Resilience During Mergers and Acquisitions: What Gets Overlooked

Due diligence in a merger or acquisition focuses heavily on financial performance, legal risk, and commercial positioning. Operational resilience typically receives comparatively limited attention during deal planning, despite the fact that combining two organisations creates precisely the conditions under which resilience tends to be most severely tested: new dependencies being created rapidly, established operational arrangements being disrupted, critical knowledge concentrated in individuals who may leave during the uncertainty of a transaction, and two control environments being merged in ways that may default toward the less rigorous of the two.
5 min read time

The pattern is consistent across organisations of different sizes and sectors. The resilience risks associated with M&A are predictable, well understood in retrospect, and persistently underweighted in due diligence and integration planning. This article covers where the risk concentrates, what due diligence should examine, and how to build resilience considerations genuinely into the deal process rather than treating them as post-completion housekeeping.

Why M&A Creates Distinctive Resilience Risk

The Conditions That Make Disruption More Likely

Several conditions that typically accompany M&A transactions create elevated operational risk and resilience risk simultaneously.

Organisational uncertainty affects staff behaviour in ways that increase operational risk. Key employees assess their personal situations and consider leaving. Management attention is divided between running the business and managing the transaction. Decision-making processes are disrupted as authority and accountability are renegotiated. These conditions are present in both the acquiring and target organisations, and they persist not just through deal completion but through the integration period that follows.

Integration activities create new technical dependencies and new process interfaces that have not been tested in a live environment. System integrations, data migrations, process harmonisations, and organisational restructurings all introduce new failure modes alongside the operational improvements they are intended to create. The period of greatest resilience risk is typically the active integration phase, not the pre-deal period.

External parties notice change. Customers, suppliers, and regulators all pay closer attention to organisations undergoing significant structural change. Regulators in particular may increase their supervisory intensity, require change-of-control approvals, or expect specific resilience and continuity assurances as a condition of approval.

Where the Risk Actually Concentrates

System Integration Risk

Combining technology systems is one of the most consistently underestimated challenges in M&A integration. Systems that appear straightforward to integrate from a commercial perspective are frequently deeply interconnected with other systems, dependent on specific data formats and interfaces, and reliant on institutional knowledge that is not documented anywhere but resides with specific individuals who may not survive the integration.

The resilience risk during system integration arises from the combination of new dependencies being introduced and existing dependencies being disrupted before the new ones are fully established. During a system migration, the organisation is simultaneously less resilient than before, because the existing system may be degraded or maintained in a transitional state, and not yet resilient in the target configuration, because the new system has not been fully tested or stabilised.

Continuity plans written before the integration began may not apply to the transitional state. Recovery time objectives may not have been reassessed against the integrated environment. And the testing that validated the original continuity arrangements has not been repeated for the new configuration.

Key Person Dependency

Critical operational knowledge in most organisations is less well documented than it should be, and this gap becomes acutely significant during M&A. The person who knows how a critical process works, how a key customer relationship is managed, or how a specific system is operated may assess their personal position during the uncertainty of a transaction and decide to leave.

When this knowledge leaves without being captured or transferred, the organisation that remains may find itself operating processes it does not fully understand, managing relationships without the context that made them effective, or dependent on systems whose operational characteristics are understood by nobody currently employed.

This risk is compounded in target organisations, where key individuals may have anticipated the transaction, had time to consider their options, and may already be less committed to the business than they were before the deal was announced.

Third-Party Contract and Supplier Risk

Third-party relationships that were stable under the previous ownership structure may change materially on a transaction. Change-of-control provisions in supplier contracts may give the supplier the right to terminate or renegotiate the agreement, potentially at a commercially disadvantageous moment for the acquiring entity. Service levels, pricing terms, and relationship continuity that were a function of the previous entity's commercial standing or negotiating position may not automatically transfer.

For regulated entities, change-of-control provisions in regulatory approvals and licences create additional complexity. Continuity of licensed status, permitted activities, and regulatory relationships requires specific attention that is often deferred until the deal is closer to completion, at which point options are more constrained.

Sub-contractor and infrastructure dependencies that have never been explicitly reviewed may become visible only when the target organisation's supply chain is examined in detail for the first time. Critical services that the target relies on through intermediaries it was unaware of create resilience risk that cannot be managed until it is identified.

Divergent Control Environments

Two organisations rarely have identical control environments, and the integration process tends to default toward the combined entity operating with the less rigorous of the two during the transition. The reason is resource and attention: the integration programme consumes management capacity that would otherwise be devoted to governance quality.

When a more rigorous control environment is being merged with a less rigorous one, the direction of travel during the transition may depend less on deliberate governance decisions and more on which controls are easiest to operate in the combined structure. Controls that require specific systems, specific roles, or specific processes that no longer exist in their original form after integration may lapse without explicit replacement.

What Resilience Due Diligence Should Cover

Service and Dependency Mapping of the Target

Due diligence on resilience should include a structured assessment of the target's important business services, the dependencies that support them, and the degree to which those dependencies are documented, tested, and genuinely understood by the target's management.

Ask for the target's important business service inventory if it has one. Ask for continuity plans and when they were last tested. Ask for the supplier dependency mapping and what change-of-control provisions exist in critical contracts. Ask what would happen to each critical service if the key individual who manages it left today.

The answers will frequently reveal dependencies that the target's management either cannot specify or specifies with less confidence than expected. These gaps are themselves a due diligence finding.

Contract Review for Change-of-Control Provisions

A systematic review of critical third-party contracts for change-of-control provisions should be among the earlier rather than later due diligence activities. Provisions that give critical suppliers termination rights or renegotiation rights on change of control need to be identified before completion so that their implications can be assessed and, where necessary, addressed through negotiation or contingency planning.

The most critical contracts are those supporting services without readily available alternatives: critical technology infrastructure, specialist service providers with long replacement lead times, and operational arrangements where the relationship itself is a significant part of the service value.

Technology Integration Risk Assessment

An assessment of the technology integration risk should be conducted before finalising the integration plan, not as a post-completion discovery exercise. This means understanding the target's technology landscape in sufficient detail to identify which systems will require integration, what the realistic timeline and risk profile of each integration is, and where the transitional state creates resilience vulnerability.

For regulated entities acquiring or being acquired by other regulated entities, specific resilience assurances may be required as part of regulatory change-of-control approval. Understanding what those requirements are before the transaction is announced avoids the situation of discovering late in the process that regulatory approval is conditional on capabilities that were not planned for.

Building Resilience Into the Deal Process

Early Resilience Assessment, Not Post-Completion Review

The most effective organisations treat resilience as a due diligence workstream from the outset of the deal process, not as an integration activity that follows completion. This means the resilience risk profile of the target is understood before the deal economics are agreed, so that the cost and complexity of managing those risks is reflected in the deal terms rather than discovered after commitment.

Where significant resilience risks are identified during due diligence, they should inform deal structure. A target with significant key-person dependency might warrant retention arrangements as a deal condition. A target with change-of-control provisions in critical contracts might warrant pre-completion engagement with the relevant suppliers. A target whose technology landscape presents integration risk might warrant a longer integration timeline built into the business case.

An Integration Risk Register

The integration programme should have its own risk register tracking resilience risks through the integration period, distinct from the enterprise risk register of the ongoing business. This register should capture the specific risks created by the integration activities themselves, the residual risks where integration timelines mean the transitional state persists longer than preferred, and the third-party and contract risks that require active management during the period.

This register should be reviewed by both the risk function and the resilience function, and should be reported to the executive committee or board at intervals appropriate to the pace and complexity of the integration.

Knowledge Capture as an Integration Priority

Identifying the individuals who hold critical operational knowledge in the target organisation, and implementing structured knowledge capture and transfer programmes before or immediately after completion, should be an explicit integration priority, not something left to happen organically. The window for capturing knowledge that currently resides with individuals who may leave closes quickly after completion.

References and Further Reading

Next Steps

The deal stacked up on paper. But did anyone test whether the combined business stays standing?

Join 150+ organisations who’ve already made calQrisk their competitive edge.