
The Independent IT Review: How to Audit the Organisation That Supports You
asitplan Strategy Team
Author
Rob Lloyd
Technical Reviewer
06 August 2026
Last Reviewed
School leaders, MAT executives, and business directors
Target Audience
The Context
School leaders and MAT executives often rely heavily on Managed Service Providers (MSPs) for technical support and strategy. However, asking an MSP to audit their own performance or security posture can create a structural conflict of interest. The challenge is establishing a method to measure the MSP's effectiveness objectively without undermining the collaborative working relationship.
Who This Guide is For
School leaders, MAT executives, business directors, and internal IT managers overseeing external contracts.
Why This Matters
When an accountability gap exists—where the provider marks their own homework—underlying issues such as missed patches, failing backup jobs, or inaccurate asset registers may remain hidden. These vulnerabilities often only surface during a catastrophic failure or cyber incident, at which point the lack of independent assurance becomes a significant governance failure.
What Good Looks Like
A mature review process separates daily operational metrics (ticket resolution times) from strategic assurance (security posture and lifecycle planning). It relies on verifiable data and, where appropriate, third-party baselines to confirm that security controls are active and strategic recommendations are evidence-based.
Approach and Methodology
- Operational vs. Strategic Assurance: Differentiate between operational service delivery ("how quickly do they answer the phone") and strategic technical assurance ("are the firewalls configured securely against current threats").
- Data-Driven SLA Reviews: Review raw ticket categorisation data to identify recurring issues. A high volume of resolved tickets might indicate poor root-cause analysis rather than efficient support.
- Configuration Evidence: Request tangible proof of security controls, such as reports showing Multi-Factor Authentication (MFA) enforcement across all administrative accounts, rather than verbal assurances.
- Asset Register Verification: Periodically cross-reference a sample of the MSP's asset report against independent discovery data or a physical spot-check to ensure accuracy.
- Privileged-Access Audits: Regularly review which MSP personnel hold Global Admin rights. Ensure these accounts are tightly restricted, monitored, and revoked when staff leave the provider.
- Backup and Recovery Testing: A successful backup job is not the same as a successful recovery. Request documented logs of the last full restore test.
- Exit Readiness: Ensure the school or Trust securely retains the "keys to the kingdom" (top-level administrative credentials and core network documentation) to prevent operational lock-in.
- Constructive Engagement: Frame the review as a collaborative exercise in continuous improvement, not an adversarial interrogation.
Evidence to Retain
- Monthly or quarterly SLA performance reports reviewed against the agreed contract.
- Documented backup restore test logs (at least annual).
- A maintained register of third-party administrative access.
Questions Leadership Should Ask
- "How do we independently verify the effectiveness of the security controls our provider has implemented?"
- "If we needed to transition to a new provider tomorrow, do we have immediate, uncontested administrative control over our own tenant?"
Common Pitfalls
- The Adversarial Approach: Approaching the review aggressively, which can cause the provider to become defensive and less transparent.
- Relying Solely on Vendor Dashboards: Using the MSP's own proprietary reporting tools as the only source of truth for auditing their performance.
- Focusing Exclusively on Cost: Prioritising reductions in the monthly retainer over the quality of security and strategic support provided.
How asitplan Can Help
asitplan provides schools with an independent, central platform to hold their own asset and audit data. By maintaining this information independently of the incumbent provider, schools can engage in more balanced, data-driven performance reviews and ensure they retain control of their technical intelligence.