10 September, 2026 | 6 min read

How to tell the difference between an MSP that maintains your estate and one that moves your business forward

Person in a white shirt and glasses viewed from behind, looking at a large digital display wall showing blue-toned data visualizations, charts, and technology monitoring screens.

Most technology leaders evaluating a managed services provider ask roughly the same questions. Can you keep our systems running? What are your SLAs? What does it cost? Those are not wrong questions, but in financial services, where infrastructure decisions carry regulatory weight and the pace of change is relentless, they are incomplete ones. Incomplete evaluation criteria lead to partnerships that quietly decay rather than partnerships that drive competitive advantage. 

The pattern I see most often is not that organisations choose bad providers. It is that they choose the wrong kind of provider for what they actually need. There is a fundamental difference between a managed service that keeps your infrastructure running and a managed service that helps your business grow. The market is full of the former. The latter is considerably rarer. 

 

The problem with measuring uptime 

Uptime percentages and ticket response times tell you the lights are on. They say nothing about whether the business is getting genuine value from the service. Most providers optimise for the contract metrics, not the customer outcome, and those two things are not always the same. 

At Version 1, our ASPIRE managed services framework is built around a different set of performance indicators. Beyond the standard SLAs that any credible provider should be hitting, ASPIRE introduces three measures that traditional MSPs rarely contract for: Experience Level Agreements, which measure how the service actually feels to the people using it; Value Level Agreements, which quantify the business outcomes the service enables; and Environmental Level Agreements, which hold us accountable for carbon impact alongside availability. 

You can hit every SLA on the contract and still have a service that is quietly failing the business: technology teams firefighting instead of building, innovation work deferred quarter after quarter, operational noise that never quite goes away. That gap between metric compliance and genuine value is where most MSP relationships decay. Working with Key Group over the past year has shown what closing that gap looks like: incidents down from double digits per month to low single digits within six months of transition, zero P1 incidents in twelve months of live service, and zero service unavailability attributable to Version 1. We contract for the outcome, not the activity. 

 

What DORA changes for every MSP conversation 

The Digital Operational Resilience Act and similar frameworks are not just tightening compliance requirements. They are fundamentally changing what good managed services looks like in regulated sectors, and financial services technology leaders need to understand the implications before they choose a partner, not after. 

The critical shift is this: DORA treats your MSP as part of your operational risk surface, not as a vendor delivering from outside it. That changes the conversation at every level. Contractually, it means registers of services, exit plans, subcontractor transparency and audit rights built in from the start. Operationally, it means tested resilience, not assumed resilience: DR scenarios rehearsed, not just documented. Evidentially, it means proof, on demand, that governance and controls work as designed. An MSP still offering generic 24/7 support and a quarterly review is not sufficient in this environment. Regulators are not interested in whether your supplier met its SLAs last month. They are interested in whether your supplier is genuinely part of your operational resilience framework, and whether you can demonstrate it. The providers that understand this are building their service models accordingly. The ones that do not are a liability waiting to materialise.

 

The question most technology leaders are not asking 

Most technology leaders evaluating infrastructure partners are still asking “which cloud?” or “how do we reduce costs?” Those are not wrong questions, but they are too shallow for where the market is heading. The more important question, and the one I rarely hear asked early enough, is this: what parts of our infrastructure and operations must remain strategic and differentiating, and what should become fully abstracted, replaceable services, even if that means giving up control? 

The organisations answering that question well are moving away from owning infrastructure towards owning experiences and outcomes. They are using managed services partners to help them understand what technology decisions to make, at what pace, and in what sequence, not simply to manage technology on their behalf. Key Group have articulated this direction more clearly than most, consolidating onto Microsoft, consuming as a service, and focusing entirely on building the experiences they deliver to customers and brokers. Our role as their managed services partner is to make that ambition operationally possible and to help them move faster than they could alone. That has included running Key Group’s AI opportunity identification through Version 1’s AI Co-Creation approach, a structured process that takes a business challenge from discovery to working prototype in one to two days, producing something a leadership team can react to and fund, rather than a report that sits in a pipeline for months. 

 

What to actually look for 

If I were advising a financial services technology leader going through an MSP evaluation, I would push them to assess four things that most RFI processes underweight: the rigour of the transition methodology, because that first engagement sets the tone for everything that follows; the depth of genuine sector expertise alongside technical credentials, because understanding the FCA’s direction and DORA’s implications is not the same as having strong Azure numbers; the quality of the continuous improvement methodology, because a CSI log populated at transition and never revisited is not improvement, it is theatre; and cultural alignment, because a five-year managed services relationship is closer to a joint venture than a procurement, and the partner needs to be willing to challenge you, not just execute your brief. 

One final practical point. One of the most common patterns in MSP evaluations is providers leading with cost reduction as the primary value proposition. A 20% reduction on current charges at contract outset sounds compelling. What happens over the following eighteen months is less so: costs gradually climb back because nothing changed about how decisions get made or how spend is governed. The saving was a one-off project, not a discipline. Sustainable cost management in a managed service is service muscle memory: FinOps embedded in the operating model, spend guardrails set at design stage, and continuous optimisation across licensing, architecture and service scope on a regular cadence. For financial services firms under margin pressure, the question is not whether to optimise costs. It is whether to optimise them once or continuously. The two approaches produce very different outcomes over a five-year contract, and the difference is not visible on day one. 

The managed services market will continue to consolidate, and the distance between commodity support and genuine strategic partnership will widen. For financial services organisations making these decisions now, the question is not which provider is cheapest or has the strongest SLA numbers. The question is which partner will help you build the business you are trying to build over the next five years. That is a different evaluation, and it produces a different answer. 

Barry McIvor is Commercial Director, Managed Services at Version 1. Version 1 has been delivering multi-sector managed services for over 30 years.