Most bad managed-services relationships were predictable at signature. Not because the provider was dishonest, but because nobody asked the questions whose answers only matter later. Here are the ones worth asking while you still have leverage.
About the work
1. Who actually does the work? The person in the meeting is often not the person who will pick up your ticket. Ask who is assigned, how many clients they carry, and what happens when they are on holiday.
2. What are the response targets, by severity? "Fast" is not a commitment. A site down and a broken mouse are not the same ticket, and a single average response time is a way of avoiding the question. Get severity definitions and targets in the agreement.
3. What happens outside business hours? Is after-hours cover included, an add-on, or a best-effort favour? Who is on call, and how does an alert reach them at 2am? A monitoring system that emails an unattended inbox overnight is theatre.
4. What is explicitly out of scope? Every agreement has a boundary. The useful version of this question is: "Give me three examples of work that would generate an invoice on top of the monthly fee."
About the first month
5. What does onboarding include, and what does it cost? Discovery, documentation, agent deployment, cleaning up whatever is currently broken. This is the most expensive month of the relationship for the provider, so find out who is paying for it.
6. Do we get the documentation? An inventory of your environment — devices, licences, accounts, network layout — should be yours, in a form you can read without their tooling. If documentation only exists inside their platform, you are renting knowledge about your own business.
7. What will you fix in the first 30 days, and what will you flag? A provider who cannot answer this after seeing your environment has not looked at it yet.
About security and risk
8. What security is included versus sold separately? Endpoint protection, MFA enforcement, patching cadence, backup testing, email filtering, log retention. Some of these will be in the base fee and some will not. The list matters more than the label on the tier.
9. How often are backups tested, and how would we see the result? Ask for the evidence, not the policy. "Quarterly restore test with a written result" is a control; "backups run nightly" is a schedule.
10. If we are audited, what do you provide? For HIPAA, PCI-DSS, SOC 2 or CMMC, ask precisely which artefacts they produce and which are your responsibility. And confirm out loud that certification comes from an independent auditor — no provider can certify its own work.
About leaving
11. What is the notice period, and what does exit look like? Who removes their tooling, who transfers admin accounts, who hands over documentation, and is any of that billable? Ask before you need it, because the answer will never be better than it is now.
12. Do we own our accounts and licences? Domain registration, Microsoft 365 tenant, security tooling, backup storage — are these in your name or theirs? Providers that hold these on your behalf can be perfectly reasonable to work with, right up until the relationship ends. Tenancy in your own name is worth insisting on.
Two answers that should stop you
If a provider will not put response targets in writing, they have decided that being measured is worse for them than losing the deal.
If offboarding is vague, expensive, or met with mild offence that you asked — that is the answer. A provider confident in the work does not need a hostage.
The one to ask yourself
What is one hour of full downtime worth to this business — payroll, lost revenue, customers who go elsewhere? Until that number exists, every quote looks expensive and every risk looks theoretical. Once it exists, most of these questions answer themselves.
If the quotes in front of you are priced in different shapes, read managed IT pricing models, explained to put them side by side. Our own answers to most of these questions are in the FAQ and on the managed IT services page.