September 24, 2026

What Should a Professional Services Firm Include in an Annual IT Assessment?

An annual IT assessment should help professional services firms turn technology concerns into clear priorities. Learn what to review across reliability, cybersecurity, recovery, support, and budgeting and what to address now, plan for next, or continue monitoring.

Image

A professional services firm's annual IT assessment should review business priorities, technology reliability and lifecycle, cybersecurity and access risk, backup and recovery readiness, critical applications and vendors, IT support performance, and applicable client, contractual, or compliance requirements.

Leadership should then convert those findings into three categories: what to address now, what to plan and budget for, and what to monitor, with clear ownership and timing for each priority.

As professional services firms move into annual planning, technology priorities often arrive from different directions.

A workstation fleet is aging. A recurring support problem keeps returning. A major software renewal is approaching. Leadership expects to hire. A client has new security requirements. Backup exists, but no one is certain when recovery was last tested.

The challenge is not creating a longer IT wish list. It is deciding what actually deserves leadership attention and investment.

For accounting, legal, engineering, architecture, consulting, and other professional firms, that decision has direct operational consequences. Technology supports billable work, deadlines, client communications, specialized applications, confidential information, and the ability to keep serving clients when something goes wrong.

An annual IT assessment provides a useful planning checkpoint but only if the review connects technology conditions to business decisions.

If your team is still clarifying what an IT assessment is, start with the broader definition; here, the focus is how to use an annual review to set priorities for the year ahead.



Start With Business Priorities and the Work Clients Depend On

An annual IT assessment should begin with where the firm is going, not with a list of devices.

Before leadership evaluates individual technology problems, it should identify the business changes likely to shape technology needs during the coming year. That may include hiring, a new office, changing client requirements, a merger or acquisition, new service offerings, increased remote work, or a major application change.

The most useful questions are operational:

  • Which workflows are most important to client delivery?
  • Which systems directly support deadlines, revenue, or billable work?
  • Where is technology already slowing employees down?
  • What changes in the business will put new demands on technology?
  • Which systems could the firm least afford to lose for an extended period?

Those questions will produce different priorities in different professional environments.

An accounting firm may need to protect capacity during tax deadlines. A law firm may place greater emphasis on document access, confidentiality, and case-management dependencies. An engineering or architecture practice may depend on high-performance workstations, large files, storage, licensing, and specialized design platforms. A consulting firm may need consistent access and security across distributed employees working from client locations.

The purpose is not to declare every inconvenience an IT priority. It is to establish the business context needed to distinguish what actually matters.

The same business-first lens should guide any discussion of managed IT for professional services firms: the support model should reflect the workflows, deadlines, information, and client commitments the firm depends on.


Review Technology Reliability, Capacity, and Lifecycle

Once business priorities are clear, leadership can evaluate whether the underlying technology environment can continue supporting them reliably.

The review should include employee devices, business-critical workstations, servers where applicable, network and wireless infrastructure, firewalls, internet connectivity, storage, and other technology that employees depend on to work.

But lifecycle planning should not be reduced to a blanket rule such as replacing every device after a fixed number of years.

A stronger approach considers several factors together:

  • Supportability: Is the hardware, operating system, or software still supported?
  • Security: Can necessary security updates and protections still be maintained?
  • Reliability: Is the technology producing recurring failures or interruptions?
  • Performance: Is it slowing the work employees need to perform?
  • Capacity: Can it support expected users, data, workloads, and growth?
  • Business criticality: How much work depends on it?
  • Replacement risk: Can replacement be planned, or is the firm waiting for an emergency?

A piece of older technology that remains supported, reliable, appropriately secured, and noncritical may warrant a different decision than an aging firewall, server, or specialized workstation that creates a single point of failure.

Leadership should ultimately be able to answer:

"If this technology fails or becomes unsupported, what happens to client work, and how difficult will it be to recover?"

The answer helps separate lifecycle planning from reactive purchasing.


Evaluate Cybersecurity, Access, and External Requirements

Cybersecurity belongs in an annual technology review, but it should be evaluated as a business-risk and responsibility issue not as a list of security products.

At a leadership level, the review should consider identity and access, privileged accounts, multi-factor authentication, endpoint safeguards, patch and vulnerability management, email security, remote access, onboarding and offboarding, third-party access, security monitoring, and incident responsibilities.

The NIST Cybersecurity Framework 2.0 provides a useful way to think about cybersecurity risk across six connected functions:

  • Govern
  • Identify
  • Protect
  • Detect
  • Respond
  • Recover

The framework is voluntary and is not a one-size-fits-all approach, allowing organizations to consider their own risks, priorities, requirements, and resources.

That distinction matters. An annual IT assessment should not imply that every professional services firm needs the same control set or faces the same compliance requirements.

Instead, leadership should ask whether current safeguards and responsibilities reflect:

  • the confidential information the firm handles;
  • how employees access and share that information;
  • important client contracts;
  • client security questionnaires or expectations;
  • cyber-insurance requirements;
  • applicable legal or regulatory obligations;
  • vendor requirements;
  • the firm's own policies and risk tolerance.

A CPA firm, law practice, consulting company, and architecture firm can all handle sensitive information while facing different contractual, regulatory, and operational requirements.

The annual review should identify which requirements actually apply and which security conditions create meaningful business exposure. It should not use generalized fear to make every technical finding appear equally urgent.



Validate Backup, Recovery, and Business Continuity Readiness

Seeing successful backup jobs is not the same as knowing the firm can recover.

An annual review should ask a broader question:

"Could the firm restore the systems and information needed to resume its most important work?"

That requires understanding what is protected, what is not, and which systems need to return first.

Leadership should consider whether:

  • critical files, systems, and workloads are included;
  • important cloud or SaaS data has been accounted for;
  • backup failures are monitored and addressed;
  • backup copies are appropriately protected from the production environment;
  • recovery has actually been tested;
  • employees and vendors understand restoration responsibilities;
  • recovery priorities reflect current business needs;
  • growth or application changes have altered what must recover first.

CISA's #StopRansomware Guide recommends maintaining offline, encrypted backups of critical data and regularly testing their availability and integrity in a disaster-recovery scenario. The guidance also recommends identifying critical systems, data, and dependencies so organizations can establish restoration priorities before an incident occurs.

For a professional services firm, those priorities should follow the work. Restoring an easy-to-recover system first is not necessarily useful if employees still cannot reach the application, client files, communications, or data needed to serve clients.

Effective backup and recovery readiness connects protected data and systems with restoration priorities, testing, responsibilities, and the way the firm actually operates.

The annual assessment therefore should not stop at “Do we have backups?”.

A more useful question is: “Does our current recovery capability still match the way the firm operates?”


Review Applications, Vendors, and IT Support Performance

The technology employees interact with every day can reveal issues that an infrastructure inventory alone will miss.

Professional services firms often depend on specialized applications: practice-management platforms, accounting and tax software, CAD and design tools, document-management systems, CRMs, project-management platforms, time and billing systems, and client portals.

During the annual review, leadership should look beyond whether those systems technically function.

Consider:

  • Are employees relying on manual workarounds?
  • Are integrations failing or creating duplicate work?
  • Are licenses being paid for but rarely used?
  • Are applications creating performance or access problems?
  • Are important renewals approaching?
  • Does the firm understand who owns support when multiple vendors are involved?
  • Are any critical applications dependent on aging hardware, unsupported software, or a single vendor relationship?

The same approach should be applied to IT support performance.

Ticket counts alone are not enough. Recurring ticket categories, repeated outages, vendor handoff problems, unresolved root causes, employee complaints, escalation delays, and documentation gaps can reveal larger operating problems.

A closed support ticket does not necessarily mean the underlying business problem has been resolved. If employees repeatedly experience the same issue, rely on workarounds, or lose billable time waiting for multiple vendors to coordinate, leadership should treat that pattern as an operational problem not simply a help-desk metric.

That is especially important in professional services, where employee time is closely connected to client delivery and revenue.

The annual review should therefore ask whether the firm's current support model including any managed IT services relationship still fits its size, complexity, applications, security responsibilities, and dependence on technology.


Turn the Findings Into an Address Now/Plan & Budget/Monitor Roadmap

A useful annual IT assessment should not end with a long list of findings.

Leadership needs decisions.

One practical way to organize the findings is to place each meaningful issue into one of three categories:

Category

What It Means

Leadership Question

Address Now

A current condition creates material operational impact, risk, instability, or another reason leadership determines waiting is unreasonable.

What deserves action now?

Plan & Budget

The need is legitimate but can be deliberately funded, sequenced, and coordinated rather than handled as an emergency.

What should we intentionally prepare and fund?

Monitor

The condition is currently acceptable or lower priority, but leadership should define when it will be reconsidered.

What are we accepting today, and what would change that decision?


An Address Now item might be unsupported critical technology, a recurring outage affecting client work, an unresolved access problem, a meaningful security gap, or a recovery process that has failed testing.

A Plan & Budget item might include lifecycle replacements, capacity expansion, an application change, infrastructure modernization, or a resilience improvement that requires coordination and funding.

A Monitor item is not the same as ignoring something. Leadership should identify what will be monitored, who owns it, when it will be reviewed again, and what trigger would increase its priority.


Each significant item should ultimately identify:

business impact → recommended action → relative priority → budget implication → dependencies → owner → timeframe → next review

That turns the technology review into something leadership can manage.


It also creates a clean distinction between assessment and budgeting:

The annual review identifies what deserves funding.

The budgeting process determines how those investments fit into the organization's financial plan.

Once leadership understands which priorities require funding, it can build an IT budget that reflects lifecycle needs, risk, projects, growth, and realistic timing.

When competing priorities are difficult to evaluate or sequence, IT consulting and vCIO services can help leadership connect technology risk, lifecycle needs, projects, vendors, and budget decisions into a practical roadmap.


Assign Ownership and Keep the Roadmap Current

“Annual” should describe the planning checkpoint not the frequency with which technology risk is managed.

annual assessment can establish the baseline for the coming year, but technology, employees, vendors, threats, applications, and business priorities will continue to change.

NIST describes cybersecurity risk management as an ongoing process and organizes its small-business guidance around understanding, assessing, prioritizing, and communicating risk rather than treating cybersecurity as a one-time project.

For each priority, leadership should know:

  • Who owns the decision?
  • Who owns implementation?
  • Which vendors or internal teams are involved?
  • What dependencies could delay progress?
  • When will status be reviewed?
  • What change would cause the priority to move from Monitor to Plan & Budget or from Plan & Budget to Address Now?

That accountability keeps the roadmap useful.

Without it, even a technically accurate assessment can become another document that receives attention once and then disappears until the next planning cycle.



Turn Technology Priorities Into a Plan Leadership Can Use

Some professional services firms have enough internal technology leadership and operational capacity to evaluate the findings, prioritize investments, coordinate vendors, and manage the roadmap themselves.

Others reach a point where the difficult part is no longer identifying technology issues, it is deciding what deserves attention, what can wait, what should be funded, and who will own the work.

That is where outside technology guidance may be useful.

The question is not: “Do we need to buy an IT assessment?”

A better question is: “Do we have the clarity, ownership, and resources needed to turn what we know into a practical technology plan?”

An experienced technology advisor can help leadership evaluate competing priorities, challenge assumptions, connect technical conditions to business impact, coordinate vendors, and turn disconnected findings into an achievable roadmap.

That may lead to a defined consulting initiative, managed or co-managed IT support, a specific project, or simply a clearer understanding of what the organization should do next.

The goal should be the right next decision not creating work for its own sake.


The Goal of an Annual IT Assessment Is Better Decisions

A strong annual IT assessment should give leadership more than a snapshot of technology.

It should clarify which systems and workflows matter most, where risk or recurring friction deserves attention, what investments should be planned, and who is responsible for moving priorities forward.

For professional services firms, that creates a technology roadmap tied to the work clients depend on not a technical report disconnected from the business.


Schedule a 30-Minute IT Fit Call

If your firm is working through technology priorities, recurring IT concerns, upcoming investments, or questions about what deserves attention first, schedule a practical 30-minute conversation with thirtyone3 technology.

We will discuss your current environment, the business impact of your concerns, and the outcome leadership wants, then determine whether our capabilities and approach fit what your organization needs. The Fit Call is a discovery conversation not a complete technical assessment and not a high-pressure sales presentation.

Schedule a 30-Minute IT Fit Call

More Questions About Annual IT Assessments

A formal leadership-level review once a year can align well with budgeting and business planning, but it should not replace ongoing technology management. Cybersecurity, maintenance, backup monitoring and testing, lifecycle management, access reviews, and risk management continue throughout the year.