Chapter 12. Conclusion
Open source due diligence is generally just one item on a long list of tasks that need to be completed successfully in a merger and acquisition (M&A) transaction. Even so, given the central role of software and the potential intellectual property (IP) risks involved, it remains an important aspect of the overall due diligence process. Open source due diligence may seem like a lengthy process, but it is often completed quickly when both sides are prepared and work with a responsive compliance service provider.
So how can you prepare?
If you are the target company, you can maintain proper open source compliance practices by incorporating the following items into your development and business processes.
- Identify the origin and license of all internal and external software.
- Track open source software (components and code snippets) throughout the development process.
- Perform source code review on new or updated code that goes into a build.
- Fulfill license obligations when releasing products or updating software.
- Provide open source compliance training to employees.
If you are the acquirer, you need to know what to look for and have the capability to resolve issues quickly.
- Decide with the target company on the appropriate audit method to use and the 3rd party to whom the audit will be entrusted. Note that some providers lack blind testing capability, some do not support a do-it-yourself (DIY) approach, and others lack the ability to detect code snippets.
- If possible, obtain multiple quotes for the audit and learn more about the audit service providers. This step is not just about cost; it is about securing the accurate deliverables that will help resolve your concerns. Make sure you have the internal expertise to compare each quote on an equal footing, and confirm that the quote covers all of the following audit parameters.
- Audit method, inputs and outputs
- Key points of contact at the target company and the acquirer for promptly discussing issues that arise
- Schedule and process, especially if on-site visits are involved
- Confidentiality parameters
- Code vulnerability and version control analysis
- Cost, both standard procedure and expedited processing
Open source compliance is an ongoing process. Maintaining good open source compliance practices prepares you for any situation involving a change in the ownership or management of software, such as a potential acquisition, divestiture, or product or service launch. For this reason, companies are strongly encouraged to invest in building and improving their open source compliance programs.