Buyer's guide
Twelve questions to ask before signing an IT support contract
Twelve questions that show how a provider actually works: who does the job, what happens when it goes wrong, and how the price moves. Whether they have an answer ready matters more than the answer itself.
By Claire Donnelly · Last reviewed 11 August 2026 · 6 min read
The short version
- Ask who will really do the work, not who is in the room selling it
- Find out what happens when the one person who knows your setup is away
- Ask how the price moves at renewal, and when headcount goes up or down
- Request a reference from a client who left, not only from happy ones
- Hesitation on a straightforward question tells you more than the answer does
What these are for
The contract itself is a separate job: response and fix targets, exclusions, notice periods and the clauses that make an agreement worthless are covered in our guide to what a good SLA looks like. Read that alongside this one.
These twelve are about the provider rather than the paperwork – the things a document cannot tell you. How many people you are actually buying, what they will do in the first three months, what happens at two in the morning, and how gracefully they behave when a customer leaves.
Ask them in a meeting rather than by email. You are listening for whether the answer arrives readily, because a provider who has thought about these has usually thought about the rest.
The twelve questions
-
1. Who will actually be doing the work?
The people in a sales meeting are rarely the ones who answer your calls. Ask how many engineers you would deal with, whether anybody is assigned to your account, and whether you can meet them before you sign anything.
Red flag: Warm assurances about "the team" with no names, or a salesperson who cannot say who would handle you
-
2. How many clients does each engineer look after?
This is the best single predictor of whether your ticket gets proper attention. Nobody publishes it, and most providers will tell you if asked directly. What you want back is a number rather than an adjective.
Red flag: A refusal to give any figure, or an answer about being "right-sized for demand"
-
3. What happens when the person who knows us is away?
Smaller providers often run on one person's memory of your setup. That works until they are on holiday during your outage. Ask where your systems are written down and who else can read it.
Red flag: The knowledge plainly lives in one head, and the reassurance is that they are always available
-
4. How will you document our systems, and can we have a copy?
Documentation is what makes cover possible and makes you portable. It should be produced as a matter of course, kept current, and handed over on request rather than treated as the provider's own property.
Red flag: Documentation described as internal, or something you would be given "if you ever left"
-
5. What does onboarding involve, and what do you need from us?
The first month sets the tone. Ask what they will do, how long it takes, what access they need, and how much of your team's time it will take - that cost is real and almost never quoted.
Red flag: Onboarding described as effortless, with no demands on your side at all
-
6. What will you have done ninety days in?
A good provider has a view on this before they know your systems: an audit done, the estate documented, backups verified, the obvious risks closed. It shows whether they intend to improve things or simply answer the phone.
Red flag: No plan beyond settling in and waiting for tickets to arrive
-
7. Who answers outside business hours, and what can they do?
Out-of-hours cover ranges from a staffed team to one person's mobile. Ask who picks up at nine on a Sunday, what they are authorised to fix there and then, and what genuinely has to wait until Monday.
Red flag: Round-the-clock cover claimed with no detail on who is awake or what they can act on
-
8. What happens in the first hour of a security incident?
Ask them to walk you through a suspected compromise: who is called, who can isolate a machine, who contacts you, and at what point you would be told. Vagueness matters more here than anywhere else on this list.
Red flag: The answer is a product name rather than a sequence of actions and people
-
9. How do we escalate when we are not happy?
Every relationship has a bad month. You want to know now who you ring above your usual contact, and whether there is a regular review where problems get raised rather than quietly accumulated.
Red flag: Escalation means emailing the same person who is already not helping you
-
10. Can we speak to a client who left you?
Any provider can produce three happy references. The revealing request is for one who moved on. Willingness matters more than the conversation, and a graceful account of why somebody left tells you a great deal.
Red flag: Immediate deflection, or the claim that no customer has ever left
-
11. How does the price change, and when?
Ask about renewal uplift, annual indexation, what happens when headcount rises, and whether you can reduce numbers mid-term. An agreement that grows easily and shrinks slowly costs more than the quote suggests.
Red flag: Increases described as "in line with the market", with no cap and no notice period
-
12. What would you not take on?
Every provider has limits - an application they do not know, a compliance regime they do not work in, a size of business they are not built for. One who claims no limits at all is either inexperienced or not listening.
Red flag: A confident assurance that they handle absolutely everything
The three that tell you most
If you only have time for three, ask about the engineer-to-client ratio, the first hour of a security incident, and speaking to a customer who left.
The first tells you whether there is capacity behind the promises. The second tells you whether anybody has done this for real. The third tells you how they behave when the relationship is not going their way, which is the only part of a supplier’s character you cannot observe until it matters.
Then write down what you were told. Most of these answers are not in the contract, and a note of what was said in the meeting is remarkably useful a year later – usually because it turns a vague disappointment into a specific, fixable conversation.
Common questions
Is it reasonable to ask all twelve?
Yes, and a good provider will be pleased you did - it is a sign you will be a considered customer rather than a difficult one. If a question makes somebody defensive at the selling stage, that is information about how a complaint would be received later.
We are only a handful of people. Do these still apply?
Most of them, and the ratio and out-of-hours questions matter more rather than less. A small business feels the loss of one engineer's attention far more sharply than a large one.
Should we send these in advance?
Send about half in advance so they can prepare the factual ones, and keep the incident-response and ex-client questions for the meeting. You learn different things from a prepared answer and an unprepared one.
What if we are renewing rather than switching?
They are just as useful at renewal, and rather more comfortable to ask, because you already know how the last year went. Renewal is the natural moment to raise anything that has been quietly annoying you.
Written by Claire Donnelly
Weighing up a provider and want a second opinion?
Send us what you have been offered. We'll tell you what the answers suggest and which questions are worth pressing - including when the honest advice is to stay where you are.
Ask for a second opinion