The COO friendly guide to negotiating IT managed service agreements
By: Henry Duncombe, Lanware - Lanware
Published: 2026-04-20 · Read time: 7 min · Category: Technology
A practical guide for COOs of small to medium financial services firms on where to focus - and where not to waste time - when negotiating an IT managed service agreement.
If you're a COO in a small to medium-sized financial services firm, negotiating an IT managed service agreement (MSA) can quickly become complex and costly, especially when well-intentioned legal advisors tend to turn a sensible contract into something disproportionate to the size and nature of the IT service involved.
This article is a practical guide designed to help operational leaders focus on what really matters.
Where too much time is spent (for very little return)
1. Liability limits: chasing numbers that don't reflect reality
This is the number-one culprit behind disproportionate negotiation and wasted time.
It's common to see demands for liability levels that are eye-wateringly high, or even uncapped, and completely detached from the commercial value of the contract and the nature of the service being delivered. The irony is that the MSP is often managing services built on third-party platforms, such as Microsoft, which accept little to NO liability themselves.
This is particularly skewed in financial services, where clients carry significant operational and regulatory risk. If their system goes down following the MSP making a change and trading is disrupted, they could lose a lot of money. There is a tendency to assume that these losses could be fully recovered from the MSP.
2. Sub-contracting: expecting perfect alignment
Many MSPs rely on subcontractors as part of their fully managed services. These vendors form part of the MSP supply chain, and the customer typically has no direct contractual relationship with them.
A common misconception is that the terms agreed to their subcontractors should "flow down" perfectly from the master agreement. In reality, this is impossible. Operational leaders should instead take a more pragmatic approach and require the MSP to have "reasonably similar terms" with its contractors.
3. Intellectual property: a clause looking for a problem
In most managed services relationships, there is no bespoke software being developed. You're buying ongoing service, capability, and outcomes, not Intellectual Property. Yet IP clauses are often scrutinised as if an MSP were building a fully custom trading system. This creates unnecessary complexity without adding meaningful protection.
4. Contract sprawl: agreements that grow far beyond the size of the relationship
This is where things become truly disproportionate. A firm with 50 staff can end up with a contract that looks more suited to a global outsourcing deal between a FTSE 100 company and a tech giant like IBM. This is typically driven by well-intentioned legal advisors who are accustomed to working on enterprise-scale contracts.
Operational leaders need to clearly explain to their legal advisors the scope and simplicity of the service and relationship and reinforce that it doesn't need the contract to turn into a 100-page document. Oversized contracts increase costs, slow down onboarding, and create obligations that are difficult for either party to operate against.
Legal advisors can only negotiate effectively when someone from the business clearly defines:
- What the MSP actually does
- What is in scope (and out of scope)
- What outcomes matter most
- How the service integrates with your business model
Where too little time is spent (but should be)
This is the part that really matters, the areas where the COO should step in and guide legal advisors, because they understand how the service works in practice.
1. Service descriptions: focus on outcomes, not activities
The service schedule is the heart of an MSA. Yet it's often not written to describe the service on an outcome basis. The following should be provided for each service to reduce ambiguity:
- A simple service description (which doesn't talk about the tech products)
- What's in scope, what's out of scope
- The customer responsibilities
- The service provider responsibilities
2. AI systems: a new priority clause
Your MSP may use AI tools for efficiency, automation, monitoring or support, and that's fine. However, the contract should explicitly define:
- Which AI systems the MSP may use
- What data they can feed into them
- Whether your data can be used for training
- Where AI processing occurs
3. Security, not just service SLAs: especially when a security service is included
MSPs will provide SLAs that tend to focus on service desk metrics such as response and resolution times for user tickets, which are raised with the service desk. Where the security service is included, e.g. SOC, these SLAs do not work. Instead, security services need specific metrics such as:
- Time to detect a threat
- Time to contain or remediate
- Incident notification timelines
Alignment over excess
A well-negotiated contract isn't the one with the biggest liability clause, the thickest appendix, or the longest SLA table. It's the contract that aligns with your business, sets clear expectations, and lets both sides focus on what really matters: delivering secure, reliable, and continuously improving technology to your organisation.
If you are interested in understanding more, please get in touch with us. We'd be happy to support you.