What "IT AMC" means in the Gulf
AMC — annual maintenance contract — is the term the UAE and the wider Gulf use for a fixed-term support agreement covering a defined list of hardware and software. The vocabulary comes from the region's facilities-management tradition, where a building's chillers, lifts and generators each go onto a maintenance schedule with an agreed number of visits a year. IT inherited the same shape: assets on a schedule, visits on a calendar, one fee for the year.
In practice that means an AMC is scoped asset by asset. Workstations and laptops, servers and storage, switches and wireless access points, the firewall, the IP telephony system, and often CCTV and other low-voltage systems — each named on a schedule, each with an agreed visit count and response window written into the contract.
That scoping is both the whole point and the whole limitation. If it is on the schedule, it is covered on the agreed terms, and you know before the year starts what you are paying. If it is not, adding it later means a contract amendment rather than a phone call. A traditional AMC also assumes the work starts when something breaks: the engineer arrives, repairs or replaces, logs the visit, and the environment goes back to being unobserved until the next scheduled call.
What a managed services contract adds
Managed IT services start from a different premise. Instead of fixing what breaks, the goal is to stop it breaking — monitoring, patching and maintenance run continuously in the background rather than waiting for a support ticket, and the provider is measured on how little goes wrong rather than on how fast they turn up when it does.
Concretely, that shows up as five additions to the AMC baseline: continuous monitoring of servers, network hardware, endpoints and the cloud tenant; patch and update management on an agreed schedule rather than whenever a technician remembers; a security baseline — endpoint protection, identity hardening, email filtering — inside the base contract instead of quoted as extras; asset and licence lifecycle planning, so replacements are forecast rather than discovered; and a portal where ticket history, the SLA clock and the asset register are visible to the client rather than summarised in a monthly PDF.
The environment is treated as a whole rather than as a checklist of named assets. That is why, under a managed contract, a new laptop is normally covered on the day it is issued instead of at the next contract review — and why the provider, not the client, is the one who notices the failing disk.
The honest comparison
Every vendor comparison table in this market lands on roughly the same dimensions. Here is ours, stated plainly rather than dressed up as a decision matrix — including the part most comparisons leave out, which is what an AMC does perfectly well.
- Coverage — an AMC covers exactly what is listed on the asset schedule; managed services generally cover the whole environment, new devices included.
- Response model — an AMC is reactive — something breaks, you raise a ticket, the SLA clock starts. Managed services aim to catch the problem through monitoring before a ticket is ever needed.
- Security — under an AMC, endpoint protection, email filtering and identity hardening are typically quoted as extras; managed services usually fold a security baseline into the base contract.
- Reporting — AMC reporting is a service log per visit. Managed services provide standing dashboards, a visible SLA record and a regular review cadence.
- Cost shape — AMC pricing is a flatter annual fee tied to a fixed asset list. Managed services pricing scales with the size of the environment — more users and devices, higher fee — which is predictable in a different way.
- Who carries the risk — under an AMC, more of the operational risk between visits sits with the client. Under managed services, more of it sits with the provider, because uptime is what the provider is actually being measured on.
The case for a traditional AMC is real, and it is rarely made honestly by the people selling the alternative. A fixed asset list means a fixed, forecastable cost. The same engineer who wired the office knows where everything is. And in an environment that genuinely does not change from one year to the next, paying for continuous monitoring of six stable devices can be paying for reassurance rather than for risk reduction.
The case against is equally simple: very few Dubai businesses are actually that static, and the asset schedule is usually the first document to fall out of date. The moment the estate grows faster than the paperwork, the gap between what you think is covered and what is covered starts widening quietly.
Which fits your business
A small, stable environment is a reasonable fit for a traditional AMC — five to fifteen users, one site, everything already living in Microsoft 365, no compliance obligation beyond the ordinary. The fixed scope keeps the annual cost predictable, provided the asset list stays honest as things change.
A business that depends on continuous uptime, is adding headcount and devices at a steady clip, carries a regulatory or client-audit obligation, or has moved most of its workload to the cloud tends to find the gaps in a reactive model expensive in a way that never appears on the AMC invoice: the lost hours between the break and the visit, and the security work that was technically out of scope.
Worth knowing before you agonise over the label — in this market the two models have largely converged. Our own AMC plans include unlimited remote support, proactive monitoring, scheduled site visits, the customer portal and quarterly reviews as standard, which a decade ago would have been sold separately as managed services. The plans are sized by headcount: Essential for 5–15 employees, Professional for 15–50, Enterprise for 50 and above. So the practical question is not "AMC or managed services", it is what is written into the scope and what is measured.
Response targets are the same kind of question. For support clients on a plan we work to published targets — one hour for a critical issue where the business has stopped or a live security incident is running, four hours for high, same business day for medium, three business days for low — measured monthly and visible in the customer portal rather than described in a proposal. Whatever provider you choose, ask for the numbers, then ask where you get to see them.
See RHM's AMC plans →
Switching providers without drama
Most of the pain in a provider switch is not technical, it is procedural: notice periods that get missed, asset lists that were never accurate, credentials that live in one person's head. Start the handover conversation before the current contract's notice window closes, not after — automatic renewal paired with a long notice clause is the single most common reason a business spends another year with a provider it has outgrown.
- Data and credential handover — ask for administrative credentials, monitoring history, ticket history and the asset register as a written deliverable with a date against it, not as a favour negotiated in the final week.
- Documentation — network diagram, firewall rules, VLAN layout, backup jobs and the restore procedure, escalation list. If none of it exists, the incoming provider has to do the archaeology before the maintenance — that work belongs in the onboarding plan and in the price.
- Licence and tenant ownership — check whose name your Microsoft 365 tenant, domain names and licences are registered in. Ours are registered to the client's company rather than to us, including where we act as their Cloud Solution Provider. If yours are not, correcting that is part of the exit, not something to sort out afterwards.
- An overlap period — a short parallel run against the outgoing contract beats a hard cutover date. It costs a few weeks of double cover and removes the scenario nobody plans for, where neither party believes they own the firewall on a Sunday.
- First-90-days expectations — discovery and inventory, then monitoring and backup verification, then the obvious remediation that discovery turned up. Ask the incoming provider what will be finished by day 90 and hold the answer against the contract at the first review.
None of this needs a lawyer. It needs the exit terms read at the start of a contract rather than at the end of one — including the exit terms of the contract you are about to sign.
How our helpdesk runs day to day →