Technology Due Diligence on an Irish SaaS Target: What US and EU Buyers Should Check

A reading of what technology due diligence on an Irish SaaS target actually examines — written for US and EU buyers, where the R&D tax credit and IP box positions are as material to the technology DD as the codebase itself.

Ireland’s combination of a 12.5% trading tax rate, a now-35% R&D tax credit, and a 10% effective rate under the Knowledge Development Box has made it a consistently attractive base for SaaS companies building IP-heavy products for the European and global market. For a buyer, that same attractiveness means the tax position is frequently interwoven with the technology architecture in ways a generic technical DD checklist won’t surface. This is what actually needs examining, beyond the standard code-and-infrastructure review.

Why Irish SaaS DD isn’t just technical DD with an EU flag

The R&D tax credit is a cash asset with a clawback tail. A target claiming Ireland’s R&D credit — now 35% of qualifying expenditure, refundable in cash over three instalments — has effectively been part-funding its development through the Irish state. That funding comes with contemporaneous documentation requirements, and a change of control can affect ongoing eligibility or invite renewed Revenue scrutiny of historical claims.

Free · 4 minutes

Do you actually know what you are running — and what it is about to cost you?

Fourteen questions on the systems you depend on, the ones nobody owns, and the support dates that turn a routine upgrade into a forced re-platform. Banded finding on screen, full sheet by email.

The IP structure often doesn’t match the org chart. Where a target has structured its IP to benefit from the Knowledge Development Box’s preferential rate on qualifying patented or copyrighted software income, the technology and legal ownership of that IP needs to trace cleanly to the entity claiming the benefit — a common gap where a group has grown through multiple entities, contractor relationships, or an earlier restructuring.

GDPR compliance is table stakes, not a differentiator. An Irish-established SaaS target handling EU customer data is, by definition, more exposed to DPC scrutiny than most targets a US buyer will have previously evaluated — Ireland’s DPC is the lead authority for an outsized share of global technology enforcement, and a target’s own compliance posture needs examining on that basis, not against a generic GDPR checklist.

Who this is for

  • The US strategic or PE buyer evaluating an Irish SaaS acquisition and unfamiliar with how the R&D credit and KDB interact with deal structure.
  • The EU buyer consolidating a SaaS platform where an Irish target is one of several targets in a roll-up.
  • The CFO of an Irish SaaS target preparing for sale who wants to understand what a buyer’s technology DD team will actually flag.

The seven examination areas

1. R&D tax credit claim history and documentation quality. The DD should confirm claims were supported by contemporaneous project documentation — descriptions of the scientific or technological uncertainty, the systematic methodology applied, and the advance achieved — since Revenue’s standards for this have tightened, and a poorly documented historical claim represents contingent liability the buyer inherits.

2. Knowledge Development Box nexus fraction integrity. Where the target claims KDB relief, the DD should verify the nexus fraction — the ratio of qualifying in-house and unrelated-party R&D spend to total R&D spend including acquisition costs and related-party outsourcing — genuinely supports the rate being claimed, since a fraction that hasn’t been maintained correctly as the business has grown or restructured can unwind the benefit.

3. IP ownership chain. Confirming the entity claiming R&D credit and KDB benefits is the same entity that actually owns the resulting IP, with a clean chain of assignment from any contractors, founders, or predecessor entities — a gap here can jeopardise both the tax position and the buyer’s clean title to the core asset being acquired.

4. Core architecture and technical debt. Standard SaaS technical DD — codebase quality, scalability headroom, infrastructure cost trajectory, and the usual key-person dependency questions — read with particular attention to whether the architecture can sustain the growth thesis behind the acquisition.

5. GDPR posture against DPC’s actual enforcement patterns. Not a generic privacy checklist, but a specific check of subject access request handling, cross-border transfer mechanisms, and breach history against the failure patterns the DPC has actually found against other Irish-established controllers.

6. Data residency and hosting architecture. Where the target hosts EU customer data, confirming the actual physical and contractual data location matches what’s represented to customers and regulators — a gap that surfaces surprisingly often between what a data processing agreement states and where the infrastructure is actually provisioned.

7. Vendor and platform dependency. Concentration risk in critical infrastructure or SaaS-of-SaaS dependencies, assessed the way a buyer would for any technology acquisition, with specific attention to contract terms that survive — or don’t — a change of control.

Where price gets affected

R&D credit clawback exposure. Weak historical documentation creates contingent liability the buyer should either price in or require the seller to indemnify against.

KDB benefit unwind risk. A nexus fraction that doesn’t hold up affects forward tax modelling on the deal, not just historical exposure.

IP title gaps. Any break in the ownership chain needs resolving before close — this is a deal-blocking issue in most structures, not a post-close cleanup item.

GDPR exposure inherited at close. An unresolved DPC-pattern gap becomes the buyer’s regulatory exposure the moment the deal completes, regardless of when the underlying failure occurred.

A subcontracting detail that surfaces in roll-ups specifically

Irish R&D credit rules cap subcontracted R&D expenditure that qualifies for the credit at the greater of 15% of in-house R&D spend or €100,000, with separate limits for university and unconnected third-party subcontracting — and subcontracted work to a connected party is excluded from relief entirely. This detail matters specifically in consolidation scenarios: where a target has historically relied on an affiliated development shop, an outsourced team under common ownership, or a sister entity for a meaningful share of its engineering, part of what looked like qualifying R&D spend may not actually have qualified for credit at all, and the DD should check the connected-party question directly rather than assuming subcontracted spend was treated uniformly.

Separately, Ireland’s examinership process — a court-supervised restructuring mechanism distinct from US Chapter 11 or UK administration — is worth a specific mention where a target has any financial distress history. A prior examinership can leave residual creditor arrangements or contract renegotiations that affect vendor terms the buyer is inheriting, and this is an Irish-specific check a US buyer’s standard DD playbook won’t automatically prompt for.

How we engage with this

We perform technology due diligence on Irish SaaS targets, with the R&D credit, KDB, and IP ownership examination integrated into the technical review rather than left to separate tax counsel working from a different data room. As a scoped Technology Due Diligence engagement, we work through the seven examination areas and flag what changes deal terms.

We don’t act as transactional counsel. We don’t provide Irish tax advice. We don’t warrant findings to the seller. We read what’s there and write it down for the deal team.

Pricing is published at /pricing/. If you’re evaluating an Irish SaaS acquisition, the place to start is a conversation.

Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.

Free interactive tool

Website compliance checklist

What your site has to do, based on what it actually does

Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.

Free interactive tool

Interactive deadline calculator

Check which regulations apply to you and when

Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.

Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.

Most technology problems are not technology problems. They are control problems.

The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.

Full Governance by Sixteen Pillars

Govern your business. Prove your compliance.

A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.

See what's coming