An accounting firm reviewing a managed IT services agreement should evaluate at least seven areas before signing: scope of services, cybersecurity responsibilities, support expectations, exclusions and additional fees, strategic planning, documentation ownership, and termination terms.

For a 5-25 employee accounting firm, the monthly price matters, but the agreement should make clear what the MSP is actually responsible for operating, what remains the firm's responsibility, and what will cost extra.

Two managed IT providers can quote similar monthly fees while offering very different levels of service.

The goal is not simply to find the lowest-priced agreement. It is to understand what the firm is buying, where responsibility begins and ends, and whether the agreement supports the reliability and security the business requires.

Why the Managed IT Services Agreement Matters

An MSP agreement is more than a pricing document. It establishes expectations between the accounting firm and its IT provider. That becomes especially important when technology is business-critical. During tax season, an accounting firm may depend on:

  • Microsoft 365
  • Tax and accounting applications
  • Document management systems
  • Client portals
  • Internet connectivity
  • Servers and cloud infrastructure
  • Backup and recovery systems
  • Cybersecurity tools
  • Remote access
  • Employee workstations

When one of these systems has a problem, the firm should not have to discover for the first time whether the MSP is responsible for it. A useful agreement should make responsibilities understandable before an incident occurs.

Here is a seven-part framework accounting firms can use when evaluating a managed IT services agreement.

1. Define Exactly What Services Are Included

Start with the scope. Terms such as managed IT, fully managed, and unlimited support can sound comprehensive, but they do not necessarily mean the same thing from one provider to another. Before comparing agreements, leadership should have a clear understanding of what to expect from a managed IT provider, including both day-to-day support and the proactive responsibilities that should be part of the relationship. The agreement should identify which services the MSP provides.

Depending on the provider, that may include:

  • Help desk support
  • Remote support
  • Onsite support
  • Workstation management
  • Server management
  • Network monitoring
  • Firewall management
  • Patch management
  • Microsoft 365 administration
  • User onboarding and offboarding
  • Backup monitoring
  • Cybersecurity management
  • Vendor coordination
  • IT documentation
  • Strategic technology planning

The firm should also understand which devices and systems are covered. For example, does the agreement cover only employee computers, or does it also include servers, network switches, wireless access points, firewalls, printers, conference-room equipment, and other infrastructure?

Ask What "Unlimited" Actually Means

If an agreement includes unlimited support, determine what is actually unlimited. Does that include:

  • Remote support?
  • Onsite visits?
  • After-hours support?
  • New employee setup?
  • Application troubleshooting?
  • Vendor coordination?
  • Project work?

"Unlimited" may apply to some support activities while other work is billed separately. That does not necessarily make the agreement unfavorable. What matters is that the distinction is clear enough for leadership to understand the expected cost and scope.

2. Clarify Cybersecurity Responsibilities

Cybersecurity deserves explicit attention because security responsibilities are often shared among the MSP, the accounting firm, software vendors, and employees. The agreement should also identify which cybersecurity controls the provider manages, which controls depend on the firm's participation, and how responsibility is handled when requirements change.

Depending on the environment, MSP-managed security may include:

  • Endpoint protection
  • Multi-Factor Authentication
  • Microsoft Entra ID
  • Conditional Access
  • Email security
  • Patch management
  • Encryption
  • Security awareness training
  • Administrative-access controls
  • Security monitoring
  • Backup protections
  • Vulnerability management

But having a security product does not automatically mean the MSP is responsible for every aspect of cybersecurity. For example, the firm may still be responsible for approving security policies, notifying the provider about employee departures, maintaining cyber insurance, following internal procedures, or making decisions about access to sensitive information.

Ask Who Is Responsible When Something Changes

Security risk often appears when the environment changes. A new employee joins. An employee leaves. Someone changes roles. A new cloud application is introduced. A partner needs temporary access.

The agreement should establish how these changes are communicated and who is responsible for implementing the appropriate controls. The goal is to avoid gaps created by assumptions.

3. Understand Support Expectations and Escalation

An accounting firm should understand how support works before it has an urgent problem.

Important questions include:

  • How are support requests submitted?
  • What are the normal support hours?
  • Is after-hours support available?
  • How are urgent issues classified?
  • What happens when a ticket cannot be resolved by the first technician?
  • How are widespread outages handled?
  • Is onsite support available?
  • How are third-party vendors involved when necessary?

Accounting firms should pay particular attention to tax-season requirements. An issue that is inconvenient in July may be operationally critical in March.

Response Time Is Not the Same as Resolution Time

This distinction matters. A provider may promise to respond to a critical ticket within a defined period, but that does not necessarily mean the issue will be resolved within that period. Resolution can depend on the nature of the problem, vendor involvement, replacement hardware, Internet providers, software developers, or other factors outside the MSP's direct control. Rather than assuming every problem can be resolved within a guaranteed timeframe, the firm should understand:

  1. How quickly will the issue be acknowledged?
  2. How will it be prioritized?
  3. Who owns the escalation?
  4. How will leadership be kept informed?

Clear escalation and communication processes can be as important as the initial response target.

4. Identify What Is Excluded and What Costs Extra

One of the most important sections of an MSP agreement may be what is not included. Common examples of separately billed work can include:

  • Major technology projects
  • Office moves
  • Cloud migrations
  • New server deployments
  • Large hardware refreshes
  • After-hours project work
  • Cabling
  • Specialized application projects
  • Remediation of pre-existing conditions
  • Certain onsite work
  • Equipment and software purchases

Every MSP structures services differently. The objective is not to demand that everything be included in one monthly fee. The objective is to eliminate avoidable surprises.

Look at the Total Cost, Not Just the Monthly Fee

Consider two hypothetical proposals.

Provider A: $2,000 per month
Provider B: $2,500 per month

Provider A appears to cost $6,000 less per year: $500/mo difference × 12 mo = $6,000.

But suppose Provider A separately charges for several services that Provider B includes. The apparent $6,000 savings may shrink, or even disappear, depending on what the firm actually needs during the year.

This is why managed IT proposals should be compared by scope, responsibility, exclusions, and expected annual cost, not monthly price alone. Understanding the factors that influence managed IT costs for accounting firms can also help leadership determine whether competing proposals are truly comparable.

5. Look for Proactive Management and Strategic Planning

A managed services agreement should explain more than what happens when an employee submits a ticket. For an accounting firm dependent on technology, the provider should also have a process for identifying problems before they become emergencies.

That may include:

  • Proactive monitoring
  • Patch management
  • Hardware lifecycle tracking
  • Warranty tracking
  • Backup monitoring
  • Recovery testing
  • Security reviews
  • Capacity planning
  • Licensing reviews
  • Technology roadmaps
  • Quarterly technology reviews

Leadership should ask: What does the provider do when nothing is broken?

That question can reveal a significant difference between reactive support and proactive technology management.

Ask How Recommendations Become a Plan

Finding a problem is only the first step. If the MSP identifies aging computers, an unsupported server, inadequate backup capacity, security gaps, or Internet resiliency concerns, there should be a process for turning those findings into priorities.

A useful planning process should identify:

What needs attention → why it matters → when it should be addressed → what it is likely to cost.

That gives leadership the ability to make technology decisions before urgency removes its options.

6. Confirm Who Owns the Documentation, Accounts, and Data

An accounting firm should maintain appropriate control over its technology environment even when an MSP manages it. Before signing, determine how the agreement addresses:

  • Network documentation
  • Asset inventories
  • Vendor information
  • Microsoft 365 tenant access
  • Domain registrations
  • DNS
  • Administrative credentials
  • Backup systems
  • Cloud platforms
  • Software licensing
  • Security configurations
  • IT procedures

The provider may maintain much of the firm's IT documentation operationally, but leadership should understand what is documented, what information the firm can access, and what happens to that information if the relationship ends.

Be Careful with Provider-Controlled Accounts

Whenever practical, important business assets should be structured so the accounting firm does not lose control simply because it changes IT providers. For example, leadership should know:

  • Who owns the firm's domain registration?
  • Who controls the Microsoft 365 tenant?
  • Who has administrative access?
  • Who controls backup accounts?
  • Where are credentials stored?
  • How can the firm obtain its documentation?

These questions may seem unimportant when the MSP relationship is working well. They become extremely important when a firm changes providers.

7. Understand the Term, Renewal, and Exit Process

Before entering an MSP relationship, understand how the relationship can end. Review items such as:

  • Initial contract term
  • Renewal provisions
  • Notice requirements
  • Termination provisions
  • Early termination fees, if any
  • Price-adjustment provisions
  • Data and documentation return
  • Transition assistance
  • Final billing
  • Hardware or software commitments

The agreement should also explain what happens during provider transition. Even if a firm is satisfied with its current provider, the agreement should establish a workable transition process in case the business eventually decides that changing managed IT providers is necessary. The incoming provider needs enough information to assume responsibility without creating unnecessary disruption. A well-defined transition process protects both the firm and the provider.

A Practical Managed IT Agreement Review Checklist

Before signing an agreement, leadership should be able to answer these 10 questions:

  1. Exactly what systems, users, and locations are covered?
  2. Which support services are included in the monthly fee?
  3. What work is billed separately?
  4. Which cybersecurity responsibilities belong to the MSP?
  5. Which cybersecurity responsibilities remain with the firm?
  6. How are urgent issues prioritized and escalated?
  7. What proactive management and planning activities are included?
  8. Who controls critical accounts, documentation, and administrative access?
  9. How are prices, renewals, and contract changes handled?
  10. What happens to documentation, credentials, and services if the relationship ends?

If leadership cannot answer these questions after reviewing the proposal and agreement, additional clarification may be appropriate before signing.

Example: Two MSP Agreements With Similar Pricing

Consider a 20-person accounting firm evaluating two managed IT providers. Both proposals appear relatively close in monthly cost.

The first proposal emphasizes:

  • Help desk support
  • Device monitoring
  • Patch management
  • Basic Microsoft 365 administration

The second includes those services but also defines:

  • Cybersecurity management
  • Backup monitoring
  • Hardware lifecycle tracking
  • Quarterly technology reviews
  • Documentation standards
  • Vendor coordination
  • Strategic planning
  • Defined onboarding and offboarding processes

The firm initially sees the decision as a price comparison. After reviewing the scope, leadership realizes it is actually choosing between two different operating models. That does not automatically mean the more comprehensive agreement is the right choice. It means the firm can now make an informed decision based on what it expects its IT provider to be responsible for. That is the purpose of reviewing the agreement carefully.

Red Flags to Clarify Before Signing

Not every ambiguous provision is necessarily a problem. Sometimes an agreement simply needs clarification. However, leadership should ask questions when it encounters:

  • Vague descriptions of included services
  • Undefined "unlimited" support
  • Unclear cybersecurity responsibilities
  • No explanation of after-hours support
  • No escalation process
  • Broad exclusions that are difficult to interpret
  • No strategic planning process
  • No clear documentation-access provisions
  • Unclear ownership of critical accounts
  • No defined transition process
  • Contract terms that leadership does not understand

The appropriate response is not necessarily to reject the provider. It is to get the ambiguity resolved before the relationship begins.

The Agreement Should Reflect How the Technology Will Be Operated

At Everleap IT, we view a managed services agreement as more than a support contract. For an accounting firm, it should establish a framework for operating a Production Ready technology environment. That means responsibilities should extend beyond responding to problems and include appropriate processes for:

  • Monitoring
  • Cybersecurity
  • Documentation
  • Lifecycle management
  • Backup and recovery
  • Capacity planning
  • Strategic planning
  • Operational reviews
  • Continuous improvement

The agreement should make those expectations visible. A provider cannot eliminate every outage, security incident, application problem, or hardware failure. But the relationship should establish how technology is managed before, during, and after those events.

How Everleap IT Approaches Managed IT Agreements

Our approach has been shaped by more than 20 years of operating production hosting environments, where unclear responsibilities and undocumented assumptions can create operational risk. For accounting firms, that experience informs how we approach:

  • Proactive monitoring
  • Cybersecurity
  • Microsoft 365 administration
  • Backup and recovery
  • Documentation
  • Hardware lifecycle management
  • Vendor coordination
  • Quarterly technology reviews
  • Strategic technology planning
  • Production Readiness assessments

The objective is to create a clear operating relationship in which both the provider and the client understand responsibilities, priorities, and expectations.

What Should You Do Before Signing a Managed IT Services Agreement?

Before signing, do three things:

First, compare scope rather than price alone. Make sure competing proposals are actually providing comparable services.

Second, identify assumptions. Ask who is responsible for security, backup, documentation, applications, vendors, employee changes, and strategic planning.

Third, understand the exit. Know what happens to accounts, credentials, documentation, licensing, and services if you eventually change providers.

A managed IT agreement should reduce uncertainty and not create uncertainty.

Everleap IT helps accounting firms throughout California's Inland Empire, including Rancho Cucamonga, Ontario, Chino, Claremont and nearby communities, operate business-critical technology through proactive monitoring, cybersecurity, lifecycle management, documentation, recovery readiness, strategic planning, and Production Readiness assessments.

If your accounting firm is evaluating managed IT services, a technology assessment can provide a clearer picture of your current technology, identify operational and security priorities, and define the responsibilities a managed IT provider should take on. Reach out today to discuss your IT environment and book a technology assessment.