The Managed Compliance Buyer's Checklist: 25 Questions to Ask Before You Sign

Twenty-five questions to ask any managed compliance provider before you sign — covering scope, staffing, platform lock-in, evidence SLAs, auditor independence, and pricing, with the good answer and the red flag for each.

Tyler Carbone
·14 min read
Checklist card for The Managed Compliance Buyer's Checklist: 25 Questions to Ask Before You Sign

Managed compliance services are easy to buy badly. The category has no standard scope, no standard pricing model, and no standard definition of what "managed" even means — one provider's fully managed SOC 2 program is another's monthly check-in call. The result is that most buyers discover what they actually bought somewhere around month four, usually when an auditor asks for evidence nobody has been collecting. This checklist is the diligence pass that prevents that. Twenty-five questions, grouped into seven areas, each with the answer you want and the answer that should worry you.

Use it as an RFP. Send it to every provider on your shortlist and compare the answers side by side — the disagreements between vendors are more informative than any individual response. And use it on us: every question here is one Agency answers directly, which is rather the point of publishing it.

A note on how to read the "good answer" lines below. They describe a standard, not a specific vendor. Some providers will clear most of these and miss a few for defensible reasons. What matters is whether a provider can answer specifically — evasion on a simple operational question is the most reliable negative signal in the entire evaluation.

The seven areas

AreaQuestionsWhat it tells you
1. Scope and ownership4Whether you are buying advice or outcomes
2. The team5Who actually does the work, and whether they are reachable
3. Platform and tooling3Your switching cost, and who owns your data
4. Evidence and SLAs4Whether "managed" has a number attached to it
5. Auditor relationships3Independence, and how much of the audit you still own
6. Pricing and contract4Your real all-in cost and your exit
7. Outcomes and proof2Whether any of the above has ever worked

1. Scope and ownership

1. What exactly is in scope, control by control?

Why it matters: "SOC 2 readiness" is not a scope. The gap between advising on a control and implementing it is most of the work.

Good answer: A written control-by-control matrix showing who owns each control — provider, customer, or shared — before you sign.

Red flag: Scope defined by hours, meetings, or "support" rather than by controls and deliverables.

2. Who owns remediation, versus who owns telling us about it?

Why it matters: This is the single biggest source of disappointment in managed compliance. Many providers identify gaps and hand them back to you.

Good answer: The provider does the hands-on work — writing policies, configuring controls, fixing failing checks — and is explicit about the narrow set of things only your engineers can do.

Red flag: "We'll guide your team through remediation." That is consulting with a managed-services price tag.

3. Is the audit included, or is it a separate line item?

Why it matters: The audit is a large, unavoidable cost. Whether it is inside or outside the quote can change your all-in number substantially.

Good answer: Stated plainly either way, with the expected audit fee named if it is separate.

Red flag: Ambiguity, or an answer that only becomes clear after you have signed the managed-services agreement.

4. What happens the day after the report is issued?

Why it matters: SOC 2 is not a project with an end date. Controls drift, employees leave, the observation period for next year starts immediately.

Good answer: Maintenance is described as concretely as readiness — continuous monitoring, access reviews, evidence collection, and the next audit cycle.

Red flag: Maintenance is an upsell you will be quoted later, or is not mentioned until you ask. See how to maintain SOC 2 compliance for what this should cover.


2. The team

This is where evaluations are usually won and lost, and where the fewest buyers push hard enough.

5. Are the people doing the work US-based?

Why it matters: Not a quality judgment — a practical one. Time-zone overlap determines how fast an evidence request or a blocked deal gets resolved, and some of your customers and government contracts will ask.

Good answer: A direct answer about where staff sit, with no hedging about "global delivery."

Red flag: Deflection, or discovering after signing that your named contact is a coordinator for a team elsewhere.

6. Will we have a named engineer, or a ticket queue?

Why it matters: Compliance work depends on context. An engineer who knows your architecture is dramatically more efficient than a rotating queue rediscovering it.

Good answer: A named individual, introduced during the sales process, who you can meet before you sign.

Red flag: "You'll have access to our team of experts." That is a queue.

7. Is there a vCISO on the engagement, and what are their credentials?

Why it matters: Someone has to own security judgment — risk decisions, scope calls, questionnaire answers, and hard conversations with auditors. That is a different skill from evidence collection.

Good answer: A named virtual CISO with verifiable credentials and relevant industry experience.

Red flag: No security leadership in the model, or a vCISO title attached to someone whose background is entirely project management.

8. What is your ratio of clients to engineers?

Why it matters: It is the most honest capacity metric in the category, and almost nobody volunteers it.

Good answer: A specific number, and a willingness to explain how it is managed as they grow.

Red flag: No answer, or a number so high that the named engineer in question 6 is nominal.

9. Who covers when our engineer is on vacation or leaves?

Why it matters: Single-person coverage is a real risk — the same single point of failure you are outsourcing to avoid.

Good answer: A documented backup, with shared context so continuity does not depend on one person's memory.

Red flag: No plan, or an answer that reveals your program lives in one individual's head.


3. Platform and tooling

10. Are you platform-agnostic, or do we have to use your tool?

Why it matters: Platform lock-in is the most common hidden switching cost in this category.

Good answer: The provider works on top of Vanta, Drata, Secureframe, or Sprinto and will run whichever you choose. Compare options in our platform comparison.

Red flag: A proprietary platform you cannot take with you, presented as a differentiator.

11. Who holds the platform contract — us or you?

Why it matters: If the provider holds it, changing providers means changing platforms, which resets evidence history and control mappings.

Good answer: You hold it, ideally at a partner discount the provider passes through.

Red flag: The provider holds it and resists changing that.

12. What happens to our evidence and control mappings if we leave?

Why it matters: Years of evidence history has real audit value. Losing it is expensive in ways that are invisible until you switch.

Good answer: Everything is in your platform tenant, exportable, and yours.

Red flag: Evidence lives in the provider's systems. The switching cost is the retention strategy.


4. Evidence and SLAs

13. Who actually collects evidence — your team or ours?

Why it matters: Evidence collection is the largest recurring labor cost in a compliance program.

Good answer: The provider collects it, pulling from the platform and chasing the exceptions the platform cannot automate.

Red flag: The platform "automates" it, which quietly means your team handles everything automation misses.

14. What is your SLA on an evidence request, in writing?

Why it matters: Auditors work to deadlines. So do your customers.

Good answer: A specific commitment in the contract, not the sales deck.

Red flag: "We're very responsive." See our guide to what auditors actually want for the volume this involves.

15. What is your SLA on a customer security questionnaire?

Why it matters: This one has revenue attached. A stalled questionnaire is a stalled deal, and these arrive with no warning.

Good answer: A turnaround commitment, plus a maintained answer library so repeat questions are not re-answered from scratch. Our guide to security questionnaires covers what to expect.

Red flag: Questionnaires are out of scope, or billed separately at an hourly rate.

16. How is control drift detected, and who fixes it?

Why it matters: Drift is guaranteed. An unencrypted volume, a departed employee with live access, an expired review — these accumulate silently between audits.

Good answer: Continuous monitoring with a named owner for remediation, and a reporting cadence you can see.

Red flag: Drift shows up as a dashboard alert that becomes your problem.


5. Auditor relationships

17. Do you have existing relationships with audit firms?

Why it matters: Auditor familiarity with a provider's evidence format measurably reduces friction and back-and-forth.

Good answer: Named firms they work with regularly, with a view on which fit which company profile. See our guide to SOC 2 auditors.

Red flag: No relationships, leaving you to source and manage the auditor alone.

18. Is the auditor independent of you, and can you explain why that matters?

Why it matters: This is the question that separates providers who understand attestation from providers who sell it. A firm cannot audit work it performed.

Good answer: An immediate, confident explanation of why they do not perform the audit, and how independence protects the value of your report.

Red flag: A bundled "we handle the audit too" that blurs the line. Your enterprise buyers and investors will find this during due diligence.

19. Can we choose our own auditor?

Why it matters: You may already have a relationship, or your customers may prefer a specific firm.

Good answer: Yes, with a caveat about efficiency if the firm is unfamiliar.

Red flag: A single mandatory auditor with no explanation of the arrangement.


6. Pricing and contract

20. Is this all-in, or are there line items we will discover later?

Why it matters: The gap between headline and all-in price is where budget overruns live — penetration testing, the audit, platform fees, questionnaire support.

Good answer: A written list of everything included and everything not.

Red flag: A low headline number that grows once scope is real. Our total cost of ownership breakdown covers the components to check against.

21. Is penetration testing included?

Why it matters: Most auditors expect a recent third-party test, and it is a meaningful line item when purchased separately.

Good answer: Included, with the type specified — an independent manual test, not only an automated scan. The distinction matters for audit acceptance, as our pen test cost guide explains.

Red flag: Not mentioned, or "included" without specifying whether a human tests anything.

22. What is the renewal increase?

Why it matters: Year-two pricing is where the economics of the relationship actually settle.

Good answer: A stated cap or a transparent basis for increases.

Red flag: Silence. Renewal is where switching costs get monetized.

23. What is the exit process and the notice period?

Why it matters: Auto-renewal windows and long notice periods are common and easy to miss.

Good answer: Clear notice terms, a defined offboarding process, and confirmed data-export rights.

Red flag: Auto-renewal with a narrow cancellation window buried in the terms.


7. Outcomes and proof

24. What is your median time from kickoff to audit-ready?

Why it matters: It is the outcome you are buying, and providers with real operating history know it.

Good answer: A specific median with the range and the main variables that move it. Compare against typical timelines by company size.

Red flag: No number, or a best case presented as typical.

25. Can we speak to two references at our stage and in our industry?

Why it matters: It is the only verification step that is hard to game.

Good answer: Two relevant references, promptly.

Red flag: Delay, or references far larger or smaller than you — usually a sign the comparable experience is thin.


How to score the answers

Weight the answers rather than counting them. In our experience the four questions that predict the most about how an engagement actually goes are 2 (who owns remediation), 6 (named engineer or queue), 14 (evidence SLA in writing), and 20 (all-in pricing). A provider can be imperfect elsewhere and still serve you well. A provider who is vague on those four will be vague in delivery.

Two answers should end an evaluation outright: a provider who will not tell you who does the work, and a provider who cannot explain auditor independence. The first means you are buying a black box. The second means they do not understand the product they are selling.

If the deeper question behind all of this is whether to hire in-house at all rather than buy a managed service, our in-house versus managed GRC decision framework scores that trade-off directly, and building versus buying models the cost side.

Key Takeaways

  • "Managed" has no standard definition. Two providers using the same word can be selling advisory calls and done-for-you delivery respectively. Force the distinction with a control-by-control scope matrix before you sign.
  • The team questions matter more than the feature questions. A named engineer, a credentialed vCISO, a disclosed client-to-engineer ratio, and a documented backup plan tell you more about outcomes than any capability list.
  • An SLA that is not in the contract is not an SLA. Ask separately about evidence requests and customer security questionnaires — the second has revenue waiting on it.
  • Platform-agnostic protects you. Hold your own platform contract so your evidence history, control mappings, and ability to change providers stay yours.
  • A provider who audits its own work has an independence problem your enterprise buyers and investors will find. The right answer explains why they don't do the audit.
  • Check the all-in number, the renewal increase, and the exit terms together. Those three define your real cost far better than the headline price does.

Agency answers all twenty-five of these directly, and is built around the standards they describe: US-based compliance engineers, a named vCISO on every engagement, platform-agnostic delivery on top of Vanta or Drata, and independent audit and penetration testing included rather than discovered later. See how the managed model works, or if you are early-stage, the startup compliance program. If you would rather start with your own gap assessment, our SOC 2 readiness checklist is a good first pass.

Frequently Asked Questions

Tyler Carbone

Tyler Carbone

Managing Director and Cofounder

Tyler Carbone is a Managing Director and Cofounder of Agency and one of the industry's leading voices on governance, risk, and compliance. He holds degrees from Harvard and a JD/MBA from the University of Virginia, and previously worked in cybersecurity at Deloitte. Tyler has helped hundreds of companies operate SOC 2, ISO 27001, HIPAA, and GDPR programs.

LinkedIn

Related Reading

Stay ahead of compliance

Expert insights on cybersecurity compliance delivered to your inbox.

We respect your privacy. Unsubscribe anytime.