Good providers should welcome clear questions. Ask for a short answer, the named owner, the last validation date, and the underlying evidence. “We handle that” is not a complete answer when production, customer commitments, or financial reporting are at stake.
Ten questions worth asking
- Which systems would interrupt production, shipping, orders, or close if unavailable? Ask for the business owner and recovery target for each.
- When was the last successful recovery test for each critical system? Ask for actual time to restore and what was not included.
- Who can access our systems today? Request privileged accounts, vendor access, and offboarding evidence.
- What open risks require a business decision? Ask for impact, cost, owner, due date, and consequence of deferral.
- What will renew or be replaced in the next 12 months? Request contract dates, lifecycle assumptions, and implementation work.
- What did you test this quarter? Look for recovery tests, access reviews, response exercises, and vulnerability-management evidence.
- Which business processes depend on undocumented knowledge? Clarify whether a provider, consultant, or individual is a single point of failure.
- How would we know a security incident affects operations? Ask for the notification path, decision owner, and escalation timing.
- What is our ERP and integration risk? Request data flow, manual workarounds, ownership, and reconciliation status.
- What would a clean transition look like if we changed providers? Ask for documentation, access transfer, asset records, and a continuity plan.
What a useful monthly report contains
- Service health and material incidents, written in business terms.
- Open risks with owner, target date, financial or operational effect, and decision needed.
- Contract, lifecycle, and project changes that affect the 12-month plan.
- Recovery and access-control evidence that was tested in the reporting period.
Request a report your team can verify
The CFO should not accept a technical dashboard as the whole answer. Ask the internal IT owner and provider to jointly identify the business process, evidence date, failed or incomplete tests, and the person accountable for closure. Operations should confirm that the stated recovery order matches production reality.
| Claim | Evidence to request | Who validates it |
|---|---|---|
| “Backups are healthy” | Dated restore result, scope, elapsed time, unresolved gaps | IT and process owner |
| “Access is controlled” | Privileged-account review, vendor access list, leaver test | IT and HR |
| “We respond quickly” | Escalation path, exercise record, contact coverage | Operations and leadership |
Replace a blanket quarterly test demand with a schedule: what was due in this reporting period, what was completed, and what slipped? The cadence should follow the organization’s risk, policy, contract, and criticality.
Ask where the provider’s promise ends
Clarify who owns plant equipment, ERP integrations, cloud identity, backups, cyber-insurance notifications, and incident communications. A provider may manage only part of that chain. Ask for a responsibility matrix and a transition package the company can retain.
Have the broker and counsel confirm any policy condition or notification obligation before an incident. The provider can supply technical facts, but should not promise that a claim will be covered. The CFO’s role is to make unresolved ownership visible and fund the agreed remedy.