Skip to main content

Certification you can stand behind.

ISO/IEC 20000-1:2018

ISO 20000-1 IT Service Management Systems

Run IT services with the discipline your SLAs promise.

IT service management
  1. Demand

    Requests in

  2. Design

    Catalogue & SLAs

  3. Transition

    Build & release

    Release

  4. Change gate

    Clause 8.5

  5. Operate

    Live services

    Incidents

  6. Incident gate

    Restore & learn

    Improve returns to Design

  7. Service levels held

    Reliable outcome

    Credibility returns to Demand

SYS/09 · Service lifecycle

Demand flows through design, transition and gated operation; incidents feed improvement until service levels hold.

What ISO 20000-1 is

ISO/IEC 20000-1 specifies a service management system: service catalogue and levels, incident, problem, change and release control, capacity and availability planning, and supplier management, wrapped in the governance that makes them stick. Certification to it tells a customer that an independent body has sampled the service records, not only the process documents.

CORE audits ISO/IEC 20000-1 in the records the service actually produces. Your auditor samples live tickets, changes, releases, problems and service reports in the tools that hold them, reads them against the service catalogue and the levels agreed with customers, and tests whether the reported figures can be rebuilt from the underlying data. Supplier and internal-provider agreements, capacity and availability plans, continuity arrangements for the services in scope, and the handling of major incidents carry weight as evidence. The findings raised most often concern service levels reported against targets no customer ever agreed, emergency change used routinely rather than exceptionally, and problem records closed without the cause being removed.

Who it is for

  • Managed service providers whose clients or tenders require a certificate of registration to ISO/IEC 20000-1
  • Internal IT organizations asked by their own group or business to hold third-party certification of their service commitments
  • Technology companies whose contracts specify certification alongside service-level obligations
  • Certified organizations transferring an active ISO/IEC 20000-1 certificate from another certification body

Business outcomes

What leadership should expect the system to change, in operational terms.

SLA performance

Services defined, measured and reported against agreed levels.

Change without chaos

Change and release control that protects stability while keeping delivery moving.

Bid credibility

A certificate of registration answers the service-capability questions that appear in procurement.

Continual improvement

Problem management and reviews convert repeat incidents into permanent fixes.

Benefits beyond the certificate

  • One service model

    Catalogue, levels and reporting consistent across teams and customers.

  • Supplier chain control

    Obligations flow down to the suppliers your services depend on.

  • Capacity foresight

    Demand and capacity planned rather than discovered at the outage.

  • Complement to ISO 27001

    Shared structure and overlapping controls mean the two can be audited together under one programme.

  • ITIL, evidenced

    Existing ITIL investment becomes demonstrable to an auditor and to customers, because the standard is auditable where the guidance is not.

Data center aisle glowing electric blue
ISO 20000-1 in the field

The main requirements

The themes your auditor will examine, in plain language. The full clause detail is worked through at Stage 2.

01

Context and scope (Clause 4)

Services, customers and locations inside the SMS boundary.

02

Leadership and planning (Clauses 5 and 6)

Policy, roles, risks and service management objectives.

03

Support (Clause 7)

Competence, communication, documented information and knowledge.

04

Service portfolio (Clause 8.2 to 8.3)

Service catalogue, service levels, business relationship and supplier management.

05

Operation (Clause 8.4 to 8.6)

Budgeting, demand, capacity, change, release, incident, request, problem, availability and continuity.

06

Evaluation and improvement (Clauses 9 and 10)

Monitoring, reporting, internal audit, management review and improvement.

What each requirement buys you

Select a requirement theme to see the business outcomes it chiefly drives. The mapping reflects where audit sampling concentrates, not a normative ISO table.

Requirement themes

Context and scope (Clause 4) chiefly drives 2 of 4 ISO 20000-1 outcomes.

Outcomes it drives

SLA performance

Services defined, measured and reported against agreed levels.

Change without chaos

Change and release control that protects stability while keeping delivery moving.

Bid credibility

A certificate of registration answers the service-capability questions that appear in procurement.

Continual improvement

Problem management and reviews convert repeat incidents into permanent fixes.

How CORE audits ISO 20000-1

Step 1

Stage 1 reviews scope, catalogue and service levels

Your auditor confirms the scope names the services, customers and locations to be certified, reads the service catalogue, the agreed service levels and the documented information the standard requires, and checks that internal audit and management review have taken place. Where parts of the service are delivered by other parties, Stage 1 establishes how you demonstrate control over them. Findings here are raised as improvement requests, not nonconformities.

Step 2

Stage 2 samples the service records themselves

The audit works in the tools that hold the evidence: incidents and service requests against their targets, major incidents and what followed, problems and whether the cause was removed, changes and releases including emergency change, capacity and availability plans against actual demand, continuity arrangements for services in scope, and supplier agreements against the levels they underpin. Reported service performance is rebuilt from the underlying data rather than accepted from the report.

Step 3

Surveillance samples delivery and change

Year 1 and Year 2 audits sample service reports issued since the last visit, new or withdrawn services and changes of scope, incident and problem trends, changes to suppliers or tooling, service level agreements renegotiated with customers, progress against service management objectives, and the closure of previous findings.

Step 4

Recertification revisits the whole cycle

In Year 3 the audit reviews the effectiveness of the service management system across three years: whether service levels have been met and reported consistently, whether problem management has reduced repeat incidents, whether the catalogue still matches what customers buy, whether governance of other parties has held, and whether the scope is still accurate.

What your auditor expects to see

Before Stage 2 can proceed, the system needs to have run long enough to have produced its own evidence.

  1. 01Service reporting cycle completed

    Service reports and service reviews issued over long enough a period to show the system operating rather than starting, with the ticket, change and release records behind them available to your auditor.

  2. 02Internal audit completed

    A full internal audit of the SMS against ISO/IEC 20000-1:2018, sampling live tickets, changes and supplier records, run by auditors independent of the queues and services they audit.

  3. 03Management review held

    A minuted management review of service performance, customer feedback, audit results and improvement, with decisions, resources and owners recorded.

  4. 04Scope defined and agreements in place

    A written scope naming the services, customers and locations to be certified, with a service catalogue, agreed service levels and supplier or internal-provider agreements that support them, and corrective actions from your own findings closed.

  5. Certification decision

    With that evidence in place, Stage 1 and Stage 2 can run. The decision that follows is taken by a reviewer who was not on your audit team.

CORE is the certification body. We assess and certify management systems. We do not build them — that separation is what makes the certificate worth holding. We do not design, document or implement the systems we audit, and we do not run your internal audits. If you need that work done, our directory of independent consultants is a starting point, and engaging one has no bearing on the decision. More on how we keep the audit and the decision separate.

The optional pre-assessment

Before Stage 1 you can ask for an optional pre-assessment: an audit-style review of your service management practices, records and tooling against ISO/IEC 20000-1:2018. It samples tickets, changes and service reports the way a certification audit does, and returns a written report of findings clause by clause, distinguishing practices that operate but are not evidenced from requirements that are not met at all.

ITIL-mature organizations often find the distance is shorter than expected, and the report says exactly where it is. It does not design your processes, write your catalogue or configure your ITSM platform: producing that work would make CORE the author of a system it must later audit, which ISO/IEC 17021-1 prohibits. Organizations that want help acting on the report can use the directory of independent consultants at /resources/find-a-consultant.

What you receive

  • Findings against each clause of the standard
  • Where the evidence is missing or incomplete
  • Whether Stage 2 could proceed on today's records
  • The same sampling method a certification audit uses
How the pre-assessment works

Training for ISO 20000-1

Courses that teach how the standard is written and how it is audited.

All courses

ISO 20000-1 questions, answered straight

Ready to certify to ISO 20000-1?

Tell us your standards, scope, effective headcount and sites. You will get a scope statement and a fixed quotation, with audit duration calculated from the accreditation body's mandatory formula.