Document-only due diligence misses the live entitlement state, so orphaned accounts, overprovisioned access, and policy drift can move into the combined organisation unchecked. That failure is not just incomplete visibility. It means leaders approve inherited identity risk without verifying who can actually do what, where, and why across the target environment.
Why the Problem Is Live Entitlement State, Not the Paper Trail
In M&A, a due diligence process that only reviews exported reports, org charts, or screenshots can say a target looks controlled while the real access model has already drifted. The issue is not just missing detail, it is that the acquired environment may contain dormant accounts, inherited admin rights, shared credentials, and stale exceptions that never appear in static evidence.
A live entitlement view answers who can reach production, which accounts are still active, whether privileged access is justified, and whether old access paths still work after reorganisations or platform changes. A document can describe governance intent, but it cannot prove present control state across directories, SaaS, endpoints, cloud consoles, or third-party connections.
The practical distinction is that documents support review, while enforced access supports verification. In acquisition work, those are not interchangeable, because the combined organisation inherits whatever the target can still do at the moment the deal closes, not what the target says it disabled last quarter.
What Breaks When Review Is Detached from Enforcement
Once due diligence becomes a paper exercise, the buyer tends to inherit a false sense of closure. Orphaned accounts can survive employee exits, cross-functional access can remain open after role changes, and exceptions approved for a transaction or integration project can become permanent by accident.
The biggest failure mode is policy drift between approved identity governance and actual enforcement. If access reviews are based on extracts instead of authoritative controls, the organisation can miss the difference between “removed in the spreadsheet” and “removed in the directory,” or between “terminated in HR” and “disabled everywhere that matters.”
That gap also weakens post-close remediation. If teams do not verify enforced access, they cannot reliably prioritise what to revoke first, which entitlements need recertification, or where emergency break-glass access has quietly become standing privilege. For identity governance teams, the question is not whether a control existed on paper, but whether it still constrained real access at the moment of transfer.
Why This Matters for Integration, Control Ownership, and Approval Decisions
In an acquisition, the most dangerous assumption is that ownership transfers cleanly with the asset. Access often spans HR systems, identity providers, cloud platforms, business applications, contractors, and managed service providers, so no single document set can confirm the full blast radius of inherited permissions.
Document-only diligence also obscures accountability. If the buyer cannot show enforced controls, it is difficult to prove that privileged access, dormant accounts, and third-party connections were actually removed or bounded before operational integration. That creates a governance problem as much as a technical one, because leaders end up approving risk they have not truly bounded.
For complex environments, the right baseline is evidence of control operation, not just control design. A strong M&A security review should therefore connect access inventory, entitlement validation, and revocation evidence before close, then re-test after Day 1 and after every major integration step.
Risk and Threat Considerations
When due diligence relies on documents instead of enforced access, the buyer can inherit accounts and privileges that were never truly retired. That creates immediate exposure to unauthorized access, privilege escalation, and lateral movement inside the combined environment, especially where legacy access paths still work after the organisational changes are announced.
Failure mechanism: Static evidence overstates control maturity, while live access remains intact across directories, SaaS platforms, cloud consoles, shared accounts, and partner connections. Attackers or insiders only need one surviving path to turn an acquisition transition into a persistence opportunity.
Impact: The combined organisation may overpay for unverified governance, absorb hidden access risk into its production estate, and discover post-close that remediation is slower and more disruptive than the deal team assumed. In the worst case, inherited access becomes a ready-made foothold for compromise or fraud.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | M&A access drift centers on account creation, disablement, and orphaned accounts. |
| AC-6 — Least Privilege | Overprovisioned inherited access is a core failure mode in post-close environments. | |
| IA-5 — Authenticator Management | Documented controls can miss still-valid credentials, keys, and tokens that preserve access. | |
| Recommendation — Validate account lifecycle controls and revoke inactive or inherited accounts before integration. Reduce inherited entitlements to the minimum necessary access after close. Rotate or revoke surviving authenticators and validate that old credentials no longer work. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | The issue is whether access is actually enforced in the live environment, not only documented. |
| A.8.2 — Privileged access rights | Inherited admin rights and standing privilege are central acquisition risks. | |
| Recommendation — Verify access control enforcement in the target systems before accepting inherited risk. Review and remove privileged access rights that are not explicitly required post-close. | ||
Practitioner Guidance
What to verify: Treat document review as a lead, not a conclusion. Verify whether access removal is enforced in the authoritative systems, whether privileged accounts are individually attributable, and whether dormant or exception-based access still authenticates anywhere.
Implementation sequence: First confirm the target’s live identity sources, then sample high-risk entitlements, then test revocation on a small set of privileged and third-party accounts before trusting any broader attestation. If you cannot observe the control operating, treat the control as unproven.
Practitioner takeaway: In M&A, the real question is not whether access was documented, but whether it can still be exercised. If the control was not enforced, the buyer inherits risk, not reassurance.
Related resources from NHI Mgmt Group
- What breaks when organisations rely on basic identity checks instead of full due diligence for remote customers?
- How should security teams run access reviews for non-human identities?
- How should security teams govern non-human identities that have persistent access?
- What is the difference between role-based access and API key governance for NHI security?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org