# IT sourcing and provider management: make or buy, contracts, performance and dependency

> What you do yourselves and what you buy: make the sourcing decision, steer managed services, measure performance, limit dependency and negotiate contracts that hold at the exit.

URL: https://techport.ai/en/it-beratung/it-strategie-und-steuerung/sourcing-und-dienstleister

---

1.  [IT Consulting](/en/it-beratung)/
2.  [IT Strategy and Steering](/en/it-beratung/it-strategie-und-steuerung)/
3.  Steering IT providers

[IT Strategy and Steering](/en/it-beratung/it-strategie-und-steuerung)

# Steering IT providers

By Redaktion techport.ai, IT-Beratung · Last updated on 21 August 2026

Hardly any mid-sized company runs its IT entirely on its own. One systems house looks after the servers, another vendor after the ERP, added to that are cloud services, a telephony provider and the firm that built the custom solution years ago. This constellation has grown rather than been designed. It leads to nobody being responsible when something breaks, and to services being paid for that nobody reviews any more.

Sourcing is not a question of inside or outside, but of which capability you have to keep in house in order to steer at all.

## How you notice it

*   During an incident two providers point at each other and you moderate.
*   Contracts renew automatically and the last performance review is years old.
*   The provider knows your systems better than you do, and changing them is considered unthinkable.
*   There are agreements on response times but nobody measures whether they are met.

## Why this happens

Provider relationships in the mid-market are personal and long standing, and that is an advantage to begin with. The disadvantage appears when trust replaces steering. Nothing is measured because you know each other. Nothing is tendered because it would feel awkward. And nothing is documented because the contact knows it all anyway. It is exactly that knowledge which is missing at the exit and makes the change expensive.

## How we go about it

1.  **Record services and dependencies.** We capture which provider delivers which service, under which contract, with which term, notice period and level of access to your systems and data. This overview is missing in almost every company.
2.  **Make the sourcing decision.** We assess per service whether it should be delivered in house, by a provider or shared, along criticality, required depth, availability of specialists and cost. Steering, process knowledge and data ownership stay in house as a matter of principle.
3.  **Make performance measurable.** We agree a few verifiable metrics per contract, for example response and restoration times by priority, availability and share of requests resolved at first contact, and set up simple reporting.
4.  **Settle contracts and exit.** We review contracts on the points that count in a dispute: service description, price adjustment, term, release of data, cooperation in a transition and the obligation to document. A contract without a settled exit is a contract without a negotiating position.

## What you gain

*   Clear responsibility during incidents instead of chains of referral.
*   A basis for price negotiations that does not rest on instinct.
*   The ability to change provider without endangering operations.

## From our projects

The most expensive point in provider contracts is rarely the price. It is the missing obligation to document. If configurations, credentials and custom solutions sit exclusively with the provider, a change costs a multiple of the actual migration, and that prospect prevents any serious negotiation. We therefore include in every contract review the question of what you would actually hold in your hands the day after a termination. The answer regularly reshapes the priorities of the current year.

## Good to know

If a provider processes personal data on your behalf, you need a data processing agreement under Article 28 GDPR covering instructions, security measures, sub-processors and the return or deletion of data at the end of the contract. You remain the controller even if the provider makes the mistake. For providers outside the EU, the assessment of the transfer basis is added. For companies within the scope of the German BSI Act, supply chain security is additionally part of your own risk management obligations.

## Häufige Fragen

One provider for everything or several specialists?

A generalist reduces your steering effort and increases your dependency. Several specialists deliver better quality in their area and create coordination effort that someone in house has to carry. For most mid-sized companies a mix works: one partner for base operations, specialists for the business critical systems, steering in house.

How do we check whether our provider is too expensive?

Not through the hourly rate alone but through the service delivered relative to the effort. It makes sense to run a market comparison every three years using the same service description, even if you do not intend to switch. The mere existence of a comparison offer changes the next renewal.

## Let us talk about Steering IT providers

In a thirty minute first call we work out where your biggest lever sits and whether we are the right people for it.

[Arrange an initial call](/en/kontakt)[Our consulting](/en/so-funktionierts)

## Further reading

[IT Governance and ComplianceLicences and IT contractsCount licences correctly, review contracts on the points that count, prepare for vendor audits, cap price increases and agree an orderly exit.](/en/it-beratung/it-governance-und-recht/lizenzen-und-vertraege)[IT Strategy and SteeringIT organisation and rolesWho decides what in IT: define roles and responsibilities, reduce dependence on individuals, and organise the work with departments and external providers.](/en/it-beratung/it-strategie-und-steuerung/it-organisation)[Operations and SupportMonitoring and availabilityMonitoring that helps instead of adding noise: choose the right measuring points, set sensible thresholds, tie alerts to people, measure availability and be able to hold commitments.](/en/it-beratung/betrieb-und-support/monitoring-und-verfuegbarkeit)[KnowledgeIT metricsDefinitions and formulas read the same way across the company.](/en/it-beratung/kennzahlen)[KnowledgeIT glossaryTerms from IT, software and security, briefly explained.](/en/it-beratung/glossar)

Back to the field [IT Strategy and Steering](/en/it-beratung/it-strategie-und-steuerung)

## Sources

*   [Article 28 GDPR, processor](https://gdpr-info.eu/art-28-gdpr/)
*   [Section 30 BSIG, risk management measures (in German)](https://www.gesetze-im-internet.de/bsig_2025/__30.html)

Rt

Written by

[Redaktion techport.ai](/ueber-uns), IT-Beratung

Mehr als 15 Jahre Erfahrung in IT-Projekten des Mittelstands, Auswahl und Einführung von Unternehmenssoftware, Aufbau von IT-Betrieb und Informationssicherheit in wachsenden Organisationen.

This page reflects the position at the date given and does not replace legal advice. For specific questions we work together with your legal advisers.

[More about us](/en/ueber-uns)

More from techport.ai

[

Software

Custom process software for mid-sized companies.

](/en/loesungen)[

HR consulting

People processes and the systems behind them.

](/en/hr-beratung)[

IT maturity check

Ten minutes to a clear position.

](/en/it-beratung/reifegrad-check)[

HR maturity check

24 statements, a result per field.

](/en/hr-beratung/reifegrad-check)[

Funding

BAFA grant plus more than 50 programmes for delivery.

](/en/foerderung)[

Process in practice

How workflows become reliable software.

](/en/sop-praxis)[

Data and AI

Analysis, forecasts and assistance systems.

](/en/daten-ki)[

About us

The people behind techport.ai.

](/en/ueber-uns)
