When PacWest Bancorp was acquired by Banc of California in 2023, the deal documents included extensive analysis of credit risk, deposit stability, and capital adequacy. What they did not include was any assessment of the target's data governance maturity. Eighteen months post-merger, the combined entity was still untangling data lineage gaps, recertifying data domains, and reconciling governance frameworks. The integration cost attributed to data governance restructuring exceeded $4 million, a number that never appeared in any pre-deal analysis.
This is the M&A governance blind spot, and it is costing acquiring banks real money that does not show up in deal models.
What Due Diligence Misses
Standard M&A due diligence covers financials, legal, compliance, and technology integration. Data governance falls into a gap between these streams. The technology team assesses system compatibility. The compliance team reviews regulatory findings. The financial team models revenue synergies. Nobody assesses whether the target's data governance fabric can sustain the combined entity's regulatory obligations.
This is a gap because governance is treated as a cost center, not as an asset with measurable value. But here is what happens when governance is absent from due diligence:
Certification debt surfaces late. The acquirer inherits all of the target's governance debt at once. Certifications that are stale, data domains that are unowned, quality thresholds that have been lowered to mask problems. The cost of remediating this debt hits post-close, when it is already too late to negotiate price adjustments.
Lineage breaks multiply. Post-merger system integration creates new lineage paths that neither entity governed independently. The combined lineage map is larger and more complex than either pre-merger map. Each break is a potential regulatory finding.
Regulatory timelines compress. The OCC and FDIC expect combined entities to demonstrate governance readiness within defined timelines post-close. When the target's governance is weak, those timelines become unachievable, and the regulatory relationship starts with a miss.
The Valuation Question
Data governance certifications have quantifiable value in an M&A context. A bank with current, validated certifications across its critical data elements has a governance asset that reduces integration cost, compresses regulatory timelines, and accelerates the realization of deal synergies. A bank without those certifications has governance debt that the acquirer will pay to remediate.
The calculation is straightforward:
- Cost of recertifying critical data elements post-merger: estimated at $150-300 per data element per domain- Cost of remediating lineage gaps discovered during integration: estimated at $50,000-200,000 per material gap- Regulatory risk of governance deficiencies in the combined entity: measurable through MRAs and consent order probability
These costs should be part of the deal model. They almost never are.
What Acquirers Should Demand
Before signing, acquirers should require:
- A current certification inventory for all critical data elements, with validity dates and owner confirmation- A data lineage map for regulatory reporting elements, with documented breaks- An attestation history showing on-cycle completion rates, not just completion rates- A governance debt assessment identifying domains where the target's governance is weaker than the acquirer's standards
These items should influence purchase price adjustments just like credit quality or capital levels. They represent real, measurable post-close cost.
For Targets, the Message Is Different
If you are a potential acquisition target, your governance certifications are an asset that increases your value. Banks with strong, current, and validated data governance reduce integration risk for acquirers. That reduction is worth a premium. Governance is not just a compliance function. It is an M&A asset.
The CoComply Angle
CoComply's certification model produces exam-ready governance evidence that travels with the bank through M&A. Certification inventories, lineage maps, and attestation histories are maintained continuously, not assembled post-facto for due diligence. When a deal is on the table, the governance evidence is already current. No scrambling. No gaps. No surprises at the price-adjustment negotiation.
Run This Before Your Next Deal
If you are evaluating an acquisition, ask the target for their data governance certification inventory and the last validation date for each. Count how many are current. The percentage of stale certifications is your governance debt estimate. Multiply by the remediation cost per element. That number belongs in your deal model. If the target cannot produce the inventory at all, the governance debt is likely larger than any reasonable estimate. Buyer beware.
