ISO/IEC 20000-1:2018
ISO 20000-1 IT Service Management Systems
Run IT services with the discipline your SLAs promise.
Demand
Requests in
Design
Catalogue & SLAs
Transition
Build & release
Release
Change gate
Clause 8.5
Operate
Live services
Incidents
Incident gate
Restore & learn
Improve returns to Design
Service levels held
Reliable outcome
Credibility returns to Demand
SYS/09 · Service lifecycle
Demand flows through design, transition and gated operation; incidents feed improvement until service levels hold.
What ISO 20000-1 is
ISO/IEC 20000-1 specifies a service management system: service catalogue and levels, incident, problem, change and release control, capacity and availability planning, and supplier management, wrapped in the governance that makes them stick. Certification to it tells a customer that an independent body has sampled the service records, not only the process documents.
CORE audits ISO/IEC 20000-1 in the records the service actually produces. Your auditor samples live tickets, changes, releases, problems and service reports in the tools that hold them, reads them against the service catalogue and the levels agreed with customers, and tests whether the reported figures can be rebuilt from the underlying data. Supplier and internal-provider agreements, capacity and availability plans, continuity arrangements for the services in scope, and the handling of major incidents carry weight as evidence. The findings raised most often concern service levels reported against targets no customer ever agreed, emergency change used routinely rather than exceptionally, and problem records closed without the cause being removed.
Who it is for
- Managed service providers whose clients or tenders require a certificate of registration to ISO/IEC 20000-1
- Internal IT organizations asked by their own group or business to hold third-party certification of their service commitments
- Technology companies whose contracts specify certification alongside service-level obligations
- Certified organizations transferring an active ISO/IEC 20000-1 certificate from another certification body
Business outcomes
What leadership should expect the system to change, in operational terms.
SLA performance
Services defined, measured and reported against agreed levels.
Change without chaos
Change and release control that protects stability while keeping delivery moving.
Bid credibility
A certificate of registration answers the service-capability questions that appear in procurement.
Continual improvement
Problem management and reviews convert repeat incidents into permanent fixes.
Benefits beyond the certificate
One service model
Catalogue, levels and reporting consistent across teams and customers.
Supplier chain control
Obligations flow down to the suppliers your services depend on.
Capacity foresight
Demand and capacity planned rather than discovered at the outage.
Complement to ISO 27001
Shared structure and overlapping controls mean the two can be audited together under one programme.
ITIL, evidenced
Existing ITIL investment becomes demonstrable to an auditor and to customers, because the standard is auditable where the guidance is not.

The main requirements
The themes your auditor will examine, in plain language. The full clause detail is worked through at Stage 2.
01
Context and scope (Clause 4)
Services, customers and locations inside the SMS boundary.
02
Leadership and planning (Clauses 5 and 6)
Policy, roles, risks and service management objectives.
03
Support (Clause 7)
Competence, communication, documented information and knowledge.
04
Service portfolio (Clause 8.2 to 8.3)
Service catalogue, service levels, business relationship and supplier management.
05
Operation (Clause 8.4 to 8.6)
Budgeting, demand, capacity, change, release, incident, request, problem, availability and continuity.
06
Evaluation and improvement (Clauses 9 and 10)
Monitoring, reporting, internal audit, management review and improvement.
What each requirement buys you
Select a requirement theme to see the business outcomes it chiefly drives. The mapping reflects where audit sampling concentrates, not a normative ISO table.
Requirement themes
Context and scope (Clause 4) chiefly drives 2 of 4 ISO 20000-1 outcomes.
Outcomes it drives
SLA performance
Services defined, measured and reported against agreed levels.
Change without chaos
Change and release control that protects stability while keeping delivery moving.
Bid credibility
A certificate of registration answers the service-capability questions that appear in procurement.
Continual improvement
Problem management and reviews convert repeat incidents into permanent fixes.
How CORE audits ISO 20000-1
Step 1
Stage 1 reviews scope, catalogue and service levels
Your auditor confirms the scope names the services, customers and locations to be certified, reads the service catalogue, the agreed service levels and the documented information the standard requires, and checks that internal audit and management review have taken place. Where parts of the service are delivered by other parties, Stage 1 establishes how you demonstrate control over them. Findings here are raised as improvement requests, not nonconformities.
Step 2
Stage 2 samples the service records themselves
The audit works in the tools that hold the evidence: incidents and service requests against their targets, major incidents and what followed, problems and whether the cause was removed, changes and releases including emergency change, capacity and availability plans against actual demand, continuity arrangements for services in scope, and supplier agreements against the levels they underpin. Reported service performance is rebuilt from the underlying data rather than accepted from the report.
Step 3
Surveillance samples delivery and change
Year 1 and Year 2 audits sample service reports issued since the last visit, new or withdrawn services and changes of scope, incident and problem trends, changes to suppliers or tooling, service level agreements renegotiated with customers, progress against service management objectives, and the closure of previous findings.
Step 4
Recertification revisits the whole cycle
In Year 3 the audit reviews the effectiveness of the service management system across three years: whether service levels have been met and reported consistently, whether problem management has reduced repeat incidents, whether the catalogue still matches what customers buy, whether governance of other parties has held, and whether the scope is still accurate.
What your auditor expects to see
Before Stage 2 can proceed, the system needs to have run long enough to have produced its own evidence.
01Service reporting cycle completed
Service reports and service reviews issued over long enough a period to show the system operating rather than starting, with the ticket, change and release records behind them available to your auditor.
02Internal audit completed
A full internal audit of the SMS against ISO/IEC 20000-1:2018, sampling live tickets, changes and supplier records, run by auditors independent of the queues and services they audit.
03Management review held
A minuted management review of service performance, customer feedback, audit results and improvement, with decisions, resources and owners recorded.
04Scope defined and agreements in place
A written scope naming the services, customers and locations to be certified, with a service catalogue, agreed service levels and supplier or internal-provider agreements that support them, and corrective actions from your own findings closed.
Certification decision
With that evidence in place, Stage 1 and Stage 2 can run. The decision that follows is taken by a reviewer who was not on your audit team.
CORE is the certification body. We assess and certify management systems. We do not build them — that separation is what makes the certificate worth holding. We do not design, document or implement the systems we audit, and we do not run your internal audits. If you need that work done, our directory of independent consultants is a starting point, and engaging one has no bearing on the decision. More on how we keep the audit and the decision separate.
The optional pre-assessment
Before Stage 1 you can ask for an optional pre-assessment: an audit-style review of your service management practices, records and tooling against ISO/IEC 20000-1:2018. It samples tickets, changes and service reports the way a certification audit does, and returns a written report of findings clause by clause, distinguishing practices that operate but are not evidenced from requirements that are not met at all.
ITIL-mature organizations often find the distance is shorter than expected, and the report says exactly where it is. It does not design your processes, write your catalogue or configure your ITSM platform: producing that work would make CORE the author of a system it must later audit, which ISO/IEC 17021-1 prohibits. Organizations that want help acting on the report can use the directory of independent consultants at /resources/find-a-consultant.
What you receive
- Findings against each clause of the standard
- Where the evidence is missing or incomplete
- Whether Stage 2 could proceed on today's records
- The same sampling method a certification audit uses
Training for ISO 20000-1
Courses that teach how the standard is written and how it is audited.
ISO 20000-1 questions, answered straight
Related standards
Ready to certify to ISO 20000-1?
Tell us your standards, scope, effective headcount and sites. You will get a scope statement and a fixed quotation, with audit duration calculated from the accreditation body's mandatory formula.
