No technical knowledge required. Each check takes minutes, and each one surfaces the same underlying question: does anyone own this outcome, or only fragments of it? Answers that start with “I think…” are the findings.
Support, security, Microsoft 365, devices, networks, vendors. For each: who is the single accountable owner? Not “the MSP” — a name. If two leaders in the room give different answers, that area is unowned.
For each one, ask: was the cause fixed, or the symptom cleared? A password reset is a symptom; asking why lockouts spiked is a cause. Five symptoms in a row means your provider runs a queue, not an operation.
How many days from start date until the new hire had laptop, accounts, and correct access — fully, without follow-ups? Ask HR and the hiring manager separately. The gap between their answers is the process.
Licenses, hardware refresh, contracts, domains, certificates. Does a single forward-looking calendar exist — or do renewals surprise finance? If it does not exist, next year's surprises are already scheduled.
Who saw it, who investigated, who decided, and where is that written down? Then one more: when was a backup last restored — actually restored, not “the job ran.” Both answers should be specific and boring.
5 clean answers: your IT has real ownership — rare and worth protecting. 3–4: typical for a growing company; the gaps are fixable with standards and a named owner per area. 0–2: your next incident is already in motion; ownership, not tooling, is the fix.