Sep 25 2026
Management

4 Questions about IT Consolidation During a Bank M&A

Mergers and acquisitions are an ever-present reality in the finance sector. Treating them solely as a business venture without considering IT systems is a major mistake.

In a merger or acquisition, it’s more than just the business that’s being combined; consolidating IT systems must also be considered as part of an M&A strategy. Without this key piece, inefficiencies, higher costs and wasted resources can mar an otherwise thoughtful move. 

After a deal closes, financial institutions should avoid a scramble to figure out their now shared systems, according to Scott Hiemstra, CDW’s director of strategy for financial services, and Brian Hilgenfeld, CDW’s vice president of financial services. 

“They rush to consolidate systems, align security standards and migrate core business applications. This reactive approach can lead to mistakes, delays and missed opportunities for synergy,” they write in a recent blog. “For example, consolidating Active Directory too quickly or too slowly can disrupt access to business-critical applications. Poor planning can also create compliance gaps or additional layers of technical debt.”

Click the banner below to learn more about setting up your financial M&A for success. 

 

That’s why IT diligence should begin as early as possible in an M&A process and should serve as “an initial gatekeeping item alongside financial diligence,” says Anthony Casarona, partner and corporate attorney at Tucson, Ariz.-based commercial law firm Rusing Lopez Lizardi & Saffer. After all, he notes, IT-related risk can affect valuation, regulatory approval, customer retention and post-closing liability for the buyer. 

In today’s M&A environment, IT consolidation can no longer be treated as a post-closing consideration. Banks must also ensure regulatory compliance throughout the process. Here are four questions that Casarona helps to answer about banking M&As and IT consolidation. 

1. What contractual or structural protections should banks build into the merger agreement itself to account for unforeseen IT integration costs or failures down the road? 

The agreement doesn’t need to solve the entire IT integration process, Casarona says, but it should appropriately allocate risks during IT diligence. He suggests several inclusions, such as certain covenants around cybersecurity controls and disclosures of cyber events, and clear indemnities where diligence uncovers a known IT or security problem. 

READ MORE: What is minimum viable data governance in financial services?

Whether or not the IT integration is even feasible between the two organizations should also be a serious consideration. “Can the target’s technology environment actually be integrated into the buyer’s environment, and at what cost? If integration will not be possible or will be prohibitively expensive, the synergies that led to the deal may never materialize,” he adds. 

2. How should banks handle the legal complexities of merging customer data systems, particularly given varying state-level data privacy laws and federal regulations? 

Just because a bank has merged with another doesn’t give it an automatic pass to use all of the data in the newly added system, Casarona says. There must be a process in place to understand what data the recently merged bank has, why it was collected, related privacy disclosures, where it resides, who has access to it and how the data will be used going forward.

Applicable state laws around consumer data privacy and security add another layer to federal oversight, such as the Gramm-Leach-Bliley Act and the Privacy of Consumer Financial Information regulation (Regulation P), which means banks in an M&A process can no longer assume a federal compliance review is enough. 

“Integration failure isn't just a technical problem,” he adds. “It can lead to regulatory criticism, remediation requirements, enforcement action, civil monetary penalties, increased regulatory scrutiny and potentially restrictions on future expansion or M&A.” 

3. What pitfalls arise from existing technology contracts during an M&A, and how should banks navigate renegotiation or termination? 

Casarona calls existing technology contracts “one of the biggest hidden costs in a bank deal.” He recommends diligence that includes thorough reviews and clear visibility into all contracts, whether they’re Software as a Service agreements or core banking systems licenses. Third-party risk management is an integral part of this consideration. 

DISCOVER: How to balance access and security in financial services.

Redundancy should also be addressed during this process. “If the buyer and the target each have a contract with a particular vendor or service provider, there may be an opportunity to consolidate and/or leverage the larger post-closing entity for a better deal with the vendor/service provider,” he says. 

4. How does the pace of IT consolidation affect regulatory approval timelines, and are there cases where regulators have conditioned or delayed approval based on IT integration concerns? 

“Yes. Regulators are focused on whether the transaction will produce a combined entity capable of operating safely, soundly and compliantly,” Casarona says. “If a deal presents unusually complicated technology conversions, substantial cybersecurity deficiencies, unresolved examination findings, weak third-party controls or questions about operational resilience, regulators can seek additional information or remediation, which can affect timing.” 

Just because each bank is compliant today doesn’t mean a regulatory review will ease scrutiny over future concerns as a combined entity, especially with risks to customers on the line. 

Avoid Taking Shortcuts During a Bank M&A 

Because of high-profile data security events and the growing use of new technologies in the space, IT and cybersecurity diligence have shifted from compliance-focused to a key valuation driver, Casarona says. That’s why speeding through the process is highly discouraged. 

EXPLORE: Why data protection is so important to financial services.

“From a legal and operational risk perspective, an overly aggressive core conversion can create customer access problems, erroneous balances, failed payments, privacy issues and regulatory exposure,” Casarona says. “In order to get the full anticipated deal value and synergistic benefits, the buyer should be focused not on how quickly it can integrate the target, but how quickly it can integrate the target without creating a level of operational, cybersecurity, privacy or customer risk that changes the regulatory and economic assumptions underlying the deal.”

Organic Media/Getty Images
Close

New Research from CDW Explores AI and Cybersecurity

Learn how AI is helping IT teams manage risk and improve resilience.