In most management system standards, clause 8 is a short shell. In ISO/IEC 20000-1 it is most of the standard. Thirteen service management processes with named requirements sit there, and a checklist templated from generic Annex SL misses about sixty per cent of what you will be audited on.

This assessment scores 48 questions across the whole standard, with every service management process covered individually. It is free, it saves as you go, and you can stop and come back to it.

What this is

A clause-by-clause pass over ISO/IEC 20000-1:2018 with its 2024 climate amendment, which is still a live separately cited document for this standard. We have the background elsewhere — the standard explained, the mandatory documents, certification, how it compares to ITIL and how it sits with ISO 27001. Come here when you want a score.

What it covers

AreaQuestions
4 — Context, scope and the SMS5
5 — Leadership, policy and roles3
6 — Risks, objectives and the service management plan3
7 — Resources, competence, documented information and knowledge8
8 — Service portfolio, catalogue, configuration, relationships and suppliers11
8 — Budgeting, demand, capacity, change, design and release6
8 — Incident, request, problem, availability, continuity and security6
9 — Monitoring, audit, management review and service reporting4
10 — Nonconformity and improvement2

Four requirements a generic checklist will not have

6.3 — the service management plan. A specific mandated artefact. There is no equivalent quality plan or environmental plan at 6.3 in any other standard, and its absence or staleness is a standing finding.

7.5.4 — the enumerated document list. Most standards ask what documented information you consider necessary. This one tells you: the change and information security policies, the service management plan, continuity plans, the process definitions, service requirements, the service catalogue, the service level agreements, external supplier contracts and internal supplier agreements.

7.6 — knowledge. A standalone requirement with no Annex SL analogue. Knowledge concentrated in one engineer with nothing written down is exactly what it exists to catch.

9.4 — service reporting. A fourth sub-clause where other standards stop at management review, and the one most often forgotten entirely. Reports have to be agreed with the customers who receive them and actually used to make decisions, not generated and filed.

Where the process grouping defeats intuition

The processes are not in lifecycle order and are not grouped where an ITIL practitioner would expect. Configuration management sits under service portfolio at 8.2.6, in a different top-level sub-clause from change management at 8.5.1. Service request management was split out from incident management in the 2018 edition and lives at 8.6.2. Availability at 8.7.1, continuity at 8.7.2 and information security at 8.7.3 are three distinct sub-clauses with distinct requirements, not one combined resilience area.

And 8.2.3 has no analogue anywhere else: where another party operates your processes, you have to demonstrate governance of them. It also limits what you can exclude from scope — you cannot certify a service management system where someone else runs the critical processes and you merely coordinate.

How the scoring works

StatusWeightMeans
Not started0%No policy, process or activity exists
Planned25%Agreed and scheduled, nothing in place yet
Partially implemented50%In place for part of the scope, or applied inconsistently
Implemented, not evidenced75%Operating as intended, but you could not prove it today
Implemented and evidenced100%Operating as intended, with records someone could sample
Not applicable—A justified exclusion, removed from the score

Free score, or the full report

The assessment and your overall score are free. The full report is a one-off $39 and gives you every question with your status and notes, the score broken down by clause, a prioritised gap list, and the documents from the ISO 20000 Toolkit that close each gap — as a PDF and a working Excel file.

How long does it take?

About 40 minutes, most of it in clause 8.

What to do with your score

Below 40% — write the service management plan and the service catalogue. Half of clause 8 becomes answerable once the services are actually defined.

40–70% — look at service level management and service reporting together. SLAs that exist but are never reviewed against performance, and reports that are produced but never used, are the two most frequently raised findings in this standard and they are usually the same underlying gap.

Above 70% — check the internal suppliers. Documented agreements with external suppliers are normal; documented agreements with internal teams delivering service components, and with customers acting as suppliers, almost never exist.

Frequently asked questions

Is this assessment really free?

Yes. All 48 questions, the clause breakdown and your overall score cost nothing. The $39 report is optional.

Is ISO 20000 the same as ITIL?

No. ITIL is guidance you adopt; ISO/IEC 20000-1 is a certifiable standard you are audited against. They overlap heavily in vocabulary, which is exactly why questions written from ITIL habits get the clause numbers wrong.

Is a revision coming?

The 2018 edition was reviewed and confirmed in 2023 and remains current, with the next systematic review due around 2028. Recent activity in the family has been in the guidance parts, not in the requirements.

Does the climate amendment apply?

Yes, and unlike ISO 14001 it remains a separately cited live amendment here, adding climate change to clauses 4.1 and 4.2. The current requirement set is the 2018 edition plus that amendment.

Can I use this for a client?

Yes. Run one assessment per client organisation.

What happens to my answers?

They are stored against your account so you can come back to them, and they are never shared. You can delete them at any time.