top of page
James F. Kenefick Website Icon

JAMES F.

   KENEFICK

From SLA to Business Assurance: Rethinking Managed Services for the AI Era

  • 11 minutes ago
  • 6 min read

For thirty years, the service level agreement has been the primary contract between an organization and its technology partners. Uptime percentages, response times, resolution windows: these numbers gave IT leaders something to point to, and they gave managed services providers a way to prove they had done their job. That model is now breaking down, because the questions boards are asking have changed. A 99.9 percent uptime guarantee says nothing about whether a business can recover from a ransomware event, absorb an AI vendor outage, or keep a regulator satisfied after an incident. Business assurance, not the SLA, is becoming the real standard managed services must meet, and the organizations that recognize this first will be the ones boards trust with the next phase of AI adoption.


I have watched this shift accelerate over the past eighteen months, largely because AI has exposed how thin traditional SLAs really are. Forrester's research on service level management put it plainly: many organizations still struggle to connect SLA metrics with business outcomes, and that misalignment creates blind spots that undermine strategic initiatives and erode confidence in IT's ability to deliver value. Forrester's own guidance is direct: stop measuring what is easy, and start measuring what matters. That is the entire argument for business assurance in one sentence, a theme I return to often in my notes on the CIO as AI operating architect, and it applies whether the conversation is about a managed IT contract, a cloud platform, or an agentic AI deployment.


IT operations team reviewing resilience and business assurance metrics in a modern operations center.

Why It Matters


The financial stakes make this more than a semantic argument. Gartner recently found that 234 billion dollars in enterprise application software spend is at risk from agentic AI, as autonomous systems begin to displace the interfaces and workflows that traditional software and service contracts were built around. When the underlying technology stack is this exposed to disruption, an SLA that only tracks uptime and ticket response time is measuring the wrong layer of risk entirely. Boards are starting to notice. McKinsey's research on operational resilience found that leading institutions are building comprehensive reporting mechanisms specifically so the board and senior management can monitor resilience directly, rather than relying on vendor-reported technical metrics after the fact.


This is precisely the gap BetterWorld Technology's work on the shift from SLA to outcomes has been built to close: the clients who ask the right questions of their managed services partner are not asking about ticket volume anymore. They are asking whether the partner can demonstrate recovery time, third-party risk exposure, and compliance posture as a single, coherent story, because that is what a board or a regulator will actually ask for. Working Excellence's research on operating models for managed services has found the same pattern from the buyer's side: procurement teams that still write RFPs around uptime percentages are negotiating the wrong contract for the risk they are actually carrying.


The Business Assurance Framework


A business assurance model rests on four commitments that go well beyond what a traditional SLA measures.

  1. Outcome alignment: the engagement is measured against business goals, such as time to market, customer retention, or regulatory standing, not just technical thresholds.

  2. Resilience assurance: recovery time, failover performance, and third-party dependency exposure are tested and reported, not assumed.

  3. Governance and accountability: a named owner exists for AI-enabled and automated decisions made within the managed environment, with a documented escalation path.

  4. Continuous measurement: performance is reported against the outcome, on a cadence the board can actually use, not buried in a monthly technical dashboard.


Gartner's own guidance on managed services pricing supports this shift, noting that business outcome key performance indicators and experience level agreements now align the services partner with the organization's actual priorities, including growth, time to market, and profitability, rather than interface-based technical delivery alone. BetterWorld Technology's guidance on experience level agreements takes this further for mid-market clients: an XLA framework only works if it is paired with the resilience and governance commitments above it, not treated as a replacement for them. Working Excellence's work on experience-level agreements reinforces the same point from the change management side: employees and customers experience the outcome, not the SLA line item, and that experience is what boards ultimately hear about.


Governance, Security, and Accountability


Business assurance only holds up if governance is explicit, and four questions belong on every board and executive agenda when evaluating a managed services partner. What is the board's role? It is to confirm that resilience and recovery commitments are tested, not merely contracted, and that the organization is not relying on an SLA document as a substitute for a verified recovery capability, a distinction I outline further in my business assurance scorecard. What risks exist? The World Economic Forum's 2026 cybersecurity research is blunt about this: cyber incidents are driving up insurance and compliance costs and recovery expenditures, while disrupting operations, eroding customer trust, and in some cases threatening the solvency of businesses, particularly smaller ones that lean most heavily on managed services partners. What metrics matter? Recovery time, third-party dependency coverage, and incident response performance now belong alongside traditional uptime metrics, because a partner that cannot report on these is not actually assuring the business, only the technology, a gap BetterWorld Technology's cybersecurity resilience guidance for managed IT was built to close.


What oversight is required? The NIST Cybersecurity Framework's Recover function offers the clearest public standard for this: recovery activities exist to restore operations efficiently after an incident, reduce time to recovery, and improve resilience by learning from what happened, and a managed services partner should be able to demonstrate exactly how its practices map to that function, including under SOC 2 and related compliance regimes for managed services. Trust, as the World Economic Forum's research on the shift from cybersecurity to cyber resilience notes, is built through clarity: translating technical posture into business impact, and communicating transparently enough that stakeholders know what to expect when the worst happens. That is a governance standard, not a technology standard, and it is the one business assurance is designed to meet.


Accountability becomes sharper still once AI enters the managed environment. Harvard Business Review Analytic Services' research on the enterprise AI trust gap found that only 6 percent of companies fully trust AI agents to run core business processes today, with 43 percent restricting agents to limited or routine operational tasks and 39 percent keeping them supervised or confined to noncore processes. A business assurance model has to account for that caution directly, with clear decision authority, escalation triggers, and audit trails for every AI-enabled action a managed services partner takes on an organization's behalf, a structure I detail in my notes on agentic AI vendor risk. Microsoft's own framing of this shift is useful here: AI is an operating model shift, not a technology upgrade, and the same is true of the managed services relationship built around it.


Executive Actions


CIOs and boards ready to make this shift should move on three fronts. First, renegotiate the next managed services contract around outcomes and resilience metrics, not technical uptime alone, using the four-pillar framework above as the baseline. Second, require the managed services partner to demonstrate its NIST Recover alignment and third-party risk exposure in writing, on a recurring cadence, rather than accepting a static SLA document signed once a year. Third, name a single accountable owner, inside the organization, for how AI-enabled actions taken by any managed services partner are governed, escalated, and audited. Working Excellence's guidance on executive alignment for managed IT value is a useful reference for boards building this cadence for the first time, and BetterWorld Technology's broader business assurance guidance for managed services buyers offers a practical starting checklist for the renegotiation itself.


Final Thoughts


Business assurance is not a rebrand of the SLA. It is a recognition that the questions boards, regulators, and customers now ask of a managed services relationship have moved well past uptime, into resilience, governance, and accountability, and that AI has made the gap between those two standards impossible to ignore. The managed services partners who move first, replacing technical metrics with business assurance commitments, will be the ones organizations trust with the next generation of AI-enabled operations. The ones who do not will keep meeting their SLA while losing the confidence of the board they are supposed to be serving.

Comments


bottom of page