The Hidden GRC Risk in Every M&A Deal: What Happens When Business Processes Collide
Key Takeaways
- M&A Creates Immediate GRC Exposure: Acquisitions combine not only assets and systems but also business processes, controls, access rights, and existing compliance gaps.
- System Consolidation Is a Governance Decision: Choosing whether to centralize, retire, upgrade, or maintain acquired systems creates distinct access, control, and business continuity risks.
- Access Risk Emerges on Day One: Toxic combinations, privileged access sprawl, orphaned accounts, and role explosion can appear as soon as previously separate environments begin operating together.
- Compliance Continues Through Integration: Regulatory and internal control obligations remain in force throughout the transition, making gaps during integration potential legal and financial liabilities.
- CFOs Need GRC Involved Before Close: Access governance, segregation of duties, privileged access, control deficiencies, and regulatory obligations should be assessed before integration complexity compounds.
Deep Dive
Not long ago, a CFO at one of the world's largest pharmaceutical companies said something that has stayed with me. We were discussing a major acquisition his company had just completed, and I asked what kept him up at night during the integration. His answer was not about valuation, synergies, or headcount. It was about business processes.
"Business processes are what define the business itself. Every dollar that comes in, every vendor we pay, every product we ship, every compliance obligation we meet—it all runs through a process. When you acquire another company, you are not just acquiring their assets. You are acquiring their processes, and all the risk that lives inside them."
He was right. And that insight sits at the heart of one of the most underestimated risk surfaces in corporate finance: the GRC and security exposure created during mergers and acquisitions.
Business Processes Are the Business
When executives talk about M&A integration, the conversation gravitates quickly toward ERP migrations, data center consolidations, and organizational charts. These are legitimate concerns. But they are downstream consequences of a more fundamental question: whose processes win?
Business processes govern everything a company touches. Procure-to-pay determines how vendors are onboarded, approved, and paid. Order-to-cash controls how customers are credited, billed, and collected. Record-to-report shapes how financial data is captured, validated, and disclosed. Hire-to-retire defines how employees are provisioned, managed, and offboarded. Each of these processes is a chain of decisions, approvals, and system transactions -- and embedded in each chain are access rights, segregation of duties controls, and audit trails.
In a merger, two sets of these chains must be reconciled. One company may run SAP. The other may run Oracle. One may have a mature Sarbanes-Oxley program. The other may have never been publicly listed. The moment those two entities share a network, an identity directory, or a financial ledger, the combined organization inherits the compliance posture of both—including the gaps.
The System Consolidation Decision: Centralize, Retire, or Upgrade
The first major GRC decision in any integration is the systems roadmap. Every application in the acquired entity falls into one of three categories:
- Centralize: Migrate users and data into the parent company's existing platform, extending current controls and policies to the acquired entity.
- Retire: Decommission the application entirely, usually when a functional duplicate exists or the system is end-of-life.
- Upgrade or maintain: Keep the acquired system running, either because migration is too complex or because the acquired company's platform is superior, requiring the parent to adapt.
Each path carries distinct risk. Centralization transfers access complexity into a production system that was designed for a different organizational structure. Retirement creates a gap period during which business continuity depends on manual workarounds. Maintaining a parallel system extends the identity perimeter, multiplies access review obligations, and can create orphaned accounts in systems that may not be governed as rigorously as the core platforms.
For CFOs, the financial exposure is not hypothetical. Audit findings tied to segregation of duties violations, unauthorized access, or inadequate controls over financial reporting can delay filings, trigger material weaknesses, and introduce liability that was not reflected in deal pricing.
Access Risk Is the First Risk to Surface
Of all the GRC risks that emerge during integration, access risk is the most immediate and the most frequently underestimated. On day one of an acquisition, the combined organization has two identity directories, two sets of role definitions, and two access models—none of which were designed to coexist.
In practice, this creates several predictable problems.
The first is toxic combinations, which occurs when a user holds roles in both the acquired and parent systems that, when viewed together, violate segregation of duties. Someone who can create purchase orders in one system and approve invoices in another has an access combination that no single system's controls would detect.
- The second is privileged access sprawl. It happens when IT staff from the acquired company retains administrative access to systems they should no longer control post-close. These accounts may not appear in standard access reviews.
The third is orphaned accounts. Employees who leave during integration may retain active credentials for weeks or months, particularly in systems that are not yet connected to the central identity provider.
The fourth is role explosion. Migrating users to a new platform often involves creating custom roles that approximate the old system's access model, rapidly multiplying the number of roles and making governance harder, not easier.
Access risk during M&A is not a future problem to solve during steady-state. It is a day-one exposure that accumulates with every week the integration plan remains incomplete.
Compliance Does Not Pause for Integration
One of the most dangerous assumptions in M&A is that regulatory obligations can be managed at the combined entity level once integration is complete. In reality, the acquired company's compliance obligations do not pause because a deal has closed.
If the target is subject to SOX, the acquirer must be prepared to extend its internal controls framework to cover the acquired entity's processes within the first full fiscal year post-acquisition. If the target operates in regulated industries—pharmaceuticals, financial services, government contracting -- product or data handling controls must remain intact through every stage of the transition. Failure to maintain these controls is not an integration problem. It is a legal and financial liability.
CFOs who have been through multiple integrations understand that the cost of a material weakness finding—in audit fees, remediation investment, market confidence, and management distraction—consistently exceeds the cost of getting access governance right from the start.
The CFO's Checklist: GRC Questions to Ask Before Day One
Based on the patterns that emerge in virtually every integration, CFOs should be pressing their teams for answers to the following questions before the deal closes—not after:
- What are the target's current SoD rule sets, and how do they compare to ours? Where will cross-system violations emerge immediately post-close?
- Does the target have any open material weaknesses or significant deficiencies in internal controls over financial reporting?
- How will privileged access to the acquired entity's systems be controlled and monitored during the transition period?
- What is the plan for access reviews at close, at 90 days, and at each system migration milestone?
- Which business processes in the acquired entity touch our most sensitive financial controls, and how will those be governed during parallel operations?
- What is the regulatory compliance footprint of the acquired entity, and what does the combined organization need to maintain to remain compliant from day one?
Processes Define the Business and the Risk
When two organizations merge, what they are really doing is deciding whose processes will govern the combined entity, which systems will carry those processes forward, and how controls will be maintained while the transition is underway.
That transition period is when GRC risk is highest. Access rights are in flux. System ownership is unclear. Controls that worked well in a single-system environment may not survive the move to a hybrid one. And the people responsible for governance are often the same people managing the integration itself.
The organizations that come through this period without material findings are not the ones that got lucky. They are the ones that treated access governance as a day-one priority, brought the right tools to bear before complexity compounded, and understood that protecting the integrity of business processes is not an IT responsibility—it is a finance leadership imperative.
The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

