Skip to content

Resource

The questions to ask before you sign with an IT provider.

Most IT proposals look the same on paper. These are the questions that separate the providers who will actually show up from the ones who sound like they will.

Dawn SizerDawn Sizer · CEO and Co-Founder, 3rd Element Consulting

Proposals are written to be compared. That is the problem.

Put three managed IT proposals side by side and they tend to blur together. Same coverage language, same promise of proactive support, same per-user price within a few dollars of each other. The document is designed to survive a comparison, not to explain how the provider actually runs.

The differences show up somewhere else. They show up in how response time is measured, what security is included instead of sold later, what happens the day an employee leaves, and what the provider does when something breaks badly. Those four areas are what our vetting checklist covers, and they are where the real gaps between providers live.

You can work through most of this in a single meeting. Ask the question, then ask how they know. A provider running to a standard will answer with a process. A provider who is improvising will answer with reassurance.

Comparing managed IT provider proposals before signing

Response standards: ask how the number is measured.

Almost every provider quotes a response time. Very few explain what they are counting. An automated ticket acknowledgement is not a response. A note that says someone will look at it later is not a response either.

Here is one of the strongest questions on the checklist. Ask: what is your average response time, how is it measured, and can you show me the actual number rather than the target in the contract? A provider who measures it will have the figure and will know the difference between an acknowledgement and a human working the issue. A provider who does not measure it will talk about how responsive they are.

Ask the follow-up too. Who answers first? If every ticket lands with a Level 1 queue whose job is to gather information and escalate, your average issue is being handled twice before anyone qualified looks at it. That is why the first response number and the resolution experience so often disagree.

Security baselines: ask what is included, not what is available.

Security is the area where proposals diverge most and read most similarly. Nearly every provider lists security services. The question is which of them are standard on every environment they manage and which are an upsell that arrives after an incident or after an insurance questionnaire forces the conversation.

So ask it directly. What security controls do you apply to every client by default, and what is priced separately? Then ask what happens if the business declines one of them. A standards-led provider will tell you there is a floor they will not manage below. A reactive provider will tell you it is entirely up to you, which sounds accommodating and means the standard is whatever you happen to buy.

This matters well beyond security itself. Cyber insurance applications and client security questionnaires both ask about controls in place, and both expect evidence rather than intent. If the baseline is optional, you will be assembling that evidence yourself later.

Offboarding: ask what happens the day someone leaves.

Offboarding is the least glamorous item in the checklist and the one that catches the most providers out. It is a routine event, it happens on short notice, and it touches identity, email, files, phones, and every third-party application the person could reach.

Ask what the process is, who starts it, and how long it takes. Then ask how you would prove, six months later, that it was done. If the answer depends on someone remembering to send an email, that is the actual process, whatever the contract says.

The same question applies to the provider relationship itself. Ask what offboarding looks like if you leave them. Credentials, documentation, and tenant ownership should belong to the business the whole time, not be something you negotiate for on the way out.

What happens when things go wrong.

Every provider has had a bad week. The useful question is not whether something has gone wrong, it is what the provider did about it and what changed afterward.

Ask them to walk you through a recent incident or outage with a client. Not the name of the client, the sequence. Who noticed it, how fast, who was told, what the communication looked like while it was unresolved, and what was changed across other clients once it was over. A provider with real operational discipline will answer that comfortably. It is a story they have already told internally.

Then ask the recovery version of the same question. When was the last time they restored a client's data from backup, and how long did it take. Backups that have never been restored are an assumption, not a control.

Use the checklist in the meeting, not after it.

The point of a vetting checklist is not to grade providers at the end. It is to keep the conversation on how the environment will actually be run while you still have leverage, which is before anything is signed.

The full checklist covers all four areas: response standards, security baselines, offboarding, and what happens when things go wrong. You can send it ahead, work through it live, or use it to compare notes after two or three meetings. It is written to be used by a business owner, not an IT person.

Schedule an IT Environment Review

The checklist

Take the full checklist into your next meeting.

All four areas in one printable PDF: response standards, security baselines, offboarding, and what happens when things go wrong. Enter your email and the download starts right away.

Common questions

Questions leadership usually asks first.

Next step

Get a clearer view of your IT environment.

Find out what is working, where the risks are, and what needs attention next.