Six written requests, one week, and a score out of 30. A practical audit of your IT provider covering documentation, backup restore testing, security baseline numbers, ticket metrics, billing line items, and who actually owns your domain and tenant.
Most owners never audit their IT company. They audit the books, the insurance renewal, the freight vendor, sometimes even the coffee contract. The one company holding administrative keys to every system in the building gets a quarterly lunch and a signature on an auto-renewal.
Fixing that requires no technical expertise, just six written requests, a calendar, and the discipline to treat "we will get back to you" as data rather than an answer. Run the checklist below over one week and you end up with a score out of 30 and a decision: keep, remediate, or replace.
Score each audit from 0 to 5. Do not soften a score because someone was pleasant on the phone. Pleasant is not a control.
Send one email asking for three documents. Do not offer to help assemble them.
Then spot-check it. Walk to five desks and compare serial numbers, and open your own Microsoft 365 admin page to compare the seat count. A 5 means all three documents arrive inside 48 hours, dated, and the spot checks match. A 0 means a diagram drawn this week from memory, or an "inventory" that is a screenshot of a monitoring dashboard. Documentation is the foundation of any real managed IT services agreement, and it is the first thing missing when the agreement is really break-fix with a monthly invoice attached.
This is where most audits find their biggest gap. Backup software is very good at producing green checkmarks and very bad at proving data is readable.
A dashboard screenshot proves a job ran, not that the data comes back. If no restore test can be produced, treat continuity as unproven and reread your contract alongside your cybersecurity coverage.
You are not evaluating tools. You are asking for six numbers, and a provider running a real security program can pull all six from existing consoles in under a day.
Note the shape of the answers too. Precise numbers with a report date mean the data is tracked; round numbers with no date mean someone estimated. Automated monitoring runs 24/7, but interpreting it is a human process.
Ask for a raw export of every ticket in the last 90 days: open date, first response timestamp, resolution timestamp, priority, requester, and category. Then measure it yourself.
If the export cannot be produced, that is the finding: a service level agreement nobody measures is a paragraph, not a commitment. This is also the structural weakness of hourly break-fix billing, where revenue rises with time spent and nothing rewards eliminating the recurring problem. Compare what you find against our guide on how to choose an MSP.
Put twelve months of invoices next to your agreement and map every recurring line item to a deliverable you can name.
You are measuring spend against defined deliverables, not hunting for the lowest number. Our breakdown of managed IT services pricing covers the common models and typical market ranges.
Run this one last and treat it as pass or fail. The question is not who administers each item, but whose legal name is on the account.
This is not about trust. It is about what happens if the relationship ends, the provider is acquired, or a key person leaves. When core assets sit in someone else's name, the arrangement is a dependency rather than a partnership. Our switching guide covers reclaiming each item in the right order.
Add the six scores for a total out of 30:
One override: any zero in Audit Six is an automatic escalation regardless of total. A perfect score elsewhere does not compensate for not owning your domain.
If you would rather have an outside party run the security and continuity portions, our free IT assessment covers the baseline questions in a few minutes and gives you something concrete to compare answers against. To walk through your findings, contact us or call 713-571-2390. Statewide, 888-792-8080 reaches the same team, with business-hours support and after-hours emergency response for outages.
About one week of part-time effort. The six requests take an hour to write, gathering your own evidence takes another hour or two, and the rest is waiting and scoring. Their turnaround time is the variable, and it is itself a meaningful result.
No. Every item here is a document request, a percentage, or a name on an account. You are checking whether evidence exists and matches reality, not evaluating a firewall configuration. A second opinion helps most when interpreting the security baseline numbers.
A provider running a documented practice treats these requests as routine, because carriers, auditors, and lenders ask the same questions. If a governance request produces defensiveness instead of documents, that reaction is a finding in its own right.
Separate day-to-day administration from ownership. It is reasonable for a provider to hold working credentials and manage access. It is not reasonable for your domain registrar, DNS, tenant billing, or backup storage to be registered in their name, or for you to hold no break-glass account.
Annually if the score was 25 or higher, and before every contract renewal regardless of score. Re-audit any section scoring below 3 at the 90-day mark, because a remediation promise without a follow-up date is just a longer version of the original gap.
LayerLogix serves organizations across Texas with 20+ Years Experience and 100% Texas-Based Support, including managed IT services in Houston, The Woodlands, Sugar Land, Dallas, Fort Worth, and Austin. Wherever your offices sit, the audit is the same six requests and the same score out of 30.
LayerLogix provides expert managed it services solutions for businesses across Houston and nationwide.
Let our team help your Houston business with enterprise-grade IT services and cybersecurity solutions.