The ISO 20000 documents and registers checklist
ISO/IEC 20000-1 is refreshingly specific about documentation. Clause 7.5.4 lists the documented information the SMS must include, and the operational clauses (Clause 8) imply a set of living registers an auditor will ask to see. Get these in place and kept current, and the evidence side of your certification is largely handled. Here is the full set.
Documented information (Clause 7.5.4)
- Scope of the SMS
- Service management policy and objectives
- The service management plan (the key SMS document)
- Change management policy, information security policy, and service continuity plan(s)
- The processes of the SMS
- Service requirements
- Service catalogue(s)
- Service level agreements (SLAs)
- Contracts with external suppliers
- Agreements with internal suppliers or customers acting as a supplier
- The procedures required by the standard
- The records required to demonstrate conformity
Plus the specifics the operational clauses require
- Service availability requirements and targets (8.7.1)
- Capacity requirements and a capacity plan (8.4.3)
- Documented risks, opportunities and risk acceptance criteria (6.1)
- Service acceptance criteria (8.5.2)
- Defined release types (8.5.3)
- Configuration information for each configuration item (8.2.6)
The registers an auditor expects
Documentation proves intent; registers prove operation. ISO 20000's operational clauses mandate records that, in practice, live as registers:
- Incident register (8.6.1), including major-incident handling
- Service request register (8.6.2)
- Problem and known-error register (8.6.3)
- Change register / RFCs (8.5.1)
- Release and deployment register (8.5.3)
- Service catalogue and configuration (CMDB) registers (8.2.4, 8.2.6)
- SLA register and supplier/contract register (8.3.3, 8.3.4)
- Capacity, availability and service-continuity registers (8.4.3, 8.7.1, 8.7.2)
- Risk and improvement (CSI) registers (6.1, 10.2)
Documents say what you intend to do; registers prove you actually did it. ISO 20000 asks for both, and the registers are what an auditor reaches for first.
How Compliance One helps
Compliance One pre-fills the Clause 7.5.4 document set as editable templates (21 of them, from the SMS policy and plan to SLAs, supplier contracts, capacity and availability plans and the service report), and ships native registers for the core four processes — incident, service request, problem and known error, and change — so the operational evidence builds itself as you work. The rest of the registers (service catalogue, CMDB, SLA, capacity and availability) follow as the module set expands, and the shared clause 4 to 10 evidence cross-maps to ISO 27001, 22301 and 9001.
See it on your own frameworks
Book a 30-minute walkthrough and we'll map this to your environment.