The method
The technology diligence method, published in full.
PRISM™ is how we score technology inside a transaction. This page publishes the method itself: the five dimensions and what each one asks, how a score is interpreted, how a finding is turned into a deal action, and what a report will and will not claim. It is the same method we use on a live engagement. You can test it against your own asset before you speak to anyone.
Why this is public
We publish the method so a buyer can check how each score was produced.
Technology diligence is usually sold as a scored assessment. The sponsor receives a number, a color, and a list of observations, and is asked to accept that something consistent produced them. The method behind the number is held back as proprietary. That keeps the buyer from seeing the one part of the work it could test.
Our method is on this page. The five dimensions below are the five we score on every engagement, and the bands are the bands we report against. Every material finding is assigned to one of the four classifications. Anyone who wants to dispute the method, including a competing provider, now has enough of it to do so. We publish it so that a sponsor can judge the method and the work directly.
Publishing the method does not make the assessment mechanical. The questions are fixed, but the thesis they are asked against changes from deal to deal. A platform that is sound under a hold-and-optimize case can be a liability under a buy-and-build case. The same evidence produces a different score in each.
The five dimensions
Five questions the deal depends on.
Each dimension is a business question first and a technical one second. Each has a role, which describes what a weak score in that dimension does to the transaction. The five roles differ, so the dimensions are not interchangeable and are not averaged as though they were.
Portfolio Fit
GateCan the technology support the investment thesis?
- A strong score
- Technology is tied to the thesis with a named owner, and the team has already demonstrated the capacity the plan assumes. The deal can be underwritten as written.
- A weak score
- Nobody owns the technology roadmap against the thesis. The model assumes capability the platform has not demonstrated.
Risk Quantification
PriceWhat technology risks create financial exposure?
- A strong score
- Material risks are documented and, where they matter, priced. Few surprises should surface after close.
- A weak score
- Risk is anecdotal and unquantified. Security, compliance, or key-person exposure can reset terms that were agreed without it.
Infrastructure & Engineering
FoundationCan the platform scale with the plan?
- A strong score
- The platform releases changes safely and scales without a rebuild. Infrastructure supports growth rather than limiting it.
- A weak score
- Delivery is manual and the architecture limits growth. Reaching the model's volume requires CapEx and a rebuild, not tuning.
Strategic Data Assets
UpsideCan the data create value?
- A strong score
- Data is trustworthy and is being used to create value, with AI past the pilot stage. This dimension holds real upside.
- A weak score
- Data is unreliable or unused and AI is ungoverned. The upside case depends on data and governance that are not in place yet.
Management & Execution
MultiplierCan this team deliver the thesis?
- A strong score
- The team ships on a predictable cadence, and the technology leader can present the value story to a board.
- A weak score
- Delivery is ad hoc, and leadership cannot yet own the value story. That execution risk adds to every other finding.
Why I and S are scored apart
I and S measure different kinds of money. A failing I score means CapEx: servers to buy, engineers to hire, systems to rebuild. A strong S score means enterprise value that data and AI can still capture. They also call for different operators. Combining them into one technology dimension would hide both the cost and the upside.
How it is scored
Every dimension is scored 0 to 100.
All five dimensions use one scale, and one composite is calculated across them, weighted to the thesis. The composite places the asset in a band. The band describes what the technology means for the deal. It is not a grade on the engineering team.
Where red, amber and green come from
The color on a dimension is derived from the same 0-100 score rather than kept as a second scale: green from 60, amber from 40 to 59, red below 40. There is one underlying number and one way of presenting it, so two engagements can be compared directly.
How it is weighted
The weighting is agreed before the work starts.
The five dimensions are fixed, and their weights in the composite change from deal to deal. We set the weighting with the deal team at scoping, in the first days of the engagement, before any evidence is collected.
Deal type is the first thing that changes it. A buy-and-build weights integration architecture and whether the data model can be merged. A carve-out weights separation cost, standalone running cost, and how long the transition services agreement really runs. A take-private weights the cost structure and what breaks under cost pressure. Growth equity weights whether the competitive advantage is real and whether unit economics hold at scale. One weighting applied across all four would overstate some deals and mislead on others.
Hold strategy is the second. The same platform is weighted differently when the plan is to grow it organically over five years than when the plan is to add six businesses to it within eighteen months. Different questions decide those two plans.
The weighting is written down and discussed with the client before it is applied. A sponsor who disagrees with an emphasis can say so at the start, when changing it costs nothing. Otherwise the sponsor might learn at the readout that the score depended on a judgment they would not have made.
This page publishes no weight table, because the report template does not include one either. A fixed set of percentages would be right for one type of deal and wrong for the rest. Publishing it would also make the composite look more objective than a weighted score can be. The rest of the method is fixed: the same five dimensions, the same 0 to 100 scale, the same five bands, and a weighting stated in writing at the start of every engagement.
Weighting cannot offset a gate. A deal with a high composite and one unresolved GATE finding still does not close on the terms agreed. For that reason, the classification a finding receives matters more than the arithmetic.
Inside the dimensions
Three dimensions are built from four components each.
All five dimensions are scored on the same 0 to 100 scale. Three of them are built from four named components rather than one judgment: R across four areas of exposure, I across four engineering sub-dimensions, and S across four gates. P and M are each scored as a single judgment against the dimension question, because the evidence there does not divide into stable parts. Instead, each of those two produces a named artifact in the report, which gives a deal team something specific to test.
Thesis Assumptions Tested
One judgment, stated assumption by assumption
- Whether the business can operate standalone, and what standalone costs
- Whether the margin and growth plan is achievable on the stack as it stands
- Whether certifications and customer contracts transfer cleanly
- Whether the plan can be executed in-house or assumes capability that has to be hired
- Whether the upside in the model is underwritable in the base case
Every assumption the thesis depends on is written out and given a verdict against the evidence: supported, partly supported, not supported, or dependent on how the deal is structured. Any verdict short of supported goes into the Financial Exposure Summary rather than remaining a caveat in the narrative.
Risk Exposure Score
0 to 100 across four areas of exposure
- Security posture and what is still open from the last independent test
- Intellectual property ownership and open-source licensing
- Compliance and regulatory exposure
- Business continuity, and whether recovery has been tested rather than documented
GATE and PRICE findings occur most often in this dimension, so each area is stated as a cost rather than a rating. The cost covers what closing the gap takes, over what period, and whether it affects price, escrow, or an indemnity.
Engineering Health Score
0 to 100 across four sub-dimensions
- Architecture & Scalability
- Cloud/Infrastructure & COGS Reality
- SDLC & Engineering Practice
- Technical Debt
The Tech Debt Cost Calculator prices the Technical Debt sub-dimension on its own, returning an annual cost and a five-year cost of inaction.
AI Readiness Index
0 to 100 across four gates
- Data Trust
- Model & Agent Governance
- Operational Integration
- Value Realization
The four gates summarize the Enterprise AI Control Plane's pillars at diligence level. A target that has been through this assessment uses the same vocabulary in the hold period.
Key-Person Risk Register
One judgment, supported by the register and a feasibility test
- Leadership depth, and the bench behind the technology leader
- Key-person concentration: who holds knowledge nobody else holds
- Delivery record: what was committed against what shipped
- Hiring and ramp capacity at the rate the plan assumes
- Engineering attrition, particularly senior and tenured
- Reliance on contractors and offshore capacity, and the continuity risk that creates
The register names the people the plan depends on. Where that exposure affects terms, it is priced through retention or escrow. The 100-day plan is then tested against what the organization can absorb. That is a separate question from whether the plan is sensible.
How a finding becomes a decision
Four classifications, and every finding is assigned one.
Every material finding is given a classification, because an unclassified observation gives the deal team nothing to act on. Each finding also has a remediation window and a confidence level. The deal team receives it as a decision with an owner attached.
Stops the deal until it is resolved or contractually protected before close.
Validated interim controls, a funded remediation plan, an accountable owner, and the escrow or holdback that protects the buyer until the work is done.
Changes the offer rather than the plan.
A costed remediation, the mechanism used to recover the cost (purchase price, escrow, or indemnity), and the evidence behind the number.
Changes what the deal is supposed to achieve, and by when.
The part of the underwritten plan that is affected, and what has to be true, in what order, for that plan to hold.
Quantified upside that becomes part of the 100-day plan.
The value modeled and the validation step that has to be completed first. Upside stays out of the base case until a pilot proves it.
Evidence discipline
Every number is given a confidence level.
Confidence describes how a number was derived, not how serious the finding is. It separates a figure a sponsor can put into an offer from a figure that needs a named validation step first.
High confidence
Grounded in direct invoices, current vendor pricing, unit counts, contractual terms, or operating data management has validated.
Medium confidence
Usable for initial underwriting, with the report naming the specific validation step required before the figure is used in final price, escrow, or the capital plan.
Low confidence
A directional scenario, flagged as one, that should not be used in base underwriting.
What the report says it did not do
Every report states what was reviewed, what was not independently validated, and which specialist workstreams sit outside a technology scope (environmental and legal, asset-condition engineering, commercial diligence, and financial-statement diligence). The report names the confirmatory work that belongs to other providers, so none of it is left implied.
What the assessment produces
The assessment produces six outputs.
The report is the main document. These are the parts of it that a deal team and an operating team use.
PRISM Score
A 0-100 composite over the five dimensions, weighted to the thesis and reported with the band it falls in.
Engineering Health Score
The I dimension, 0 to 100 across its four sub-dimensions.
AI Readiness Index
The S dimension, 0 to 100 across its four gates.
Financial Exposure Summary
CapEx requirement, EBITDA drag, and the three-year cost of inaction.
100-Day Plan input
Remediation priorities and the quick wins, sequenced for the first hundred days.
CLEAR™ handoff
The diligence findings are used as the post-close operating plan.
How the work runs
The assessment runs three to four weeks and ends with a readout.
A PRISM review is document review, interviews, a written deliverable, and a readout with the people who have to act on it. The deliverable is board-ready: two to three pages of executive summary plus a 100-day technology roadmap the operating team can start on day one.
- 01
Document review
Architecture, roadmap, incident history, contracts, security posture, spend, and whatever the data room already holds.
- 02
Stakeholder interviews
CEO, CTO or VP Engineering, CISO, product lead, and one or two key engineers. The engineers usually know where the architecture diagram no longer matches the running system.
- 03
Written deliverable
Findings classified, priced, dated, and given a confidence level, consolidated into one register.
- 04
Readout
A working session with the deal team and, where it helps, management. Questions get answered live rather than in a follow-up memo.
What a review covers
- Product and roadmap
- Engineering execution and velocity
- Architecture and platform
- AI and data maturity
- Security and trust
- Cloud, tooling, and cost
- Team and operating rhythm
- Board and executive communication
After close
After close, the findings are the input to the 100-day plan.
PRISM is the assessment method, and CLEAR™ is the operating method used after close. Each PRISM dimension maps to a CLEAR phase, so the numbers underwritten before close are the numbers the hold is measured against.
| PRISM dimension | CLEAR™ phase | Outcome in the hold |
|---|---|---|
| P: Portfolio Fit | Clarify | Thesis alignment confirmed |
| R: Risk Quantification | Realize | Priced risk converted to verified exit value |
| I: Infrastructure & Engineering | Leverage + Execute | Platform scaled |
| S: Strategic Data Assets | Accelerate | AI deployed, data monetized |
| M: Management & Execution | Execute | Team deployed, 100-day plan runs |
Related material
Three other ways to check the work.
The framework entry
PRISM in the method library, alongside the other frameworks the practice uses.
The deliverable
What a report reads like: the fifteen sections, a worked finding in each classification, and the evidence discipline applied.
The self-assessment
The same five dimensions scored on your own asset in about ten minutes, returning one of the five bands.
Frequently asked questions
Frequently asked questions.
- Does publishing the method let someone else run it?
They can ask the questions, and the questions are the easy part. The value of an assessment depends on the judgment applied to the answers. That means knowing which finding affects price and which one is noise, what a remediation costs, and how much a management team can take on alongside its day job. That judgment comes from having run the systems, not from having the list.
- If the method is fixed, is the assessment just a checklist?
The dimensions are fixed and the weighting is not. The same evidence scores differently under a buy-and-build thesis than under a hold-and-optimize one, because the question is always what this technology does to this deal. A checklist produces a color. This method produces a classification, a remediation window, and a number someone can put in an offer.
- How is this different from a code review or a large-firm technology diligence?
A code review tells you the code is messy. A thorough process review gives you a long list of observations. Neither tells you what a finding means for the deal. PRISM classifies every finding as GATE, PRICE, THESIS, or LEVER and ties it to price, terms, or the 100-day plan. It is written by an operator who has held P&L responsibility, for a sponsor who has to make an offer.
- How long does a live engagement take?
A full review runs three to four weeks. Inside a live process, core diligence is typically seven to ten business days after a substantially complete data room and timely access to management. Multi-site coverage, passive OT asset discovery, specialist certification review, and detailed value-creation modeling are scoped to the thesis, the structure, and the timeline.
- Can I score my own company before talking to anyone?
Yes. The PRISM Technology Readiness Scorecard runs the same five dimensions in about ten minutes and returns the same five bands. It gives a directional result rather than a diligence report. It shows where to look, but not what the findings cost.
- What sits outside the scope?
Environmental and legal, asset-condition engineering, commercial diligence, and financial-statement diligence. Each report names them so a sponsor can see which confirmatory work still belongs to another provider, and who owns it.
Bring us a deal and we will run this against it.
Tell us the situation in a few lines: the asset, the thesis, and the date the offer has to be defensible by. If a PRISM assessment fits, you have already read the method it will follow. Sujit reads every note.