Transformation Risk insights series

A practical use case for managing transformation risk in divestitures: How assurance protects value before and after separation

  • July 23, 2026

This series explores how taking a portfolio-wide approach can help organizations align transformation efforts, reduce risk, and drive meaningful outcomes across business, tech, and controls.

Key takeaways:

  • Divestitures are business transformations, not just transactions—and can introduce significant risks across operations, technology, data, controls and governance if separation planning is incomplete.
  • The greatest post-separation challenges often center on financial reporting and compliance, shared technology and data dependencies, transition services agreements, governance, and operating model changes.
  • Organizations can reduce disruption by defining the separation perimeter early, strengthening reporting and control readiness, identifying stranded costs and capability gaps, and designing a future-state operating model before close.
  • After separation, the focus shifts to stabilizing operations, reducing residual risks, executing TSA exits, and embedding new processes and controls to help the remaining business operate effectively and realize the intended benefits.

Divestitures can reshape your portfolio, streamline your operations, sharpen strategic focus, and unlock value that can strengthen the business that remains. But the same transactions that promise focus and efficiency can expose hidden dependencies and risks across both sides of the transaction. While the separated business must be ready to operate independently or transition into a buyer’s environment—with reliable reporting, controls, systems, governance, and talent—the remaining company faces a different risk profile. Unsupported carve-out financials, shared technology and data dependencies, control obligations under transition services agreements (TSAs), stranded costs, control and capability gaps, and operating model disruption can all erode value after close. A divestiture is more than just a legal, tax, or financial transaction. It's a simultaneous transformation of operations, technology, data, contracts, and controls.

“Control readiness isn’t a back-office workstream. It’s a deal value issue.”

Helena Yoon, Partner, Digital Assurance & Transparency, PwC US

Targeting the transformation risks inherent to divestitures and carve-outs

What are the biggest transformation risks in divestitures and carveouts?

For companies that have just divested or spun off a part of their business, risk often concentrates in four areas: regulatory reporting and compliance; data, technology, and TSAs; program governance; and operating model, including people.

RemainCos often have significant responsibility for the financial, legal, tax, and compliance foundation of the separation. If that foundation is incomplete or unsupported, issues can surface during audit, regulatory review, buyer diligence, valuation discussions, or post-close operations.

Carve-out financial statements or financial information, where required, are a common pressure point. To accurately prepare them, you’ll need a clear definition of the business being separated, complete data, supportable allocation methodologies, and well-documented assumptions across everything from revenue and cost allocations to corporate overhead, shared service charges, intercompany balances, and management judgments. There can also be residual exposure: incomplete legal restructuring may result in unexpected tax exposure, compliance issues, licensing and permitting challenges, stranded obligations, or liabilities that follow RemainCo post-separation.

Intercompany analysis can uncover similar risk: poor visibility into intercompany balances, guarantees, services, settlements, and transfer pricing arrangements can all lead to financial misstatements, cash flow disruption, tax risk, and settlement disputes.

Technology and data dependencies are often more complex than expected. Shared systems, applications, infrastructure, reports, interfaces, licenses, assets, and third-party tools can easily create separation delays and control gaps if they aren’t identified early.

A robust transaction perimeter and entanglements analysis should determine what transfers, what remains, what’s shared, what should be replicated, and what needs temporary support under a transition services agreement. Incomplete identification of shared systems, assets, applications, and dependencies may lead to any combination of operational disruption, TSA expansion, ownership disputes, and separation delays.

Contract and data separation can create similar risk. Customer, vendor, outsourcing, technology, licensing, real estate, and service contracts may include assignment restrictions, consent requirements, shared-use provisions, or embedded operational dependencies. Without that clarity, organizations can face privacy, cybersecurity, continuity, and reporting risks.

TSAs can help maintain continuity, but they also introduce control complexity. If you provide services that affect the separated business’s financial reporting—like payroll, ERP access, transaction processing, report generation, IT operations, or access administration—that can lead to ill-defined control responsibilities, service levels, evidence expectations, audit rights, issue escalation, performance reporting, and exit plans.

Successful divestitures happen when your different workstreams all move together—finance, tax, legal, IT, cybersecurity, data, HR, operations, compliance, contracts, communications, TSA. Without disciplined governance, these groups may hit individual milestones, while broader transformation risks remain unresolved. Two areas often create value leakage:

Stranded costs and dyssynergies — When a business is divested, the RemainCo may retain corporate overhead, shared service costs, underutilized systems, vendor commitments, stranded facilities, duplicated roles, or operational inefficiencies. Failure to identify and address these costs can negatively affect profitability, operating margins, and value realization after close.

Post-close capability gaps — A divested business may take people, processes, systems, data, licenses, or institutional knowledge that your company still needs. If these dependencies are not identified early, you may be left without critical capabilities, processes, or controls after close.

A divestiture changes how your remaining business operates. Roles shift. Reporting lines change. Shared services may be reduced or redesigned. Control owners may transfer with the divested business, remain with your company, or exit the organization. Undefined operating structures, unclear accountability, and talent gaps can result in Day One instability, operational disruption, control breakdowns, and key employee attrition. If accountability isn’t reassigned quickly, your organization can face missed approvals, incomplete reconciliations, access issues, reporting delays, and audit findings.

Separation success depends as much on organization design and talent planning as it does on legal execution.

How do you tackle transformation risk in divestitures or carveouts?

The strongest divestiture programs address RemainCo risks before close. That means looking across the remaining enterprise, not just the asset being separated. The key is to understand how business, technology, data, controls, and people decisions interact across RemainCo. Management should focus on four priorities:

Validate the separation perimeter. Identify legal entities, contracts, intercompany arrangements, shared systems, data, assets, services, and dependencies. Legal separation should be coordinated with tax, treasury, regulatory, operational, technology, data, and control considerations so RemainCo understands what transfers, what remains, what is shared, and what requires temporary support. The transaction perimeter may define what is being sold, but the separation plan should also clarify the obligations, services, systems, data, and controls RemainCo must retain, redesign, or exit after close. Without that clarity, RemainCo may face Day One service disruption, retained obligations, stranded contracts, orphaned systems, delayed TSA exits, or unassigned responsibilities that are costly to remediate after close.

Establish reporting and control readiness. Support carve-out financial statements or financial information, define control ownership, document evidence expectations, and assess SOC 1 needs where TSA services affect financial reporting. Data separation requires equal discipline: management should define which data transfers; which data must be retained for legal, tax, regulatory, audit, or operational purposes; which data should be restricted, who can access it, and how it will be protected; and how completeness and accuracy will be validated. Without this discipline, RemainCo may struggle to substantiate retained financial information, preserve audit evidence, demonstrate control ownership, or support judgments made during the separation. These gaps can affect close timelines, create TSA-related control ambiguity, increase audit or regulatory scrutiny, and weaken confidence in RemainCo’s post-close reporting and control environment.

Identify value leakage risks. Quantify stranded costs, dyssynergies, capability gaps, and other operating exposures that could affect margins or continuity after close. A transaction management office should provide leadership with visibility into cost exposures, capability gaps, unresolved decisions, and remediation owners needed to protect value. For RemainCo, value leakage often shows up as recurring cost drag or operational friction rather than one-time separation cost. Stranded overhead, duplicated roles, underutilized technology, retained vendor commitments, and unresolved capability gaps can reduce margins, slow execution, and make it harder for the remaining business to achieve the simplification and value creation expected from the divestiture.

Design the future-state operating model. Define the governance, decision rights, talent needs, service delivery model, process ownership, control accountability, technology enablement, and TSA exit plans needed for the post-separation RemainCo. Rather than simply shrinking the legacy operating model, management should redesign how work gets done, who owns key decisions, and how services and controls will operate after close. Without that redesign, RemainCo may be left with unclear accountability, fragmented service delivery, insufficient process ownership, or talent gaps. These issues can lead to operational disruption, delayed decision-making, control gaps, and slower stabilization at the exact point when the remaining business needs continuity and focus.

On Day One, your goal should be clarity. Leaders should know which services remain transitional, who owns key controls, how evidence will be retained, how access will be governed, how issues will be escalated, and what must happen to exit TSAs on schedule.

After you close, the focus shifts to stabilization and value realization: reducing stranded costs, closing capability gaps, updating controls, executing systems and data separation, monitoring TSA performance, and embedding the new operating model.

Risk will always surface in one form or another. Whether management identifies it during planning or reacts to it after close is where value can be lost. The earlier you address these issues, the better positioned you are to protect value, reduce disruption, and operate with confidence after separation.

How can PwC help?

PwC helps organizations manage divestiture risk across their transaction lifecycles, with different readiness assessments both before and after separation. Our focus is on protecting your value, maintaining your control, and preparing your company for Day One—and beyond.

Before separation

PwC can help organizations improve deal readiness, identifying separation dependencies and reducing risks that could affect reporting, TSA design, and post-close value realization.

  • Carve-out financial statement and financial information readiness
  • Legal entity, intercompany, and control separation assessments
  • SOX and ICFR readiness, where applicable, including related IT general control considerations
  • Program governance and TMO risk oversight
  • Transaction perimeter and entanglements analysis
  • Contract, data, systems, access, and cybersecurity separation planning
  • TSA scope, governance, control ownership, audit rights, evidence expectations, and exit planning
  • SOC 1 readiness assessment for financially relevant TSA services
  • Stranded cost and dyssynergy analysis
  • Cyber, identity and access risk assessment
  • Future-state capability gap assessment
  • Target operating model, organization design, and talent planning

After separation

PwC can also help your management teams stabilize a remaining business, monitor TSA performance, reduce residual risk, and embed your new future-state operating model.

  • Post-close control framework redesign and documentation
  • ITGCs, access management, and cybersecurity control alignment
  • SOX and ICFR monitoring, where applicable, including related ITGC considerations
  • Policy, process, and control harmonization
  • TSA governance, monitoring, and exit execution
  • SOC 1 reporting support for in-scope TSA services
  • Data separation validation and migration control support
  • Continuous monitoring and executive risk reporting
  • Stranded cost reduction and dyssynergy tracking
  • Remediation of post-close capability gaps
  • Operating model refinement and accountability alignment
  • Change management and control owner training

The most effective divestitures do more than separate a business. They take a portfolio-wide view of transformation risk to help your company emerge with clearer accountability, stronger controls, fewer dependencies, and a sharper path to value realization—because what remains after separation matters as much as what was sold.

Digital Assurance and Transparency

Powering digital progress through trust

Explore more from our Transformation Risk insights series

Contact us

Helena Yoon

Helena Yoon

Partner, PwC US

Brandon Laws

Brandon Laws

Partner, PwC US

Michael  Niland

Michael Niland

US Divestitures Services Leader, PwC US

Casey Donahue

Casey Donahue

Principal, Cyber, Risk & Regulatory, PwC US

Follow us