Showing posts with label certification. Show all posts
Showing posts with label certification. Show all posts

Thursday, February 26, 2009

How Managed Service Provider Accreditation Helps Buyers


In today's changing volatile economy, companies find the predictable monthly service charges of a managed service provider (MSP) highly attractive. They can deploy technology, confident that they're not pouring money down a black hole. The problem is, scads of technology providers are now trying to recast themselves as MSPs.

How can you tell which ones are qualified?

That's Charles Weaver’s job. He's CEO of the 8,000-member International Association of Managed Service Providers. His nine-year-old group offers an accreditation program for managed service providers, and it's closer to a bar exam than a pro forma blessing. No MSP has ever received a perfect score, and it can take as many as three tries before a company passes. (For more on MSP accreditation, see When Selecting Qualified MSPs, Assume Nothing.)

Part Technology, All Business
The Managed Services Accreditation Program (MSAP) has two parts: a written exam and a physical inspection. The written exam is only about one-fourth weighted toward technology, says Weaver. The other 75 percent relates to the business. "It's not a technology certification. We look at everything from their financials to their facilities. We make sure they're a healthy stable company. We ask questions about disaster recovery and security, but a lot of the exam is designed to determine their financial stability."

The physical inspection follows, during which Weaver or one of the 15 IAMSP board members visits the facility. They check for physical security and process documentation, among other issues. "Documentation is a big problem at the small and midsize service providers," says Weaver. "They fail to write things down, and that puts their business at risk." If they fail the test, the IAMSP shows them how to improve, and they can take the test again (at a cost of $1500).

Dealing with Growth
The accreditation program has been so successful that Weaver is hoping to set up partnerships with consulting firms to help MSPs prepare. The IAMSP has already added sub-categories relating to accreditation for green IT facilities and master MSPs (those who lease services to smaller MSPs).

But keeping up with the growth in the industry is keeping Weaver busy. "Companies are demanding managed services because they're trying to cut costs. But they're finding very green, very immature vendors who say they're an MSP because they went to a seminar," he says.

If you're entrusting your company's technology to an MSP, then invest the time to determine whether your MSP is accredited, and what that accreditation process involved.

Wednesday, December 31, 2008

When Selecting a Qualified MSP, Assume Nothing


Hiring a managed services provider shouldn't be a leap-of-faith decision-making process. Perhaps you have staff that could fulfill their responsibilities, but instead you entrust a key component of your IT infrastructure to another company.

You believe they can do the job better and more efficiently. However, is that belief proven to be justified?

This begs another question: who licenses or certifies a managed service provider?

The topic came onto our radar thanks to a handful of companies claiming SAS 70 certification. The SAS 70 standard was developed by the American Institute of Certified Public Accountants (AICPA) to govern service organizations. (SAS stands for statement of auditing standards; see the AICPA page relating to auditing standards for more information.)

Certification's Real Meaning
You may assume that a managed service provider claiming SAS 70 certification has submitted itself to rigorous tests relating to its internal processes. However, according to Judith Sherinsky, technical manager of audit and attest standards at the AICPA: "There is no such thing as SAS 70 certification."

Sherinsky says that undergoing a SAS 70 audit only results in what she calls a "restricted use report," one intended to help auditors at the customer determine the reliability of transaction processing at the managed service provider.

For such a report to be useful to a customer, it must have meaningful context. "If the service provider organization provides several services, the report is useless if it doesn't cover the services the customer is interested in," she says.

Let's be clear: any MSP willing to undergo an audit is good for the industry, and helpful for the buyer. I'm merely highlighting the need for due diligence.

We'll return to this topic, both to keep you updated on what we learn about other standards and certifications (for instance, the ISO/IEC 20000 standard for service providers, and the MSPAlliance Accreditation program).

Attestation vs. Certification
In fact, Sherinsky suggests that customers of managed service providers check out the AICPA's attestation standards. These encompass a review of engagements that are the responsibility of "another party," that is, a service provider. An attestation report covers the processes between two parties, while an SAS 70 report covers processes internal to a service provider.

When your service provider claims certification under certain standards, don't take them at face value. Ask them exactly what it means, and how it's relevant to your relationship.

Any "seal of approval" is only of value in the procurement process when you have a sense of how stringent the benchmark requirements are, and whether they apply to your specific needs.