Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 20000 Internal Audit Checklist — guide from Governance Docs

ISO 20000 Internal Audit Checklist: Clause 4 to 10

An ISO 20000 internal audit is a prerequisite of certification, not a follow-up
to it. Clause 9.2 requires audits at planned intervals and your certification body will ask for the
results at stage 1. This is a working checklist by clause, plus how to build the programme.

The ISO 20000 internal audit programme comes before the checklist

An ISO 20000 internal audit programme must be planned. Clause 9.2 asks for a programme that takes account of the importance of the processes concerned
and the results of previous audits. Build the ISO 20000 internal audit programme around the services
in scope: those with the tightest service levels, the most customers or the most suppliers get
audited more often and in more depth. Record that reasoning — a programme that cannot explain
its own frequencies is itself a finding.

Two further ISO 20000 internal audit requirements catch smaller IT functions. Auditors must be objective and impartial, so
the person who runs change management cannot audit it. And results must reach relevant management and
feed management review under 9.3.

The ISO 20000 internal audit checklist by clause

Clause 4 — Context. Are internal and external issues current, including
climate change under the 2024 amendment? Are interested parties recorded, including customers,
users and suppliers? Is the scope expressed in services, and does it match what is actually
delivered?

Clause 5 — Leadership. Can management describe the service management
policy and their own accountability? Are roles documented, and do the named people know they hold
them?

Clause 6 — Planning. Are risks and opportunities addressed with owned
actions? Are service management objectives measurable and monitored? And the one to test hardest:
does a service management plan exist under clause 6.3, and does it actually describe
how the SMS is planned, resourced and improved?

Clause 7 — Support. Competence against defined requirements for service
roles. Communication with customers and users. Document control — including anything held in
the ITSM tool rather than as a document. And clause 7.6 knowledge: is knowledge
captured and available, or does it leave with people?

Clause 8 — Operation. The substance. Is the service catalogue current? Are
service levels agreed with customers and reported back, or set internally? Are suppliers
managed, including internal groups and customers acting as suppliers? Trace one change end to end
through design, build, transition and release. Take one incident and one problem and follow them.
Check availability, continuity and capacity: have the plans been tested, and did anything change as
a result?

Clause 9 — Performance evaluation. What is measured, against what target,
and who sees it? Does management review cover all required inputs and produce decisions with owners
and dates?

Clause 10 — Improvement. Take a nonconformity: was root cause reached, was
effectiveness verified, and did anything change as a result?

Audit programme, checklists and forms, ready to use.

The ISO 20000 Toolkit includes the internal audit procedure, a risk-based programme template, clause-by-clause checklists and the nonconformity and corrective action forms, alongside the full ITSM document set.

Explore the ISO 20000 Toolkit →

Findings that recur at almost every ISO 20000 internal audit

  • No service management plan under clause 6.3.
  • Service levels never reported to the customer, so nobody can show they are met.
  • A service catalogue that has drifted from what is actually delivered.
  • Suppliers unmanaged where they deliver part of an in-scope service.
  • Continuity and availability plans never tested.
  • Problem management existing on paper only, with every record reactive and
    nothing preventive.
  • Corrective actions closed on completion rather than on verified effectiveness.

Getting value from an ISO 20000 internal audit

The most informative audit of this standard is a trace, not a clause march. Take one service and
follow it end to end: its catalogue entry, the agreement behind it, the capacity and availability
plans supporting it, a recent change, a recent incident, the service report sent to the customer, and
the management review that discussed it. One trace tests most of clause 8 plus 9 and 10, and it
exposes the gap between the documented service and the delivered one — which is the gap that
actually matters.

References

More on ISO 20000

All of these are covered by the ISO 20000 Toolkit, with practice-level documentation in the ITIL 4 Toolkit.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.