ChecklistManaged Services

Running a managed service week to week: a governance checklist

A contract describes a service; governance keeps it that way. Without regular forums, clear decision rights and change control, a managed service drifts from what was signed, and AI-run work drifts faster because a prompt or threshold edit can change outcomes overnight. This checklist covers three governance tiers, a decision-rights matrix, change control for AI configuration, improvement tracking and exit readiness.

Reviewed 6 min read

On this page
  1. Why managed services drift between contract and daily work
  2. Tier 1, operational: daily and weekly checks
  3. Tier 2, monthly service review: the pack and the decisions
  4. Tier 3, quarterly executive review: outcomes and direction
  5. Decision rights between client and provider
  6. Change control for models, prompts, thresholds and tool access
  7. Continuous improvement: who claims a benefit and who signs it off
  8. Exit readiness, reviewed every quarter
  9. Hypothetical governance calendar for a customer-service managed service
  10. Questions and answers
  11. Sources

Why managed services drift between contract and daily work

The contract is fixed on the day it is signed; the work changes every day after. Volumes shift, policies change, systems are upgraded, staff turn over and, in an AI-run service, the configuration itself moves. Small adjustments pile up: an exception rule added to clear a backlog, a confidence threshold lowered to hit a speed target, a report quietly dropped. Each makes sense locally. Together they change the service you bought.

Governance makes those changes visible and puts each decision with the right party. ColdAI's model treats Operate and Optimize as continuing phases rather than a hand-off1, and service management standards such as ISO/IEC 20000-1 describe the same idea as a managed cycle of planning, delivery and improvement2. The checklists below turn that into forums you can actually run.

Tier 1, operational: daily and weekly checks

0 of 6 checked

Tier 2, monthly service review: the pack and the decisions

0 of 6 checked

Tier 3, quarterly executive review: outcomes and direction

0 of 5 checked

Decision rights between client and provider

DecisionClientProviderForum
Adding or removing processesApprovesProposes and pricesMonthly review recommends; executive review decides
Priorities within scopeSets them for the periodAllocates people and automationWeekly call resolves conflicts
Policy exceptions, such as paying without a purchase orderDecides, or delegates within written limitsExecutes and logs each oneReported monthly
AI changes that alter decisions or customer-facing outputApproves on evidenceProposes with re-validation resultsChange board
AI changes that do not alter outcomesInformedApproves and logsReported monthly
Spend beyond agreed volume bandsApprovesFlags in advanceQuarterly review
Incident messages to customers or regulatorsDecides and sendsSupplies facts and timelinePost-incident review

Adapt the rows to your contract. The test is that every recurring decision has exactly one approver.

Change control for models, prompts, thresholds and tool access

This is the release process inside the service. Approval tiers and confidence thresholds for individual actions an agent takes belong to the agent's own design, covered in human-in-the-loop approvals.

  1. Classify the change

    Model or model-vendor version, prompt or instruction edit, confidence threshold, new tool permission or new data source. Give each class a default risk level so routine changes do not queue behind risky ones.

    Owner
    Provider service lead
  2. Assemble the evidence

    Run the new configuration on a regression set of past items with known right answers and compare it with the current one. For new tool permissions, attach the access review.

    Output
    Re-validation pack
  3. Approve at the right level

    The provider approves changes that leave outcomes untouched; the client approves anything that alters decisions or customer-facing output.

    Owner
    Change board
  4. Release with a way back

    Release in stages where volumes allow, raise sampling for a defined period and keep the previous configuration ready to restore.

    Output
    Release note with rollback point
  5. Record the result

    Log versions, approver, evidence and what the post-release samples showed, so an auditor can reconstruct any decision later.

    Output
    Change log entry

Continuous improvement: who claims a benefit and who signs it off

In the Optimize phase, improvement ideas come from root-cause data, process mining and the people doing the work. Give each backlog item an expected benefit, the measure that will show it and an owner. When the item ships, the provider claims the benefit, but someone on your side, usually the process owner or finance, signs it off against the baseline. Where a gainshare applies, that sign-off is what releases payment.

Exit readiness, reviewed every quarter

0 of 5 checked

Hypothetical governance calendar for a customer-service managed service

Questions and answers

How many governance meetings does a managed service need?

Enough that every recurring decision has a forum, and no more. Most services work with a short daily or weekly operational check, a monthly service review, a quarterly executive review and a change board that meets as often as changes require. If two forums review the same pack, merge them.

Who should chair the monthly service review?

The client's service owner, because the review exists to hold the service to account. The provider's service lead presents the pack and the actions. Chairing from the client side keeps the agenda on outcomes you care about rather than on the provider's own reporting choices.

What happens when the client and provider disagree about whether a target was missed?

Settle the facts before the argument. Both sides should work from the same raw data and the calculation method written into the service schedule, so the first step is a joint reconciliation of the disputed figures. If the disagreement is about what a measure means rather than what it shows, fix the definition through change control instead of litigating each month. Only unresolved commercial disputes should climb to the executive review and then to the contract's formal dispute process.

Should prompt edits really go through change control?

Yes, when they can alter decisions or what customers see. A prompt is part of the service's logic, and a small wording change can shift outcomes at volume. Routine edits that do not affect outputs can follow a light path, but they still belong in the change log.

Sources

  1. Managed Services: six-phase methodology — ColdAI
  2. ISO/IEC 20000-1:2018 — Service management system requirements — International Organization for Standardization · checked 10 October 2026

More in Managed Services

Back to Managed Services

Next step

Test your governance model before the first service review

Share the service schedule from your contract and the forums you plan to run. We will point out decisions without a clear owner, missing change-control steps for AI configuration and gaps in exit readiness.

Review a governance model