09.09.2026

Share Deal in the Financial Sector: Data Valuation, Information Security and ISO 27001

Financial institutions hold extensive customer, transaction, risk and model data. These datasets can drive growth, risk management and efficiency, but are also dependent on a high level of confidentiality, integrity and availability. In a share deal, the target company remains the data controller; however, the cloud, data lakes, platform consolidation and migration create new boundaries of trust. Data valuation must therefore assess data protection, information security, ISO 27001, data quality and operational resilience as a whole.

Arrange a no-obligation initial consultation
Your ISiCO-Expert:
Dr Jan Scharfenberg
Partner Information Security, Managing Director

The share deal does not automatically change controllership

From a data protection perspective, a share deal is not a free pass. Although the target company remains the same legal entity and therefore, in principle, remains the controller for its data processing activities, the investor does not automatically acquire its own right of access or use in relation to operational data.

Disclosure in the data room, later reporting lines, central platforms or group-wide analyses are already separate processing operations that must be reviewed in terms of purpose, necessity, role model and security.

In the financial sector in particular, the greatest intervention often arises only after closing: a sponsor plans group-wide reports, a central data warehouse, cloud migration, outsourcing, shared analytics or new AI governance. These projects may create new recipients, new purposes, international access or different role models. They must therefore be treated as separate processing operations and not merely as technical integration.

Information security and operational resilience determine migration value

Every migration changes trust boundaries: new administrators, temporary interfaces, test environments, cloud access, keys, logs and data copies are created. Without security by design, permissions can multiply, consent or purpose information can be separated, sensitive data can be replicated in tests or audit trails can be interrupted. Information security must therefore be part of the migration business case and not only reviewed shortly before go-live.

Value-relevant factors are not only confidentiality and cyber defence, but also integrity and availability. Incorrect transformations, incomplete reconciliation, lack of rollback capability or untested recovery can impair regulatory reports, models and core operational processes. Cyber resilience and operational resilience therefore determine when synergies can be realised and how high the risk buffer in the purchase price needs to be.

Which financial data are value-relevant

A business data valuation should not merely count customer data, but determine the function of each data cluster in the business model. Typical assets are:

  • Customer, account, contract and transaction data, including history and interaction data.
  • KYC, AML, fraud and sanctions data with traceable origin and currency.
  • Credit, risk, pricing and portfolio data, as well as related models and features.
  • Regulatory reporting data, control evidence and auditable data chains.
  • Product, channel and usage data for customer management, service and digital business models.
  • Metadata, business glossary, data lineage and quality rules as the basis for enterprise data governance.
  • Model and training data for analytics and AI, provided that purpose, quality and rights support their use.

The value of data is particularly high where data are current, complete, consistent and linkable across systems. Conversely, large historical datasets can create more costs than benefits because of unclear retention, lack of purpose compatibility, duplicates or non-traceable transformations.

The biggest risks in digital due diligence

Risk area Typical problem Impact on data valuation
Data lineage KPIs and models cannot be traced back to the source and transformation. Reporting, model and audit risks; high reconstruction effort.
Data quality Duplicates, missing values, inconsistent customer IDs or manual corrections. Analytics and automation effects are realised later or not at all.
Purpose and legal basis Data are to be used for cross-selling, profiling or AI even though the collection purpose does not support this. Planned data monetisation must be reduced or redesigned.
Legacy and migration Legacy systems are poorly documented; mapping, history and controls are lost during migration. High migration costs, dual-run effort and operational risk.
Cyber and third parties Cloud, SaaS and outsourcing chains are incompletely recorded; access rights are too broad. Security, concentration and outage risks reduce enterprise value.
Models and AI Training data, features and decisions are not traceable or are biased. Model risk, remediation work and limited AI readiness.
ISMS scope and ICT governance ISO 27001 scope, risk treatment and control evidence cover only sub-areas; migration, cloud, third parties or DORA requirements are not integrated. The expected level of security and resilience maturity is overestimated; gap closing, testing and regulatory remediation increase costs and time to value.

Migration is a valuation object, not an IT add-on

A migration influences both costs and usability. Data can lose meaning during mapping, histories can be cut off, consent or purpose information can be separated and audit trails can be transferred incompletely. For this reason, technology due diligence should capture not only system age and operating costs, but also data model, interfaces, quality rules, reconciliation and exit capability.

Value destruction often occurs gradually: a new platform is technically live, but historical data are no longer fully comparable, models need to be recalibrated or regulatory reports require manual bridges. The investment case must therefore reflect migration risks in both time and financial terms.

ISO/IEC 27001 as a due diligence framework: not a substitute for DORA

ISO/IEC 27001:2022 provides a risk-based framework for an information security management system and is a robust starting point for information security due diligence. Scope, risk analysis, risk treatment, Statement of Applicability, internal audits, management review, corrective actions and operational control evidence should be reviewed. It is particularly important to determine whether core banking, payment, risk, data and cloud environments are actually covered.

For financial companies, sector-specific requirements for ICT risk management, incident handling, resilience testing and third parties remain independently applicable. ISO 27001 can support evidence and the control model, but does not replace a review of DORA, outsourcing, regulatory findings or specific migration risks. For the valuation, what matters is therefore the connection between ISMS, enterprise data governance and operational resilience.

ISO 27001 review area Expected evidence Relevance for data valuation
Scope and target architecture Entities, core processes, data platforms, cloud, SaaS and outsourcing services within the scope. Scope gaps increase integration, control and certification costs.
Risk analysis and SoA Current ICT and information risks, Statement of Applicability, treatment, acceptances and budget. Untreated high risks become remediation items relevant to the purchase price.
IAM, logging and monitoring Privileged access, recertifications, segregation, keys, logs and security monitoring. Effective controls protect transaction data, models and auditability.
Incident and resilience Incident history, crisis exercises, backup, restore, restart, reconciliation and testing. Demonstrated resilience reduces outage, loss and recovery discounts.
Third parties and improvement Provider register, security requirements, concentration, exit, audits, management review and findings. Cloud and outsourcing risks influence time to value and long-term operating costs.

Review rule for finance

An ISO 27001 certificate is valuable where scope, risk treatment and control effectiveness match the real platform and service provider landscape. For in-scope financial companies, it must also be traceable how the ISMS is connected with DORA and the operational resilience model.

Data protection and access risks in the share deal

GDPR due diligence should clarify whether data were lawfully collected, can be used for the planned purposes and how information, erasure and data subject processes work. It is also relevant whether consents or objections are demonstrable across systems. Missing evidence can significantly reduce the economic value of marketing, profiling or analytics data.

  • Data room: aggregated portfolio, risk and customer metrics instead of complete account or transaction data.
  • Clean team for competitively sensitive or strongly personal analyses.
  • After closing: no blanket sponsor access to operational customer data.
  • Group reporting and central services with a clear role, purpose and permission architecture.
  • Cloud and international access only after review of the legal, contractual and security structure.
  • Erasure, blocking and retention logic must be transferred into every migration.

Information security in migration

Technology due diligence should assess the security and control architecture of each migration wave. Particularly relevant are time-limited admin rights, separation of development, testing and production, data masking, encryption, key management, immutable logs, reconciliation, rollback, backup and exit capability. If these controls are missing, the business case must be adjusted for rework, delay and additional operational risk.

Opportunities: enterprise data governance as a value enhancement programme

The greatest opportunity lies in binding enterprise data governance. It defines critical data elements, owners, quality rules, data lineage, access models and consistent terminology. This makes regulatory reports more robust, reduces manual reconciliations and accelerates product, risk and customer decisions.

On this basis, modern platforms can improve fraud detection, credit management, customer service, pricing and operational efficiency. However, AI readiness is not created by buying a platform, but through trustworthy, documented and legally usable data. AI governance must therefore be interlinked with data protection, model development, security and business responsibility.

An effective ISO 27001 ISMS and a robust DORA control model can accelerate the transformation because responsibilities, evidence and escalation routes are already embedded.

How financial data are valued

Income and risk impact

The income-based approach does not only include additional revenues. Value can also arise from lower credit losses, less fraud, better price management, lower processing costs, faster reports and lower error rates. These effects are forecast and discounted as additional or avoided cash flows.

Cost and replacement-cost approach

The cost approach captures collection, historisation, cleansing, enrichment, documentation and technical provision. Long, consistent time series that cannot be reproduced in the short term can be particularly valuable. However, the cost approach must not be confused with realisable market value.

Migration and compliance discount

Costs for data cleansing, mapping, dual run, reconciliation, model validation, security hardening, adjustment of the ISMS scope, DORA and third-party measures, contractual and role redesign, and decommissioning of legacy systems must be deducted. In addition, a risk discount must be applied for uncertain legal bases, poor data lineage, open audit or supervisory findings, untested recovery or high dependency on individual service providers.

Review questions for data due diligence and M&A due diligence

  1. Which data drive revenue, risk decisions, regulatory reports and core operational processes?
  2. Are critical data elements, owners, definitions, quality rules and data lineage documented?
  3. Which data processing activities are based on consent, and are evidence and withdrawals effective across systems?
  4. Which data may be used for new purposes such as cross-selling, profiling, fraud detection or AI?
  5. Which legacy systems are indispensable for history, retention or evidence?
  6. How high are the costs and duration of mapping, cleansing, dual run, reconciliation and decommissioning?
  7. Which cyber, cloud, outsourcing and concentration risks exist?
  8. Which core processes, platforms, cloud and outsourcing services are within the scope of the ISO 27001 certification?
  9. Are the Statement of Applicability, ICT risk treatment, DORA mapping, audit findings and corrective actions current and funded?
  10. When were incident response, crisis organisation, backup, restore, reconciliation and provider exit last tested?
  11. Which value-creation effects can be realised without migration and which depend on a multi-year transformation?

The answers must be translated into the investment case. A theoretical data value without a robust migration path is not an argument for the purchase price. Conversely, a target with moderate data maturity can be attractive if the gaps are clearly quantified, reflected in the purchase price and addressed through a realistic transformation plan.

Purchase agreement and 100-day plan

Material risks can be addressed through warranties, disclosures, indemnities, covenants and, where applicable, closing conditions. Relevant statements include those relating to data quality, data protection incidents, regulatory findings, critical service providers, model and reporting processes, and the completeness of the system and data landscape.

  • Day 1: limit roles, privileged access, sponsor reporting and ongoing migration changes to the necessary minimum; confirm incident and escalation routes.
  • By day 30: confirm critical data inventory, data flow map, provider register and prioritised findings; mirror ISO 27001 scope, SoA and DORA mapping against the target architecture.
  • By day 60: approve the migration business case with security controls, waves, reconciliation, backup, rollback, dual-run costs and a robust restore test.
  • By day 100: launch an integrated ISMS and enterprise data governance operating model with owners, quality and security KPIs, DORA responsibilities and decision rights.
  • Value-creation KPIs: data quality, degree of automation, reporting time, error rate, model performance, access-review coverage, restore success rate, open high risks, legacy reduction and realised cash-flow effects.

Conclusion: data strategy determines realisable value

In a finance share deal, the value of data is not the same as the size of the database. The decisive question is whether data are legally usable, technically correct, technically migratable, secure and permanently traceable. Integrated data valuation combines data protection, enterprise data governance, ISO 27001, DORA, cybersecurity, models, migration and the value-creation plan.

Only this connection shows which part of the promised data value can actually be realised within the investment period.

FAQ: share deal, data protection and data valuation

#1 Why is data migration relevant to the purchase price?

Because cleansing, mapping, dual run, reconciliation, model validation and legacy decommissioning can cause significant costs and take considerable time. In addition, a faulty migration can reduce the legal and business usability of data.

#2 May the investor use customer data for group-wide analyses?

Not solely on the basis of the share deal. New recipients, purposes and platforms must be reviewed separately and implemented with a clear role, access, contract and security model.

#3 How is the value of AI-ready data determined?

Through realistically expected revenue, risk and efficiency effects, reduced by costs for quality, documentation, rights, model governance, security and integration.

#4 Which red flag is particularly critical for financial data?

Missing data lineage for business-critical KPIs, models or regulatory reports. Without traceable origin and transformation, data can be managed and audited only to a limited extent.

#5 Does ISO 27001 certification replace the DORA review?

No. ISO 27001 structures the ISMS and can support many types of evidence. However, DORA and further sectoral requirements for ICT risks, incidents, testing and third parties must be reviewed independently. What is value-relevant is the mapping between certification scope, the real system landscape and the regulatory control model.