Diligence is one of the few engagements where our incentive has to be visibly neutral. We are not bidding for the remediation work, and we say so up front, because an assessment written by the team hoping to fix it is worth very little.
We look at the things that determine what happens after the deal: code quality and test coverage, architecture and its scaling limits, security posture, licensing and IP hygiene, infrastructure cost trajectory, and usually most predictive how much critical knowledge lives in one or two people’s heads.
The report separates what is genuinely broken from what is merely unfashionable. Plenty of profitable systems are unglamorous, and a rewrite recommendation should have to earn itself. Findings come with severity, estimated remediation cost, and how they should affect the price.