Broker guides

TMS Vendor Acquired? A Freight Broker’s 30-Day Due-Diligence Checklist

# TMS Vendor Acquired? A Freight Broker’s 30-Day Due-Diligence Checklist

A transportation management system can sit inside quoting, dispatch, documents, billing handoffs, reporting, and customer service. When its vendor is acquired, the useful first question is not “Should we leave?” It is “What has actually changed, what remains unknown, and which operating evidence do we need before the next load or renewal?”

On August 24, 2026, Descartes announced that it acquired Tai Software for approximately US$100 million in cash. Tai’s homepage links to the same announcement. That confirms an ownership event. It does not establish a price increase, support change, product shutdown, forced migration, staffing change, security problem, or contract amendment. Descartes also labels expected integration and benefits as forward-looking statements. Treat the announcement as a trigger to verify—not a reason to speculate.

This checklist gives freight brokerage owners and operations managers a 30-day method for building an evidence file without disrupting live freight.

> Scope: This is an operational due-diligence method, not legal, cybersecurity, privacy, accounting, or contract advice. Your agreement and applicable law control. Use qualified advisers for material contract, security, or data decisions.

Day 0: establish the fact pattern

Start with first-party records. Save the dated announcement, the vendor’s customer notice, and any notice delivered through your contracted communication channel. Record four facts:

  1. the acquiring and acquired legal entities;
  2. the announcement and closing dates, if stated;
  3. the source URL or notice identifier; and
  4. what the source explicitly says about current customers.

Then create an unknowns register. Put every unanswered question in it instead of turning an absence of information into a conclusion. Useful statuses are `confirmed`, `unchanged in writing`, `change announced`, `answer pending`, and `not applicable`.

Hours 1–48: preserve the current state

Do not reconfigure production merely because ownership changed. Preserve a dated baseline that lets the team detect a real change later:

  • executed agreement, order form, amendments, renewal date, cancellation notice period, and current invoice;
  • contracting entity, payment instructions, account owner, support contacts, hours, escalation path, and open case numbers;
  • administrator list, active users, roles, service accounts, API or EDI credentials, and connected partners—without copying secret values into the review file;
  • enabled modules, current plan, usage allowances, purchased services, and written commitments;
  • one authorized sample export and a list of available export formats;
  • a recent completed-load record, its supporting documents, and the financial-system handoff evidence; and
  • privacy notice, security documentation, incident contact, subprocessor list, retention terms, and deletion process currently supplied by the vendor.

Keep the baseline in an approved location with restricted access. The FTC’s business security guidance recommends limiting access to sensitive data, setting security expectations with service providers, and monitoring whether providers meet those expectations. It does not say an acquisition itself is a security incident.

Days 3–10: send one written question set

Route one consolidated request through the vendor’s official support or account channel. Name an owner and due date for every answer.

1. Contract and billing

  • Does the contracting entity change?
  • Do remit-to details, tax forms, billing contacts, renewal mechanics, price, included usage, or cancellation deadlines change?
  • Is any affirmative customer action required? If so, where is it stated in the agreement or notice?

Never change payment instructions from an email alone. Validate them through a known vendor channel and your brokerage’s payment-control process.

2. Support and escalation

  • Are support hours, channels, response targets, named contacts, or escalation paths changing?
  • Will existing cases keep their identifiers and history?
  • What is the effective date of any change?

3. Product and integrations

  • Which production features, modules, URLs, mobile apps, APIs, EDI connections, webhooks, load-board links, tracking providers, accounting connections, and customer or carrier portals are changing?
  • Which items are live today, contractually committed, planned, or merely being evaluated?
  • Will credentials, allowlists, partner agreements, endpoints, or test environments need action?

Ask for product-specific answers. “The platforms will work together” is not an acceptance criterion.

4. Data, privacy, and security

  • Does the data controller, processor, hosting arrangement, data location, privacy notice, subprocessor list, incident contact, retention rule, or deletion process change?
  • Will the acquiring company receive or use existing customer data differently?
  • Are customer approvals, notices, or contract amendments required?

NIST SP 800-161 Rev. 1 is broad supply-chain risk guidance for systems and organizations. It supports assessing supplier risk across acquisition and use, but it is not a freight-broker rule and does not decide whether a specific vendor change is acceptable.

5. Access, export, and exit

  • Will user, administrator, SSO, MFA, audit-history, or service-account behavior change?
  • Can the brokerage still retrieve customer, carrier, location, load, document, billing-handoff, report, and configuration records in documented formats?
  • What access remains after cancellation, for how long, at what cost, and through which process?

For regulated broker records, 49 CFR 371.3 currently requires a record of each transaction, lists required content, sets a three-year retention period, and gives each party to the brokered transaction a right to review the required record. The rule does not require a particular TMS or promise that a vendor export satisfies every obligation. The brokerage still needs to map required records to its actual systems and retention controls.

Days 11–20: run a two-load continuity rehearsal

Use synthetic data or records the brokerage is authorized to review. Do not interfere with live freight.

Select one ordinary completed load and one completed load with a meaningful exception, such as a carrier replacement, appointment change, accessorial, or document correction. For each, test whether the team can:

  1. identify the customer, carrier, lane, equipment, dates, and final instructions;
  2. retrieve the governing load documents and distinguish current from superseded versions;
  3. reconstruct status changes and exception ownership;
  4. trace the customer-invoice and carrier-payment handoffs without claiming the TMS is the accounting system;
  5. export or preserve the records the brokerage has designated as required; and
  6. complete the exercise using current roles, integrations, support paths, and recovery instructions.

Score each control `pass`, `pass with manual step`, `fail`, or `not tested`. Save screenshots only when policy allows, redact sensitive information, and record the tested date, user role, environment, and export format.

Days 21–30: make an evidence-based decision

Use three gates:

  • Contract gate: contracting, price, renewal, billing, cancellation, and required actions are understood in writing.
  • Continuity gate: required workflows, integrations, access, support, and recovery steps have an owner and a tested result.
  • Exit-readiness gate: the brokerage can identify, retrieve, retain, and hand off the records it has designated as necessary.

If all three gates pass, document the decision to continue and set the next review date. If an answer remains pending, keep it open with an owner and due date; uncertainty is not automatically a failure. If a material requirement fails, use the existing contract-review, risk, and migration process. Do not threaten cancellation, duplicate live transactions, or start an emergency cutover without the appropriate approvals.

Public facts versus verified ServeOps functionality

Public facts used here: Descartes and Tai published the August 24, 2026 acquisition announcement; FTC guidance addresses service-provider security expectations and oversight; NIST publishes cybersecurity supply-chain risk guidance; and 49 CFR 371.3 states specified broker transaction-record requirements. None of those sources evaluates ServeOps or predicts an outcome for Tai customers.

Verified ServeOps functionality: none is claimed in this guide. It does not assert that ServeOps imports or exports a particular record, migrates data, preserves document versions, supports a named integration, provides SSO or MFA, maintains audit history, monitors vendors, satisfies retention obligations, processes payments, or guarantees continuity, portability, security, support, or price stability. Demonstrate every required behavior in the current product and plan.

If ServeOps is on your shortlist, apply the same two-load continuity rehearsal before relying on it for live freight. The verified offer language is unchanged: 60-day free trial; card collected upfront; no charge for 60 days; cancel anytime; then $49 per seat/month or $490 per seat/year. Start the controlled evaluation with synthetic or properly authorized data, and treat every unverified requirement as not tested.

Related Broker Guides

Sources