
A private equity director runs a diligence call with the CTO of a scale-up the fund is about to close on. The call goes well. Product roadmap clear. Engineering team strong. Architecture defensible. Then the director asks one question and the call falls apart.
“Walk me through your IT stack. Every tool. Who owns it. What data flows through it. Who has access. When it was last reviewed.”
The CTO opens a spreadsheet. Forty-eight rows. Then he stops, scrolls back to the top, and admits he is not sure it is complete. Marketing has its own tools. Sales has its own tools. Customer success has its own tools. Finance has its own tools. People has its own tools. Each function has bought what it needed since the company was twelve people. Nobody decommissioned anything. Nobody mapped what data goes where. Nobody owns the question.
The diligence call ends politely. The valuation drops two days later.
This pattern is universal in scale-ups, and it is about to get worse. The SaaS sprawl that has been accumulating for a decade is now being layered with AI sprawl. A copilot in marketing. A forecasting model in sales. A summariser in customer success. A coding assistant in engineering. A meeting agent in operations. Each one is bought by a function, runs in a function, and pulls data the buying function does not fully understand the scope of. Nobody maps the joins.
The board sees the same headlines as the CEO. AI is a productivity multiplier. AI agents will reshape work. Companies that adopt AI will outpace the ones that do not. So the CEO encourages adoption, the function heads buy what catches their eye, and twelve months later the company has thirty AI tools in production, each with its own data scope, audit trail, and exception handling, and nobody owns the question of how they fit together.
The PE diligence question becomes the regulator question becomes the customer question. “What data did the model see. Who authorised the access. Where is the audit trail. Can you show me how the decision was made.”
SaaS sprawl was the previous decade’s audit headache. AI sprawl is this decade’s, layered on top of the SaaS one nobody fixed.
The right frame is the same one that handles the risk map and the AI readiness overlay. The operating model. Every box has a named owner. Every box has an IT stack underneath it. Every tool in that stack has a purpose, a data scope, an access list, and a review date. The map is the inventory. Without it the question is unanswerable. With it the question is a quarterly check.
When I was COO at Clearswift the entire commercial thesis of the company was helping enterprises answer that question for their own data. We were in the IT security and data governance market. The discipline I learned there was not about the products. It was about the operating model that made the answer cheap to produce. The audit was an output, not an event.
At Lumeon the same discipline applied to a different shape. Clinical pathway orchestration in a regulated environment. Every workflow on the TOM had its tool stack named, its access controls codified, its data flows mapped. When a regulator or a payer asked the audit question, the answer came out of the operating model, not out of a panic.
Most scale-ups have neither. The IT stack is a list nobody updates. The AI stack is a list nobody has yet started. The TOM is the thing that turns both into something defensible.
The board’s job is not to audit the stack. The board’s job is to ask whether the audit is producible on demand. If the CEO has to schedule a six-week exercise to answer the question, the answer is no. If the CEO can produce the inventory by operating area in fifteen minutes by clicking through the TOM, the answer is yes.
The first time a chair asks the question is usually when a PE term sheet is on the table, a regulator has written, or a customer has demanded a SOC 2 update. By that point the gap is visible and expensive. The right time to ask the question is at the next quarterly board meeting, when nobody is asking.
The chair’s question is not “is our IT stack secure”. It is “show me the map of every tool in every box of the operating model, the owner of each, the data scope of each, the last review date of each. If you cannot show me, that is what the next quarter is for.”
For a worked example of the operating model with both overlays, explore the interactive target operating model.