All resources
Guide 7 min read

ISO 20000 vs ITIL: the standard and the framework

C1The Compliance One team3 October 2026

Ask ten IT teams whether ISO 20000 and ITIL are the same thing and you will get a muddle of answers. They are related, they overlap heavily in vocabulary, and they are not the same. The clean way to hold it: ITIL is a framework of best-practice guidance; ISO/IEC 20000-1 is a certifiable standard. One tells you good ways to do service management; the other is what an accredited body audits you against.

What each one is

ITIL (now ITIL 4) is a library of guidance — practices, value streams, and a service value system. It is descriptive and flexible: you adopt the practices that fit, in the way that fits. There is no 'ITIL certificate' for an organisation; individuals hold ITIL qualifications, but a company cannot be 'ITIL certified'.

ISO/IEC 20000-1 is a management-system standard. It states requirements ('shall' statements) for a Service Management System, and an accredited certification body can audit your SMS and certify it. That certificate is what goes in the RFP response.

How they fit together

They are complementary, not competing. In practice most organisations adopt ITIL-style practices to run service management well, and certify the resulting management system to ISO 20000 to prove it. ISO 20000 does not mandate ITIL — you can meet its requirements with any sensible approach — but the two share so much vocabulary (incidents, problems, changes, service levels, configuration items) that teams running ITIL find ISO 20000 a natural fit.

ITIL tells you how to play well. ISO 20000 is the referee who certifies that you did.

Where ISO 20000 adds the discipline ITIL leaves optional

Because it is an auditable standard, ISO 20000 is firm where guidance is soft. It requires a documented SMS scope, policy and plan; documented service requirements, a service catalogue and SLAs; recorded, classified, prioritised incidents, requests, problems and changes; a change management policy with major-impact criteria; capacity and availability requirements and targets; a service continuity plan that is tested; management review and internal audit; and continual improvement with evaluation criteria. It also requires the organisation to retain accountability even when other parties operate parts of the service.

How Compliance One helps

Compliance One gives you the ISO 20000 side of the equation: the clause 4 to 10 requirement library with an applicability register, native registers for incidents, service requests, problems and changes, the mandatory document templates, and crosswalks to ISO 27001 and 22301. Run your service management the ITIL way; prove it the ISO 20000 way, with the evidence in one place.

See it on your own frameworks

Book a 30-minute walkthrough and we'll map this to your environment.