Most MSP annual reviews are a status update dressed up as a strategy meeting. The MSP walks through a slide deck, everyone nods, the contract renews. Chris McGlasson, fractional CIO and founder of ClearStack Advisory, has sat on both sides of this conversation, and he built a framework for companies in the $10M-$20M revenue range to run a review that actually surfaces problems before they become expensive: SCORE. Security, Cost, Outcomes, Roadmap, Escalation.

At this revenue size, IT spend is significant enough to matter but rarely has a dedicated executive scrutinizing it line by line. That's exactly the gap an MSP can quietly grow into, and exactly why an annual review needs real structure.

Why the standard annual review doesn't work

A typical review covers uptime percentages and a list of tickets closed. Those numbers are usually fine, because they're the easiest metrics for an MSP to control and present favorably. They rarely answer the questions that actually matter: is this relationship still the right fit, is the cost structure still reasonable, and is the roadmap keeping pace with where the business is going. Chris McGlasson built SCORE around those gaps.

S: Security

Security answers should come with specifics. A vague "we've got it covered" is the answer that should end the meeting and start a search for a new provider.

C: Cost

Cost transparency is one of the clearest signals of the relationship's health. An MSP that hesitates on this question is protecting margin at the client's expense.

O: Outcomes

Outcomes questions separate a vendor that manages tickets from a partner that manages risk. Chris McGlasson notes that the last question is the one that tends to get the most honest answer, since it asks the MSP to think like an owner instead of a contractor.

R: Roadmap

A roadmap that looks identical to last year's is a sign the relationship has stalled into maintenance mode.

E: Escalation

Escalation questions matter more than any SLA on paper. The contract says four hours. The real answer is whoever picks up the phone at 11pm on a Saturday.

What to do with the answers

Vague or defensive answers on any of the five categories are worth a follow-up conversation, not necessarily an immediate exit. But a pattern across two or more categories, especially security and cost, is a strong signal the relationship needs either a hard reset or a replacement. Companies at $10M-$20M in revenue often don't have someone whose job it is to run this review with the rigor it needs. That's usually where a fractional CIO earns their retainer in a single meeting.


Not sure where your IT really stands? Start with a Clarity Audit: a focused assessment of your backups, security, vendors, and AI readiness. It's the first step in every engagement I take on.


About the author: Chris McGlasson is a fractional CIO and the founder of ClearStack Advisory, where he helps mid-market companies build AI governance, IT strategy, and technology roadmaps without the overhead of a full-time CIO. He previously built and sold LANPRO Systems, an IT services firm serving 350+ enterprise clients.