency gains, then you need to know whether the data exists to make those things possible - and whether the organisation has any capability to act on it.
Consider a hypothetical: you acquire a £600m B2B distribution business. The investment thesis centres on margin improvement through better demand forecasting. The target has a modern ERP, clean-looking dashboards and a data analyst team of three. On the surface, it looks capable. But when you dig in, the forecasting model is a spreadsheet rebuilt manually each month by one analyst who is already considering leaving. The ERP data is eighteen months out of date in two of the five product categories that drive 60% of revenue. The thesis is at risk before the ink is dry.
Standard due diligence would not have caught that. An AI audit would.
What an AI audit actually covers
An AI audit in the post-acquisition context is not a vendor assessment or a security review. It is a structured evaluation of four things:
1. Data infrastructure and quality
What data does the business actually hold, and is it clean, structured and accessible? This means looking at source systems, data pipelines, storage architecture and - critically - how data flows between commercial, operational and financial functions. A business that cannot join its sales data to its cost data at order level is not AI-ready, regardless of what tools it uses.
2. Existing AI and analytics capability
What tools, models and processes are in place? Who built them, who maintains them and what decisions do they actually inform? Many businesses have AI in name only - a PowerBI dashboard someone calls "AI-driven" because it refreshes automatically. Separate what exists from what functions. A useful test: ask the leadership team to name a decision in the last quarter that changed because of a model output. If they cannot, capability is theoretical.
3. Team and organisational capability
AI tools without the people to run them are shelfware. Assess the data and analytics headcount: their seniority, their commercial orientation and whether they sit close enough to the business to have influence. A data team buried in IT and managed by the CFO's office is structurally disconnected from value creation. Also assess dependency risk - if one person holds the institutional knowledge, that is a single point of failure.
4. Governance and risk
This includes data privacy compliance, model documentation, AI usage policies and any regulatory exposure. In regulated sectors - financial services, healthcare, food and beverage - this matters more. But even in unregulated businesses, the absence of any AI governance structure tells you something about how seriously leadership treats data as an asset.
How to structure the audit: a four-week sprint
You do not have three months. You need a working view within the first thirty to sixty days post-close. The following structure delivers that.
Week one: System and data mapping
Pull the architecture documentation. If it does not exist - and it often does not - have someone build a basic map of source systems, data flows and reporting outputs. Identify where data lives, who owns it and what the handoffs look like.
Week two: Stakeholder interviews
Speak to the CFO, CTO or IT lead, the commercial director and whoever runs data or analytics. Ask the same questions to each: what data do you use to make decisions, what would you do if you had better information, and what data do you not trust? The gaps between answers reveal a great deal.
Week three: Capability and tool assessment
Audit the actual tools in use against what they are being used for. Score each against three criteria: does it work, does anyone use it, and does it influence decisions? Tools that score poorly on the last criterion are not assets - they are costs.
Week four: Findings and prioritisation
Produce a prioritised output with three tiers: foundational fixes needed before any AI investment makes sense, quick wins that could show value within ninety days, and longer-term capability build that should inform the hundred-day plan.
Turning audit findings into a value creation lever
The audit is not the end point. It is the input to a decision: what do we build, what do we buy and what do we fix?
A common mistake is treating the audit output as a technology roadmap. It is not. It is a commercial roadmap that happens to involve technology. Every finding should map to a value creation hypothesis from the investment thesis. Demand forecasting accuracy maps to working capital improvement. Customer churn modelling maps to net revenue retention. Pricing analytics maps to gross margin. If a capability does not connect to a thesis lever, deprioritise it.
The businesses that create the most value from AI post-acquisition are not necessarily those with the best technology at entry. They are the ones whose operating partners arrive with a clear picture of the gap between current capability and what the thesis requires - and close that gap methodically.
For larger portfolio businesses, deploying an orchestrated agentic system through a framework like Eclipse can accelerate the move from data foundation to autonomous decision-support. But that only makes sense once the data infrastructure is sound. Build in the right order.
The cost of skipping this step
If you do not run an AI audit in the first sixty days, you will run it eventually - probably when the hundred-day plan is underperforming and you are trying to diagnose why. By that point, you have lost the window to reshape the operating structure, the technology contracts are locked in and the team you needed has moved on.
The audit also matters for exit. Buyers at your exit - whether strategic or financial - will ask about data and AI capability with more rigour than they did three years ago. A business that can demonstrate model-driven decisions, clean data infrastructure and measurable AI-driven improvements in margin or retention commands a better multiple. That story starts now, not in year four.
Rodan offers a structured AI audit as a paid diagnostic engagement, designed specifically for post-acquisition situations. It delivers a prioritised findings report and capability roadmap within four weeks. If you have closed a deal in the last ninety days and have not yet assessed the data and AI position of the business, that is the right starting point.



