20 Questions Every Manager Should Ask Before Moving to the Cloud

Last month, the IT manager of a mid-sized manufacturing firm put it plainly: ‘We are considering moving our accounting and inventory software to a hosted platform, but I have no idea how to explain the risks to the board.’ The problem is not technical — it is strategic. Managers across Turkish SMEs are now broadly familiar with the concept of cloud computing, but most struggle to look past the polished numbers in a vendor presentation and see the real risk picture. This checklist is designed to close that gap: it is a decision-support tool for the manager who needs to speak the same language as the technical team without becoming one.

Cloud computing, in practical terms, means software and infrastructure delivered as a service over the internet. Instead of purchasing servers and paying upfront licence fees, a company pays a monthly or annual subscription; the vendor handles maintenance and updates. From a total cost of ownership (TCO) perspective, the initial capital outlay drops significantly, particularly for firms with fewer than fifty employees. But cost advantage alone is not a sufficient basis for a decision. The real question is whether the risks this model introduces are manageable — and whether your organisation has the tools to evaluate them before signing a contract.

Vendor evaluation is the first and most critical section of the checklist. In which country are the vendor’s data centres located? Depending on your sector, Turkish regulations may restrict the transfer of certain data outside national borders; your legal counsel should confirm whether this applies to your business before any contract is signed. How long has the vendor been delivering this specific service, and can they provide reference customers in comparable industries? What uptime guarantee does the service level agreement (SLA) carry, and does the contract include financial penalties for breaches? Perhaps most importantly: if the vendor ceases operations or discontinues the service, what is your path to recovering your own data? These questions do not make you a difficult customer — they separate a serious vendor from a sales-driven one.

Data security questions span both technical and legal dimensions. Are data encrypted in transit and at rest, and which encryption standard is applied? Access control is equally important: who can reach your data, are access logs maintained, and can you audit those logs as a customer? Is multi-factor authentication available for user accounts? Has the vendor’s infrastructure undergone independent security audits, and are those reports accessible to customers? Backup frequency and whether backups are stored in geographically separate locations are also questions that belong in this section — not in a follow-up meeting after the contract is signed.

Regulatory compliance deserves a dedicated review, especially for firms operating in finance, healthcare, or public-sector supply chains. If the data supporting your e-declaration (e-Beyanname) processes will reside on this platform, you need to confirm that the vendor meets the data retention requirements set by the Revenue Administration. Accounting records must remain accessible for the full statutory retention period, and this obligation should be explicitly guaranteed in the service contract. For companies handling international transactions, the treatment of IBAN-based payments and the recording of foreign currency transactions on the platform also require verification before go-live.

Business continuity planning is the section managers most often skip. When your internet connection fails or the vendor’s systems become temporarily unavailable, how long can your operations continue? Is there an offline working option for critical processes? The actual frequency and duration of past outages — information best obtained from reference customers rather than the vendor’s own materials — tells you far more about SLA reliability than any brochure. Does the vendor’s disaster recovery plan cover customer data, or only its own infrastructure? Are the recovery time objective (RTO) and recovery point objective (RPO) defined in the contract with measurable commitments?

When it comes to making the final call, ROI calculations should not be the only compass. Vendor lock-in risk — specifically, whether you can export your data in a standard format and what it would cost to migrate to a different platform — is part of the total value equation. Running a limited pilot, moving one non-critical process to the hosted platform for a few months, gives both the technical team and management a grounded basis for evaluation. Finding a vendor that answers every question on this checklist to a satisfactory standard takes time. That time, however, is a far smaller investment than recovering from operational disruptions that a thorough review would have prevented.

This article was originally written in Turkish by Gökhan MERCANOĞLU on June 21, 2010 and has been automatically translated into English and other languages using machine translation.


supply chain resilience should be designed not to record the company’s past, but to strengthen its future decisions. The right architecture creates visibility, speed, control, and learning capacity. Otherwise, data is collected and reports multiply, while decision quality remains unchanged.


Gökhan Mercanoğlu
MRP, Üretim ve Tedarik Zinciri