Is my IT provider doing a good job? Start with specific commitments
Choose the concern or decision you want to resolve. Put the agreement and service schedule beside your current requirements. Identify the relevant systems, responsibilities and review period before asking whether delivery matches the commitment.
Include your team's experience of responsiveness and disruption, with dates and examples. Keep those observations separate from questions about controls or services the team has not checked. A positive experience with support does not, by itself, establish that a recovery test succeeded.
Request evidence matched to the question
The Canadian Centre for Cyber Security's Cyber security considerations for consumers of managed services (ITSM.50.030) covers provider assessments, access control, recovery and exit arrangements. Use those topics to frame questions relevant to your own agreement and systems.
| Question | Ask to inspect | Keep this limit visible |
|---|---|---|
| What supports the reported security work? | The agreed controls, covered systems, dated reports and open findings | A tool name or report title alone does not establish that a control works |
| Who has administrator access? | An account list with its date, system coverage, authorisations and unresolved exceptions | A list for one system says nothing about accounts in systems it does not cover |
| What recovery has been demonstrated? | A restore-test record naming the systems, date, result and unresolved issues | A successful test establishes a result within its test conditions, not every future recovery outcome |
| Does the reported service match the agreement? | The service schedule beside records for the same period | A report stating that work is complete is a reported claim until its supporting evidence is checked |
| What happened to agreed actions? | The action, owner, agreed date, current status and supporting record | An open item needs context: check approvals, scope and any agreed change before assigning responsibility |
| Do billed quantities match the available records? | Invoices, agreed charging units and relevant user, device or licence records for the same period | An unexplained difference is a question to investigate, not a finding of overcharging |
| What changes need planning? | Relevant supplier support notices, system requirements and proposed work | A proposed plan is not evidence that a change has been completed |
A request you can adapt
Agree a practical response date that fits the decision and the work needed to gather records. Use the provider decision worksheet to record findings, their limits and follow-up actions. It includes an illustrative example and blank rows; it does not calculate a score.
Separate the record from what it proves
For each answer, record the document reference, date, scope, what you inspected and what remains unknown. Use these suggested categories to keep the discussion clear. They are not ratings of your provider.
| What you have | What to record | Next step |
|---|---|---|
| A supplied record | What the record says, its date and the systems it names | Check whether it answers the question; identify any further verification needed |
| A reported claim | The statement and who made it; supporting evidence not yet checked | Request the relevant record or test and clarify what it would establish |
| Missing information | The unanswered question and the evidence requested | Ask what is available, who can provide it and when to follow up |
| A stated exclusion | The provider's explanation and the relevant agreement wording | Confirm the scope and decide how the business need should be met |
| A verified observation | The check performed, result, scope and who performed it | Record the finding without extending it to untested systems or future performance |
Discuss the gap and the proposed response
Ask whether the concern involves an agreed commitment, a changed requirement, an exclusion or something still unresolved. If corrective work is proposed, record the action, owner, approval, cost treatment and how completion will be checked. Use dates suited to that work and your decision; do not substitute a generic review interval.
If the same fault keeps returning, use the recurring-problem evidence request. For questions about reporting, use what your provider's monthly report should show.
Record whether to keep, improve or investigate a replacement
Compare the supported findings, unresolved questions and business requirements. Record why you want to retain the arrangement, seek specific changes or explore another provider. Set a next action and owner for anything still open. A missing document alone should not determine the decision.
If renewal is the trigger, use the renewal guide to confirm the actual notice requirements and organise the review around them. If alternatives are needed, compare proposal scope and assumptions against the problems you want addressed.
Use online reviews for the claims they actually describe
Read what a reviewer says happened, when it happened and what work they describe. A review that does not discuss a restore test cannot establish its result. A testimonial about one project does not establish how your different systems will be supported.
Treat a claim in a review as a claim to assess. Look for context and corroborating information where it matters to your decision. Apply the same questions to the current provider and any proposed replacement; do not infer technical quality from a star rating alone.
Know when the question needs further verification
Collecting documents is not the same as independently verifying their accuracy or the systems they describe. If a decision depends on configuration, technical testing or interpreting a report beyond your expertise, involve someone qualified to assess that question. Define the scope and record what remains outside it.
actually. offers an independent review of evidence about your existing IT provider.
The review is a paid service.
See the actually. review to discuss the question, evidence and scope.
