Chapter 6
Risk, the multiple and the platform: the six levers that decide what the company is worth at exit
Posture, governance, data rights, add-ons, continuous diligence and the exit itself. These levers rarely appear on a value creation plan because they do not move a P&L line this quarter. They move the number the P&L is multiplied by.
Chapter 6 of 10Risk, the multiple and the platform13 min
Bain's 2026 report gives the reason this chapter exists: multiple expansion "powered over 50% of all buyout returns" in the prior cycle and is no longer available, so a deal now needs 10% to 12% annual EBITDA growth to earn what 5% once did.1 That makes the multiple something to protect rather than something to expect, and four of the six levers here are protective. The other two, add-on integration and continuous diligence, are the platform levers, and they matter because platform buyouts in software fell to 41% of deal value in early 2026 while add-ons rose to about 45%; in Europe, add-ons reached 71.4% of buyout deal count, a decade high.2 Buy-and-build is the default deal now, and its integration cost is the lever AI changes most.
X1 · Security and compliance posture
What it is. Certifications, evidence and incident readiness maintained as a condition of enterprise sales and as protection against the event that resets a multiple: the breach, the regulator's letter, the customer's audit finding. The operational side is O9; this card is the posture as an asset.
The line it moves. The multiple, through avoided events; win rate, through removed gates.
Typical range and the evidence. Medium. The enforcement side is measured: HHS's Office for Civil Rights announced in March 2026 its twelfth action under its risk-analysis initiative, a settlement with "a Maryland software company" and business associate after a breach affecting fifteen million people, for failure to conduct "an accurate and thorough risk analysis."3 The amount was $10,000; the precedent, a software business associate named for a missing risk analysis, is what to cite internally. Vanta's survey data that buyers spend nine working weeks a year on vendor security reviews establishes the friction; nothing independent establishes the conversion effect, and the card does not claim one.4 In Europe, a software company selling into financial services has been an ICT third-party provider under DORA since January 2025, with contractual, audit-access and incident-reporting obligations that smaller competitors will not clear.5
Conditions. O9 in place; the annual risk analysis done and documented; an incident plan that has been rehearsed; a named executive owner.
Kill criteria. None; the failure mode is an event, and the metric is that it does not happen.
- Frameworks certified or attestedSales gateAt close0 to 1Year 12Year 33
- Risk analysis current and covering AI systemsRegulatoryAt closeNoYear 1YesYear 3Yes, annual
- Incident plan rehearsed in the last twelve monthsRiskAt closeNoYear 1YesYear 3Yes
- Enterprise deals lost on security reviewRevenueAt closeUnknownYear 1MeasuredYear 3Near zero
Horizon and stage. Deploy. Year one.
How it translates. A: HIPAA business-associate posture is the license to operate. B: the company's own posture is its product's credibility. C: PCI. D: SOC 2 and ISO at scale. E: enterprise and, in Europe, DORA.
X2 · AI governance and product liability
What it is. Disclosure, human review, bias testing, accuracy substantiation and vendor terms for the AI the company ships to customers and the AI it uses internally, built to the statutes that already bind rather than to a framework, and maintained as a line in general and administrative expense rather than a project.
The line it moves. General and administrative expense; the risk retained; and, through liability, the multiple.
Typical range and the evidence. Strong, because it is law and case law. The EU's Digital Omnibus on AI entered into force on July 27, 2026, moving the stand-alone high-risk obligations to December 2, 2027, while Article 50 transparency, the duty to tell users they are dealing with an AI and to label AI-generated content, still applies from August 2, 2026, with watermarking for systems already on the market from December 2, 2026, and penalties up to "EUR 35 million or 7 percent of global annual turnover."6 A 2026 budget built on the old August 2026 high-risk deadline is overbuilt; a product without Article 50 disclosure is late. In the United States the exposure is product liability: in Mobley v. Workday a federal court certified in May 2025 a nationwide collective of applicants aged forty and over against the software vendor, on the theory that the vendor acted as its customers' agent.7 The FTC's Operation AI Comply produced the case that matters for accuracy claims: Workado advertised its detection software as "98% accurate" when it was "only 53%," and the order requires substantiation on file.8 The SEC's and DOJ's AI-washing cases (Delphia, Joonko, Nate, Presto) turn on two questions a buyer now asks a seller: is a human in the loop, and whose model is it.9 And the British Columbia tribunal in Moffatt v. Air Canada held that "it makes no difference whether the information comes from a static page or a chatbot," which settles who is liable for what an agent tells a customer.10 In healthcare the state rules are specific: California's disclaimer on generative-AI patient communications, its bar on AI denying care on medical-necessity grounds, Texas's disclosure duty and $200,000 per-violation penalties, Colorado's re-enacted act from January 2027 with covered entities largely exempt, and Utah's and Illinois's rules on mental-health chatbots.11 Nobody has published a credible cost for an AI governance program, and the IAPP's 2025 finding that 77% of organizations are working on one is the only adoption figure worth citing.12
Conditions. The register (O13) as the inventory; a policy that names the human sign-off points (money, patients, employment, coverage); marketing claims about AI performance substantiated on file before publication; customer contracts updated to describe AI processing, sub-processors and retention before the first customer-facing agent ships.
Kill criteria. Any AI feature shipped without its disclosure, its evaluation set and its human sign-off point documented in the register.
- AI features with disclosure, evaluation and sign-off documentedRiskAt close0%Year 1100%Year 3100%
- Performance claims with substantiation on fileRiskAt closeNoneYear 1AllYear 3All
- Adverse-impact audits on screening toolsRiskAt closeNoneYear 1QuarterlyYear 3Quarterly
- Customer contracts updated for AI processingRiskAt close0%Year 1100%Year 3100%
Horizon and stage. Deploy. Day one hundred to year one.
How it translates. A: the healthcare statutes in full; a person signs every clinical document and every coverage outcome. B: the product makes regulatory determinations, so the sign-off and the audit trail are the product. C: consumer-facing disclosure and payments rules. D: Article 50 at scale, and employment-tool liability if the product touches hiring. E: enterprise customers will send their own AI questionnaires.
X3 · Data governance and rights
What it is. De-identification standards, retention terms, customer consent and data-use clauses turned from a constraint into an asset: the company knows which data it may use for which purpose, can prove it, and has written the rights it needs into the contracts it signs from now on.
The line it moves. The multiple, because an underwritten data asset is worth more than a claimed one; and the feasibility of R2 and R10.
Typical range and the evidence. Strong for the rules, and the rules are where the value hides. Under HIPAA, analytics, evaluation and any non-covered tool use data de-identified by removing the eighteen identifier classes at 45 CFR 164.514(b)(2) or under an expert determination that re-identification risk is "very small," and prompts and outputs containing protected health information are electronic protected health information.13 The provider terms are facts to record, not assumptions: Anthropic's covered models require thirty-day retention and cannot coexist with zero-data-retention on one organization; OpenAI's business associate agreement covers its API and enterprise products, not its Business plan.14 The diligence finding from P2 sits underneath this card: no published figure exists for how often a software target lacks the contractual right to use customer data for model training, and the buyer who counts it at diligence and fixes it in year one owns something the seller did not.
Conditions. The contract database from P2; the gateway from P7 enforcing data classes by model; a data-use clause approved by counsel in the standard paper; a de-identification method that survives an expert review.
Kill criteria. Any model call carrying regulated data to an endpoint without the right agreement is an incident and stops the agent.
- Customers whose contracts permit data use for product improvementFeasibility of R2, R10At closeCounted in P2Year 1Rising at renewalYear 3Majority
- Model calls carrying regulated data outside a covered endpointRiskAt closeUnknownYear 1ZeroYear 3Zero
- Retention terms recorded per agent in the registerRiskAt closeNoneYear 1AllYear 3All
- Data classes with an approved de-identification methodRiskAt closeNoneYear 1AllYear 3All
Horizon and stage. Reshape. Day one hundred to year one.
How it translates. A: protected health information governs everything. B: the data-use right across customers' submissions is the asset being built. C: merchant and cardholder data under PCI, and consumer data under state privacy law. D: uniform terms make the fix a single change. E: bespoke paper makes it a negotiation per customer.
X4 · Add-on integration
What it is. Code, data, customer, support and back-office consolidation of acquired add-ons at a fraction of the historical cost and time: the acquired codebase migrated or retired with agents (O2), customers migrated with the onboarding tooling (G2), support desks merged behind one resolution agent (G1), finance and procurement folded into the platform's (O6, O12), and the acquired company's SaaS portfolio reclaimed on day one.
The line it moves. One-time integration cost; then every G and O lever at the combined scale.
Typical range and the evidence. Strong for the volume, medium for the cost, and the cost is where the public record is worst. The PitchBook figures above say add-ons are now the majority of software deals. No consultancy has published a 2023 to 2026 benchmark of integration cost as a share of deal value or months to integrate for software buy-and-build; the "1% to 3% of deal value" line that circulates online is unsourced and does not appear here. The evidence for the mechanism is Google's migration paper and Amazon's Java campaign (O2): the code half of an integration compresses, and the bottleneck moves to senior-reviewer capacity, which is the scarce resource in a sponsor-backed integration.15 No sponsor has published figures for AI-driven consolidation of support or finance across add-ons, so the non-code half is run as an internal measurement.
Conditions. A platform that is itself integrated (P7 done once, not per company); a migration playbook; senior reviewers reserved for the integration rather than borrowed from the roadmap; the acquired company's contracts read with P2 before close.
Kill criteria. Integration cost above 150% of plan at the halfway point pauses the program; customer migration with retention below the platform's own rate reverses it.
- Months to migrate an add-on's customers to the platformIntegration costAt close12 to 24Year 19Year 36
- Integration cost, % of add-on enterprise valueIntegration costAt closeUnmeasuredYear 1MeasuredYear 3Falling
- Acquired codebases retiredR&D, hostingAt close0Year 11Year 3All but one
- Add-on support merged behind the platform's agentSupport COGSAt closeNoYear 1YesYear 3Yes
Horizon and stage. Reshape. Years one to three.
How it translates. A: a services or regional add-on, evaluated against the platform the company has become. B: content and framework add-ons, where the integration is the rules engine. C: the roll-up pattern, where each add-on brings merchants to the payments rail. D: tuck-ins of features; integration is a product decision. E: the business is the sum of prior add-ons, and this lever is the reason the codebases are still separate.
X5 · Continuous diligence
What it is. P1 through P4 run as a standing capability on the add-on pipeline, so that every target is read in full before the letter of intent and the platform's own data (churn reasons, pricing, product gaps) is compared against the target's.
The line it moves. Price paid on add-ons; integration risk.
Typical range and the evidence. Weak, and stated so. Blackstone's account of using models to replicate a target's own models within hours, which "contributed to a decision to pass on the deal," is the one concrete published example of AI diligence killing a deal; it names no target.16 EQT, the most-cited AI-native sponsor, has published no hit rates for its sourcing platform.17 No PE firm publishes its own diligence hours saved. The card exists because the platform lever (X4) is only as good as the price paid, and the tooling is the same tooling the company already runs.
Conditions. P1 to P4 tooling retained after close; a deal-team analyst who owns the pipeline; the platform's own warehouse as the comparison set.
Kill criteria. A target whose automated findings are not reproduced by a person on a sample before the letter of intent.
- Targets read in full before letter of intentPriceAt close0%Year 1100%Year 3100%
- Days from data room to first-pass findingsDeal costAt closeWeeksYear 1DaysYear 3Days
- Post-close surprises above thresholdIntegration riskAt closeBaselineYear 1FewerYear 3None
Horizon and stage. Reshape. Year one to exit.
How it translates. C and E, where the add-on pipeline is real; A where a regional add-on is contemplated; marginal for B and D.
X6 · Exit readiness
What it is. The lever ledger, the baselines, the register and the AI revenue disclosure built as the data room from day one, so that the buyer's diligence (which will be the tooling in P1 to P4) finds what the seller already knows, and the AI claims survive it. It includes the honest reporting of payments revenue on gross profit and net take, the seat-exposure figure from P4 updated annually, and the Rule of 40 position stated in the buyer's terms.
The line it moves. The multiple.
Typical range and the evidence. Strong for the multiples, medium for any AI premium. Software Equity Group's 2026 annual report gives the arithmetic: median EV to trailing revenue in the fourth quarter of 2025 of 2.4x for companies growing 10% or less, 5.8x for 10% to 20%, 12.7x for 20% to 30%; and by Rule of 40 band, 1.6x at 10% or under, 6.0x at 20% to 30%, 9.8x at 30% to 40% and 14.0x above 40%, with the note that "profitability provides valuation support, but growth is the primary driver of multiple expansion beyond 10.0x."18 (Its above-30%-growth band prints below the 20% to 30% band, an inversion that reads as sample noise and is not cited.) SaaS M&A in the same report averaged 6.9x and had a median of 4.0x, which is how much a handful of outliers distort market talk. Aventis's August 2026 update puts the median public multiple at 4.6x and the median Rule of 40 score at 26, with only fifteen percent of the index above 40 and the median company at 11.8% growth plus 14.6% margin: buying its score with margin, which is where these levers act.19 McKinsey's 130% premium for product-embedded AI is cited on the hub with its missing growth control; the a16z view that 85% to 90% gross margin is "an orange flag" is the counterweight, and for a seller both are true at once.20 The AI-washing cases in X2 are the buyer's checklist. Bessemer's Rule of 40 framing, with top-decile cloud companies at around 48, is the language the buyer will use.21
Conditions. O13's register maintained from day one; P4's exposure judgment revisited annually; payments reported on gross profit; a data room that is the operating system's export rather than a project.
Kill criteria. Any AI claim in the exit materials without a substantiating measurement in the register.
- Rule of 40 scoreMultipleAt closeBaselineYear 1+5Year 3+15 to +25
- Revenue with a product-embedded AI componentMultipleAt close0%Year 15%Year 325 to 40%
- Seats in agent-compressible roles, % of ARRMultipleAt closeMeasuredYear 1FallingYear 3Below 25%
- Lever ledger current to the last quarterData roomAt closeNoYear 1YesYear 3Yes
Horizon and stage. Reshape. Year two to exit.
How it translates. A: from a 34 to a 52 on the Rule of 40, with product-embedded AI. B: a regulated-workflow multiple defended with retention and pricing power. C: an EV-to-gross-profit story, because payments compress EV to revenue mechanically. D: the seat-exposure story, told with the migration data. E: the mix story, services down and subscription up, told so that shrinking services revenue reads as improvement.
Sources
- Bain & Company, Global Private Equity Report 2026, March 2026, and press release February 23, 2026. https://www.bain.com/insights/topics/global-private-equity-report/ (I)↩
- PitchBook, "PE pivots as platform buyouts in software fall to decade low," June 25, 2026, https://pitchbook.com/news/articles/pe-pivots-as-platform-buyouts-in-software-fall-to-decade-low ; PitchBook, "Surge in add-ons and club deals signal investor caution in Europe," Q1 2026 data, https://pitchbook.com/news/articles/surge-in-add-ons-and-club-deals-signal-investor-caution-in-europe (I)↩
- HHS Office for Civil Rights, MMG Fusion resolution agreement, March 5, 2026. https://www.hhs.gov/press-room/ocr-mmg-fusion-hipaa-agreement.html (I, regulator)↩
- Vanta, State of Trust 2025, October 29, 2025. https://www.businesswire.com/news/home/20251029144534/en/Vanta-State-of-Trust-2025-AI-Threats-Outpace-Security-Expertise (V, commissioned survey)↩
- EIOPA, Digital Operational Resilience Act, https://www.eiopa.europa.eu/digital-operational-resilience-act-dora_en ; Jones Day, "Digital Operational Resilience Act Now in Effect," January 2025 (I, regulator and law firm)↩
- Gibson Dunn, "EU AI Act Omnibus: Agreement Postponed High-Risk Deadlines and Other Key Changes," May 27, 2026, https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/ ; Usercentrics, "EU AI Act high-risk delay and Article 50 transparency," updated July 31, 2026, https://usercentrics.com/knowledge-hub/eu-ai-act-high-risk-delay-article-50-transparency-consent/ (I, statute via two law and compliance sources)↩
- Holland & Knight on Mobley v. Workday, N.D. Cal., May 16, 2025. https://www.hklaw.com/en/insights/publications/2025/05/federal-court-allows-collective-action-lawsuit-over-alleged (I)↩
- Benesch, "One Year In, FTC's 'Operation AI Comply' Continues," October 21, 2025. https://www.beneschlaw.com/insight/one-year-in-ftcs-operation-ai-comply-continues-under-new-administration-signaling-enduring-enforcement-focus/ (I, public enforcement actions)↩
- Global Investigations Review, "US enforcement agencies intensify scrutiny of AI washing," Americas Investigations Review 2026. https://globalinvestigationsreview.com/review/the-investigations-review-of-the-americas/2026/article/us-enforcement-agencies-intensify-scrutiny-of-ai-washing (I)↩
- McCarthy Tétrault, "Moffatt v. Air Canada: A Misrepresentation by an AI Chatbot," on 2024 BCCRT 149, February 19, 2024. https://www.mccarthy.ca/en/insights/blogs/techlex/moffatt-v-air-canada-misrepresentation-ai-chatbot (I, published decision)↩
- California AB 3030, SB 1120, AB 489 via LegiScan; Texas HB 149, https://capitol.texas.gov/tlodocs/89R/billtext/html/HB00149F.htm ; Colorado SB26-189 and HB26-1139, https://leg.colorado.gov/bills/sb26-189 ; Utah HB 452; Illinois HB 1806 (I, statutes)↩
- IAPP, AI Governance Profession Report 2025, May 21, 2025. https://iapp.org/resources/article/at-a-glance-ai-governance-profession-report-2025/ (I)↩
- 45 CFR 164.514(b); 45 CFR 160.103; 45 CFR 164.308(a)(1)(ii)(A), eCFR. https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.514 (I, regulation)↩
- Anthropic, "Covered Models under a Business Associate Agreement," July 1, 2026; OpenAI BAA help article. https://support.claude.com/en/articles/15455031-covered-models-under-a-business-associate-agreement-baa ; https://help.openai.com/en/articles/8660679 (V, vendor documentation)↩
- Nikolov et al., arXiv:2501.06972, January 2025, https://arxiv.org/abs/2501.06972v1 (I); AWS DevOps Blog, August 1, 2024, https://aws.amazon.com/blogs/devops/amazon-q-developer-just-reached-a-260-million-dollar-milestone (V, internal estimate)↩
- Blackstone, "Accelerating Value with AI," April 25, 2024. https://www.blackstone.com/insights/article/accelerating-value-with-ai/ (V, sponsor's own account)↩
- EQT, "AI Promises to Make Private Equity Faster," October 24, 2025. https://eqtgroup.com/thinq/technology/first-ai-native-private-equity-firm (V, no outcome data)↩
- Software Equity Group, 2026 Annual SaaS Report, March 2026. https://sandhill.com/wp-content/uploads/2026/03/SEG-Research-2026-Annual-SaaS-Report.pdf (I)↩
- Aventis Advisors, "SaaS Valuation Multiples: 2015–2026," August 31, 2026. https://aventis-advisors.com/saas-valuation-multiples/ (I, practitioner)↩
- McKinsey, June 23, 2026, as on the hub (I); Mostly Metrics reporting Sarah Wang of a16z, November 9, 2025, https://www.mostlymetrics.com/p/can-bad-gross-margins-ever-be-a-good-sign (I)↩
- Bessemer Venture Partners, "The Rule of X," updated July 18, 2025. https://www.bvp.com/atlas/the-rule-of-x (I)↩
Boring AI
AI for manufacturers, operators and service businesses — not startups chasing hype. Every other week.
Your address is used only to send this newsletter. No sharing, no selling, no tracking pixels. Unsubscribe from any issue.