All insights

What does co-managed IT look like for an accounting firm?

2 min readBy Brendon Whiting, Founder · 28 May 2026

The firm keeps someone internal handling the day-to-day, usually a practice manager or a technically capable partner, and an external provider covers security, infrastructure, patching and escalation. It suits practices too large to have nobody and too small to employ a proper team, which describes a great many Adelaide firms.

The alternatives both have real drawbacks at this size. Fully internal means one person holding everything, which works well until they are on leave, unwell or resign, at which point the firm discovers how much lived only in their head. Fully outsourced works and can feel remote, since nobody on the provider's side knows that a particular partner always needs their file open a certain way, or which client is difficult in March.

Co-managed splits along a sensible line. The internal person keeps the practice-specific knowledge and the everyday work: new starters, small changes, first-line questions, the things that benefit from someone who knows the firm. The provider takes what nobody can reasonably do alone: security monitoring, the Essential Eight controls, infrastructure, patching across the fleet, and cover when the internal person is away. AFM Services adopted exactly this model alongside their move to Xero and their Essential Eight uplift.

Two conditions make it work rather than produce confusion. Write down who does what, particularly for the grey area of who handles an urgent problem at five on a Friday, because unclear boundaries in a co-managed arrangement are worse than either alternative. And ensure documentation and access sit with both parties, since the whole point is removing the single-person dependency rather than relocating it. If you want to talk about how the split would work for your practice, call 1800 456 567.

Keep your internal capability, add depth behind it

Co-managed IT gives your internal person backup, security expertise and escalation, without the firm losing the knowledge it already has.

Frequently asked questions

Usually less on the external fee and not necessarily less overall, since you are still paying the internal person. The reason to choose it is capability rather than price: institutional knowledge stays in the firm while specialist security and infrastructure work comes from outside, which is difficult to achieve either fully in or fully out.

Typically the everyday: new starters, small changes, first-line questions and the practice-specific knowledge that takes years to accumulate. What they hand over is what nobody can reasonably do alone, meaning security monitoring, infrastructure, patching at scale, escalation and cover when they are away.

That is the main argument for the model rather than a problem with it. Under a co-managed arrangement the documentation, tooling and access already sit with a provider as well, so a resignation is a gap rather than a crisis. Firms wholly dependent on one internal person discover the difference at the worst moment.

Questions? Let's talk.

Call 1800 456 567 or fill out the form.

  • 30-minute discovery — no jargon, no pressure
  • Plain-English Essential Eight Cyber Security Scorecard
  • A clear plan tailored to your business

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, 25 Grenfell Street, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.