Skip to content

How to Audit Your IT Company: A Practical Checklist

By Donovan Brown
August 11, 2026
13 sections
How to Audit Your IT Company: A Practical Checklist

Six written requests, one week, and a score out of 30. A practical audit of your IT provider covering documentation, backup restore testing, security baseline numbers, ticket metrics, billing line items, and who actually owns your domain and tenant.

01

Introduction

Most owners never audit their IT company. They audit the books, the insurance renewal, the freight vendor, sometimes even the coffee contract. The one company holding administrative keys to every system in the building gets a quarterly lunch and a signature on an auto-renewal.

Fixing that requires no technical expertise, just six written requests, a calendar, and the discipline to treat "we will get back to you" as data rather than an answer. Run the checklist below over one week and you end up with a score out of 30 and a decision: keep, remediate, or replace.

02

Set the Rules Before You Start

  • Everything in writing. Email each request. Verbal answers cannot be scored, and response time is one of the measurements.
  • Artifacts, not assurances. "Backups are running" is an assurance. A restore log with a timestamp and a file you chose is an artifact. Only artifacts earn points.
  • Frame it as governance. Your insurance carrier, bank, or board wanting evidence of controls is true and non-confrontational.
  • Set a deadline. Five business days per request is generous for anyone running a documented practice and impossible for anyone who is not.

Score each audit from 0 to 5. Do not soften a score because someone was pleasant on the phone. Pleasant is not a control.

03

Audit One: Documentation

Send one email asking for three documents. Do not offer to help assemble them.

  • A current network diagram. Firewall, switches, wireless, servers, hypervisors, ISP circuits, and VPN paths, carrying a revision date inside the last twelve months.
  • An asset inventory. Every workstation, server, firewall, switch, and access point with serial number, warranty expiration, assigned user, and OS version.
  • A license and subscription record. Microsoft 365 SKUs and seat counts, endpoint security licenses, backup capacity, and every line-of-business renewal with its date.

Then spot-check it. Walk to five desks and compare serial numbers, and open your own Microsoft 365 admin page to compare the seat count. A 5 means all three documents arrive inside 48 hours, dated, and the spot checks match. A 0 means a diagram drawn this week from memory, or an "inventory" that is a screenshot of a monitoring dashboard. Documentation is the foundation of any real managed IT services agreement, and it is the first thing missing when the agreement is really break-fix with a monthly invoice attached.

04

Audit Two: Backups and a Real Test Restore

This is where most audits find their biggest gap. Backup software is very good at producing green checkmarks and very bad at proving data is readable.

  • You pick the file. Name a document, in a specific folder, as it existed roughly 45 days ago. Ask for it restored to a scratch location with the restore log and timestamp.
  • Demand a full-system restore test. One server or critical VM booted in isolation, with a screenshot showing the login screen and the date, plus wall-clock time start to finish.
  • Get RTO and RPO in writing. How long until you are working again, and how much data you accept losing. If nobody gave you these numbers, nobody designed for them.
  • Ask where copies two and three live. Three copies, two media types, one offsite and immutable. Immutability matters because ransomware deletes backups first.
  • Ask when the last restore test ran. "Quarterly" is an assurance. A dated report is an artifact.

A dashboard screenshot proves a job ran, not that the data comes back. If no restore test can be produced, treat continuity as unproven and reread your contract alongside your cybersecurity coverage.

05

Audit Three: The Security Baseline

You are not evaluating tools. You are asking for six numbers, and a provider running a real security program can pull all six from existing consoles in under a day.

  • MFA coverage percentage. Every user, administrator, and remote path, VPN and email included. The only acceptable target is 100 percent, with a short, named, dated exceptions list.
  • EDR deployment percentage. Endpoints with a managed detection agent that checked in within seven days. Legacy antivirus is not EDR, and an agent that stopped reporting in March is not coverage.
  • Patch compliance percentage. Workstations and servers current within 30 days, OS and third-party applications. Third-party is where the number usually collapses.
  • Global Administrator count. Every Global Admin in your Microsoft 365 tenant. Microsoft's guidance is to keep this very small; double digits is a finding.
  • Local administrator count. How many everyday users are local admins on their own machines. Standard-user-by-default blocks a lot of commodity malware for free.
  • Offboarding lag. Name three people who left this year, then compare their last day to the date each account was disabled.

Note the shape of the answers too. Precise numbers with a report date mean the data is tracked; round numbers with no date mean someone estimated. Automated monitoring runs 24/7, but interpreting it is a human process.

06

Audit Four: Tickets

Ask for a raw export of every ticket in the last 90 days: open date, first response timestamp, resolution timestamp, priority, requester, and category. Then measure it yourself.

  • Median first response time. Median, not average. One four-minute reply should not offset three tickets that sat overnight, but an average hides exactly that.
  • Median time to resolution by priority. If every ticket carries the same priority, priority is not being used.
  • Reopened ticket rate. Tickets closed then reopened within 14 days, as a percentage of closures. Above roughly 10 percent suggests tickets are closed to satisfy a metric, not because the problem is gone.
  • Repeat-issue concentration. Top five recurring problems by count. If the same printer, VPN, or application appears monthly, nobody has been paid to fix the root cause.
  • Volume trend. Rising counts against stable staffing means the environment is degrading.

If the export cannot be produced, that is the finding: a service level agreement nobody measures is a paragraph, not a commitment. This is also the structural weakness of hourly break-fix billing, where revenue rises with time spent and nothing rewards eliminating the recurring problem. Compare what you find against our guide on how to choose an MSP.

07

Audit Five: Billing

Put twelve months of invoices next to your agreement and map every recurring line item to a deliverable you can name.

  • Seat reconciliation. Billed seats versus active users. Seats billed for departed employees are the most common finding here, and they compound quietly for years.
  • Bundle transparency. A line called "managed services" covering 80 percent of the invoice is not a deliverable. Ask what it includes and excludes, in writing.
  • Pass-through and markup. Markup on rebilled hardware and licensing is legitimate; undisclosed markup on a cost-plus agreement is not.
  • Project work billed hourly. Anything invoiced as a project that the agreement already covers. Recurring incidents billed as projects is the pattern to flag.
  • Renewal terms. Auto-renewal window, notice period, annual escalator. Put the date you must act by on your calendar today.

You are measuring spend against defined deliverables, not hunting for the lowest number. Our breakdown of managed IT services pricing covers the common models and typical market ranges.

08

Audit Six: Access and Ownership

Run this one last and treat it as pass or fail. The question is not who administers each item, but whose legal name is on the account.

  • Domain registrar. Registered to your company, with a company-controlled email as administrative contact. Get the registrar name and log in yourself to confirm.
  • DNS hosting. Where records actually resolve from, and whether you can reach that console.
  • Microsoft 365 or Google Workspace tenant. Your company as billing owner, plus a break-glass Global Admin whose credentials you hold and your provider does not.
  • Firewall, switch, and wireless credentials. Available on request, not locked solely inside a vendor password manager you have no seat in.
  • Backup console and cloud storage. The account holding your backup data should be yours, or the contract should state how you retrieve it on 30 days notice.
  • Line-of-business portals. Accounting, ERP, practice management, CAD. Confirm your company is the account holder of record.

This is not about trust. It is about what happens if the relationship ends, the provider is acquired, or a key person leaves. When core assets sit in someone else's name, the arrangement is a dependency rather than a partnership. Our switching guide covers reclaiming each item in the right order.

09

The Scoring Rubric

  • 5 - Complete and current. Delivered inside the deadline, dated, survives spot checks.
  • 4 - Complete but late, or one gap acknowledged in writing.
  • 3 - Partial. Most of it exists, some is stale, spot checks find mismatches.
  • 2 - Assembled on demand. It clearly did not exist before you asked. The effort is real; the program is not.
  • 1 - Verbal only, after more than one reminder.
  • 0 - Not produced. Deflection, silence, or "that is not covered under your agreement."

Add the six scores for a total out of 30:

  • 25 to 30 - Healthy. Document the findings, close the small gaps, re-run annually.
  • 18 to 24 - Fixable. Send the findings with a 90-day date on each item and re-audit failed sections at day 91, not day 180.
  • 10 to 17 - Serious. Remediate and evaluate alternatives in parallel. A co-managed IT arrangement can stabilize things while you decide, because it adds capability without a full transition.
  • Under 10 - Structural. The operating model is the problem, not the effort. Build a transition plan.

One override: any zero in Audit Six is an automatic escalation regardless of total. A perfect score elsewhere does not compensate for not owning your domain.

10

What Each Failure Actually Means

  • No network diagram: nobody has modeled your environment, so every change is improvisation and a post-outage rebuild is guesswork.
  • No asset inventory: you cannot know what is missing, unpatched, or out of warranty, and it fails most cyber insurance questionnaires.
  • No test restore: you own backup jobs, not a recovery capability.
  • MFA under 100 percent: the uncovered accounts are where an intrusion starts, and unmet attestations are a common reason claims get contested.
  • Patch compliance unknown: there is no patch program, only default updates and hope.
  • Excess Global Admins: one phished administrator becomes a tenant-wide compromise.
  • No ticket metrics: the service level agreement is decorative.
  • High reopen rate: symptoms get cleared, root causes do not.
  • Unmappable line items: you are buying a bundle nobody has priced against outcomes.
  • Assets in the provider's name: your switching cost is set by someone other than you.
11

Where to Start

  • Monday: send all six requests in a single email with a Friday deadline. One email produces one clean response-time measurement.
  • Tuesday: pull your own evidence in parallel. Your Microsoft 365 admin center shows seat counts and admin roles, and your registrar shows who owns the domain.
  • Wednesday and Thursday: spot-check the documentation against five real desks, then run the restore test with a file you selected and a timestamp you can read.
  • Friday: score all six, write a one-page findings summary, and put dates on the remediation items.

If you would rather have an outside party run the security and continuity portions, our free IT assessment covers the baseline questions in a few minutes and gives you something concrete to compare answers against. To walk through your findings, contact us or call 713-571-2390. Statewide, 888-792-8080 reaches the same team, with business-hours support and after-hours emergency response for outages.

12

Frequently Asked Questions

How long does an IT provider audit actually take?

About one week of part-time effort. The six requests take an hour to write, gathering your own evidence takes another hour or two, and the rest is waiting and scoring. Their turnaround time is the variable, and it is itself a meaningful result.

Do I need technical knowledge to audit my IT company?

No. Every item here is a document request, a percentage, or a name on an account. You are checking whether evidence exists and matches reality, not evaluating a firewall configuration. A second opinion helps most when interpreting the security baseline numbers.

Will asking for this information damage the relationship?

A provider running a documented practice treats these requests as routine, because carriers, auditors, and lenders ask the same questions. If a governance request produces defensiveness instead of documents, that reaction is a finding in its own right.

What if my provider refuses to hand over admin credentials?

Separate day-to-day administration from ownership. It is reasonable for a provider to hold working credentials and manage access. It is not reasonable for your domain registrar, DNS, tenant billing, or backup storage to be registered in their name, or for you to hold no break-glass account.

How often should I re-run this audit?

Annually if the score was 25 or higher, and before every contract renewal regardless of score. Re-audit any section scoring below 3 at the 90-day mark, because a remediation promise without a follow-up date is just a longer version of the original gap.

13

Geographic Coverage

LayerLogix serves organizations across Texas with 20+ Years Experience and 100% Texas-Based Support, including managed IT services in Houston, The Woodlands, Sugar Land, Dallas, Fort Worth, and Austin. Wherever your offices sit, the audit is the same six requests and the same score out of 30.

Related Services

Need Help With Managed IT Services?

LayerLogix provides expert managed it services solutions for businesses across Houston and nationwide.

Serving Houston, The Woodlands, and nationwideGet a Free Consultation
Back to Blog
Keep Reading

Related Articles

Need Expert IT Support?

Let our team help your Houston business with enterprise-grade IT services and cybersecurity solutions.

Call NowBook a Call