Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 20000 Certification — guide from Governance Docs

ISO 20000 Certification: How the Process Actually Works

ISO 20000 certification demonstrates that an organisation’s service management
system meets ISO/IEC 20000-1:2018 — the only certifiable standard for IT service management.
This guide covers what it involves, and the specific reason teams running mature ITIL practices
still fail their first attempt.

What ISO 20000 certification actually covers

ISO 20000 certification is an independent audit of your service management system (SMS) against
ISO/IEC 20000-1:2018, the third edition, by an
accredited certification body. The certificate covers a defined scope expressed in
services — not departments, not systems.

That scoping rule catches people out. You cannot certify “the IT department”; you certify the
delivery of named services to named customers. Writing that list is the first real piece of work, and
it usually reveals two or three things you operate that nobody ever formally agreed to deliver.

Why ITIL maturity does not guarantee ISO 20000 certification

This is the single most useful thing to understand before starting. ITIL describes practices;
ISO/IEC 20000-1 specifies a management system with auditable requirements. A team with excellent
incident, change and problem management is well placed on clause 8 — and can still fail on the
management system wrapper around it.

The requirement most often missed is clause 6.3, “Plan the service management
system”
. It has no direct ITIL equivalent and no counterpart in ISO 9001 or ISO 27001, so
teams assume their process documentation covers it. It does not: clause 6.3 asks how the SMS itself
will be planned, resourced and improved. Clause 7.6 Knowledge is similarly explicit
in this standard and routinely overlooked.

Clause 8 is where the standard becomes specific, and it is organised as one general requirement plus six practice areas:

  • 8.1 Operational planning and control
  • 8.2 Service portfolio — service planning, control of parties involved, the service catalogue and asset management.
  • 8.3 Relationship and agreement — business relationship management, service level management and supplier management.
  • 8.4 Supply and demand — budgeting and accounting, demand management and capacity management.
  • 8.5 Service design, build and transition — change management, service design, build and the controlled transition into live operation.
  • 8.6 Resolution and fulfilment — incident management, service request management and problem management.
  • 8.7 Service assurance — service availability management, service continuity management and information security management.

Every document the audit asks for, ready to edit.

The ISO 20000 Toolkit provides over 70 templates — the service management plan, service catalogue, SLA and supplier agreement templates, the full process set and the audit pack, each mapped to the clause it satisfies.

Explore the ISO 20000 Toolkit →

The stages of ISO 20000 certification

  1. Gap analysis. The cheapest step in ISO 20000 certification: score current practice against clauses 4–10, mapping what
    your existing ITIL practices already evidence.
  2. Implementation. Scope, service management plan, policy, objectives, service
    catalogue, agreements and the process set. See our
    ISO 20000 implementation guide.
  3. Run the SMS. Real incidents, changes, reviews and service reports need to
    accumulate before an audit has anything to sample.
  4. Internal audit and management review. Prerequisites of ISO 20000 certification,
    not follow-up activities.
  5. Stage 1 audit. Documentation and readiness: scope, the service management plan,
    the catalogue, the agreements, and whether internal audit and management review genuinely ran.
  6. Stage 2 audit. The full on-site assessment, sampling records across the period
    and interviewing the people who run the services.
  7. Surveillance and recertification. Annually, with full recertification on a
    three-year cycle.

How long ISO 20000 certification takes and what drives the cost

Six to twelve months is realistic for an IT function with established ITSM
practice, and nine to eighteen from a standing start or across multiple delivery towers. Audit days
scale with headcount, number of services in scope, sites and the number of parties involved in
delivery — that last one matters more here than in most standards, because outsourced and
multi-supplier delivery adds real audit time.

If you already hold ISO 27001 or ISO 9001, clauses 4, 5, 6, 7, 9 and 10 largely transfer. Budget
that saving against clause 8, which is almost entirely service-management specific.

Why first attempts at ISO 20000 certification fail

  • No service management plan. Clause 6.3, and the most commonly missed
    requirement in the standard.
  • Targets rather than agreements. Service levels set internally that no customer
    ever signed. An auditor will ask who agreed them and how performance is reported back.
  • Processes run well but evidenced inconsistently across several tools.
  • Suppliers outside the SMS, when they deliver part of a service in scope.
  • No internal audit or management review yet.

For how the standard fits alongside other frameworks, see
ISO 20000 alignment and our comparison of
ISO 20000 and ITIL.

References

More on ISO 20000

All of these are covered by the ISO 20000 Toolkit, with practice-level documentation in the ITIL 4 Toolkit.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.