blog

AstraZeneca, Bristol Myers Squibb & the Hidden IT Challenge Behind Every Mega-Merger

Written by Gareth Martin | Aug 4, 2026, 2:32:29 PM

Why operational data quality could determine whether a $400 billion merger creates value, or destroys it.

Reports that AstraZeneca has held preliminary discussions with Bristol Myers Squibb have raised the prospect of one of the largest pharmaceutical mergers in history.

It's early, but the scale alone makes the story significant. Together, the two businesses would have a combined market capitalisation of almost $400 billion (before the reports emerged). A completed deal could create the world’s fourth-largest pharmaceutical company by market value and potentially the largest by revenue. While a company’s market capitalisation and a country’s annual GDP measure fundamentally different things, for a comparison (not equivalence), a combined valuation approaching $400 billion would be comparable to the annual economic output of Chile or Pakistan.

Behind every transaction of this size sits another merger that receives far less attention: The merger of two enormous technology estates That is where much of the promised value will either be realised, or quietly lost. The strategic case may be clear. The operational case is not. Mergers do not create value simply by adding two balance sheets together. The gap between promised value and delivered value is the real M&A challenge. Technology integration sits at the centre of it.

Every Acquisition Creates An Operational Data Problem

On the day a transaction completes, the legal ownership may change immediately. The technology estate does not. Instead, the combined organisation inherits:

    • two application portfolios
    • two or more CMDBs
    • multiple discovery tools
    • overlapping cloud environments
    • duplicated infrastructure
    • competing identity platforms
    • separate software contracts
    • different asset registers
    • inconsistent service models
    • conflicting data standards
    • and two sets of operational processes

Both businesses may possess detailed information about their estates. That does not mean the information agrees. One database may describe an asset using its hostname. Another may record it by serial number. A cloud platform may identify it through an instance ID. A procurement system may classify it according to the department that bought it. The same asset can therefore appear several times, with different owners, lifecycle states, locations and business relationships. Visibility alone does not resolve that conflict. The combined organisation needs to establish which records are accurate, which are duplicates, how assets relate to services and which systems are genuinely business critical. Until that happens, leaders are not managing one technology estate. They are managing several incomplete interpretations of it.

Compliance: The Evidence Burden Multiplies

A pharmaceutical merger would bring together highly regulated research, manufacturing, clinical, commercial and corporate environments operating across multiple jurisdictions. The combined business would need to understand:

    • where regulated and sensitive data resides
    • which applications process that data
    • which infrastructure supports critical research or manufacturing
    • who owns each application and service
    • whether required controls are operating
    • which systems are approaching end of life
    • and whether audit evidence is complete and current

The problem is not simply identifying the regulations that apply. The harder task is proving that the organisation’s real operational environment complies with them. During an acquisition, data lineage and ownership can become blurred. Applications change hands. Infrastructure is migrated. Support responsibilities move between teams. Temporary integrations become permanent. Legacy systems remain active longer than planned. Without accurate asset, application and dependency data, compliance teams may be unable to show:

    • what changed
    • when it changed
    • who approved it
    • what business service was affected
    • and whether the required controls remained in place

This is especially dangerous when the two businesses use different definitions, classification systems or governance models. The combined company may believe it has a control framework. What it may actually have is two control frameworks sitting over an incomplete operational picture.

Gartner predicts that by 2027, 80% of data and analytics governance initiatives will fail where they are not connected to clear business outcomes. In a merger, governance cannot remain a theoretical exercise. It has to support concrete outcomes such as regulatory evidence, operational resilience and safe system consolidation.

Cost: You Cannot Eliminate What You Cannot Identify

M&A business cases often rely heavily on cost synergies. Technology teams are expected to remove duplication across:

    • software licences
    • applications
    • infrastructure
    • cloud services
    • managed-service contracts
    • hardware support
    • data centres
    • security tooling
    • and operational teams

The commercial logic is sound. The execution is much harder. Consider software licensing. Both companies may be paying for the same product under separate agreements. Some licences may be assigned but unused. Others may be installed without a confirmed entitlement. Contract renewal dates may be scattered across spreadsheets, procurement platforms and asset-management systems. Without a reconciled view, the new organisation risks making one of two expensive mistakes:

    • Keeping duplication because it cannot confidently identify what is redundant
    • Removing technology without understanding the services and processes that depend on it

The same applies to cloud resources. A cloud instance may appear inactive but still support a monthly reporting process. An application may look duplicated but serve a specific regulatory jurisdiction. A legacy server may appear safe to retire while still supporting a laboratory or manufacturing dependency that was never documented. Cost reduction without trusted context becomes guesswork, and poorly informed cost reduction can create more expense than it removes.

Efficiency: Two Operating Models Do Not Automatically Become One

Mergers frequently produce overlapping teams and processes. Both organisations may have their own:

    • service desks
    • incident-management processes
    • change models
    • monitoring platforms
    • discovery schedules
    • escalation paths
    • asset-management practices
    • and technical specialists

The immediate temptation is to standardise quickly. But standardisation without operational understanding can slow the business down. Teams spend months attending workshops to establish:

    • which systems exist
    • which platform owns each record
    • which data source should take precedence
    • who supports each application
    • and which integrations can safely be removed

This is the hidden labour cost of weak operational data. Highly paid specialists are pulled into reconciliation exercises. Teams maintain temporary spreadsheets. Decisions are deferred because nobody trusts the available information. Integration programmes become dependent on a handful of people who understand the legacy environments.

Efficiency is not achieved merely by selecting a common ITSM platform or CMDB. It is achieved when the organisation can create a trusted, shared operational model that people can actually use.

Operational Performance: Integration Cannot Disrupt The Business

The IT estate cannot simply stop while it is redesigned. Incidents will continue. Changes will continue. Security vulnerabilities will continue to emerge. Applications will continue to be deployed. Cloud environments will continue to change. The organisation therefore faces a difficult balancing act: integrate rapidly enough to capture value, but carefully enough to avoid operational disruption. This requires dependable answers to fundamental questions:

    • What supports this business service?
    • Which applications depend on this database?
    • What will be affected if this server is migrated?
    • Which team owns the service?
    • Has the environment changed since the integration plan was approved?
    • Is the operational model still accurate?

When those answers are unavailable, change becomes slower and riskier. Teams either delay decisions while they investigate, or proceed without a complete picture. Neither outcome supports the merger case.

Data Quality Is Not An IT Hygiene Issue

It is tempting to treat data cleansing as a secondary workstream, something to address after the major integration decisions have been made. That is backwards. The quality of operational data determines whether those integration decisions can be made intelligently in the first place. Poor-quality data undermines:

    • due diligence
    • synergy modelling
    • application rationalisation
    • licence optimisation
    • infrastructure consolidation
    • compliance reporting
    • service continuity
    • cyber-risk assessment
    • and AI adoption

It also prevents executives from determining whether the merger is delivering the value promised. The technology estate may be changing, but leadership still needs a consistent baseline against which cost, risk and performance can be measured. Without that baseline, the organisation cannot separate genuine improvement from reporting noise.

TekWurx: Delivering Operational Trust At Enterprise Scale.

TekWurx has spent twenty years helping some of the world's largest and most highly regulated organisations to establish trusted operational data. Recent examples include:

    • A Federal Reserve Bank selected TekWurx, who successfully migrated an enterprise discovery platform within a 40-day window. All while maintaining 99.9% CMDB accuracy and eliminating more than £1 million in operational costs and inefficiencies.

    • When an international stock exchange tried to implement a discovery programme, it only identified only 7% of expected assets. After four failed internal projects. TekWurx used our product uControl, to transform coverage to 98% . This enabled, trusted service mapping, cloud integration and a CMDB that became a reliable foundation for operational decision-making.

    • When an International Bank was weeks away from an audit, they turned to uControl, which successfully modelled 633 business applications and delivered 100% DORA compliance within a single working week.

uControl: Turn Visibility Into Trusted Operational Context

Discovery establishes what exists. uControl addresses the next and more difficult question: Which operational information should the combined organisation trust?

uControl ingests data from multiple operational systems, normalises data and reconciles conflicting information to create trusted service context. Instead of forcing an organisation to accept one inherited platform as the unquestioned source of truth, it allows data from multiple discovery tools, CMDBs, ITSM platforms and asset repositories to be compared and governed.

That makes it possible to:

    • establish authoritative records
    • connect infrastructure to applications and services
    • model both discovered and non-discovered environments
    • identify changes and drift
    • preserve traceability
    • and provide governance across the integration lifecycle

uControl explicitly addresses the problem of operational information becoming fragmented, duplicated and inconsistent across discovery, ITSM, CMDB and asset repositories, the exact condition created by large-scale M&A.  Discover both estates. Reconcile operational data. Identify cost opportunities. Protect service performance. Book a 30-minute uControl demonstration and we'll show you how to acquire complete operational trust in your new IT estate.