Join our Newsletter — 33% off our NHI Course

Should MSPs use quarterly business reviews to discuss security and compliance as well as service delivery?

Yes, because service delivery, security, and compliance are inseparable in a managed relationship. A good QBR should cover incidents, response performance, SLA adherence, supply chain risk, and remediation plans alongside operational and financial metrics. That combination shows whether the service is actually resilient, not just busy.

What a QBR should cover when an MSP is accountable for both operations and trust

A quarterly business review is not just a service scorecard. For an MSP, it is the forum where uptime, response quality, security posture, and compliance obligations are judged together, because clients experience them together. If security and compliance are separated from service delivery, the review can miss the real question: whether the provider is operating the relationship safely and sustainably.

The practical value of a QBR comes from showing how operational metrics connect to control outcomes. Incident trends, SLA performance, backlog, recurring root causes, access change hygiene, and remediation status should be discussed as one system, not as parallel reporting streams. That makes it easier to spot whether good service numbers are masking weak control discipline, or whether security work is improving resilience in a measurable way.

For managed services, the review should also surface third-party dependencies and shared responsibilities. Service delivery can look strong while a supplier, platform dependency, or exception process is quietly increasing exposure. A useful QBR makes those dependencies visible early enough for corrective action, rather than waiting for an audit finding or a client incident.

Why security and compliance belong in the same review as delivery metrics

Security and compliance are not separate “extra” topics for MSPs, because both affect the credibility of the service itself. A provider that meets ticket targets but cannot explain incident handling, privilege management, or remediation closure is not demonstrating mature delivery. Likewise, a compliance-only review that ignores operational performance can miss the conditions that cause control failure later.

This is where managed service governance overlaps with broader cloud and control frameworks. CSA Cloud Controls Matrix is useful because it ties governance, IAM, audit, and supply chain controls to service accountability, while SOC 2 Trust Services Criteria (AICPA) reinforces that availability, confidentiality, and processing integrity are business assurances, not side topics. In practice, that means a QBR should show whether the service is meeting commitments and whether the controls behind those commitments are still operating as designed.

A good review also supports evidence-based conversations with clients. The goal is not to recite control names, but to show trends, exceptions, and corrective actions in a way that a business owner can understand. If the service team cannot connect a service issue to its security or compliance consequence, the review is too narrow.

What makes a QBR useful instead of performative

The best QBRs are decision meetings. They should leave the client with a clear view of what is stable, what is deteriorating, and what needs escalation. That requires more than dashboards. It requires context around recurring incidents, overdue remediations, unresolved risk acceptances, and any control gaps that could change the service’s risk profile before the next quarter.

Service Account Security Guide is relevant here because MSP delivery often relies on privileged operational accounts, and those accounts can become hidden failure points if they are overused, shared, or poorly governed. Access Reviews and Certification Guide is equally useful because quarterly reviews should not just report on access changes, they should confirm that access decisions are being reviewed, challenged, and closed out with evidence.

At scale, the value of a QBR is consistency. The review should answer the same core questions every quarter so trends are visible: Are incidents improving? Are exceptions shrinking? Are remediation items closing on time? Are the same control weaknesses recurring? If not, the meeting risks becoming a narrative update rather than an operating control.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CSA Cloud Controls Matrix and NIST CSF 2.0 set the technical controls, while SOC 2 (AICPA) defines the regulatory obligations.

Framework Control / Reference Relevance
CSA Cloud Controls Matrix IAM — Identity and Access Management QBRs for MSPs often need governance over access, exceptions, and shared responsibility.
Recommendation — Review access governance evidence and exceptions alongside service KPIs.
SOC 2 (AICPA) CC7.2 — Change Management QBRs should track remediation, recurring issues, and operational changes that affect control integrity.
CC9.2 — Vendor and Third-Party Risk Management MSP business reviews should cover supplier and dependency risk as part of service assurance.
Recommendation — Report control-impacting changes and their remediation status each quarter. Assess third-party dependencies and document mitigation actions in the QBR.
NIST CSF 2.0 GV.OC-03 — Mission and Risk Context The review should connect service metrics to client risk and business context.
PR.AA-05 — Least Privilege and Access Permissions MSP service delivery frequently depends on privileged access that should be reviewed for scope and necessity.
Recommendation — Tie service outcomes to current risk context and business priorities. Validate that privileged access remains least-privileged and justified.

Practitioner Guidance

What to prioritise: Put the highest attention on any issue where service performance and control failure overlap, especially repeat incidents, overdue remediation, access exceptions, and supplier dependency. Those are the items most likely to change the real risk profile between quarters.

What to verify: Confirm that every material security or compliance discussion ends with an owner, due date, and evidence of closure. If the review cannot show how an issue moved from identified to resolved, it is not yet a control-effective QBR.

Common mistake: Treating the QBR as either a customer-success meeting or a compliance status meeting. The better test is whether the conversation explains why the service is trustworthy, not only whether it is busy.

Practitioner takeaway: An MSP QBR should prove that service quality, security, and compliance are being managed as one operating model, because separating them usually hides the very risks clients most need to see.