Most businesses put their effort into choosing the new provider and almost none into leaving the old one. That is the wrong way round. Switching IT provider goes wrong at the exit, not the entry, because the outgoing supplier holds things you may not know they hold: the administrator account for your Microsoft tenant, the registration of your domain name, the only copy of the firewall configuration, and the passwords to equipment sitting in your own building. A handover is the list of what comes back and the date each item arrives. Without that list, you are not switching providers. You are starting again with the same hardware.

What has to come back to you

Eleven things, and the useful exercise is asking your current provider for them before you have decided anything. The answer you get tells you a great deal on its own.

  1. Global administrator access to your Microsoft 365 or Google tenant, held by a named account inside your own business.
  2. Registrar access to every domain you own, with your business named as the registrant.
  3. DNS control, which is separate from registrar access and frequently sits somewhere else entirely.
  4. Administrator credentials for the firewall, switches, wireless controllers and any server.
  5. The backup platform: the console login, the retention settings, and confirmation of where the data physically sits.
  6. Licence agreements and subscription ownership, in your business name and on your payment method.
  7. The asset register: what you own, its age, its warranty status and where it is.
  8. Network documentation, including the address ranges, VLANs and any site-to-site links.
  9. Line and circuit details for broadband, leased lines and telephony, with account numbers.
  10. Removal of the outgoing provider’s remote monitoring agent from every device.
  11. Written confirmation that their access has been revoked, with a date.

Item eleven is the one people forget to ask for. Item six is where money leaks, because the seat count you inherit is rarely the one you need. Where UK businesses overpay on Microsoft 365 sets out what a review turns up.

Switching IT provider starts with who holds the keys

Two items on that list cause most of the trouble, and both come down to whose name is on the record.

The Microsoft tenant. In our experience a small business tenant is usually set up by the provider using an account they created and control. That account is the highest privilege in your business. If it belongs to a company you are leaving, you need it transferred and then you need their access removed, in that order. Doing it the other way round locks everyone out including you.

The domain. In our experience domains are often registered by the IT provider or the web designer with themselves recorded as the registrant instead of the client. The business has paid the renewal for years and does not own it. This is usually carelessness and not malice, and it is no less awkward for that, because the fix requires cooperation from the party you are leaving.

Neither is difficult to check and both are a short job. Whether the work sits inside or outside the business is a separate decision, and managed support against in-house IT takes it.

The lever that covers your data, and only your data

An IT provider handling your staff records, your customer database or your email is processing personal data on your behalf, which in most arrangements makes them a processor and you the controller. The ICO is direct about what that requires: whenever a controller uses a processor, a written contract needs to be in place between the parties, and controllers remain primarily responsible for overall compliance and for demonstrating it.

That contract has to set out the subject matter, duration, nature and purpose of the processing, then eight further specific terms. Two of the eight are useful on the way out. The ICO’s guidance on what needs to be in the contract says processors must either delete or return all personal data at the end of the contract, depending on the controller’s choice. They must also delete existing copies unless UK law requires them to keep the data.

Processors must also provide the information needed to show that they have met their Article 28 obligations. They must allow audits and inspections and contribute to them where required.

Read the scope carefully, because it is narrower than the list above. Article 28 reaches personal data: the mailboxes, the HR records, the customer database. It says nothing about your firewall configuration, your VLAN documentation or your domain registration. Those are commercial terms you write into the contract yourself. What the law gives you is a floor under the part that matters most, and our experience is that SME arrangements frequently have no written contract at all. Note also that the ICO has flagged this guidance as under review following the Data (Use and Access) Act, so the detail may move.

What the first thirty days should look like

A good incoming provider spends the first month finding out what they have taken on, and says so. Four things should happen.

  1. A documented discovery, covering every device, every cloud service and every line, produced as a document you keep instead of notes they keep.
  2. A written list of what they found wrong, separated into what they will fix under the agreement and what costs extra.
  3. Confirmation that backups exist, and a test restore of a real file.
  4. A named person, with the hours they work and the route to reach them outside those hours.

A licence review belongs here too, and it is usually the fastest saving a new provider will find.

If the first thirty days produce nothing in writing, the next twelve months will not either.

Before you sign anything

Four questions, asked of whoever you are appointing, before the contract and not after.

  1. Who will be named as the registrant of our domains, and as the owner of our licences?
  2. What does your handover pack contain if we leave you in three years?
  3. Which of the eleven items above will you document in the first month?
  4. What is written down about deleting or returning our data at the end?

A provider who answers the second question easily is telling you something about the other three. The ones worth appointing have a leaving process and describe it without being asked twice.

We take on businesses across the North East and the handover is where the work starts, so our managed IT support service begins with a documented discovery of what you already have. If you are weighing a change and want to know what your current provider holds, that list at the top is the thing to ask them for first.