The slice of diligence
that gets missed.

Microsoft 365 configuration risk exists in every holding but rarely appears in operational due diligence or portfolio monitoring. InquilionGRC works with the investment committee directly, or alongside whoever has been appointed to carry out the overall technical due diligence.

You do not run the organisation. You own it, fund it or oversee it. Your concern is portfolio-wide governance visibility, standardised risk reporting across holdings and knowing what configuration risk you are inheriting or carrying.

Before acquisition, a transaction assurance assessment provides independent evidence of configuration risk, allowing material findings to inform deal terms, warranties or post-completion remediation plans.

After completion, that same assessment becomes the governance baseline for the portfolio company board, avoiding duplicated work and giving the investment committee a clear starting position from day one.

Across the portfolio, every company is assessed against the same governance benchmarks, producing comparable reporting for investment committee review regardless of company size, sector or Microsoft 365 licence tier.

One assessment serves the whole investment lifecycle.

How the engagement works.

The commercial structure

Who commissions
The PE house, fund or group. In a transaction, the investment committee. Post-completion, the portfolio company board.
Who receives the deliverables
The commissioning party. In a transaction, the investment committee receives all three reports. Post-completion, the Board Governance Report becomes the portfolio company board's governance baseline and the board delegates the Risk and Compliance Reports exactly as in a direct engagement.
Engagement basis
Per assessment. One target, one assessment, one engagement, one cost. No subscription, no retainer, no ongoing commitment.
Where it begins
Transaction assurance pre-acquisition, or a Board Review as a post-completion baseline.
Who delivers remediation
The portfolio company's IT function or MSP, scoped by the Compliance Report. InquilionGRC does not deliver remediation.
What carries forward
If the portfolio company later wants standing governance oversight, the assessment carries forward as the baseline. That is a separate decision, made by the portfolio company board, at a later date.

One benchmark.
Every holding.

Before acquisition.

Independent configuration evidence in time to inform deal terms, warranties and the 100-day plan.

After completion.

The same assessment becomes the portfolio board's governance baseline. Nothing is duplicated.

Across the portfolio.

Comparable RAG positions across all holdings in a single view, whatever their size, sector or licence tier.

For your investors.

Governance standards evidenced to co-investors and limited partners, not asserted to them.

How the findings read for an investment committee.

The underlying assessment is identical to a direct board engagement. The methodology is the same. The evidence is the same. The language shifts to deal terms, remediation cost exposure and portfolio comparability. The board-framed versions are on The Reports.

PE framing · Executive summary

The target organisation's Microsoft 365 environment is partially governed. Four of the fourteen assessed domains present material configuration risk that should be reflected in deal terms or post-completion remediation planning. Estimated remediation effort is moderate and addressable within a standard 100-day plan. The overall governance position is comparable to the lower quartile of assessed portfolio companies in this sector.

PE framing · Risk report entry

Domain
Identity and Access Management
Governance rating
Amber
Deal relevance
Configuration gap affects authentication controls for all user accounts. If unaddressed, represents ongoing operational risk to the portfolio company and potential warranty exposure.
Estimated remediation
Low complexity. Addressable within existing Microsoft 365 licence. No additional technology spend anticipated.
Portfolio comparability
Finding is consistent with the majority of assessed portfolio companies at point of acquisition. Typically resolved within the first remediation cycle.
Board action
The portfolio company board should commission remediation of the red-rated domains within the first 90 days post-completion. The Compliance Report provides sufficient scope for the portfolio company's IT function or MSP to execute without further assessment. Progress should be reported to the investment committee at the first post-acquisition board cycle.

The extracts use fictional findings for a fictional organisation. No real client data is shown.

Put it on the diligence list.

A conversation takes thirty minutes and commits you to nothing.

REQUEST INFO