Rodan · Resources · PE

Tech DD Question Bank

Expanded discovery questions for portfolio company management interviews. Use alongside the twelve-criteria Tech DD Readiness Score.

What is inside

  • Finance / ops questions on revenue recognition, board KPI production and EBITDA adjustments
  • Technology questions on critical systems, admin access, backups and licence posture
  • Data and privacy questions on registers, processors, incidents and Article 30 readiness
  • People questions on key-person risk and undocumented processes
  • Follow-ups you can ask when answers are vague or contradictory

Email unlocks the full printable bank. Free to access, we just ask for an email. Print or save as PDF straight from your browser.

How to use this bank

  • Ask open questions first. Score criteria after the interview, not during it.
  • Prefer evidence: screenshots, export samples, named owners, dated registers.
  • If two people give different answers on the same metric, mark data quality and source-of-truth criteria down.
  • Pair with the interactive Tech DD Readiness Score for a Red / Amber / Green band.

Finance / ops

Core

  • Which system is authoritative for revenue recognition this month?
  • How are board KPIs produced today (owner, tools, manual steps)?
  • Where do EBITDA adjustments live, and can a third party reproduce them?
  • What is the time from period close to a usable board pack?
  • Which metrics in the board pack have written definitions, and which are tribal knowledge?
  • How do you reconcile management accounts to the ledger used for statutory reporting?

Follow-ups

  • Show the last board pack and walk the lineage of revenue, margin and cash.
  • If the finance lead is away for a week, who can still produce the pack?
  • Which adjustments would a buyer challenge first, and where is the supporting schedule?
  • Are cohort, LTV or recurring-revenue metrics used in IC papers? If so, where do they come from?

Technology

Core

  • List systems that would stop trading or reporting if unavailable for 48 hours.
  • Who has production admin access, and how are leavers handled?
  • What is backed up, tested, and recoverable in under 24 hours?
  • Where do integrations live: APIs, warehouses, iPaaS, or spreadsheet bridges?
  • What material SaaS and open-source licences would a buyer need to review?
  • How are secrets, API keys and service accounts stored and rotated?

Follow-ups

  • When was the last restore test, and what failed?
  • Are there shared admin logins on finance, CRM or warehouse tools?
  • Which systems have no named business owner?
  • Is MFA enforced on every system that holds customer or financial data?

Data and privacy

Core

  • Do you maintain a current systems register and processor list?
  • Where does customer personal data sit, and which vendors process it?
  • Have you had a security or privacy incident in the last 24 months?
  • Are DPAs signed with every processor that touches personal data?
  • Does an Article 30 record of processing exist, and does it match the register?
  • Could you fulfil a data subject request within 30 days with evidence?

Follow-ups

  • Which transfers go outside the UK / EEA, and what mechanism is documented?
  • Is special category data processed? Where, and under what lawful basis?
  • Have marketing pixels and customer lists been classified before any AI use?
  • Who owns breach notification if something happens on a Friday night?

People

Core

  • If your reporting lead left tomorrow, what breaks in the first week?
  • Which processes exist only in one person's head or personal spreadsheet?
  • Who can grant or revoke access across the critical systems list?
  • Is there a documented handover for month-end and board pack production?
  • Which contractors or agencies hold privileged access?

Follow-ups

  • Ask two people separately how a key metric is defined. Compare answers.
  • Which roles are single points of failure for integrations or cloud admin?
  • What knowledge lives in Slack, WhatsApp or personal drives rather than systems?

Scoring reminder

Each Tech DD criterion scores 1 (critical gap) to 5 (investment-grade). Overall band = mean score. Red 1.0–2.4, Amber 2.5–3.4, Green 3.5–5.0. Mid-market portcos commonly land Amber on metric definitions and Red on access control and key-person until post-deal hygiene.