Provider checklist
Ten questions to ask your IT provider (and what good answers look like)
A confident answer is useful. A current asset list, restore record, admin-access export, or patch report is better.
Use this in your next provider meeting
Ask for the record behind the answer.
These questions are not a trap. They give leadership and the provider the same operating picture: what exists, who owns it, what has been tested, and what still depends on memory.
-
Can you show me our full asset list: every device, server, and account you manage?
Why it matters: You cannot protect, patch, back up, or offboard what nobody has counted. One missing laptop or service account is an unmanaged door.
What a good answer looks like: A current, dated export with an owner, device status, operating system, and coverage for each item. Exceptions are listed and explained without rebuilding the list from memory.
-
Which of our systems would not survive losing this vendor relationship?
Why it matters: Leadership needs to know which credentials, licences, automations, documentation, and support paths depend on one provider. Hidden dependency turns a vendor change into an operating crisis.
What a good answer looks like: A written dependency and exit list. Your firm controls or can transfer admin credentials, domains, licences, backups, documentation, and third-party contacts.
-
When did you last test-restore our backups? Show me the record.
Why it matters: A successful backup job proves that data was copied. It does not prove that the right data can be restored within a useful time.
What a good answer looks like: A dated test record showing what was restored, where it was restored, how long it took, who checked it, and what failed. A dashboard with green job icons is not a restore test.
-
Who has admin access to our environment, on your side and ours?
Why it matters: Privileged access can change security settings, read data, create accounts, and disable protection. Leadership should know every person and service with that reach.
What a good answer looks like: A current list of named admin accounts, service accounts, emergency access, and MFA status. Shared accounts have a documented owner and a removal plan.
-
What happens, step by step, when something breaks at 9am on a Tuesday?
Why it matters: “Call support” is not an operating process. A normal business-hours failure still needs triage, ownership, escalation, communication, and a decision path.
What a good answer looks like: A short written sequence with contact methods, response ownership, escalation points, client communication, and the person who can approve material changes.
-
What’s patched automatically, what’s manual, and what’s behind?
Why it matters: Patching claims often hide three different realities. Some systems update automatically, some require planned work, and some have fallen outside support.
What a good answer looks like: A current compliance report tied to the asset list, with the automatic scope, manual schedule, exceptions, overdue systems, and a named owner for each gap.
-
If a client sent us a security questionnaire today, what could you hand us within 48 hours?
Why it matters: Client questionnaires test whether operating evidence already exists. Reconstructing every answer from email and memory creates delay and inconsistent claims.
What a good answer looks like: A ready evidence pack with current policy exports, device and admin lists, backup records, patch reports, training records, and clear Not Verified labels for missing proof.
-
What are we paying for that we’re not using?
Why it matters: Unused licences and overlapping tools waste money. They can also leave dormant accounts, unclear ownership, and forgotten data behind.
What a good answer looks like: A line-by-line service and licence review that compares invoices with active users, deployed tools, contract terms, and an owner’s decision to keep or remove each item.
-
What would you fix first in our environment if it were your firm?
Why it matters: This forces priorities into the open. A provider who sees the environment every day should be able to name the most material gap without selling a shopping list.
What a good answer looks like: One to three specific actions, each tied to evidence, business impact, relative effort, and an owner. The answer separates urgent exposure from routine improvement.
-
When we offboard an employee, what exactly happens, and how fast?
Why it matters: Departing staff can retain email, files, applications, remote access, shared credentials, and managed devices. One missed handoff can outlive the employee for months.
What a good answer looks like: A checklist triggered by a named person, with timing, account disablement, session revocation, device return, data transfer, shared-password changes, and a completion record.
When answers stay vague
Turn vague into documented.
If several of these get vague answers, that is usually an evidence problem, not a people problem. The review turns vague into documented.
Fixed CAD $2,500, 100% credited toward remediation or Managed Technology Operations.
Book a 20-minute fit callStart with the review
Start with a 20-minute fit call.
Enter your details, choose a platform, then pick a time. Prefer email? Write to info@pineit.ca or use the contact form.