Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 20000 vs ITIL — guide from Governance Docs

ISO 20000 vs ITIL: The Differences That Matter

ISO 20000 vs ITIL is the most common question in IT service management, and it
rests on a category error. They are not competing options. One is an auditable standard an
organisation can be certified against; the other is a body of guidance that describes how to do the
work well. Most mature IT functions end up using both.

ISO 20000 vs ITIL: the fundamental difference

ISO/IEC 20000-1:2018 is a specification. It uses “shall”, it defines auditable
requirements, and an accredited certification body can certify an organisation against it. That
certificate is a thing you can put in a tender response.

ITIL is guidance. It describes practices in depth and explains why they work. No
organisation is certified against ITIL — ITIL certification exists only for individuals.
That distinction matters commercially: a customer asking for proof of your service management
maturity cannot be satisfied by your staff’s personal ITIL certificates.

Where ISO 20000 vs ITIL overlap

ISO 20000 vs ITIL overlap heavily in clause 8. If you run ITIL practices well, much of the operational half of the standard
is already evidenced: incident, service request and problem management map onto clause 8.6;
change, service design and release map onto 8.5; availability, continuity and information security map
onto 8.7; capacity and demand onto 8.4; service level and supplier management onto 8.3.

Clause 8 is where the standard becomes specific, and it is organised as one general requirement plus six practice areas:

  • 8.1 Operational planning and control
  • 8.2 Service portfolio — service planning, control of parties involved, the service catalogue and asset management.
  • 8.3 Relationship and agreement — business relationship management, service level management and supplier management.
  • 8.4 Supply and demand — budgeting and accounting, demand management and capacity management.
  • 8.5 Service design, build and transition — change management, service design, build and the controlled transition into live operation.
  • 8.6 Resolution and fulfilment — incident management, service request management and problem management.
  • 8.7 Service assurance — service availability management, service continuity management and information security management.

Documentation for both, in one place.

The ISO 20000 Toolkit covers the certifiable SMS end to end, and the ITIL 4 Toolkit provides the practice-level documentation that sits underneath it — over 70 templates each.

Explore the ISO 20000 Toolkit →

ISO 20000 vs ITIL: what ITIL does not give you

This is where ISO 20000 vs ITIL stops being academic. ITIL has no equivalent of the management
system wrapper: context and interested parties, leadership and policy, planning of objectives and
risks, competence and documented information, internal audit, management review and improvement.
Nor does it have clause 6.3, the service management plan, which is the requirement
most ITIL-mature organisations discover late and the most common reason a first certification attempt
fails.

Put plainly: ITIL tells you how to run change management well. ISO 20000 asks who owns the SMS,
how it is resourced, how it is audited, and how you prove any of it to a third party.

ISO 20000 vs ITIL: what the standard does not give you

Equally, the standard is deliberately thin on how. It requires problem management; it does not
explain root cause technique, or how to structure a major incident process, or what good looks like
in practice. That is exactly what ITIL supplies. An organisation that implements only the standard
tends to produce a compliant but hollow system — processes that satisfy an auditor and irritate
everyone who has to use them.

ISO 20000 vs ITIL: which one do you actually need?

If a customer, tender or regulator is asking for evidence, you need ISO 20000
certification
, and ITIL is the fastest route to the operational content. If nobody is asking
and you simply want better service delivery, ITIL alone is sufficient and cheaper.
The mistake is pursuing certification purely as a badge: the standard rewards organisations that
genuinely run their services well, and audits are conducted by people who can tell the difference.

See our guides to ISO 20000 certification, the
ISO 20000 implementation guide and
ISO 20000 alignment with other frameworks.

References

More on ISO 20000

All of these are covered by the ISO 20000 Toolkit, with practice-level documentation in the ITIL 4 Toolkit.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.