Is the QBR Process Relevant to Enterprise IT? Benchmarking for Enterprise IT

Is the QBR Process Relevant to Enterprise IT?

August 31, 202610 min read

Quarterly Business Reviews are most commonly associated with Managed Service Providers. An MSP brings together information about a customer's environment, reviews what happened during the previous quarter, demonstrates improvements, identifies emerging risks and agrees priorities for the months ahead.

It is a model that makes obvious sense when there is a service provider and a customer. But does the same process have a place within an Enterprise IT department?

At first, the answer may appear less obvious. Enterprise IT doesn't have an external customer paying for a managed service, and it usually doesn't have dozens of comparable customer environments against which to benchmark performance. Yet the fundamental purpose of a good QBR isn't really customer comparison. It is about using evidence to understand where you are, what has changed and what needs to happen next.

Seen from that perspective, the QBR can be just as relevant to Enterprise IT as it is to an MSP.

Enterprise IT Still Has Customers

Enterprise IT may not issue a monthly invoice to its users, but it is still a service provider. Employees depend on IT to work effectively, individual departments rely on applications and data, security and compliance teams depend on appropriate controls, and senior management expects technology investments to support wider business objectives.

That creates many of the same questions that an MSP receives from its customers. Is the environment becoming more secure? Are we meeting our compliance obligations? Are we paying for technology that isn't being used? Are users actually adopting the services we have purchased? What risks are emerging, and where should investment be directed next?

The difference is primarily the audience. Instead of an MSP demonstrating value to a customer, Enterprise IT is demonstrating performance, control and direction to the organisation it supports.

A well-designed Enterprise IT QBR therefore provides a regular opportunity to move the conversation beyond operational activity. Rather than reporting how many tickets were closed or how many changes were completed, IT can demonstrate whether the organisation's technology environment is actually improving.

If There Are No Other Customers, What Do You Compare Against?

This is perhaps the biggest apparent weakness in applying the MSP QBR model to Enterprise IT.

An MSP managing many Microsoft 365 tenants can potentially compare one customer with others. It may be able to identify that a customer's security posture is below its peer group, that its licence utilisation is unusually poor or that another organisation has achieved significantly better adoption of a particular service.

An Enterprise IT department doesn't normally have that external dataset.

But it doesn't necessarily need one.

For Enterprise IT, one of the most valuable benchmarks is the organisation's own previous performance.

If Microsoft Secure Score has improved from 62% to 74%, that provides evidence of improving security posture. If the organisation had 143 inactive Microsoft 365 licences last quarter and now has 37, there has been measurable progress in licence governance. If dormant user accounts have been reduced or MFA coverage has increased, the direction of travel is visible.

Equally importantly, the QBR can expose deterioration. A growing number of unmanaged applications, increasing cloud expenditure or previously unidentified AI usage might indicate that Shadow IT, Shadow AI or AI Sprawl is increasing.

The important comparison therefore becomes less about how the organisation performs against somebody else and more about a simpler question: are we getting better or worse?

Over successive quarters, that creates an operational baseline that becomes increasingly valuable.

The Enterprise Itself Provides Multiple Benchmarks

Historical performance isn't the only comparison available.

A large organisation may contain dozens of potential internal benchmarks. Different countries, subsidiaries, departments, offices and user groups may all consume the same technology in very different ways.

Imagine an organisation operating across the UK, Germany, France and the United States. One region might have substantially better MFA coverage than another. One business unit might have a much higher proportion of inactive accounts. Another may be consuming expensive Microsoft 365 licences while making limited use of the services those licences provide.

Those differences don't need to become simplistic league tables. Their value is in highlighting exceptions that deserve investigation.

If Finance has substantially better licence utilisation than Sales, why? If one subsidiary has significantly more dormant accounts than the rest of the organisation, what is different about its joiner, mover and leaver processes? If one country has considerably weaker security configuration, is that intentional, a technical constraint or simply something that has been overlooked?

This is where comparison becomes useful. The purpose isn't to declare one department better than another. It is to use differences within the organisation to identify where further investigation or action is required.

Policy Can Be More Important Than Peer Comparison

Enterprise IT also has another benchmark that can be more meaningful than comparing itself with another organisation: its own policies and objectives.

If organisational policy requires MFA for all applicable users, knowing that another company has achieved 92% coverage isn't particularly important. The relevant target is the organisation's own requirement.

The same principle applies across security, compliance, identity management, software usage and cost control. If dormant accounts should be disabled after a defined period, exceptions can be identified. If privileged access must be reviewed quarterly, the QBR can provide evidence that the process is being followed. If the organisation has committed to specific Cyber Essentials controls or internal security objectives, progress can be measured against those requirements.

Financial objectives work in much the same way. An organisation approaching its Microsoft annual renewal might establish a target to identify unused or inappropriate licences before the renewal date. The following QBR can then demonstrate what was identified, what action was taken and what financial impact resulted.

In this model, the QBR evolves from a reporting exercise into part of the organisation's governance framework.

A Quarterly Meeting Shouldn't Mean Quarterly Visibility

There is, however, an important limitation with the traditional QBR process.

Three months is a very long time in modern IT.

A security configuration can change immediately. A privileged account can be created tomorrow. An employee can leave while retaining unnecessary access. A new SaaS application can spread through a department in a matter of weeks, while AI services can be adopted by employees long before they appear in an official application inventory.

Waiting until the end of the quarter to discover these things isn't operational visibility.

The better model is therefore to separate the frequency of the review from the frequency of the monitoring.

The QBR may happen every three months, but the information supporting it should be gathered and understood continuously.

This fundamentally changes the nature of the meeting. Instead of IT teams spending days before every QBR collecting screenshots, exporting spreadsheets and attempting to reconstruct what happened during the previous quarter, the review becomes a strategic checkpoint based on information that has been monitored throughout the period.

The question changes from "What happened?" to "What did we learn, what did we do about it and what should we do next?"

Operational Visibility Creates a Continuous Improvement Process

This approach fits naturally with the CIQ Cloud Operational Visibility lifecycle of

Discover → Monitor → Understand → Govern → Optimise.

Operational Visibility for Continuous Improvement

Discovery establishes what exists across the organisation: users, licences, applications, services, configurations and other technology resources. Continuous monitoring then establishes how that environment changes.

The next stage is particularly important. Data alone doesn't create value. Enterprise IT needs to understand what those changes mean. An increase in licence consumption might indicate growth, waste or simply a change in working practices. A reduction in Secure Score may represent an important security issue or an intentional configuration decision. Unexpected AI usage might indicate valuable innovation, an emerging governance requirement or both.

Once the organisation understands what is happening, it can govern appropriately and then optimise its environment. That might mean changing a security configuration, removing unnecessary access, reclaiming unused licences, introducing a new policy or helping a department make better use of technology it already owns.

The process then continues.

The QBR becomes a regular point at which the organisation reviews progress through that lifecycle rather than an isolated exercise that begins and ends every three months.

Turning Technical Metrics Into Business Conversations

One of the greatest benefits of an Enterprise IT QBR may actually be communication.

IT teams naturally work with technical metrics. Secure Score changes, dormant accounts, licence assignments, storage consumption, application usage and configuration status are all valuable operational information.

Senior management, however, is unlikely to want a presentation consisting of hundreds of technical measurements.

The QBR provides an opportunity to translate those measurements into business outcomes.

For example, instead of simply reporting that 106 unused licences were discovered, IT can explain the potential financial impact and whether those licences can be removed before the next renewal. Rather than presenting a list of dormant accounts, the discussion can focus on how identity governance has improved and where remaining access risks exist.

Similarly, discovering previously unknown AI usage isn't merely another number for a dashboard. It may indicate that employees are adopting AI faster than organisational governance processes can accommodate, creating a conversation about how the business can support innovation without losing visibility or control.

This is a fundamentally different form of IT reporting. It connects operational evidence with risk, expenditure, governance and business priorities.

The QBR Can Help IT Decide What to Do Next

The QBR also has value even if the information never leaves the IT department.

Enterprise IT teams face an almost unlimited number of possible improvements but finite budgets and resources. Security teams identify risks, finance wants savings, employees request new capabilities, vendors recommend upgrades, compliance teams require evidence and technical teams have existing backlogs.

Without good operational information, prioritisation can easily become driven by whichever issue is currently receiving the most attention.

A QBR supported by continuous Operational Visibility provides a more evidence-based approach.

Perhaps licence optimisation was a major priority during the previous quarter, but the data now shows that unused licences have been substantially reduced. At the same time, privileged access risk or unmanaged AI adoption may be increasing. That information can help IT deliberately shift its attention to the areas where improvement is now most valuable.

Instead of asking what projects IT is currently working on, the organisation can begin asking what does the evidence tell us we should work on next?

That is a much more powerful management process.

So, Does Enterprise IT Need a QBR?

Not necessarily in exactly the same form as an MSP.

There may be no reason to reproduce an MSP-style customer presentation or manufacture external comparisons simply because they are traditionally associated with QBRs.

What Enterprise IT can take from the QBR model is the discipline of periodically reviewing its environment, demonstrating measurable progress, identifying emerging risks and agreeing what should happen next.

The absence of multiple customers doesn't remove that value. It simply changes the benchmarks.

Enterprise IT can compare current performance with previous quarters, one part of the organisation with another, actual performance against policy, expenditure against budget, utilisation against investment and results against agreed objectives.

Over time, those comparisons create something arguably more useful than a generic industry benchmark: a detailed understanding of the organisation's own direction of travel.

From Quarterly Business Review to Continuous Improvement

This is ultimately where the Enterprise IT QBR becomes most valuable.

The objective isn't to create another quarterly report.

It is to establish a regular strategic checkpoint within a continuous process of understanding and improving the organisation's technology environment.

CIQ® Cloud supports that process by providing Operational Visibility across the cloud applications and technology services organisations depend upon. By bringing together security, compliance, usage, cost and operational information, Enterprise IT can establish baselines, identify changes, investigate exceptions and track the impact of decisions over time.

The meeting may still happen once a quarter.

But the visibility behind it should exist every day.

And that changes the most important question in the QBR from "What happened during the last three months?" to:

"Are we improving, and what should we do next?"

For Enterprise IT, that is a question worth asking every quarter.

Peter is a veteran of the Enterprise Systems Management and MSP space. He has worked for industry leaders such as NetIQ, Vodafone and ran a Systems Management consultancy for many years.
Back to Blog

Start your free 14 - day trial of CIQ® Cloud and see how effortless Microsoft 365, Google Workspace and cloud monitoring can be.

No credit card required • Cancel anytime • Purpose-built for Office 365, Google Workspace and cloud-first environments

Image

Innovation

Fresh, creative solutions.

Image

Integrity

Honesty and transparency.

Excellence

Excellence

Top-notch services.

Copyright 2006 - 2026. Almaden, Inc . All Rights Reserved.