ISO 20000-1
The international standard for IT service management
Overview
What is ISO 20000-1?
ISO/IEC 20000-1 is the international standard for IT service management. It sets out the requirements for a service management system that plans, delivers, supports and improves services, giving your customers independent evidence that the services they rely on are managed properly.
ISO/IEC 20000-1 is published jointly by ISO and the IEC. It began life in the UK as British Standard BS 15000 in 2000 and became an international standard in 2005. The current edition was published in 2018 and updated by an amendment in 2024.
Where a framework such as ITIL describes good practice, ISO 20000-1 defines the requirements an independent auditor can certify against. It covers the whole lifecycle of a service, from planning and design through to delivery, support and improvement.
Who ISO 20000-1 is For
ISO 20000-1 applies to any organisation that delivers services to customers, whether those customers are external clients or other parts of the same business. It is most commonly adopted by:
- Managed service providers (MSPs) and IT outsourcing companies
- Cloud, hosting, SaaS and data centre providers
- Internal IT departments and shared service centres
- Organisations bidding for public and private sector contracts that ask for evidence of service management capability
There is one limit worth knowing about early. ISO 20000-1 expects you to demonstrate control over the other parties involved in delivering your services, and there are rules about how much of a service can sit with a third party before a scope stops being certifiable. If most of your delivery is subcontracted, the answer is usually to define the scope differently rather than to abandon the idea, but it is far cheaper to find that out at the gap analysis than at the stage 1 audit.
What the Standard Covers
Alongside the leadership, planning, support, performance evaluation and improvement requirements shared with other ISO management system standards, ISO 20000-1 sets out requirements for how services are run day to day, including:
- Service portfolio: planning services, maintaining a service catalogue, managing assets and configuration information, and controlling the other parties involved in the service lifecycle
- Relationships and agreements: service level management, business relationship management and supplier management
- Supply and demand: budgeting and accounting for services, demand management and capacity management
- Design, build and transition: change management, service design and transition, and release and deployment management
- Resolution and fulfilment: incident management, service request management and problem management
- Service assurance: availability management, service continuity management and information security management
- Measurement and reporting: monitoring and measuring the service management system, and reporting on service performance, so what you tell customers about service levels is evidenced rather than asserted
ISO 20000-1 and ITIL
ITIL is a widely used framework of IT service management good practice, and many organisations that pursue ISO 20000-1 already use it. The two work well together: ITIL offers guidance on how to run services, while ISO 20000-1 sets the requirements that prove your approach works. Organisations cannot be certified to ITIL, although individuals can hold ITIL qualifications. They can be certified to ISO 20000-1.
ISO 20000-1 and ISO 27001
Many IT service providers hold both certifications. ISO 27001 protects the information you handle, while ISO 20000-1 ensures the services built on that information are delivered reliably. Both are built on the high-level structure shared across ISO management system standards, so they combine naturally in a single integrated management system with shared policies, risk management, internal audits and management reviews. There is even a standard for doing it: ISO/IEC 20000-7 sets out how to integrate a service management system with ISO 9001 and ISO/IEC 27001, and we use it as a reference when we design a combined system. If business resilience matters to your customers, ISO 22301 fits the same model.
Already Certified to ISO 20000-1?
Most of our work is with organisations that already hold certification and need to keep it valid. We support you through surveillance and recertification audits, carry out independent internal audits, and can take system upkeep off your team's hands altogether.
If you have not yet reviewed the 2024 amendment, it is worth doing so. Amendment 1:2024 requires organisations to determine whether climate change is a relevant issue for their service management system, and notes that interested parties may have climate-related requirements. Certification bodies now expect to see this considered.
Certification
Certification is carried out by an independent certification body, not by a consultancy. We help you achieve UKAS-accredited certification by preparing your system for audit and supporting you through it. UKAS is the UK's national accreditation body, and accredited certification carries more weight with customers and in tenders. Certification bodies are themselves held to a standard: ISO/IEC 20000-6 sets out what a body must do to audit and certify a service management system, which is part of why an accredited certificate means something. Read more about accredited and non-accredited certification.
Why get certified
Key Benefits of ISO 20000-1
Win and Keep Contracts
Give clients and procurement teams independent proof that your services are managed to an international standard, which is increasingly expected in tenders and supplier assessments.
More Reliable Services
Structured incident, problem and change management reduces outages, repeat issues and failed changes, so customers see fewer disruptions.
Clear Service Levels
Agreed service levels, measured and reported consistently, give customers confidence and give your team a shared view of what good looks like.
One System with ISO 27001
Shared structure means ISO 20000-1 and ISO 27001 run as one integrated system, cutting duplicated effort across policies, audits and reviews.
How we work
Our Certification Process
Initial Conversation
We talk through your services, your customers and why you are considering ISO 20000-1, whether that is a tender requirement, a client request or a drive to improve.
Gap Analysis
We assess your current service management practices against ISO 20000-1. If you already use ITIL or hold ISO 27001, we build on what is in place.
Scope and System Design
We help you define which services are in scope and design a service management system that fits the way your team already works. Where services are delivered with or by other parties, this is where we work out a scope that both reflects your business and satisfies the certification body.
Implementation
We develop the processes, documentation and records the standard requires, at the level of support you need, from guidance to a full system build.
Internal Audit and Management Review
We audit the system independently and support your management review, so you go into certification with evidence that it works.
Certification and Beyond
We support you through the stage 1 and stage 2 certification audits, then help you stay certified through surveillance visits and recertification.
Common questions
Frequently Asked Questions
ISO/IEC 20000-1 is the international standard for IT service management. It sets out the requirements for a service management system covering how services are planned, designed, delivered, supported and improved. Organisations can be independently certified against it.
Ready to Talk About ISO 20000-1?
Whether you are starting out, adding ISO 20000-1 to ISO 27001, or keeping an existing certificate on track, we will give you a fixed-price quote after a short, no-obligation conversation.
