Provider oversight

Ask for evidence, not reassurance.

Questions a manufacturing CFO can use to understand whether an IT provider is protecting the systems the business depends on.

Good providers should welcome clear questions. Ask for a short answer, the named owner, the last validation date, and the underlying evidence. “We handle that” is not a complete answer when production, customer commitments, or financial reporting are at stake.

Ten questions worth asking

  1. Which systems would interrupt production, shipping, orders, or close if unavailable? Ask for the business owner and recovery target for each.
  2. When was the last successful recovery test for each critical system? Ask for actual time to restore and what was not included.
  3. Who can access our systems today? Request privileged accounts, vendor access, and offboarding evidence.
  4. What open risks require a business decision? Ask for impact, cost, owner, due date, and consequence of deferral.
  5. What will renew or be replaced in the next 12 months? Request contract dates, lifecycle assumptions, and implementation work.
  6. What did you test this quarter? Look for recovery tests, access reviews, response exercises, and vulnerability-management evidence.
  7. Which business processes depend on undocumented knowledge? Clarify whether a provider, consultant, or individual is a single point of failure.
  8. How would we know a security incident affects operations? Ask for the notification path, decision owner, and escalation timing.
  9. What is our ERP and integration risk? Request data flow, manual workarounds, ownership, and reconciliation status.
  10. What would a clean transition look like if we changed providers? Ask for documentation, access transfer, asset records, and a continuity plan.
Feedback from CFOsBefore approving an expensive replacement or implementation, map the cost of acting, waiting, and doing nothing. The provider should help quantify the dependencies rather than simply recommend a platform.

What a useful monthly report contains

  • Service health and material incidents, written in business terms.
  • Open risks with owner, target date, financial or operational effect, and decision needed.
  • Contract, lifecycle, and project changes that affect the 12-month plan.
  • Recovery and access-control evidence that was tested in the reporting period.