Score Your IT Provider: The 40-Point 3AM Test Audit
A scored audit of your current IT provider across eight categories. Run it in an hour and find out whether you have a partner or a vendor.
The short answer
The 3AM Test asks whether you would trust your IT provider to handle a critical failure at three in the morning without you. The scored version audits eight categories at five items each: after-hours response, recovery capability, documentation, security posture, proactive work, business alignment, contract and exit, and the human layer.
The 3AM Test is a single question. If something critical breaks at three in the morning, would you trust your IT provider to handle it without you.
Most owners answer that instinctively and then discover the instinct was based on very little. Nothing has broken at 3AM yet, the invoices arrive on time, and the help desk is polite. That is not evidence, it is an absence of evidence.
This audit turns the instinct into a score. Eight categories, five items each, scored zero to three. It takes about an hour, most of which is asking your provider questions and writing down the answers.
Category one: after-hours response
What is the escalation path outside business hours, in writing. Who is on call this week, by name. What is the guaranteed response time and what happens when it is missed. Whether after-hours support is included or billed separately, and at what rate. When after-hours response was last tested rather than assumed.
The scoring test here is specificity. "We're available 24/7" scores a one. A written protocol naming the on-call engineer, the phone tree, the response SLA, and the last date it was tested scores a three.
Category two: recovery capability
When was the last full restore test, not a backup completion report. What is the documented recovery time objective for your primary systems. Where the second copy lives and whether it is immutable. Whether the recovery plan has been executed by someone other than the person who wrote it. How long a full restore actually took the last time it was done.
A backup that has never been restored is a hypothesis. This category is where the largest gap between belief and reality usually sits.
Category three: documentation
Whether your environment is documented in a system, and whether you can see it. Whether that documentation includes network diagrams, credentials, vendor accounts, and licensing. Whether it is current within 90 days. Whether you would receive it if you terminated the relationship. Whether a new engineer could pick it up cold.
The termination question is diagnostic. A provider who treats your documentation as their intellectual property has structured the relationship around switching cost.
Category four: security posture
Whether you have had an independent assessment, not a vendor-run scan of their own work. Whether multi-factor authentication covers every account including service and admin accounts. Whether administrative access uses separate privileged accounts. Whether there is centralized logging with retention, and how long. Whether the provider's own environment is secured, since they hold keys to yours.
That last item is the one nobody asks and it is the one that has caused the largest small business breaches in the last few years.
Category five: proactive work
Whether ticket volume is trending down over time. Whether there is a documented root cause process for repeat issues. Whether patching is verified rather than scheduled. Whether hardware and license renewals arrive as a plan or as a surprise. Whether the provider brought you a problem you had not noticed in the last six months.
The last item separates monitoring from watching. Plenty of providers monitor. Fewer tell you what they saw.
Category six: business alignment
Whether there is a technology roadmap tied to your business plan. Whether you get a quarterly review with someone who understands your P&L. Whether the provider knows your busiest month. Whether spending decisions come with an explanation of the alternative you did not buy. Whether they have ever told you not to spend money.
Category seven: contract and exit
Whether the term is month to month or locked. Whether pricing is transparent and per unit. What the termination process is and how long it takes. Whether you own your data, licenses, and domains. Whether there is an offboarding commitment in writing.
Score this honestly. Long lock-in with a painful exit is a business model choice and it tells you what happens if service degrades.
Category eight: the human layer
Whether you know your engineer's name. Whether the same person answers, or you re-explain your environment each time. Whether the provider's turnover has been visible to you. Whether they answer the phone or route to a form. Whether anyone there has been to your office.
Reading the score
Out of 120, our brackets are simple. Above 96 and you have a partner, keep them. Between 72 and 96 and you have a competent vendor with specific gaps, which are usually fixable if you name them. Between 48 and 72 and you are carrying real risk you have not priced. Below 48 and the honest description is that you are uninsured against your own infrastructure.
The point of scoring is not to fire anyone. In most cases the right move is to hand the completed scorecard to your current provider and ask them to fix the three lowest items in ninety days. Good providers welcome that. The response itself is a data point.
Get the scorecard
The scorecard workbook has all 40 items, the scoring guidance for what a zero, one, two, and three look like on each, automatic category rollups, and a summary sheet you can put in front of a provider or a board.
No sales call required to download it. If you want a second set of eyes on the result, we do a no-charge review of completed scorecards, including for businesses that are not our clients and are not going to be.
Frequently asked questions
How do I know if my IT provider is any good?
Score them rather than relying on instinct. Ask for specifics: the written after-hours protocol, the measured elapsed time of the last full restore, whether documentation transfers on termination, and whether they have ever advised you not to spend money. Vague answers reveal vague planning.
What is the 3AM Test?
A single question: if something critical breaks at 3AM, would you trust your IT provider to handle it without you. Any hesitation points to missing evidence, authority, or response ownership in the relationship.
Should I fire my IT provider if they score badly?
Usually not immediately. In most cases the right move is to hand the completed scorecard to your current provider and ask them to fix the three lowest items within 90 days. Good providers welcome that conversation, and how they respond is itself a data point.
What questions should I ask my IT provider about backups?
Ask when the last full restore test was, not when the last backup completed. Ask for the measured elapsed time. Ask whether the offsite copy is immutable, and whether anyone other than the plan's author has executed a recovery. A backup that has never been restored is a hypothesis.
Related reading
- Your Backups Are Not a Recovery Plan
- Run a 60-Minute Ransomware Drill With Your Leadership Team
- Build an IT Budget From Operating Priorities
- How to Switch IT Providers Without a Bad Month
- Read Your Cyber Policy Before You Need to Use It
- The Quarterly Technology Review Every Owner Should Demand
Use the score to start a useful conversation
I would bring the completed audit into the provider meeting with the weakest five answers highlighted. Ask for the evidence together. A strong provider should welcome the chance to clarify ownership, demonstrate recovery, and turn a real gap into scheduled work.
The number is a starting point. The quality of the evidence and the response to a weak answer tell you more about the relationship.
Printable provider review
Bring the scored audit to your next provider meeting.
Download the 40 questions as a branded, printable PDF with room for scores, evidence, owners, and the three actions that move first.
