Sequentur Blog

Helping you stay ahead of IT challenges

Real-world IT knowledge from engineers solving problems every day.

Practical IT knowledge for businesses that can’t afford downtime

How to run a quarterly business technology review

Business,Review,Word,Written,On,Wood,Block.,Business,Review,Text

If you’ve sat through a quarterly technology review with an IT provider, you probably know the script. Someone shares a screen. There’s a chart of tickets by category, a patch compliance figure in the high nineties, a backup success rate, and an “upcoming projects” slide with the same three items as last time. Everyone agrees things look fine, and the meeting wraps up early. A few weeks later a new hire starts with no laptop waiting, and the server everyone knew was old finally gives out. Both were visible months earlier, and the meeting had nowhere to put them.

A quarterly review is supposed to be where technology decisions get made before they turn into emergencies. The numbers on the screen are there to help with those decisions. Here’s how to run one that works that way, and what to bring to it as the owner.

This is written for owners and executives who meet with a managed IT provider or a virtual CIO every quarter, or who are about to start. If you don’t have an IT partner, there’s a section near the end on running a smaller version yourself. The review is also where the rest of this series comes together: the IT roadmap and the annual IT budget get checked against what happened, and the year of work described in virtual CIO services for small business gets steered one quarter at a time.

Short answer

A quarterly business technology review, or QBR, is a 60 to 90 minute meeting held every three months between the people who run the business and the people who run its IT. It should cover five things: what got done compared with what was promised, how the roadmap is moving, spending against the budget, open risks, and what comes due in the next two quarters, such as renewals, end of support dates, hires, and projects. The status numbers go out a few days ahead, so the meeting itself goes to the three to five decisions that are due. The business owner brings what has changed in the business and what’s about to, because that’s the part IT can’t see from where it sits. Every review ends with a short written record of what was approved, what was deferred and until when, and which risks were accepted and by whom. A quarterly technology review that produces no decisions has turned into a status report, and the agenda is the place to fix it. Businesses that skip the review still make all the same decisions. They make them later, under a deadline, with fewer options, and at a higher price.

Quarterly technology reviews at a glance

QuestionShort version
What is it?A standing meeting with your IT provider or vCIO to look back at the last quarter and decide what happens in the next one.
Is a TBR the same thing?Yes. Providers also call it a technology business review, an IT business review, or a strategic business review.
How long should it take?60 to 90 minutes. Much shorter, and it was probably a readout.
Who has to attend?Whoever approves spending. Without them you can discuss things, but you can’t decide them.
What does it cover?Work done against work promised, roadmap progress, budget against plan, open risks, and the next two quarters of deadlines.
What gets sent ahead?The status numbers, plus a one-line list of the decisions you’ll be asked to make.
What should the owner bring?What changed in the business, what’s about to change, and the dates IT has no way of knowing.
What should come out of it?A one-page record of decisions, deferrals, and accepted risks, each with a name and a date.
How do you know it’s working?Fewer surprises. Unplanned spending and last-minute decisions should both come down over a year.
What if we don’t have an IT provider?Run a shorter version yourself, with your office manager and your bookkeeper.

What the review is for

A quarterly review has two jobs: looking ahead, and following up.

Looking ahead means seeing decisions coming while there are still options. Every business runs into technology deadlines it didn’t pick: a contract’s notice period, a laptop fleet getting old, a vendor dropping support for something you rely on, an insurance renewal with new questions on the form. Those deadlines arrive whether or not anyone is paying attention. The review is where someone is watching for them.

Following up means checking that last quarter’s decisions turned into something. Approving a project in March doesn’t mean much if it’s still “being scoped” in September, and the quarterly review is the one place that shows up in front of the person who approved it.

Everything else on the agenda, from ticket trends to patch numbers, is there to support one of those two jobs. A slide that doesn’t help anyone look ahead or follow up belongs in an appendix, if anywhere.

Why so many reviews turn into status reports

Reviews drift into status reports for a handful of ordinary reasons:

  • The agenda comes from the reporting tools. Ticket counts and patch percentages are easy to export, so they fill the deck. What’s coming due next quarter isn’t in any dashboard, so it never makes the slides.
  • Nothing goes out in advance. If people see the numbers for the first time in the meeting, the meeting gets spent reading them.
  • The person who approves spending isn’t there, or joins late and leaves early. Anything that comes up gets “taken offline,” and that tends to be the last anyone hears of it.
  • The asks aren’t framed as decisions. “We should probably look at the firewall at some point” is an observation. Nobody can approve it.
  • Nothing gets written down. Without a record there’s nothing to follow up on, so every review starts from zero.

Each of these has a fix, and the agenda below is built around them.

What a quarterly technology review should cover

Here’s an agenda for a 90 minute meeting with a managed IT provider or vCIO. For a business under about 30 people, the same blocks fit into an hour as long as the status numbers go out ahead and people have read them.

MinutesBlockLed byWhat it’s for
0 to 5Decisions needed todayvCIO or account leadEveryone knows from the start what the meeting has to produce
5 to 15Last quarter’s decisionsvCIOWhat happened to everything approved, deferred, or accepted last time
15 to 30What changed in the businessOwner or CEOHires, clients, locations, plans, anything that moves the IT plan
30 to 40Service and projectsProviderTrends, exceptions, and any missed commitments, with the reasons
40 to 50Roadmap and budgetvCIO, with financeWhat moved, what slipped, and spending against plan
50 to 65RisksvCIOThe security summary and any change to the risk register
65 to 75The next two quartersvCIOEvery decision date coming up: renewals, end of support, insurance, projects, hires
75 to 90Decide and read backOwnerApprove, defer to a date, or accept the risk in writing, then confirm it all out loud

The order isn’t random. The decisions get named in the first five minutes and made in the last fifteen, and that last block is protected: if the meeting runs long, the time comes out of the service review, never out of the decisions. And the business talks before IT does. Fifteen minutes on what’s changed in the business is the most useful part of the meeting for the provider, and it’s also the part that gets skipped most often.

Who should be in the room

The person who approves spending is the one seat you can’t fill with a delegate. If the owner can only give the meeting 45 minutes, fit the business update and the decisions inside those 45 minutes and let the rest run without them. Virtual CIO services for small business goes through the rest of the room on both sides of the table, including why whoever handles your support day to day belongs there too.

Last quarter’s decisions

Open last quarter’s record and go down it line by line. Each item is done, in progress with a date, or stuck, and stuck needs a reason.

If an item has been stuck for two reviews, waiting longer won’t move it. Fund it properly, give it a different owner, or drop it and write down that the business is accepting whatever risk it was meant to close. Any of those is fine. Leaving it on the list for a third quarter isn’t. By then people skim past that line, and the next time it comes up, it’s an emergency.

What changed in the business

This is the owner’s part of the meeting, and it’s where the IT plan gets corrected most often. A few minutes of plain conversation about the business turns up things no monitoring tool will ever show:

  • Six people starting in February, which means laptops ordered in December and accounts and licenses ready before their first day.
  • A large client asking for a security questionnaire or a SOC 2 report before it renews.
  • An office lease ending next year, which turns the network and the server closet into a project with a deadline.
  • A new service line, a second location, or early talk about buying or selling a business.
  • Someone leaving who knows how a system works and has never written it down.

None of these sound like technology news, and that’s why they don’t reach IT unless someone says them out loud in this meeting. Aligning IT strategy with business goals walks through the annual version of this conversation. The quarterly version is shorter and more practical: what changed since last time, and what should the plan do about it?

Service and projects

Ticket counts on their own don’t tell leadership much. Thirty tickets in a quarter could mean a healthy office or a struggling one. What helps is the detail behind the number:

  • Recurring problems. The same issue month after month is often a project waiting to be proposed. There’s more on this further down.
  • Missed commitments. Any response or resolution time that missed the SLA, and why. A provider that brings up its own misses without being asked is one you can work with.
  • The gaps behind the percentages. If patching is at 96 percent, the useful part is the other 4 percent: which machines, and why. It’s usually a laptop that rarely connects, or a machine running software nobody wants to touch.
  • Projects. What finished, what’s late, and what the delay is costing.

Keep this block short. If it takes twenty minutes to present, most of it should have been in the pre-read.

Roadmap and budget

Walk the roadmap quarter by quarter: what was supposed to happen, what did, and what slipped. When something slips, ask what it holds up. Roadmap items lean on each other, and a delay in one piece can push back two others that didn’t look connected to it.

Then compare spending with the plan, by category. The provider’s numbers only cover what it bills, though. Card subscriptions, software a department bought for itself, and the phone bill all live in your books, so finance should bring the full figure. Also list unplanned spending separately and ask the same question about every item: could we have seen this coming? Early on, the answer will mostly be yes. If it’s still yes a year later, the look-ahead part of the meeting isn’t doing its job.

The deferred list belongs in this block too. How to plan technology spend for the year explains why every deferral needs a name and a date attached, and how this part of the review feeds the midyear reforecast.

Risks

The security summary goes here, presented live and in the same format every quarter: a handful of posture numbers, the top three risks, what changed since last time, and the ask. How to present an IT security report to non-technical leadership explains that format, including why it lands better in the room than in an email.

After security, go through the risk register: anything new, anything that got worse, and any accepted risk that’s due for another look. Accepting a risk is a perfectly reasonable decision. It just shouldn’t be a permanent one, so every accepted risk gets a review date, and the quarterly review is where those dates come back around.

The next two quarters

This is the block that pays for the meeting. List every technology decision date in the next six months:

  • Renewals, listed by the day notice is due, which comes well before the renewal date. How to manage software licenses and renewals shows how to work out the decision date for each one.
  • End of support dates for operating systems, servers, firewalls, and the software you run the business on.
  • The cyber insurance renewal and its questionnaire, which tends to ask about controls that haven’t been checked since last year.
  • Client security reviews, audits, and client contracts with security terms coming up for renewal.
  • Hiring plans, office moves, and lease dates.
  • Projects due to start, and what they need from the business before they can.

Our rule of thumb is that anything with a decision date in the next two quarters gets flagged, and anything due in the next quarter gets decided. Notice periods commonly run 30 to 90 days, and getting a second quote or planning a replacement takes a couple of months on top of that. Looking six months out means every deadline comes up in two reviews before it arrives, once as a heads-up and once as a decision.

Decide and read back

Each decision should come in framed the same way: what’s being decided, the options with a cost next to each one (including doing nothing, which has a cost too), a recommendation, and the date it has to be settled by. That’s the format laid out in how to write a technology disaster recovery plan that leadership will approve, and it works just as well for a firewall replacement or a hiring plan.

Every item leaves the room in one of three states: approved, deferred to a specific date by a specific person, or declined with the risk accepted in writing. “Let’s think about it” isn’t one of them. If something needs more information first, that’s a deferral, and it gets a date like any other.

Three to five decisions is a normal quarter. If you keep facing ten, the monthly check-ins aren’t carrying their share, or small items are being saved up for a meeting they don’t need. If you keep facing none, the look-ahead isn’t looking far enough.

Finish by reading the decisions back, with owners and dates. It takes two minutes, and it catches misunderstandings while everyone is still in the room.

What the business owner should bring

Most QBR advice is written for the provider. This part is for you. Your provider can see every laptop on your network and still have no idea you just signed a lease on a second office. Bring:

  1. What’s changed, and what’s about to. Hires and departures over the next six months, with rough dates. New clients, lost clients, new services, new locations. Anything you’d mention to your accountant.
  2. The dates only you know. The insurance renewal, an upcoming audit, a big client’s contract renewal, the office lease, your own planning calendar. If you’re thinking about buying a business or selling yours, say so, even if it’s early. Few things change an IT plan more.
  3. What technology cost you. The full spend from your books, card subscriptions included, plus anything a department bought on its own. Subscriptions sitting on company cards are where a lot of money hides.
  4. The complaints that never become tickets. Ask your office manager or team leads what annoys people. The slow app, the conference room WiFi, the three sign-ins it takes to reach one report. People find workarounds and never report them, and the workarounds cost hours every week.
  5. Questions from outside. Any security questionnaire from a client, and any question from your insurer or auditor about how your systems are protected.
  6. The decisions you’ve been putting off. If something has bothered you for two quarters, put it on the agenda yourself. Nobody else is going to raise it for you.

You don’t need to prepare a presentation. A page of notes is plenty, and sending it a few days ahead means your provider can come with answers instead of promises to look into it.

What to send ahead, and what to keep for the room

Status is reading material. Have the provider send a short pack three to five business days before the meeting, two to four pages long, covering service numbers, project and roadmap status, spending against the budget, and the six-month list of decision dates. Add a one-line list of the decisions that will be asked for, so nobody walks in cold.

Keep the security summary and the full case for each decision for the meeting itself. Both work better presented than read, because the questions they raise are the useful part.

Ask for the same layout every quarter. A pack that changes shape every time can’t be compared with the last one, and comparing quarters is most of what it’s for.

Then read it before you walk in. A meeting where half the room is seeing the numbers for the first time turns straight back into a readout.

What should come out of it

Within two business days, the vCIO or account lead should send a one-page record of what was decided. It doesn’t need to be elaborate:

ItemDecisionOwnerBy when
Firewall reaches end of support in JuneReplace it from the second quarter budget lineProviderInstalled by May 15
File server move to SharePointDeferredCEODecide at the July review
Three sales accounts without MFATurn MFA on, no exceptionsOperations managerMarch 31
Phone system contractKeep it until the office lease ends, risk acceptedCFOLook again in October

The owner replies to confirm it, and it becomes the first agenda item next quarter. After a year, these records are a written history of what the business decided, when, and why. They settle arguments about what was agreed, they make the next budget far easier to build, and when a new CFO or a new provider arrives, they’re one of the first things to hand over.

The quarterly review also shouldn’t be the only place decisions happen. Most engagements include a monthly working session to keep active projects moving, and anything urgent gets decided by phone or email when it comes up. The quarterly meeting is for the decisions that need the whole picture in front of them.

How to use what the review produces

Trends show up once you have four quarters side by side. A few ways to turn them into better decisions:

Turn recurring problems into a business case

Say the review shows that 11 of your 30 computers are more than five years old, and those 11 produced over half of last quarter’s tickets. Each ticket probably cost someone 20 to 40 minutes of work, plus the interruption. Put a rough hourly cost on that time and you have a number to set against the cost of replacing those machines a year early. Often the old machines turn out to be the expensive option. Sometimes they don’t, and keeping them another year is the right call.

The same thinking works for a VPN that drops every week for people working from home. For a lot of firms, the numbers make the case for moving the file server to SharePoint and OneDrive, so there’s no VPN left to drop.

Watch what keeps getting deferred

One deferral is normal. Three in a row means the item either isn’t needed (drop it and record the risk as accepted) or is needed and keeps getting avoided because it’s expensive or awkward. Either way, the third deferral deserves a harder conversation than the first two got.

Count the surprises

The simplest scorecard for the review itself is two numbers tracked every quarter: how much was spent on technology that wasn’t in the plan, and how many decisions were made at the last minute. A fuller set of measures is in how to align your IT strategy with your business goals, but these two are enough to start with. In the first year of a working review, both should come down. If they don’t, say so at the next meeting.

Feed the annual plan

The third quarter’s review should hand annual planning everything that’s been deferred, the trends from the last four quarters, and the decision dates that fall in the first half of next year. That’s most of what the annual budget and the roadmap rebuild need, and it means next year’s plan starts from facts instead of memory.

Why skipping the review costs more than holding it

Without a review, the same decisions still get made, only later, when a renewal notice or a dead server forces them. The price goes up in predictable ways:

The decisionMade a quarter earlyMade at the deadline
A software or service renewalRenegotiated, cut to the seats you use, or replacedRenews on its own for another full term, at whatever the price is now
An aging server or laptop fleetReplaced on a schedule, with time to move data properlyReplaced after it fails, at rush prices, after the downtime
Software reaching end of supportAn upgrade with a budget line and a dateA forced migration on the vendor’s timeline
The cyber insurance questionnaireControls checked and fixed before the form arrivesAnswered from memory, and a wrong answer can sink a claim later
A big client’s security reviewAnswers ready, and the deal keeps movingWeeks of scrambling while the deal waits
New hiresLaptops and accounts ready on day oneA first week spent waiting for equipment

Each row on its own looks like a bad week. Together they account for a lot of what shows up as unplanned IT spending. Deadline decisions also tend to fall to whoever happens to be closest. That might be an office manager signing a renewal because the email said to act now, or a manager buying software on a personal card because the request went nowhere. The review puts those decisions back with the people who are accountable for them, while there’s still time to compare options.

If you’d like to put a number on what this costs your business, virtual CIO services for small business includes a payback test you can run in an afternoon with figures you already have.

Running a review without an IT partner

You can run a version of this without a provider, and for a business of 10 to 25 people it’s worth doing. Keep it to an hour, with the owner, the person who looks after IT day to day (often an office manager), and your bookkeeper.

Before the meeting, pull together:

  • Every technology charge from the last quarter, from card statements as well as accounts payable.
  • A list of computers and their ages, even a rough one.
  • Anything that renews, expires, or loses support in the next six months.
  • Anything that broke, how long it was down, and what fixing it cost.
  • Any questionnaire, audit, or insurance renewal coming up.

Then make one to three decisions and write them down, with names and dates. That alone is a big step up from deciding everything when it breaks.

If filling in that list turns out to be hard, because nobody knows what renews when or who has admin access to what, that tells you something too. It’s one of the signs a business has outgrown DIY IT, and it suggests a provider with a vCIO would pay for itself.

Quarterly reviews for Tampa Bay businesses

Sequentur is headquartered in Clearwater, Florida, with a team in Tampa, so for clients around Tampa Bay we run the quarterly review in person, usually at the client’s office. That goes for our managed IT services in Clearwater clients and our IT consulting in Tampa engagements alike. It’s a better meeting that way. People put their phones down, the decision maker stays for the whole thing, and the conversation drifts into the business more easily than it does on a video call. For clients outside the area, the same agenda runs over video.

The local calendar shapes the agenda too. Hurricane season starts on June 1 and ends on November 30, and that gives two of the four reviews a specific job for a business here.

The spring review is the readiness check. It’s where the annual restore test, the disaster recovery plan, and the emergency contact list get reviewed. If the restore test turns up a problem in April, there’s time to fix it before the season starts. In August there isn’t. We also walk through a few what-ifs every spring: the office is closed for a week, the whole neighborhood loses power, the internet provider is down for days. For each one, who can still work, from where, and on what? And is there a copy of your data far enough away that the same storm can’t reach it? The answers often turn into roadmap items. For the connection side, see setting up redundant internet.

The first review after November 30 is the debrief. Were there closures, outages, or days when people couldn’t work? What did they cost, and what would have prevented them? Write the answers down while they’re fresh. By spring they’ll be fuzzy, and they’re some of the most useful input next year’s roadmap will get.

Common mistakes

  1. Reading the slides aloud. If it was in the pre-read, it doesn’t need presenting. Spend the time on the questions it raised.
  2. Nobody in the room who can say yes. Without the person who approves spending, every ask ends with “I’ll check and get back to you.”
  3. Letting the decisions get squeezed. Name them up front and protect the closing block, so a long meeting cuts the service review instead.
  4. Counting tickets instead of reading them. Totals hide the pattern. The recurring issue, or the five machines behind half the tickets, is what leads to a decision.
  5. Only looking backward. A review that never looks six months out will keep missing the deadlines it was meant to catch.
  6. A scorecard that’s always green. Every provider misses something eventually. If the review never shows a miss, you’re getting an edited version.
  7. Deferring without a date. “Next quarter, maybe” has no date on it, so it never comes back up.
  8. No written record. Without one, next quarter starts with an argument about what was agreed.
  9. Every recommendation comes with a quote. A good review sometimes recommends spending less: cutting unused seats, dropping a tool, waiting another year. If yours never does, ask how your vCIO is paid. vCIO vs IT manager explains why that question tells you so much.
  10. Canceling the quiet quarters. When nothing has broken for months, the review is the easiest meeting to push. Hold it anyway. A quiet quarter is when there’s time to plan.

How this fits the rest of your IT

Most of the planning in this series ends up on this agenda. The renewal register feeds the look-ahead. The security summary and the leadership disaster recovery summary get presented in it on their own schedules. Once a year, the alignment review resets the plan, and the quarterly reviews keep it on course until the next one.

If your provider doesn’t hold a quarterly review at all, or holds one that isn’t written into your contract, the checklist in what should be in a managed IT services agreement shows where it belongs. If you’re starting with a new provider, the first review should be on the calendar before onboarding wraps up. And if you’re still deciding whether you need a provider for any of this, managed IT services for small business lays out what the full relationship includes.

What is next in this series

The next article covers how to plan a hardware refresh cycle for your small business: what a refresh cycle is, why replacing equipment after it fails costs more than replacing it on a schedule, typical lifespans for workstations, laptops, servers, and network equipment, how to budget for replacements without one large hit every few years, and how to track the age of every device so the next refresh shows up in a quarterly review long before it shows up as a dead machine.

How Sequentur can help

If your quarterly reviews have turned into status reports, or you don’t have them at all, schedule a call and we’ll walk you through how we run ours. If you’re in Tampa, Clearwater, or anywhere else around Tampa Bay, we’re happy to meet in person.

Get the Best IT Support

Schedule a 15-minute call to see if we’re the right partner for your success.

Invalid Email
Invalid Number
Please check the captcha to verify you are not a robot.
Testimonials

What Our Clients Say

Here is why you are going to love working with Sequentur

Need help?

FAQs About Our Managed IT Services