Skip to content

Consulting and recruiting

Technology due diligence on a staffing firm: ATS, data and AI use

By SourceX Editorial · Updated

Short answer

Technology due diligence on a staffing firm should confirm that the buyer will own, move and govern the data and tools it is paying for. Cover five areas: the ATS contract and ownership, data export rights, data quality measured on a real export, an inventory of AI tools that touch candidates, and the privacy notices behind the candidate database.

Key takeaways

  • Run a real ATS export during diligence; contract language about data ownership does not prove the data can be moved.
  • Duplicate, stale and unlinked records can make the usable candidate database far smaller than the headline count.
  • Every AI tool that touches candidates needs an owner, a review of the vendor's data terms and a record of human oversight.
  • Privacy notice versions, matched to record collection dates, decide which records support new uses after close.

What technology diligence on a staffing firm should answer#

Technology diligence on a staffing firm answers three questions: can the platform keep the target's desks running after close, can it combine the target's data with its own, and can it govern the AI tools already in use. For a buy-and-build platform, integration effort and data usability usually matter more than the target's feature list.

Scope the work around records, not software brands. Recruiters can learn a new ATS in a few training sessions; a candidate database that cannot be exported cleanly, or that was collected under narrow notices, cannot be fixed by training.

Map the systems before reading any contract#

A system map shows where every record family lives and how records move between systems. Ask the target's operations lead to walk through one placement from job order to final invoice and note every system it touches, including spreadsheets.

The walkthrough usually surfaces shadow systems that never appear in the IT inventory: a recruiter's personal texting app, a shared spreadsheet of client rates, or a VMS portal where the only copy of a timesheet lives.

Map the systems before reading any contract
SystemCommon examplesDiligence question
Applicant tracking systemBullhorn, JobAdder, Crelate, AviontéWho holds the contract, and can every object and attachment be exported?
Vendor management system portalsClient-mandated VMS and MSP portalsWhich client data sits only in the client's portal?
Back office and payrollStaffing back-office suites and payroll providersDo pay and bill records link to ATS placements?
Onboarding and screeningE-signature, I-9 and background check toolsWhere are sensitive documents stored, and for how long?
Sourcing and outreachJob boards, texting and email sequencing toolsDo source platforms' terms limit reuse of imported profiles?
ReportingBI dashboards and spreadsheetsWhich metrics are calculated outside the ATS, and by whom?

ATS contract, ownership and export rights#

The ATS contract decides whether the platform can take the data with it, and an export test decides whether that right works in practice. Ask for the full subscription agreement, order forms and any data processing agreement, not a summary from the vendor's sales team.

  • Confirm the contracting entity and whether the subscription can be assigned on a change of control.
  • Read the data ownership, export and post-termination access clauses, including any fees for bulk export.
  • Check API limits and whether attachments such as resumes and signed documents export with their records.
  • Run a full test export of candidates, contacts, job orders, submittals, placements, notes and files.
  • Note custom fields and workflow configurations that will need mapping in a migration.
  • Find out whether the ATS vendor uses customer data to train its own AI features, and how to opt out.

Data quality tests to run on the export#

Data quality tests turn a vague claim about database size into a usable record count. Run them on the test export, not on a dashboard the target provides, and have someone from the platform's own operations team review the results.

Record the results as findings with examples rather than scores. An integration team needs to know which fields are broken and why, not just that quality is low.

Data quality tests to run on the export
TestHow to run itWhat it reveals
DuplicatesMatch candidates on email, phone, and name plus locationHow much of the headline count is real
Field completenessCheck skills, location, availability and source fieldsWhether matching and search will work
RecencyCount records with recruiter activity in recent yearsThe active share versus the archive
Placement linkageTrace placements to job orders, submittals and invoicesWhether outcomes connect across systems
Status hygieneLook for job orders and submittals that never closedHow disciplined recruiters are with the ATS
Note qualitySample free-text notes for structure and sensitive contentValue and privacy risk of unstructured history

AI tools inventory and governance#

An AI tools inventory lists every tool that reads, scores or writes candidate and client data, including features switched on inside the ATS. Staffing firms now use AI for resume parsing, matching, outreach drafting, interview scheduling, candidate chatbots and call or interview note-taking, often without a central list.

For each tool, record the owner, the decisions it influences, whether a person reviews its output before a candidate is rejected, the vendor's terms on training with customer data, and any bias audits or candidate notices required where candidates are located. Ask whether any client MSA requires AI disclosure or prohibits specific tools.

Gaps here are usually integration items rather than deal breakers. A tool that rejects candidates automatically with no human review, however, is a governance issue to fix soon after close and may warrant a closer look from employment counsel.

Privacy notices determine what the platform may do with the candidate database after close, so collect every version with the dates it was live. Match those dates to record creation dates and flag records collected under notices that do not cover the platform's plans.

A provenance record makes this repeatable. The Data & Trust Alliance's Data Provenance Standards define a Use group of metadata that includes consent documentation location, confidentiality classification, license to use and intended data use. Capturing similar fields for each record family gives the platform a ready answer when a client, regulator or data buyer later asks where records came from.

Also ask how deletion requests were honored, what retention schedules apply to screening and onboarding documents, and whether any data has been shared with or licensed to third parties.

Illustrative: a staffing platform finds two databases in one#

Illustrative: a fictional PE-backed engineering and IT staffing platform is acquiring a regional firm. The target reports a large candidate database in its ATS and runs an AI matching feature on every new job order.

The test export shows that a migration from a previous ATS left two copies of many candidates, with notes split between them, and that resumes from the old system did not export with their records. The matching feature ranks candidates, but recruiters see only the top results, which counsel treats as a human-review gap. The platform budgets a migration and deduplication project, adds a review step to the matching workflow, and keeps the legacy archive under a retention plan instead of merging it blindly.

How SourceX helps after close#

Platforms often inherit legacy ATS archives that will be retired after migration. SourceX can assess those archives with a metadata-only fit check before subscriptions lapse, so the platform knows whether any de-identified workflow records are worth preparing and licensing.

Any package that proceeds follows the SourceX five-step transaction, with candidate personal data removed in Preparation and a SourceX Evidence Packet recording provenance, licensing rights, permitted use, the privacy record and release authorization.

Frequently asked questions

Who should run technology diligence on a staffing target?

Usually a small team: someone from the platform's operations or IT side who knows staffing systems, privacy counsel for notices and AI tools, and the integration lead who will own the migration. Generic IT diligence providers often miss staffing-specific issues such as VMS dependencies and ATS export gaps.

How deep should the export test go before signing?

Deep enough to prove every record family and attachment type can leave the system with its links intact. A sample export covering candidates, job orders, submittals, placements, notes and files, reviewed by someone who will run the migration, usually answers the question. Full exports can follow under the purchase agreement.

Should the platform move the target onto its own ATS right away?

Not before the data quality findings are addressed. Migrating duplicates, broken links and expired records just moves the problems. Many platforms deduplicate and clean first, migrate active records, and keep the legacy archive read-only under a retention plan until it can be retired.

What if the ATS subscription is in a founder's personal name?

Treat it as a closing item. The subscription and its data need to sit with the operating entity being acquired, or be assigned to the buyer, before or at closing. Confirm the vendor's assignment process and make sure admin credentials are transferred, not just shared.

Do the target's AI tools create risk for the platform?

They can, because after closing the platform becomes responsible for how they are used. Tools that screen or rank candidates may raise hiring-law questions where candidates are located, and vendor terms may allow training on candidate data. Inventory them, review the terms, and decide which to keep, change or retire.

Sources

  • The Use group of the Data & Trust Alliance Data Provenance Standards includes elements for confidentiality classification, consent documentation location, privacy-enhancing technologies applied, allowed and excluded processing and storage geographies, license to use, intended data use, and copyright, patent and trademark status. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify