Managed IT Provider Checklist for Canadian Businesses
Compare managed IT providers on ownership, access, security, recovery and exit terms before you compare monthly prices. This practical Canadian checklist helps you keep the questions, evidence and responsibilities clear.
Choosing an MSP is a security and continuity decision as well as a service purchase. A provider may receive access to multiple systems and data, so a credible proposal should explain what is protected, who is responsible, how incidents are handled and how you leave if the relationship ends. The Canadian Centre for Cyber Security identifies these issues in its ITSM.50.030 guidance for consumers of managed services.
Use this checklist during an RFP, renewal or provider transition. It is procurement guidance, not legal advice, a certification, or proof that any provider meets every requirement.
Questions to ask before you sign
Ask for specific answers and retain the evidence that supports the agreed scope.
| Area | Ask the provider | Keep as evidence |
|---|---|---|
| Ownership | Who owns the domains, tenants, devices, data, licences, backups and recovery accounts? | Account and asset register; responsibility matrix |
| Access control | Which people and tools can access our environment, and how are least privilege, MFA, emergency access and offboarding handled? | Access list; review schedule; offboarding record |
| Contracts and compliance | Which legal, privacy and contractual responsibilities apply, including subcontractors and breach communication? | Agreement; data-handling terms; escalation contacts |
| Data protection | How are credentials, secrets and sensitive data handled in transit, at rest and during support? | Documented controls; approved tools; exception register |
| Incident response | What happens when an account, endpoint, provider tool or supplier is compromised? | Roles; notification path; incident record template |
| Continuity and recovery | What is backed up, what are the recovery objectives, and when was a restore last tested? | Backup scope; RTO/RPO assumptions; restore evidence |
| Supply chain | Which platforms, subcontractors and downstream services are involved, and who owns their risk? | Vendor inventory; dependencies; review notes |
| Exit and handoff | How do we retrieve data, configurations, credentials and documentation if we change providers? | Exit steps; export format; transition responsibilities |
| Retention and destruction | What is retained after termination, for how long, and how is deletion or return confirmed? | Retention schedule; deletion or return confirmation |
Download the blank MSP due-diligence worksheet (TXT). It contains no provider scores or sensitive-data fields; keep completed copies private.
Red flags that deserve a second question
Everything is included
A proposal should name covered systems, users, devices, response targets, exclusions and who performs physical work. A broad label is not a measurable responsibility.
Compliance is guaranteed
Compliance depends on the organization, services, controls, evidence and obligations in scope. Ask which controls the provider will perform and which remain with your business.
Backups are automatic
Ask what is protected, how long it is retained, who can delete it and whether a representative restore has been tested. A backup status screen is not the same as recovery evidence.
No exit plan
Customer-owned accounts, documented configurations and a defined handoff protect continuity. Confirm how access and records return to you before the relationship starts.
Bring useful, non-sensitive information
You do not need to send passwords, private exports or secret keys to begin a scope conversation.
Environment outline
Approximate users, devices, locations, major applications, connectivity dependencies and current provider responsibilities.
Business priorities
Critical workflows, deadlines, recurring problems, recovery expectations, regulatory concerns and the cost of disruption.
Existing evidence
Current agreements, asset lists, backup reports, incident notes and recovery tests, with sensitive details redacted.
Make the next step measurable
North Star can help scope managed IT, Microsoft 365, cybersecurity, cloud, backup and recovery work around the systems, responsibilities, deadlines and evidence you actually have. Customers keep ownership of their domains, tenants, data, code, analytics, billing and recovery accounts unless a written agreement says otherwise.
Service is remote-first across Canada. Physical work is scheduled according to scope and availability from the real dispatch locations in Prince George, BC and Grande Prairie, AB. This checklist does not promise compliance, recovery, response time or a particular result.
Review managed IT service scope or compare published managed IT pricing before requesting an assessment.
Managed IT provider questions
What should a managed IT contract include?
It should identify covered systems and users, responsibilities, access, response targets, exclusions, security handling, recovery assumptions, billing, escalation and exit or handoff terms. The exact contract depends on the environment and services.
Should the MSP own our administrator accounts?
Customers should understand and retain control of their domains, tenants, data, billing and recovery paths. Grant the access required for the agreed responsibility, document it and plan how access is reviewed and removed.
How can we tell whether backups work?
Confirm the protected data, retention, recovery objectives, permissions and dependencies, then review evidence from representative restore tests. A successful backup job alone does not prove that the business can recover.
Does hiring an MSP transfer our privacy obligations?
No. The organization remains responsible for understanding its legal and contractual obligations. The agreement should define the provider responsibilities, safeguards, subprocessors, incident route and evidence needed for the services in scope.
Can North Star review our current provider agreement?
North Star can discuss the technical responsibilities, access, systems, risks and transition questions in a scoped assessment. Legal interpretation and contract advice remain with your qualified legal or privacy advisors.
Turn the checklist into a practical scope
Share a non-sensitive outline of your users, systems, priorities and current responsibilities. North Star will identify the next technical step; the assessment is not an emergency channel or a quote.
Discuss managed IT requirementsContact North Star