That’s why IT diligence should begin as early as possible in an M&A process and should serve as “an initial gatekeeping item alongside financial diligence,” says Anthony Casarona, partner and corporate attorney at Tucson, Ariz.-based commercial law firm Rusing Lopez Lizardi & Saffer. After all, he notes, IT-related risk can affect valuation, regulatory approval, customer retention and post-closing liability for the buyer.
In today’s M&A environment, IT consolidation can no longer be treated as a post-closing consideration. Banks must also ensure regulatory compliance throughout the process. Here are four questions that Casarona helps to answer about banking M&As and IT consolidation.
1. What contractual or structural protections should banks build into the merger agreement itself to account for unforeseen IT integration costs or failures down the road?
The agreement doesn’t need to solve the entire IT integration process, Casarona says, but it should appropriately allocate risks during IT diligence. He suggests several inclusions, such as certain covenants around cybersecurity controls and disclosures of cyber events, and clear indemnities where diligence uncovers a known IT or security problem.
READ MORE: What is minimum viable data governance in financial services?
Whether or not the IT integration is even feasible between the two organizations should also be a serious consideration. “Can the target’s technology environment actually be integrated into the buyer’s environment, and at what cost? If integration will not be possible or will be prohibitively expensive, the synergies that led to the deal may never materialize,” he adds.
2. How should banks handle the legal complexities of merging customer data systems, particularly given varying state-level data privacy laws and federal regulations?
Just because a bank has merged with another doesn’t give it an automatic pass to use all of the data in the newly added system, Casarona says. There must be a process in place to understand what data the recently merged bank has, why it was collected, related privacy disclosures, where it resides, who has access to it and how the data will be used going forward.
