Back to blogTips & Guides

Managed IT Provider Due Diligence Checklist for NZ SMBs

||8 min read
Share
Blue-and-white checklist clipboard with IT icons and a New Zealand map outline on a clean, modern background

Take Control of Your IT Environment

Reduce risk, improve performance, and gain full visibility across your systems with CorIT Tech’s managed IT and security services. Let’s assess where you are today and show you what better looks like.

Book Your IT Assessment

Avoid IT headaches: how to choose the right managed IT partner

Choosing a new managed IT service provider is not just an IT task; it is a business decision that will show up in your revenue, customer experience, and staff morale. Many New Zealand small and medium businesses review IT contracts around financial year planning, but only a few run proper due diligence. That is when organisations can be swayed by a slick sales pitch or the lowest quote and end up paying for it later with outages and security problems.

When the wrong partner is in place, the impact is felt across the business. Unplanned downtime stops jobs and projects, weak security keeps directors awake at night, support during incidents is slow or confusing, and trying to leave the provider is harder than it should be. The good news is you can avoid most of that with a clear, business-focused process for selecting and onboarding a managed IT service provider.

This article shares a practical checklist for assessing managed IT service providers, a simple scoring matrix your board can trust, and a 30-60-90 day transition plan shaped for New Zealand organisations. It is written for owners, directors, and operations or IT managers in 10- to 250-person businesses across sectors like professional services, construction, manufacturing, healthcare, and non-profit.

What is at stake when you change managed IT service providers

IT is now threaded into almost every activity in your business. If your email or files go down, you miss customer calls, you miss tenders, and your team sits waiting. Slow systems quietly cut into productivity and margins each day. On top of that, privacy expectations and sector rules mean poor IT decisions can turn into regulatory or legal problems.

Common New Zealand scenarios include an engineering firm in Christchurch losing access to email during a tender period, or an Auckland medical practice discovering that backups were not working properly after a near-miss privacy incident. These are not just IT hiccups; they are business risks that affect revenue and trust.

Hidden transition risks can be just as painful as the obvious ones. Documentation may be lost or incomplete when the old provider leaves. Legacy systems that nobody wants to support may still be critical to daily operations. There can be finger-pointing between the old and new provider when issues come up. Staff may be confused if ticketing processes and communication channels are not explained clearly.

Treating due diligence as risk management and cost control is far cheaper than paying later for emergency fixes, long outages, or security incidents. A careful selection process helps you avoid surprises and gives your board confidence that IT is being handled in a structured, accountable way.

Designing an RFP that gets answers you can use

A simple, focused request for proposal (RFP) can work well for SMBs when you are renewing a contract, planning a major cloud move, dealing with fast growth, or when performance with your current provider has dropped. The goal is not a huge document, but one that gives providers enough context to respond clearly and specifically.

A practical RFP usually starts with a short business overview and your main locations around New Zealand. It should include a summary of your current technology and key pain points, such as remote staff, legacy applications, or specialist industry software. It should also spell out a clear scope, for example expected support hours, the number and types of devices and servers, cloud platforms in use, and your security expectations.

Targeted question themes help you compare real capability, not just marketing talk. For service delivery and response, you might ask, "How do you prioritise incidents and what are your target response and resolution times?" For cybersecurity and compliance, you can ask, "How do you help New Zealand SMBs align with privacy expectations and sector regulations?"

Cloud capability is also critical. A useful question could be, "Describe your experience modernising line-of-business apps and file storage for New Zealand SMBs using Microsoft 365 and Azure." To understand sector knowledge, ask, "What experience do you have with businesses in our sector and their specific software and risks?"

Wherever you can, ask for concrete examples such as short case summaries, sample monthly reports, response metrics, and reference clients in similar industries or regions. This gives you something tangible to put side by side when you compare providers and reduces the risk of decisions based on promises alone.

Building a simple scoring matrix your board will trust

A scoring matrix turns a messy set of quotes and proposals into a clear, repeatable decision. It keeps the process transparent for owners and directors and reduces the risk of choosing the most charming salesperson instead of the best long-term partner.

One simple model is to set weightings for your key areas. For example, you might allocate 30 percent to service and support, 25 percent to security, 20 percent to cloud capability, 15 percent to cultural fit, and 10 percent to price. These percentages can be adjusted to reflect your organisation's priorities, but the principle is to avoid letting price dominate.

Within each area, define criteria and score each provider from 1 to 5. For New Zealand SMBs, practical criteria for service and support include local presence and time zone alignment, after-hours support, the ability to provide both remote and onsite support across New Zealand, and clear service level agreements (SLAs). For security, look for proactive monitoring, a structured incident response process, regular backup testing, user training and phishing simulations, and New Zealand data residency options where required by your industry.

Cloud and Microsoft 365 capability can be assessed by looking at their experience with Teams, SharePoint, OneDrive, and common industry integrations such as project tools for construction or practice systems in healthcare. Cultural fit is also important: consider their communication style, willingness to work alongside your internal IT or power users, and their understanding of regional and sector realities.

Shortlist two or three managed IT service providers, have your leadership team score them independently against the matrix, then compare results. Where scores differ, talk through why and use that to shape follow-up questions or reference checks. This creates a more objective, auditable decision process for the board.

Due diligence checklist: what to ask before you sign

Before you sign a new agreement, work through a clear due diligence checklist. Focus on how the provider operates day to day, how they manage security and risk, and how they will partner with you over time.

On the operational and support side, ask them to describe their onboarding process for a firm like yours, for example a 50-person organisation with remote staff across New Zealand. Request their standard SLAs and ask them to share recent performance against those commitments. Clarify how they handle major incidents outside normal business hours and on public holidays, and who makes decisions during a serious outage.

For security and risk management, ask how they monitor for threats and who is watching alerts after hours. Confirm how often they test backups and recovery, and what recovery time you can realistically expect for critical systems. It is also reasonable to ask about their own cybersecurity posture, including security certifications where relevant, insurance cover, and their internal incident response plan.

Strategic and cultural alignment matters just as much. Ask how they will help you develop a three-year IT roadmap aligned to your business goals in New Zealand. Explore how they work with internal IT or tech-savvy staff if you have them, and how responsibilities will be divided. Ask what success looks like in the first 12 months and how they will measure and report on that, for example through uptime statistics, ticket trends, and security metrics.

Capture answers in a simple comparison table so that your leadership team can review them together. Keep your focus on outcomes like uptime improvements, reduced security risk, better staff experience, and predictable monthly IT costs, rather than just the technical tools used.

A 30-60-90 day transition plan that reduces disruption

A structured 30-60-90 day plan is one of the clearest signals that a provider knows how to change over support without chaos. It also gives your team confidence that the transition will be managed carefully.

  • In the first 0 to 30 days, the focus should be discovery and stabilisation. This typically includes auditing the environment, collecting documentation, validating backups/core services/security controls, addressing quick wins, and setting clear support channels and staff communications.
  • From 31 to 60 days, the goal usually shifts to optimisation and security uplift. This phase tackles recurring performance issues (VPN, Wi-Fi, ageing hardware) and implements baseline security improvements such as MFA, better patching, updated endpoint protection, and short security awareness sessions, while confirming industry-specific needs.
  • From 61 to 90 days, the focus moves to strategy and measurable outcomes. The provider should report on early metrics (tickets, incidents, downtime, feedback), agree a 12 to 24 month roadmap (cloud, hardware lifecycle, collaboration, security projects), and define success measures like fewer incidents, faster resolution, easier audits, and clearer budgeting.

Handled well, those first three months turn your next IT contract into a strategic advantage rather than a necessary burden. Managed IT service providers that can walk you through these steps in plain language are usually better placed to support your New Zealand business over the long term.

Turning IT support into a strategic asset

For New Zealand SMBs, choosing a managed IT service provider is a decision that directly affects productivity, security posture, customer experience, and the predictability of IT costs. A focused RFP, a simple scoring matrix, thorough due diligence, and a structured 30-60-90 day transition plan give owners and directors confidence that IT risk is being managed and that investment in technology is aligned with business goals.

As a New Zealand, based technology partner, we at CorIT Tech see every week how this structured approach reduces downtime, strengthens cybersecurity, improves staff experience, and provides clearer IT budgeting. By treating provider selection as a business decision rather than a technical one, you can turn your next IT agreement into a long-term strategic asset for your organisation.

Secure Reliable IT Support That Grows With Your Business

If you are ready to reduce downtime and take the stress out of your technology, our team at CorIT Tech is here to help. Explore how our managed IT service providers can keep your systems secure, monitored and performing at their best. We will work with you to tailor a solution that fits the way your business actually operates. Have questions or need a quick quote? Simply contact us and we will get back to you promptly.

Frequently Asked Questions

What is managed IT provider due diligence for an NZ SMB?

Managed IT provider due diligence is a structured way to check whether an IT partner can reliably support your business, security, and growth. It focuses on service quality, cybersecurity, documentation, and how hard it will be to transition, not just the monthly price.

How do I choose the right managed IT service provider for my small business in New Zealand?

Start by defining your scope, locations, key systems, and the business problems you need solved, then run a simple RFP with targeted questions. Compare providers on response and resolution times, security practices, and proven experience with businesses like yours, then score the results so the decision is consistent and defensible.

What should an RFP include when hiring a managed IT provider?

A practical RFP includes a short business overview, your sites across New Zealand, a summary of current technology, and your main pain points like remote work or legacy apps. It should also define support hours, device and server counts, cloud platforms, and security expectations, plus questions about incident prioritisation and target response times.

What are the biggest risks when switching managed IT providers?

Common risks include downtime that stops work, slow incident response, and security gaps that increase the chance of a privacy or compliance issue. Transition risks also include missing documentation, unsupported legacy systems, and confusion for staff if ticketing and communication channels are not clearly explained.

What is the difference between choosing the cheapest IT provider and choosing the best-fit provider?

The cheapest quote can hide weak service levels, poor security controls, and extra costs when outages or urgent fixes happen. A best-fit provider is selected for reliability, clear accountability, and the ability to support your business outcomes, which usually reduces risk and unplanned costs over time.