Skip to main content

Provider checklist

Ten questions to ask your IT provider (and what good answers look like)

A confident answer is useful. A current asset list, restore record, admin-access export, or patch report is better.

Use this in your next provider meeting

Ask for the record behind the answer.

These questions are not a trap. They give leadership and the provider the same operating picture: what exists, who owns it, what has been tested, and what still depends on memory.

  1. Can you show me our full asset list: every device, server, and account you manage?

    Why it matters: You cannot protect, patch, back up, or offboard what nobody has counted. One missing laptop or service account is an unmanaged door.

    What a good answer looks like: A current, dated export with an owner, device status, operating system, and coverage for each item. Exceptions are listed and explained without rebuilding the list from memory.

  2. Which of our systems would not survive losing this vendor relationship?

    Why it matters: Leadership needs to know which credentials, licences, automations, documentation, and support paths depend on one provider. Hidden dependency turns a vendor change into an operating crisis.

    What a good answer looks like: A written dependency and exit list. Your firm controls or can transfer admin credentials, domains, licences, backups, documentation, and third-party contacts.

  3. When did you last test-restore our backups? Show me the record.

    Why it matters: A successful backup job proves that data was copied. It does not prove that the right data can be restored within a useful time.

    What a good answer looks like: A dated test record showing what was restored, where it was restored, how long it took, who checked it, and what failed. A dashboard with green job icons is not a restore test.

  4. Who has admin access to our environment, on your side and ours?

    Why it matters: Privileged access can change security settings, read data, create accounts, and disable protection. Leadership should know every person and service with that reach.

    What a good answer looks like: A current list of named admin accounts, service accounts, emergency access, and MFA status. Shared accounts have a documented owner and a removal plan.

  5. What happens, step by step, when something breaks at 9am on a Tuesday?

    Why it matters: “Call support” is not an operating process. A normal business-hours failure still needs triage, ownership, escalation, communication, and a decision path.

    What a good answer looks like: A short written sequence with contact methods, response ownership, escalation points, client communication, and the person who can approve material changes.

  6. What’s patched automatically, what’s manual, and what’s behind?

    Why it matters: Patching claims often hide three different realities. Some systems update automatically, some require planned work, and some have fallen outside support.

    What a good answer looks like: A current compliance report tied to the asset list, with the automatic scope, manual schedule, exceptions, overdue systems, and a named owner for each gap.

  7. If a client sent us a security questionnaire today, what could you hand us within 48 hours?

    Why it matters: Client questionnaires test whether operating evidence already exists. Reconstructing every answer from email and memory creates delay and inconsistent claims.

    What a good answer looks like: A ready evidence pack with current policy exports, device and admin lists, backup records, patch reports, training records, and clear Not Verified labels for missing proof.

  8. What are we paying for that we’re not using?

    Why it matters: Unused licences and overlapping tools waste money. They can also leave dormant accounts, unclear ownership, and forgotten data behind.

    What a good answer looks like: A line-by-line service and licence review that compares invoices with active users, deployed tools, contract terms, and an owner’s decision to keep or remove each item.

  9. What would you fix first in our environment if it were your firm?

    Why it matters: This forces priorities into the open. A provider who sees the environment every day should be able to name the most material gap without selling a shopping list.

    What a good answer looks like: One to three specific actions, each tied to evidence, business impact, relative effort, and an owner. The answer separates urgent exposure from routine improvement.

  10. When we offboard an employee, what exactly happens, and how fast?

    Why it matters: Departing staff can retain email, files, applications, remote access, shared credentials, and managed devices. One missed handoff can outlive the employee for months.

    What a good answer looks like: A checklist triggered by a named person, with timing, account disablement, session revocation, device return, data transfer, shared-password changes, and a completion record.

When answers stay vague

Turn vague into documented.

If several of these get vague answers, that is usually an evidence problem, not a people problem. The review turns vague into documented.

Fixed CAD $2,500, 100% credited toward remediation or Managed Technology Operations.

Book a 20-minute fit call
Pine IT

Start with the review

Start with a 20-minute fit call.

Enter your details, choose a platform, then pick a time. Prefer email? Write to info@pineit.ca or use the contact form.

Book a 20-minute fit call