Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 20000 Implementation — guide from Governance Docs

How to Implement ISO 20000: A Ten-Step Plan

ISO 20000 implementation catches teams out for one reason: they already run ITIL
and assume the certificate is a formality. ITIL describes practices; ISO/IEC 20000-1 specifies a
management system with auditable requirements. Doing ITIL well does not automatically satisfy it.
This is a ten-step plan for closing that distance.

Before step one of ISO 20000 implementation: define the services

The scope of an SMS is expressed in services, not departments or systems. If you cannot list the
services you deliver, to whom, and what each is supposed to achieve, the rest of the standard has
nothing to attach to. This is also the step that surfaces the awkward truth that several things you
operate are not really services anyone agreed to.

The ten steps of ISO 20000 implementation

  1. Gap analysis (2–3 weeks). Against clauses 4–10, mapping what your
    existing ITIL practices already evidence.
  2. Scope and context (2–3 weeks). Services in scope, the parties involved,
    and the interfaces with suppliers and internal groups.
  3. Policy, roles and objectives (1–2 weeks). Service management objectives
    that are measurable.
  4. Plan the service management system (3–5 weeks). Clause 6.3
    requires a service management plan — a distinctive requirement with no direct equivalent in
    ISO 9001 or ISO 27001, and one that is routinely missed.
  5. Service portfolio (3–5 weeks). Clause 8.2 — planning the services,
    controlling the parties involved, and managing the service catalogue and assets.
  6. Agreements and relationships (3–6 weeks). Service level agreements with
    customers, supplier agreements, and the reporting that makes them meaningful.
  7. Service management processes (8–14 weeks). Incident, service request,
    problem, change, configuration, release, capacity, availability, continuity, and information
    security within the SMS. Most exist already; the work is making them consistent and evidenced.
  8. Knowledge and competence (2–4 weeks, overlapping). Clause 7.6
    Knowledge
    is explicit in this standard, which is unusual and worth doing properly.
  9. Run the SMS (3–6 months). Real incidents, changes, reviews and service
    reports before an audit can sample them.
  10. Internal audit, management review, certification. Both prerequisites.

Over 70 ITSM templates, ready to edit.

The ISO 20000 Toolkit provides the service management plan, service catalogue, SLA and supplier agreement templates, the full process set and the audit pack — editable and mapped to the clause each satisfies.

Explore the ISO 20000 Toolkit →

The three steps ISO 20000 implementation always underestimate

Step 4, the service management plan. The most commonly missed requirement in the
standard, because ITIL has no direct equivalent and teams assume their process documentation covers
it. It does not: clause 6.3 asks how the SMS itself will be planned, resourced and improved.

Step 6, service level agreements. Many organisations have targets rather than
agreements — numbers set internally that no customer ever signed. An auditor will ask who
agreed them and how performance is reported back.

Step 7, evidencing what you already do. The processes usually run well and are
recorded inconsistently across tools. Closing that gap is unglamorous and takes longer than building
something new, because it means changing habits rather than writing documents.

How ITIL fits into ISO 20000 implementation

ITIL is the most common starting point and a genuine advantage: if your incident, change and
problem practices are mature, much of clause 8 is evidenced already. What ITIL does not give you is
the management system wrapper — context, leadership, planning, documented information,
internal audit, management review and improvement — nor the service management plan. Treat
ITIL as the operational content and ISO 20000 as the governance frame around it, and the project
becomes a gap-closing exercise rather than a rebuild.

A realistic total for ISO 20000 implementation

Six to twelve months for an IT function with established ITIL practice, and nine
to eighteen from a standing start or across multiple delivery towers. If you already hold ISO 27001
or ISO 9001, clauses 4, 5, 6, 7, 9 and 10 largely transfer. See also our overview of
ISO 20000 alignment, or start from the
free ISO templates.

References

Implementation guides for the other standards

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.