ISO/IEC 20000 explained: the IT service management standard
If your organisation runs IT services for customers or users — a managed service provider, a SaaS or cloud operator, an outsourcer, or an internal IT function — sooner or later someone asks a pointed question: can you prove your services are actually under control? ISO/IEC 20000-1 is the standard that answers it. It is the international, certifiable standard for a Service Management System (SMS): the set of processes and capabilities you use to plan, design, transition, deliver and improve IT services so they meet agreed requirements and deliver value.
It is the audited companion to ITIL practice, and it is built on the same management-system spine as ISO 27001, ISO 22301 and ISO 9001 — so if you hold any of those, a lot of 20000 is already done.
A management system, not a toolset
The current edition is ISO/IEC 20000-1:2018 (the third edition). Like every modern ISO management-system standard it uses the Annex SL high-level structure: clauses 4 to 10 cover context, leadership, planning, support, operation, performance evaluation and improvement. You set the SMS scope, a service management policy and objectives, and a service management plan, then you run the operational core — Clause 8 — which is where IT service management actually happens.
The service lifecycle Clause 8 asks you to run
- Service portfolio: a service catalogue describing your services and their intended outcomes, plus asset and configuration management (a CMDB where services are classified as configuration items).
- Relationship and agreement: business relationship management (customers and satisfaction), service level management (SLAs with targets, workload limits and exceptions), and supplier management (contracts and agreements).
- Supply and demand: budgeting and accounting for services, demand management, and capacity management.
- Service design, build and transition: change management (with a change policy and emergency changes), service design and transition, and release and deployment management.
- Resolution and fulfilment: incident management (including major incidents), service request management, and problem management with a known-error base.
- Service assurance: service availability management, service continuity management, and information security management.
ISO 20000 is the difference between 'we follow ITIL' and 'here is the audited evidence that our incidents, changes, problems and service levels are managed and improving.'
One rule people miss: you cannot outsource everything
A distinctive requirement of ISO 20000 is that the organisation must retain accountability and demonstrate control even when other parties (external suppliers, internal suppliers, or a customer acting as a supplier) are involved. Other parties cannot operate all of the services, components or processes in scope. If they do, you cannot claim conformity. The standard wants a responsible owner, not a pass-through.
How Compliance One helps
Compliance One ships the full ISO/IEC 20000-1:2018 clause library (66 requirements across 14 domains) enabled by default with an applicability register — there is no Annex A and no Statement of Applicability. It adds native IT service management registers for the core four processes (incident, service request, problem and known error, and change), pre-fills the mandatory documents from Clause 7.5.4 (scope, policy, plan, change and information-security policies, service continuity plan, service catalogue, SLA and supplier-contract templates, capacity and availability plans), and cross-maps the shared clause 4 to 10 spine to ISO 27001, 22301 and 9001 so one evidence set drives an Integrated Management System.
See it on your own frameworks
Book a 30-minute walkthrough and we'll map this to your environment.