Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 20000 vs ITIL — guide from Governance Docs

ISO 20000 vs ITIL: The Differences That Matter

Update: ITIL (Version 5) is now released. See ITIL 5 explained — what changed for the full picture.

ISO 20000 vs ITIL is the most common question in IT service management, and it rests on a category error. They are not competing options. One is an auditable standard an organisation can be certified against; the other is a body of guidance that describes how to do the work well. Most mature IT functions end up using both.

ISO 20000 vs ITIL: the fundamental difference

ISO/IEC 20000-1:2018 is a specification. It uses “shall”, it defines auditable requirements, and an accredited certification body can certify an organisation against it. That certificate is a thing you can put in a tender response.

ITIL is guidance. It describes practices in depth and explains why they work. No organisation is certified against ITIL — ITIL certification exists only for individuals. That distinction matters commercially: a customer asking for proof of your service management maturity cannot be satisfied by your staff’s personal ITIL certificates.

Where ISO 20000 vs ITIL overlap

ISO 20000 vs ITIL overlap heavily in clause 8. If you run ITIL practices well, much of the operational half of the standard is already evidenced: incident, service request and problem management map onto clause 8.6; change, service design and release map onto 8.5; availability, continuity and information security map onto 8.7; capacity and demand onto 8.4; service level and supplier management onto 8.3.

Clause 8 is where the standard becomes specific, and it is organised as one general requirement plus six practice areas:

  • 8.1 Operational planning and control
  • 8.2 Service portfolio — service planning, control of parties involved, the service catalogue and asset management.
  • 8.3 Relationship and agreement — business relationship management, service level management and supplier management.
  • 8.4 Supply and demand — budgeting and accounting, demand management and capacity management.
  • 8.5 Service design, build and transition — change management, service design, build and the controlled transition into live operation.
  • 8.6 Resolution and fulfilment — incident management, service request management and problem management.
  • 8.7 Service assurance — service availability management, service continuity management and information security management.

Documentation for both, in one place.

The ISO 20000 Toolkit covers the certifiable SMS end to end (74 templates), and the ITIL Toolkit (Version 5) provides the practice-level documentation that sits underneath it (57 templates, including the eight lifecycle activity policies).

Explore the ISO 20000 Toolkit →

ISO 20000 vs ITIL: what ITIL does not give you

This is where ISO 20000 vs ITIL stops being academic. ITIL has no equivalent of the management system wrapper: context and interested parties, leadership and policy, planning of objectives and risks, competence and documented information, internal audit, management review and improvement. Nor does it have clause 6.3, the service management plan, which is the requirement most ITIL-mature organisations discover late and the most common reason a first certification attempt fails.

Put plainly: ITIL tells you how to run change management well. ISO 20000 asks who owns the SMS, how it is resourced, how it is audited, and how you prove any of it to a third party.

ISO 20000 vs ITIL: what the standard does not give you

Equally, the standard is deliberately thin on how. It requires problem management; it does not explain root cause technique, or how to structure a major incident process, or what good looks like in practice. That is exactly what ITIL supplies. An organisation that implements only the standard tends to produce a compliant but hollow system — processes that satisfy an auditor and irritate everyone who has to use them.

ISO 20000 vs ITIL: which one do you actually need?

If a customer, tender or regulator is asking for evidence, you need ISO 20000 certification, and ITIL is the fastest route to the operational content. If nobody is asking and you simply want better service delivery, ITIL alone is sufficient and cheaper. The mistake is pursuing certification purely as a badge: the standard rewards organisations that genuinely run their services well, and audits are conducted by people who can tell the difference.

See our guides to ISO 20000 certification, the ISO 20000 implementation guide and ISO 20000 alignment with other frameworks.

The ISO/IEC 20000 family as at September 2026. Only Part 1 is certifiable, but the supporting parts are what auditors and implementers actually read alongside it, and several were revised recently: ISO/IEC 20000-1:2018 (requirements, with Amd 1:2024 for climate action), ISO/IEC 20000-2:2019 (guidance on applying the SMS), ISO/IEC 20000-3:2019 (scope definition and applicability), ISO/IEC TS 20000-5:2022 (implementation guidance), ISO/IEC 20000-6:2017 (requirements for certification bodies), ISO/IEC 20000-10:2018 (concepts and vocabulary) and ISO/IEC TS 20000-11:2021 (the relationship between 20000-1 and ITIL). Anything citing 20000-1:2011, 20000-2:2012 or 20000-3:2013 is describing a withdrawn edition whose clause numbers no longer exist; our own ISO 20000 Toolkit had its reference lists rebuilt onto this family, and onto the 2018 clause structure (8.2.4 service catalogue management, 8.3.3 service level management, 8.3.4 supplier management), on 11 September 2026.

References

More on ISO 20000

All of these are covered by the ISO 20000 Toolkit, with practice-level documentation in the ITIL Toolkit (Version 5).

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.