This is the working list of ISO 20000 mandatory documents — what ISO/IEC
20000-1:2018 requires you to be able to produce, organised by clause, plus the second tier that no
clause names outright and no audit ever skips.
The ISO 20000 mandatory documents do not include a manual
The ISO 20000 mandatory documents do not include a service management manual. Clause 7.5 asks you to maintain the documented
information the standard specifies plus whatever else you determine is necessary for the SMS to be
effective. Writing a manual that restates the clauses earns nothing at audit, because it evidences
no activity. What earns something is the plan, the catalogue, the agreements and the records.
The ISO 20000 mandatory documents, by clause
- Clause 4 — internal and external issues, interested parties and their
requirements, and the documented scope of the SMS, expressed in services. - Clause 5 — the service management policy, and roles,
responsibilities and authorities. - Clause 6 — the risks and opportunities and the actions addressing them;
measurable service management objectives; and the service management
plan required by clause 6.3. That plan is distinctive to this standard and is the item most
often absent. - Clause 7 — evidence of competence, records of
communication, control of documented information, and the knowledge requirement at
7.6, which few other management system standards make explicit. - Clause 8 — the substantive set: the service catalogue,
service level agreements with customers and agreements with
suppliers, plus the documented processes and records behind the practice areas listed
below. - Clause 9 — results of monitoring and measurement, service
reports, the internal audit programme and results, and the results of
management review. - Clause 10 — nonconformities, the actions taken and the results of
corrective action, plus evidence of continual improvement.
Clause 8 is where the standard becomes specific, and it is organised as one general requirement plus six practice areas:
- 8.1 Operational planning and control
- 8.2 Service portfolio — service planning, control of parties involved, the service catalogue and asset management.
- 8.3 Relationship and agreement — business relationship management, service level management and supplier management.
- 8.4 Supply and demand — budgeting and accounting, demand management and capacity management.
- 8.5 Service design, build and transition — change management, service design, build and the controlled transition into live operation.
- 8.6 Resolution and fulfilment — incident management, service request management and problem management.
- 8.7 Service assurance — service availability management, service continuity management and information security management.
Over 70 ITSM templates, already mapped to the clauses.
The ISO 20000 Toolkit provides the service management plan, service catalogue, SLA and supplier agreement templates, the full process set across all six practice areas, and the audit and management review pack.
Beyond the ISO 20000 mandatory documents: what auditors still ask for
Beyond the ISO 20000 mandatory documents, a second tier exists that no clause names and no audit skips. The configuration
information behind change and release control — a CMDB or its equivalent, current
enough to be useful. Service continuity and availability plans, with evidence they
have been tested rather than written. Capacity forecasts that someone actually
reviews. Records of the parties involved in service delivery, including internal
groups and customers acting as suppliers, which clause 8.2 brings into scope and teams routinely
forget. And service reports issued to customers, because a service level agreement
with no reporting behind it is an assertion.
How much detail the ISO 20000 mandatory documents need
Clause 7.5 settles it: the extent of documented information varies with the size of the
organisation, its services, processes and the competence of its people. A twenty-person managed
service provider does not need what a bank’s IT function needs. The working test is whether a
competent newcomer could run the process from what is written, and whether what is written matches
what people actually do.
One trap specific to the ISO 20000 mandatory documents: many organisations already document their processes in an ITSM
tool rather than in documents. That is perfectly acceptable — documented information does not
have to be a Word file — but it must be controlled, versioned and retrievable. “It is in the
tool” is only an answer if you can show who changed it and when. See our
ISO 20000 implementation guide, or start with the
free ISO templates.
References
- ISO/IEC 20000-1:2018 — the service management system requirements on iso.org.
- ISO/IEC 20000-1:2018/Amd 1:2024 — the climate action amendment.
More on ISO 20000
- ISO 20000 certification
- ISO 20000 implementation guide
- ISO 20000 mandatory documents — you are here
- ISO 20000 internal audit checklist
- ISO 20000 vs ITIL
- ISO 20000 alignment
All of these are covered by the ISO 20000 Toolkit, with practice-level documentation in the ITIL 4 Toolkit.