Warning signs include undefined ownership for inherited accounts, late discovery of privileged exceptions, missing offboarding plans for duplicate access, and integration timelines that assume security cleanup can happen later. Those symptoms show the transaction was assessed as a deal, not as a living identity environment.
Why shallow diligence shows up first in identity, not in integration charts
Shallow M&A diligence usually misses the parts of identity that do not fit neatly into an org chart: inherited accounts, shared admin paths, dormant entitlements, and exceptions that survived from the target’s old operating model. When those conditions are present, the deal may look tidy on paper while the real access environment is already carrying hidden operational and security debt.
A useful way to read the warning signs is to ask whether the diligence team understood the target’s identity estate as a living control plane. If it only counted directories, named major systems, or accepted “cleanup after close,” it likely underweighted the work needed to discover who can actually access what, under which approvals, and with what revocation path.
That is why inheritance is a stress test. The more the transaction depends on manual discovery after signing, the more likely it is that entitlement drift, privilege creep, and unknown ownership were never truly assessed. A shallow review often treats identity remediation as a post-merger integration task, but in practice it is part of the deal risk itself.
For the lifecycle dimension of this problem, NHIMG’s IAM and IGA Basics explains the governance functions that diligence should have tested up front, especially ownership, entitlement review, and joiner-mover-leaver discipline. When those controls are absent or only partially mapped, the transaction has not been evaluated at the level of access reality.
What the strongest warning signs usually look like
The clearest sign of shallow diligence is not just that something is missing, but that the missing item affects operational closure. Undefined ownership for inherited accounts means no one can approve, review, or revoke them with confidence. Late discovery of privileged exceptions usually means the review focused on nominal roles rather than the actual highest-risk access paths.
Another common signal is the discovery of duplicate access that has no offboarding plan. That usually indicates the diligence team did not trace how identities will be reconciled after legal close, system consolidation, or workforce overlap. If the team cannot explain how duplicate accounts will be removed without breaking business operations, then it has not modeled the access dependency properly.
Shallow diligence also shows up when integration plans assume security cleanup can happen after the transaction is complete. That assumption is often wrong because access sprawl, shared credentials, and stale entitlements can create immediate exposure once environments are connected or support teams are merged.
The broader identity picture is well captured in NHIMG’s Ultimate Guide to NHIs, Key Challenges and Risks, which highlights visibility gaps, over-privilege, and unmanaged credentials as recurring failure modes. In an acquisition, those same failure modes often surface because the diligence process reviewed the target as a business unit, not as an access environment with its own risks and dependencies.
A final clue is weak evidence quality. If diligence cannot produce a current entitlement inventory, a recent access review trail, or a clear remediation owner for exceptions, then the process likely relied on representation rather than verification. That is not enough when inherited access can survive the transaction boundary.
How to tell whether identity risk was really assessed, not just acknowledged
Identity diligence becomes credible when the team can answer three practical questions: who owns the accounts, which privileges are exceptional, and how access will be removed or re-attested after close. If any of those answers are vague, delegated to a future project, or dependent on a system conversion that has not been funded, the review is probably too shallow.
It also matters whether diligence distinguished ordinary user access from administrative and machine access. M&A assessments often count users but miss the accounts that matter most, including shared admin credentials, service accounts, and integration identities. Those are the accounts most likely to create hidden concentration risk during separation or integration.
NHIMG’s Joiner-Mover-Leaver Guide is useful here because it frames the lifecycle question correctly: merger activity is not only about provisioning new access, but also about revoking old access and reconciling inherited access paths. If a diligence plan has no credible leaver and transition model, it has probably not measured the true cleanup cost.
For practitioners, the question is not whether the target has identity controls in theory. It is whether those controls are still trustworthy under transaction pressure, when ownership shifts, systems overlap, and exception handling becomes the easiest place for risk to hide.
Risk and Threat Considerations
Shallow M&A diligence creates direct exposure because inherited access often becomes the easiest route into the combined environment. Unowned accounts, unresolved exceptions, and delayed cleanup can leave privileged paths active long enough for accidental misuse, insider abuse, or external compromise to persist across the deal boundary.
Failure mechanism: The review misses or deprioritizes access paths that do not sit in a standard control report, such as shared administrative accounts, dormant entitlements, and cross-environment exceptions. Once the environments are linked or operational teams are merged, those paths can survive longer than intended and become difficult to attribute or remove.
Impact: The organisation can inherit undiscovered privilege, lose confidence in access governance, and spend the post-close period reacting to identity debt instead of integrating securely. In the worst case, the deal expands the blast radius of a compromised or overprivileged account before remediation has even started.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Inherited accounts and cleanup gaps hinge on credential lifecycle and revocation. |
| AC-2 — Account Management | Shallow diligence leaves ownership, provisioning, and deprovisioning unresolved. | |
| AC-6 — Least Privilege | Late privilege exceptions indicate unreviewed excessive access in the target estate. | |
| Recommendation — Inventory and revoke credentials that survive the transaction boundary. Validate account owners and close orphaned access before integration. Reduce exceptional access to the minimum needed for transition. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | M&A diligence must identify and remove inherited and duplicate access paths. |
| CIS-5 — Account Management | Ownership gaps and offboarding failures are account-management failures during acquisition. | |
| Recommendation — Reconcile inherited accounts and remove unneeded access paths early. Assign owners for inherited accounts and enforce timely deprovisioning. | ||
Practitioner Guidance
What to verify: Before you trust a diligence workstream, require evidence of account ownership, privileged exception inventories, and a documented revocation path for duplicate or inherited access. If those three items do not exist, treat the identity work as incomplete regardless of how polished the integration plan looks.
Decision rule: If the transaction plan depends on “cleaning it up later,” assume the risk has already moved into the combined estate. The right sequence is to identify high-risk access, assign an owner, and define removal or recertification steps before relying on any broader cutover timetable.
Practitioner takeaway: Identity diligence is shallow whenever it can describe systems but cannot explain who controls access, which exceptions matter most, and how that access will be unwound without business disruption.
Related resources from NHI Mgmt Group
- What are the signs that identity governance is too shallow for modern environments?
- Why is it important to integrate identity and data governance?
- What are the signs that an AI governance programme is too shallow?
- What are the signs that an identity governance programme is too slow for current enterprise needs?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 10, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org