The Customer’s Role in Managed IT: Why Shared Responsibility Must Be Clear
Many organizations procure managed IT services expecting risk and responsibility to transfer to their provider. However, while an MSP offers operational capability and expertise, accountability for business outcomes, information assets, compliance, and risk remains with the customer.
Poorly defined roles lead to assumptions, creating gaps that cause service failures, security incidents, and disputes. For boards and leadership teams, understanding shared responsibility is a governance requirement.

Why This Matters in Regulated Organisations
Regulated and compliance-conscious organisations face increasing scrutiny. Driven by UK GDPR, Cyber Essentials Plus, ISO/IEC 27001, ISO/IEC 20000-1, and other requirements, they must demonstrate control over critical services and information assets.
A common misconception is that outsourcing IT outsources accountability—it does not.
While external providers can manage operations, the organisation is responsible for aligning these activities with business objectives, regulatory obligations, risk appetite, and governance expectations.
Auditors, regulators, customers, and insurers seek evidence of oversight, not just outsourcing. The key question is no longer "Who provides the service?" but "How does the organisation demonstrate governance and control over the service being provided?"
Where Organisations Commonly Go Wrong
Shared responsibility failures often result from assumptions rather than technical issues. Examples include customers assuming providers manage all cybersecurity controls, while providers assume customers own risk decisions.
Customers may expect compliance reporting, but providers might believe only operational reporting was agreed upon. Procurement might assume onboarding includes all assets, and operations may think the provider discovered everything automatically.
Each party believes expectations are clear, but ownership is rarely documented. This becomes evident during security incidents, major outages, compliance audits, contract renewals, supplier reviews, and change projects.
Organizations then realize activities weren't explicitly assigned, shifting the focus from service quality to responsibility.

The Governance Implications
Unclear ownership poses several governance risks.
Control Gaps
Critical activities may be neglected as parties assume others are responsible.
Audit Findings
Auditors often find weaknesses in supplier management due to undefined responsibilities, oversight, evidence, or reporting mechanisms.
Increased Operational Risk
Unclear accountability can lead to delayed decisions, unresolved vulnerabilities, unmanaged assets, or ineffective change control.
Disputes and Frustration
Discrepancies between expectations and contractual realities quickly erode trust between customer and supplier.
Service issues often stem from governance problems.

What Good Looks Like
Organizations with mature managed service relationships prioritize clear responsibility definitions, using tools like the RACI model. RACI clarifies who is Responsible, Accountable, Consulted, and Informed, eliminating ambiguity and fostering mutual understanding.
Key areas to define include:
Security Responsibilities
Vulnerability management
Patch management
User access reviews
Security monitoring
Incident response
Risk acceptance decisions
Service Management Activities
Service reviews
Major incident management
Change approvals
Capacity planning
Continual improvement actions
Compliance and Governance
Policy ownership
Compliance evidence collection
Audit support
Risk reporting
Supplier assurance reviews
Asset and Data Ownership
Asset inventories
Information classification
Data retention decisions
Business-critical application ownership
Good governance requires clarity, not complexity.
Shared Responsibility Should Be Visible, Not Assumed
Strong managed service relationships rely on transparency. Boards should know who owns cyber risk decisions, approves significant changes, maintains compliance evidence, reviews service performance, and accepts residual risk. Assumptions can undermine audits and reviews. Documented ownership and regular reporting foster confidence.
A Governance-Led Approach
At cyberISMS, responsibility mapping is key to effective managed services. Assurance stems from defined ownership, measurable controls, transparent reporting, and consistent governance processes. Whether aligning with standards like ISO/IEC 20000-1, ISO/IEC 27001, or UK GDPR, the goal is clear accountability, eliminating assumptions, and ensuring both provider and customer understand their roles in maintaining secure, stable, and compliant services.

Final Thought
Managed IT involves sharing responsibility effectively, not just transferring it.
Clear responsibilities lead to better control, assurance, audit readiness, and predictable outcomes. Assumed responsibilities create gaps, which are quickly exposed.
Call to Action
If your organisation uses a managed service provider, ask: "Can we clearly demonstrate who is responsible, accountable, consulted, and informed for every critical service, security, and compliance activity?"
If unsure, consider reviewing your service governance model. At cyberISMS, we help organisations establish clear accountability, enhance supplier governance, and align services with standards like ISO/IEC 20000-1, ISO/IEC 27001, Cyber Essentials Plus, and UK GDPR expectations.
Clear accountability reduces ambiguity. Strong governance reduces risk.




Comments