The Actually Review: our flagship independent assessment

Now accepting reviews

An independent audit of what your IT provider reports.

A comprehensive, evidence-based review of your technology, cybersecurity, service providers, spending and strategy. The result is a plain-language picture of where you stand, what matters most and what should happen next. Based in Toronto, we work with businesses across Canada. Your IT team or provider remains responsible for operating your technology.

An open, bound technology review report on a desk, annotated in pencil in the margin, with a pencil and reading glasses beside it, black and white
The deliverable, not a dashboard.

Why it exists

There is often a gap between reported and verified.

Your provider may be sending reports. Your team may be completing checklists. Your systems may appear operational. But routine reporting may not answer the questions leadership actually needs answered. The Actually Review examines the evidence behind the reports.

What is an independent IT review?

An independent IT review is an assessment of a company's technology carried out by a firm that does not manage that technology and does not sell it. It verifies what the internal team or the IT provider has reported: that backups restore, that security controls are active, that spending matches what was agreed. The reviewer has no stake in the answer.

What we review

What our independent IT audit covers.

01

Business & leadership

  • Objectives, growth plans, priorities
  • Governance and risk tolerance
  • Technology dependence
  • and previous incidents
02

Technology environment

  • Infrastructure and cloud services
  • Networks, devices, identity
  • Documentation and monitoring
  • and lifecycle planning
03

Cybersecurity

  • Access controls and MFA
  • Endpoint and email protection
  • Patching and vulnerabilities
  • and incident response
04

Backup & recovery

  • Coverage and retention
  • Off-site or immutable copies
  • Restoration testing
  • and recovery time expectations
05

IT operations

  • Tickets and escalations
  • Onboarding and offboarding
  • Change management
  • and vendor coordination
06

Providers & contracts

  • Scope and service levels
  • Pricing and reporting
  • Cybersecurity obligations
  • and exit provisions

Plus a full review of spending and planning: current costs, licensing, duplication, unused services and the technology roadmap.

Methodology

We do not audit by questionnaire alone.

Leadership interviewsProvider interviewsDocumentation reviewContract reviewReport reviewTechnical evidenceConfiguration samplingProcess observationControl validationIndependent analysis

We agree the business question, scope, criteria and access before the examination. The work may combine the methods above, depending on what needs to be established.

A report or questionnaire is evidence to examine, not a conclusion by itself. Findings distinguish what the records and agreed checks support from what remains unverified, including sampling, period and scope limitations.

For a focused review of security controls, see independent cybersecurity verification. The broader Review also examines provider commitments, spending and technology planning.

Illustrative audit finding

A successful backup report. An unanswered recovery question.

See how evidence becomes a finding, a business implication and a next step.

A fictional example to explain the report format. It contains no client data and does not describe a completed engagement.

Read the guide to backup testing
Agreed criterion
In this example, the business needs the selected application restored within its agreed recovery target.
Evidence examined
The provider's backup report records successful jobs. A supplied restoration record identifies an application, but does not record the elapsed recovery time or an application usability check.
Finding and limit
The supplied records do not establish that this application can be recovered within the target. That is an evidence gap, not proof that the backups have failed. Other applications and recovery scenarios remain outside this example.
Business implication
Leadership cannot use these records alone to plan how long the selected application could be unavailable.
Recommended action
Ask the provider to agree a restoration test with the business, record its scope and elapsed time, and document the business user's usability checks.
Follow-up verification
actually. can examine the resulting test evidence and any agreed observation or validation. The report should state what was established, the period and scope examined, and any remaining limitations.

Rating approach

Every finding is placed in business context.

Risk.
What could happen if the issue remains unresolved?
Impact.
How could it affect operations, finances, customers or reputation?
Urgency.
How quickly should leadership act on the finding?
Effort.
What time, cost and complexity may be required?

This prevents a long technical list from becoming an unmanageable collection of equally urgent recommendations.

A bound review document alone on a long boardroom table, page markers along its fore edge and one marker in yellow, empty chairs beyond, black and white
The review, before it becomes a conversation.

What you receive

What you receive after the IT audit.

01

Executive Briefing

02

Independent Assessment Report

03

90-Day Action Plan

04

Technology Risk Register

05

Provider Discussion Guide

In their words

“The Actually Review provided a level of strategic insight that went beyond day-to-day IT support. It gave our leadership team an independent perspective on technology risk and a clear roadmap for strengthening our environment.”

Leadership Team, Goodkey, Weedmark & Associates Limited

Two engagements, and the deliverables each of them produced, are described in the case record.

What happens after

A review is where the work begins, not where it ends.

01Manage the action plan internally
02Ask your provider to complete the work
03Use actually. to verify remediation
04Begin quarterly oversight

Your team or provider carries out changes. We report findings and can independently examine the follow-up evidence. The review may inform a decision to retain or change your provider; actually. does not take over IT delivery. Where a review should become a standing rhythm, it leads into Actually Oversight.

Before the engagement

Scope, access, cost and timing.

Start with the decision leadership needs to make. We agree what the audit will examine before the work begins.

What access will you need?

We agree access before the engagement begins. The starting point may be interviews, reports, contracts and documentation. Verification may also require read-only or supervised access to selected systems and configurations. The scope identifies what we can examine and what remains outside the review.

How much does an independent audit cost?

The fee is quoted before work begins. It depends on the agreed scope, the size and complexity of the environment, and the evidence and validation required. Tell us the question you need answered so we can explain what the work would involve.

How long will the work take?

Timing depends on scope, the availability of evidence and the interviews or validation required. We discuss those requirements when scoping the engagement. A focused control review and a review of the wider technology environment require different amounts of work.

What happens to our existing IT provider?

Your provider or internal team continues to operate your systems and carry out changes. actually. examines the evidence, reports findings and can verify remediation. An audit can inform a decision to retain or change a provider; we do not take over IT delivery.

Read more about what determines an independent IT audit's cost, or discuss the question you need examined.

Who should consider a review

Particularly valuable when…

You are unsure whether your provider is performing
Reports appear too simple or consistently green
Your provider contract is renewing
You have experienced a cybersecurity incident
You are acquiring or selling a company
A senior IT employee has left
Technology costs are increasing
The board is asking more cybersecurity questions

Not ready to commission a review? Start by asking your provider directly. Ten questions to ask your IT provider is a free checklist covering the same ground this review examines, with the document, date or number that answers each one.

You already know what you have been told.
Now find out what the evidence says.

Weighing it up? The FAQ covers cost, access and timing, and what a review means for your current provider.