Ask Actually

How to chair your own quarterly review with your IT provider.

In short

Send your provider a short agenda and an evidence request before the quarterly meeting. Ask what dated records exist for backups, patching, accounts and incidents. In the meeting, record what was reported, what records arrived, what you compared, and which questions stay open.

If the quarterly meeting is a slide deck you sit through, you leave with the provider's summary. Chairing it yourself lets you set the agenda and keep your own notes of what was claimed, what records arrived, and what stays open.

Send the evidence request before the meeting

Ask in writing, ahead of the meeting, with a date range. Ask which records exist for each item rather than assuming any particular report is kept.

The Canadian Centre for Cyber Security's baseline cyber security controls for small and medium organizations recommend that organizations back up systems containing essential business information and ensure recovery mechanisms restore those systems, and that two-factor authentication be implemented wherever possible and required for important accounts such as system administrators and financial accounts. Those are recommendations in that guidance, and a reasonable starting point when choosing agenda items.

The same centre's guidance for consumers of managed services lists questions to put to a provider, including whether it can produce a third party certificate of evaluation against a security standard, and whether it can provide an audit trail of administrator actions. Either answer is worth writing down.

Keep four columns in your notes

Write the notes in four separate states. Reported: what the provider states or summarises. Record supplied: a document, export, screenshot or log you received. Check performed: the exact comparison you made and its narrow result. Open or out of scope: a question nobody answered, or a system the provider says it does not cover.

These states are not interchangeable. Receiving a backup report means you hold a document that reports a state; on its own it does not establish that a restore test ran, that the export is complete, or that it covers systems it does not name.

One check needs no technical skill. Compare the active user accounts on a supplied list with your payroll list of current staff, then ask about any name on one list and not the other. That comparison tests two lists against each other on the day you run it. It does not establish whether access was removed, or what is true in systems neither list names.

Separate a discrepancy from its explanation

If two records disagree, you have found a difference, not a cause. A gap between a ticket count and your own memory of outages is consistent with several ordinary explanations, including how tickets are categorised, work done outside the ticket system, or an unclear request on your side. The cause stays unresolved until someone explains it, so put the question to the provider rather than recording a conclusion.

Record the provider's explanation as an explanation. Record separately what you compared, whether a corrected record was promised, and whether a corrected record arrived. A verbal answer in the room and a revised export two weeks later are different entries in the notes.

Carry the open items into the keep, improve, renew or replace decision

Close the meeting by reading the open items aloud, with a name and a date beside each. Ask who agreed each date. At the following quarterly meeting, start with that list.

Missing records are not proof of poor delivery, and a prompt, complete response is not proof that the arrangement suits you for another term. Dated notes give you something to work from in the next conversation: keep the provider as is, ask for specific changes, test the market at renewal, or look harder at one area.

For the wider method, see the guide on how to evaluate the managed IT provider you already have. If you would rather someone independent examine the evidence with you, see the actually. review.

actually. offers an independent review of evidence about your existing IT provider.

The review is a paid service.

Sources

This is one question. An independent review answers the rest, with evidence.

Request an Independent Review