Outsourcing IT support can improve coverage, skills and accountability, but a provider cannot immediately repair years of undocumented decisions. If the customer does not know which users, systems, licenses, administrators or vendors exist, the first months of service become discovery under pressure.
A readiness assessment helps the business organise what it already knows, identify urgent risks and set realistic expectations before proposals are requested or a contract begins.
Readiness area 1: business priorities
List the business processes that depend on technology:
- sales and customer communication;
- finance, invoicing and payments;
- order, warehouse or retail operations;
- project and document management;
- employee collaboration;
- remote and field work;
- customer portals or websites;
- management reporting.
For each process, identify the critical systems, operating hours and acceptable disruption. This helps providers prioritise service correctly.
Readiness area 2: user and location baseline
Prepare an accurate count of:
- employees and contractors;
- executives and assistants;
- remote and field users;
- offices, warehouses, shops and project sites;
- working hours by location;
- expected growth or closure;
- users requiring after-hours support.
Do not price from payroll headcount alone. Some employees may not use company systems, while contractors and shared devices still create support demand.
Readiness area 3: device and infrastructure inventory
Record:
- laptops and desktops;
- mobile devices;
- printers and scanners;
- meeting-room systems;
- servers and storage;
- firewalls, switches and access points;
- internet links and VPNs;
- UPS and network cabinets;
- specialist or operational devices.
Include assigned user, location, age, warranty, operating system and support status.
Readiness area 4: cloud and application portfolio
List:
- Microsoft 365 or Google Workspace;
- ERP, CRM, finance and HR systems;
- industry-specific platforms;
- backup and security tools;
- websites, domains and hosting;
- telephony and contact-centre services;
- integrations and automated workflows;
- department-purchased SaaS products.
Record business owner, administrator, vendor, renewal and support contact for each platform.
Readiness area 5: administrator and credential ownership
The customer should know who controls:
- Microsoft 365 tenant;
- domains and DNS;
- firewalls and networks;
- servers and cloud hosting;
- backup platform;
- endpoint and remote-support tools;
- business applications;
- internet and telecom accounts.
Recover missing ownership before switching providers where possible. Use named accounts and MFA rather than sharing one administrator password.
Readiness area 6: employee lifecycle
Define how HR and managers communicate:
- new joiners;
- role or location changes;
- contractor end dates;
- employee exits;
- device and SIM return;
- mailbox and file ownership;
- application access approval.
Microsoft Entra describes identity governance through joiner, mover and leaver stages. Its lifecycle workflow guidance offers a useful structure even when the business uses manual approvals.
Readiness area 7: backup and recovery
Prepare answers to:
- Which systems and data are backed up?
- How frequently?
- Where are copies stored?
- Who receives failure alerts?
- When was the last restore test?
- What is the expected recovery time?
- Who confirms that restored data is usable?
- Which systems remain unprotected?
Do not hide known gaps from bidders. Clear risk information allows a responsible transition plan.
Readiness area 8: cybersecurity baseline
Review:
- MFA coverage;
- privileged accounts;
- endpoint protection and encryption;
- patch status;
- email security;
- firewall and remote access;
- guest and external sharing;
- former-user access;
- security alerts and incidents;
- insurance or contractual requirements.
NIST Cybersecurity Framework 2.0 provides a non-prescriptive structure across Govern, Identify, Protect, Detect, Respond and Recover. The NIST CSF 2.0 can help management organise current capabilities and desired outcomes.
Readiness area 9: support history
Export or summarise the last six to twelve months of:
- tickets and recurring issues;
- major outages;
- security incidents;
- backup failures;
- vendor escalations;
- projects and changes;
- user complaints;
- emergency purchases.
This history helps the new provider estimate demand and identify early improvements.
Readiness area 10: vendor and contract register
List:
- service provider;
- contract and renewal date;
- support entitlement;
- portal and escalation contacts;
- payment owner;
- administrator access;
- termination notice;
- dependency on other services.
The managed provider may coordinate these vendors but cannot replace missing contracts or support entitlement.
Readiness area 11: service expectations
Define what the business expects for:
- service hours;
- remote support;
- onsite support;
- after-hours incidents;
- priority and response;
- new-user setup;
- standard changes;
- vendor coordination;
- monthly reporting;
- projects outside recurring scope.
A provider cannot design the right service if management simply asks for “complete support.”
Readiness area 12: customer responsibilities
The business must commit to:
- timely approvals;
- accurate joiner and leaver information;
- valid licenses and warranties;
- access to premises and systems;
- use of approved support channels;
- decisions on recommended risk treatment;
- participation in recovery and project testing;
- one accountable customer owner.
Readiness area 13: budget structure
Separate the expected budget into:
- recurring managed support;
- onsite allowance;
- monitoring and management tools;
- security and backup licenses;
- cloud and Microsoft 365 licenses;
- hardware replacement;
- transition and remediation;
- planned projects;
- contingency.
A low monthly retainer cannot absorb every legacy risk and project requirement.
Readiness area 14: transition information
Prepare:
- current provider notice terms;
- documentation and credential return requirements;
- open tickets and projects;
- planned changes and renewals;
- critical dates;
- employee communication;
- old tool removal and new tool deployment;
- acceptance criteria.
Score the organisation’s readiness
| Status | Characteristics | Action |
|---|---|---|
| Ready | Assets, owners, systems, vendors, risks and expectations are documented. | Proceed to structured RFP and due diligence. |
| Partly ready | Core information exists but access, backup or documentation gaps remain. | Run a short discovery and risk-closure phase. |
| High transition risk | Accounts, data, vendors and responsibilities are unclear. | Protect critical access and recovery before committing to a fixed service assumption. |
A two-week readiness sprint
Days 1–3
Confirm users, locations, critical systems, administrators and contracts.
Days 4–6
Review devices, infrastructure, backup, security and support history.
Days 7–9
Define service hours, onsite expectations, customer responsibilities and reporting.
Days 10–12
Identify urgent risks, missing documentation and transition dependencies.
Days 13–14
Approve the baseline, budget categories and provider evaluation process.
The outsourcing readiness checklist
- Business-critical services and owners are known.
- User and location counts are accurate.
- Devices and infrastructure are listed.
- Cloud applications and renewals are visible.
- Administrator ownership is confirmed.
- Joiner, mover and leaver responsibilities are documented.
- Backup scope and restore evidence are understood.
- Cybersecurity gaps are visible.
- Support history and recurring problems are available.
- Vendor contracts and dependencies are listed.
- Service expectations are specific.
- Customer responsibilities are accepted.
- Budget separates recurring service, tools and projects.
- Transition obligations are understood.
Assess the quality of current documentation
Documentation should be judged by whether another qualified person can use it. A spreadsheet listing device names is not enough if network diagrams, administrator ownership, backup procedures and vendor contacts are missing.
Classify each area as current, incomplete, unverified or absent. Assign an owner and date for critical gaps. Prioritise records needed to protect access and recovery: tenant ownership, domain control, firewall configuration, backup credentials, encryption keys and support contracts.
Identify inherited technical debt
New providers often discover old equipment, unsupported software, undocumented integrations and temporary workarounds. These items should not be hidden inside the monthly fee.
Create a technical-debt register containing:
- affected service;
- business impact;
- current workaround;
- risk if left unchanged;
- recommended action;
- estimated timing and budget category;
- decision owner.
This allows the provider to distinguish normal support from remediation and projects.
Prepare the internal communication plan
Employees should know when the provider changes, how to request support, which channels are no longer valid and what information should be included in a ticket. Managers should understand new approval requirements for access, hardware and projects.
Communicate the launch date, support hours, urgent contact method, expected response by priority and the process for unresolved issues. A simple user guide reduces confusion during the transition.
Set acceptance criteria for the first month
Before service starts, agree what must be true for transition to be considered complete. Examples include validated administrator access, full asset baseline, working ticket channels, monitoring coverage, backup review, priority definitions, vendor register and first management report.
Open risks may remain, but they should have owners, dates and commercial treatment. Acceptance should be based on evidence rather than the passage of time.
Confirm data ownership and retention
Before outsourcing begins, identify who owns business data, how long it must be retained and who may approve deletion or export. Include departed-user mailboxes, shared drives, project archives, backups, customer records and application databases. The provider can operate retention and recovery processes, but the business must define the legal and operational requirement.
Record where data is hosted, which suppliers can access it, how exports are produced and what must be returned at contract end. This becomes important during audits, disputes, incidents and provider transitions.
Frequently asked questions
Does the business need perfect documentation before outsourcing?
No. The purpose is to make gaps visible so discovery, risk and pricing are handled honestly.
Should the new provider perform the readiness assessment?
It can, but the customer should retain the baseline and may use independent advice where provider selection is still open.
How long does an IT support transition take?
It depends on size, risk and documentation. The transition should continue until accounts, tools, documentation, monitoring and service ownership are accepted.
What should be fixed before signing?
Critical administrator ownership, backup access, expired contracts and uncontrolled provider access deserve immediate attention.
Who should own outsourced IT internally?
A named business owner should coordinate priorities, approvals, service reviews and management decisions.
Outsourcing works best when the customer enters the relationship with clear priorities and visible responsibilities. Dubai businesses preparing for a structured operating model can review managed IT services in Dubai.