You keep the client.
We provide the evidence.

InquilionGRC gives MSPs a clean way to offer their clients independent Microsoft 365 governance evidence at board level. The MSP keeps the client relationship and the remediation work.
InquilionGRC provides the evidence layer above it.

Boards now treat Microsoft 365 as a governance environment. Identity, access, email, documents, collaboration, device control and information governance are concentrated inside the same platform. Configuration choices translate directly into governance posture.

Each assessment covers sixteen governance domains: fourteen for Microsoft 365 and two further Azure domains where they are in scope. Where a domain cannot be assessed at the client's licence tier or through available interfaces, it is reported as outside assessment scope rather than passed or failed.

The team configuring and managing an environment is rarely well placed to assure it independently. Boards, audit committees and other governance stakeholders are starting to ask for evidence that sits outside the operational team.

Independent assurance is stronger when it is separate from remediation.

How the partner model works.

The commercial structure

Who signs the partner agreement
The MSP.
Who pays InquilionGRC
The MSP. InquilionGRC does not invoice the MSP's end client directly.
Who invoices the end client
The MSP, at its own price.
Who owns the client relationship
The MSP.
Who delivers remediation
The MSP. InquilionGRC does not deliver remediation.
Where each engagement begins
A Board Review or onboarding baseline.
What the end client receives
Three reports delivered to the end-client board: a Board Governance Report, a Risk Report and a Compliance Report. The board decides what is acted on, by whom and how.
What the MSP receives
Nothing directly from InquilionGRC. The end-client board shares the Compliance Report with the MSP to inform remediation.

This division matters: the board gets independent evidence.
The MSP gets a structured route into remediation, licence improvement and recurring governance support.

Independence
is not negotiable.

The board owns the outputs.

All three reports are delivered to the end-client board. The board decides what is acted on, by whom and how, and shares the Compliance Report with the MSP to enable remediation.

We present to the board.

InquilionGRC is available to present the Board Governance Report directly to the end-client board, audit committee or agreed governance forum. The MSP may attend joint review sessions where the end client agrees.

No rebranding.

The MSP may not rebrand, alter or represent InquilionGRC assurance outputs as its own independent assessment.

No remediation by InquilionGRC.

Remediation belongs to the MSP. If we fixed what we found, we could no longer independently assure it.

Access and data handling.

Common questions.

No. The MSP keeps the end-client relationship and the remediation work. InquilionGRC provides the independent evidence layer.

No. The point is structural, not personal. Independent assurance is stronger when it is provided separately from the remediation function.

No. The assessment uses an Entra application registration with read-only permissions, supplemented by a dedicated assessment account at Global Reader level. Privileged roles are used only where the agreed scope requires them, on a time-bound basis.

Some Microsoft 365 and Purview checks are not available, complete or practical through app-only collection. For those checks, a dedicated assessment account is used with least-privilege roles. Baseline is Global Reader.

No. The MSP may not rebrand, alter or represent InquilionGRC assurance outputs as its own independent assessment. Joint review sessions are encouraged where the end client agrees.

Yes. The end client owns the report and decides on sharing, subject to the engagement terms.

No. InquilionGRC produces governance assurance evidence. It does not certify compliance and does not provide regulatory approval.

The report is not a criticism of the MSP. Most environments evolve over time: licences change, Microsoft releases new controls, board expectations increase and configuration decisions are often made under budget constraints. In many cases the MSP has already recommended improvements that were deferred. An independent report evidences those points at board level, creates a structured remediation path and gives the board a clearer basis for funding the work. The purpose is not blame. It is to turn informal technical concern into board-visible governance action.

Bring your clients the evidence layer.

A partner conversation takes thirty minutes and commits you to nothing.

REQUEST INFO