# Due diligence on a managed IT provider's subcontractors

A managed IT provider may use other companies for service-desk coverage, specialist support, monitoring tools or on-site attendance. The buyer needs to.

Category: IT Services
Published: September 13, 2026
Source: https://www.vendoreye.ae/blog/due-diligence-on-a-managed-it-provider-s-subcontractors

A managed IT provider may use other companies for service-desk coverage, specialist support, monitoring tools or on-site attendance. The buyer needs to understand which parties can access systems or information and who remains accountable for their work. A single contract does not make the underlying delivery chain irrelevant.

## Map the parties and their roles

Ask the provider to identify subcontracted functions and the entities involved. Distinguish a software platform from a company whose staff actively manage the customer's environment. Record where support is delivered and what information each party can access.

Have the organisation's security, privacy and legal owners assess the relevant arrangement. A local account manager does not establish that every support activity or data flow remains in the same location.

## Examine access and oversight

Ask how the provider authorises personnel, limits permissions and records actions within the agreed service. Establish who reviews subcontractor suitability and how changes are communicated to the buyer. The appropriate technical team should assess evidence rather than rely only on a generic supplier declaration.

For example, an after-hours support partner may need a different access arrangement from a courier delivering replacement equipment. The review should reflect the actual function instead of treating every subcontractor as equivalent.

## Test incident and change responsibility

Ask who owns a ticket when work passes between the prime provider and a specialist. Confirm how approvals, findings and next actions are recorded. The user should not be left to coordinate separate companies that each consider the issue outside their responsibility.

Review the process for introducing another subcontractor or tool with access to customer information. A material change should be assessed through the agreed route rather than treated as an invisible internal procurement choice by the provider.

## Preserve control at exit

Establish how subcontractor access is removed, customer records are returned or handled under the agreed terms and open cases are transferred. Identify dependencies on accounts or systems that the buyer cannot administer directly.

Document the assessed chain and its limitations in the appointment record. Revisit it when the service expands or delivery arrangements change. Due diligence should provide a clear basis for trusting the defined operating model, not an unqualified claim that every present and future partner of the IT provider has been independently approved.

## Related buying guides
- [Reference questions for UAE managed IT providers](/blog/reference-questions-for-uae-managed-it-providers)- [Piloting a managed IT provider before full takeover](/blog/piloting-a-managed-it-provider-before-full-takeover)- [How to choose a managed IT service provider in the UAE](/blog/how-to-choose-a-managed-it-service-provider-in-the-uae)[Browse all IT Services guides](/blog?category=IT%20Services).

[Find businesses listed under IT Services on Vendoreye](https://www.vendoreye.ae/find-vendors?q=IT%20Services&amp;term_kind=Category). Check each candidate’s actual offering, availability and relevant evidence. A directory listing is a starting point for evaluation, not an endorsement.