Private equity and portfolios
AI disruption risk in a software portfolio: how to assess each company
By SourceX Editorial · Updated
Short answer
To assess AI disruption risk in a software portfolio, score each company from 1 to 5 on four factors: workflow depth, system-of-record status, data ownership and switching costs. Low totals mark products an AI agent could replace; high totals mark products AI is more likely to strengthen. Each scoring band carries one default action, from defend to invest.
Key takeaways
- Score each company from 1 to 5 on workflow depth, system-of-record status, data ownership and switching costs.
- Thin products that perform one step on data held in another system are the most exposed to AI agents.
- Systems of record with deep workflows and clear data rights are more likely to absorb AI than lose to it.
- Data ownership is the factor most often scored on hope, so score it from contract language.
- One default action per band keeps the assessment from becoming a report nobody acts on.
How do you assess AI disruption risk for a software company?#
AI disruption risk for a software company is assessed by asking whether an AI agent or a general-purpose AI product could do what customers pay the software for, without the software. The answer depends less on the company's AI roadmap than on where its product sits in its customers' daily work.
A group COO needs one method that works across very different products: a scheduling tool, a compliance tracker, an accounting module, a dispatch board. The rubric below scores the same four factors for each, using evidence the company already holds.
The score prompts action; it is not a valuation. Two companies with the same total can deserve different plans, and the board discussion about why matters more than the number.
The four factors in the rubric#
The four factors capture how hard it would be for an AI tool to step around the product. Each is scored from 1, exposed, to 5, resilient, and every score should point to evidence rather than to the management presentation.
- Workflow depth: how many steps of the customer's work run inside the product, from intake through decision to outcome.
- System-of-record status: whether the product holds the authoritative record of the work, or reads from another system.
- Data ownership: whether the company has clear rights to use the records generated in the product, under customer contracts and terms of service.
- Switching costs: how hard it is for a customer to leave, counting integrations, retraining, data migration and compliance history.
The scoring rubric#
The scoring rubric describes the ends and the middle of each scale so that different reviewers land on similar numbers. Use 2 and 4 for companies that sit between the descriptions.
| Factor | Score 1: exposed | Score 3: mixed | Score 5: resilient |
|---|---|---|---|
| Workflow depth | One step, such as drafting a document or a summary | Several steps, but key decisions happen outside the product | End-to-end work from intake to outcome runs in the product |
| System of record | Reads from another system and writes nothing authoritative | Authoritative for some records, such as schedules, but not others | The authoritative record of the customer's core work |
| Data ownership | Contracts bar any use of customer data beyond providing the service | Aggregated or de-identified use allowed; other uses unclear | Clear rights to use generated records to improve and extend the product |
| Switching costs | Customers can export and leave with little effort | Integrations and retraining slow a move | Regulatory history, integrations and embedded records make leaving costly |
Bands and one action per band#
Add the four scores for a total between 4 and 20, then apply the default action for the band. The board can override the default, but it should record why, so the next review can test whether the reason held.
| Total score | Band | Default action |
|---|---|---|
| 4 to 8 | Exposed | Defend and harvest: protect renewals, cut roadmap spend, and check whether historical records hold value outside the product |
| 9 to 12 | Contested | Deepen the workflow: bring adjacent steps into the product and secure data rights at renewal |
| 13 to 16 | Positioned | Build AI into the product on records the company has the right to use |
| 17 to 20 | Resilient | Invest: treat AI features as a pricing and expansion lever |
Evidence to collect before the scoring session#
Evidence for every factor already exists inside each company. Ask for it before the session and score from it, so the discussion is about facts rather than confidence.
- Product analytics showing which steps customers complete in the product and which they export to finish elsewhere.
- The integration list, marking which systems the product reads from and which systems read from it.
- Customer contract templates and the largest negotiated contracts, for their data use clauses.
- CRM churn reasons and lost-deal notes that mention AI tools or new competitors.
- Support tickets asking for AI features, or describing customers using outside AI tools alongside the product.
Where data ownership changes the answer#
Data ownership is the factor that most often changes a company's band once someone reads the contracts. Many vertical software agreements allow aggregated use to improve the service but say nothing about training models or disclosure to third parties. A company that assumed it could build AI on tenant data may find it needs consent first, which moves it down a band.
Score the factor from the clause, not from the CEO's recollection of it, and flag unclear cases for counsel. Where rights are weak, the action for the contested band, securing rights at renewal, becomes the priority whatever the other scores say.
Data ownership also decides whether historical records could be licensed. A low-scoring product with clear rights to years of linked history may have an option a higher-scoring product with restrictive contracts does not.
Illustrative: scoring three vertical software companies#
Illustrative: a fictional software holding company scores three businesses. The first is a marina management product that runs slip bookings, billing and maintenance work orders. The second is a scheduling add-on for driving schools that syncs with a separate student management system. The third is an elevator inspection compliance tracker that stores the records inspectors and regulators ask for.
The marina product scores high on workflow depth and system-of-record status and lands in the positioned band, so the group funds an AI work order assistant. The scheduling add-on scores low on everything except switching costs and lands in the exposed band; the group protects renewals and asks whether its long booking and rescheduling history has value elsewhere. The compliance tracker scores resilient on the strength of its regulatory record and integrations.
The exposed company's history goes to a metadata-only licensing assessment. That does not change its band, but it gives the board one more option for a product the group no longer plans to grow.
How SourceX fits a disruption assessment#
SourceX is relevant to the data ownership factor and to the last action in the exposed band. Licensing historical records is not a defense against disruption, but it can be a sensible option for a product whose records are worth more than its roadmap. Using the Supply and Rights steps of the SourceX five-step transaction, a company learns which records it holds and whether its customer contracts allow licensing, starting from metadata.
The SourceX Enterprise Data Value Framework then lets the group compare record families across companies on its qualitative drivers, such as uniqueness, domain expertise, scale, recency, rights and AI utility, with reproducibility, preparation cost and privacy burden counting against value, alongside the disruption scores.
Frequently asked questions
Is vertical SaaS at risk from AI?
Some of it is. Products that perform a single step on data held elsewhere are more exposed than products that hold the authoritative record of a customer's work. Many vertical software companies are well placed to add AI to workflows they already own, which is why scoring each company matters more than a sector view.
How often should a holding company rescore its portfolio?
Rescore whenever something material changes, such as a competitor launch, a contract template update or a shift in churn reasons, and otherwise at a fixed annual or semiannual review. The rubric runs quickly because each company already holds the evidence it needs.
Should management score its own company?
Management should prepare the evidence and propose scores, but the group should run the session. Leaders naturally score their own product generously, especially on data ownership and switching costs. A short session with the group COO, the company CEO and a product lead balances the view.
Does a low score mean the company should be sold?
Not on its own. A low score sets the default plan to defend renewals and limit new spend, but an exposed company can still produce steady cash. Sale timing depends on many factors beyond AI exposure, which the board weighs separately.
Can licensing data make a product more exposed?
It can, if the licensed records help a buyer build a competing product. Field-of-use limits, non-exclusive terms and leaving live product data out of scope reduce that risk. For companies in the positioned or resilient bands, counsel should check whether a license touches the records the product's advantage depends on.
Related resources
- IndustrySoftware development agencies data
- IndustryFintech software data
- InsightCan engineering firms sell their data to AI companies?
- InsightProprietary algorithms in your code: exclude or include?
- SolutionTurn the data your company already creates into a licensing asset
- SolutionOperational data: the step-by-step record of how work gets done
See if your company qualifies
A short company assessment. No data uploads are needed.