AQC Group regional partnerIraq

ISO/IEC 20000-1:2018IT service management systems

ISO/IEC 20000-1 sets out what a service provider needs in place to plan, deliver, support and improve the services it has agreed with its customers. It is the certifiable standard for service management: ITIL describes good practice, and ISO/IEC 20000-1 states requirements that an auditor can check. It is used mainly by providers of IT services, for outside clients or for their own organization.

A woman wearing headphones works at two monitors beside a window

01At a glance

Standard
ISO/IEC 20000-1:2018
Subject
IT service management systems
Certificate
Issued by AQC Group. Valid for three years, with a surveillance audit each year.
Often combined with
ISO/IEC 27001, ISO 9001
Facts checked
9 October 2026, against iso.org

Who it is for

  • Managed service providers and IT outsourcing firms
  • Hosting, cloud and data centre operators
  • Internal IT departments that serve a large organization
  • Telecom and network service providers
  • Software companies that run and support what they build
  • Service desks and shared service centres

02What you gain

What certification to ISO/IEC 20000-1 gives you

A requirement in service tenders

Contracts for outsourced IT, hosting and support often ask for ISO/IEC 20000-1 certification or evidence of an equivalent system. The certificate is that evidence.

Service levels you can prove

Targets are agreed, measured and reported to the customer on a schedule. A dispute about whether the service was delivered is settled by the record.

Changes that break less

Changes are assessed, approved, tested and scheduled before they go live, with a way back if they fail. That removes a frequent cause of outages.

Problems fixed at the cause

Recurring incidents are analysed as problems and the cause is removed, so the service desk stops answering the same call.

Clear lines with suppliers

Where other companies or internal teams deliver part of the service, their obligations are written down and measured against what you promised the customer.

03What it asks of you

What ISO/IEC 20000-1 asks you to have in place

In plain terms and in our words, not the standard's. The standard itself is the authority, and you will need a copy.

  1. Scope, policy and a service management plan

    State which services the system covers, for which customers and from which locations. Top management sets a service management policy and objectives and approves a plan: the services you provide, the resources, the roles, the tools and the known limits. You remain accountable for the whole system even where others run parts of it. A provider that hands every service and process in the scope to other parties cannot be certified.

  2. Service catalogue, assets and configuration

    Keep a catalogue of the services you offer, written so that customers can understand it. Know which assets deliver each service. Record the configuration items that matter, such as servers, applications, network devices and licences, and how they depend on each other, and keep those records accurate as things change.

  3. Customers, service levels and suppliers

    Agree service levels with each customer in writing, measure performance against them and review the results with the customer at planned intervals. Record complaints and manage each one to a close. Hold agreements with suppliers, external or internal, whose targets support what you promised the customer, and monitor how they perform.

  4. Budget, demand and capacity

    Budget and account for the cost of services, so that decisions about them are made on figures. Forecast demand. Plan the people, technology and information needed to meet it, and monitor actual use against the plan.

  5. Change, release and deployment

    Have a change management policy that says which changes are controlled and how they are classified, emergency changes included. Assess, approve, schedule and review each change. New or significantly changed services are planned, designed, built and tested against agreed acceptance criteria. Releases are deployed in a controlled way, with a plan for reversing one that fails.

  6. Incidents, service requests and problems

    Record every incident and service request, classify and prioritize it, resolve or fulfil it and close it, with a defined route for major incidents. Analyse incident data to find problems and their root causes. Record known errors and workarounds until a permanent fix is in place.

  7. Availability, continuity and information security

    Agree availability targets, monitor them and investigate unplanned downtime. Assess the risks to service continuity, keep a continuity plan and test it. Set an information security policy for the services, apply controls that match the risks, and handle security incidents by a defined procedure.

  8. Measuring, auditing and improving

    Report on the performance of the services and of the system itself. Run internal audits and management reviews. Keep a list of opportunities for improvement, decide which to act on using set criteria, and check afterwards whether each one delivered what was expected.

04The audit

How certification to ISO/IEC 20000-1 works

  1. Application and quotation

    You tell us your scope, sites and headcount. We quote the audit days the standard's rules require.

  2. Stage 1 audit

    A review of your documented system and your readiness. You get a list of anything to settle before stage 2.

  3. Stage 2 audit

    The auditor follows your processes on site and samples records, to see that the system is in use and works.

  4. Decision

    Nonconformities are answered, the file is reviewed independently of the audit team, and AQC Group issues the certificate.

  5. Surveillance and recertification

    A shorter audit in each of the next two years, then a full recertification audit in the third.

What the auditor looks at

  • The scope statement, and how other parties that deliver part of the service are controlled
  • Service level agreements, the reports sent to customers and what was done about missed targets
  • A sample of changes followed from request to the review after implementation
  • Incident, major incident and problem records, and whether known errors lead to fixes
  • Configuration records compared with what is actually running
  • Availability and continuity plans, the last test and its results

What affects audit time

  • The number of people who work within the service management system
  • The number and variety of services in the scope, and how many customers they serve
  • The number of sites, and whether the service desk or operations run around the clock
  • How much of the service is delivered by suppliers or by other internal teams

How certification works, step by step

05Often combined with

06Questions

Questions about ISO/IEC 20000-1

We follow ITIL. Why would we need ISO/IEC 20000-1?

ITIL is a framework of recommended practices. People study it and take examinations in it, and an organization adopts as much of it as suits its work. It is not a standard that an organization is audited and certified against. ISO/IEC 20000-1 is a set of requirements. A certification body can audit your service management system against them and issue a certificate.

The two fit together. Processes built on ITIL cover much of what the standard asks for. What the standard adds is the management system around those processes: a defined scope, a policy and objectives, internal audit, management review and documented evidence. ISO also publishes guidance on how ISO/IEC 20000-1 and ITIL relate.

How is it different from ISO/IEC 27001?

ISO/IEC 27001 is about protecting information. It starts from the risks to confidentiality, integrity and availability and covers everything within its scope. ISO/IEC 20000-1 is about delivering services as agreed: service levels, changes, incidents, capacity, continuity. It includes information security, but as one part of managing the service and in less depth.

The two standards share the same management system structure, so the policy framework, internal audit, management review and corrective action can be run once for both. A provider that holds one already has part of the other in place.

Is the 2018 edition still current?

Yes. ISO reviewed ISO/IEC 20000-1:2018 in 2023 and confirmed it, which means the edition remains current. Amendment 1, published in February 2024, asks organizations to consider whether climate change is a relevant issue for their system.

Does it apply only to IT services?

No. The standard was developed in the IT field and its vocabulary of incidents, changes, releases and configuration comes from there. Its requirements are generic, though, and are meant to apply to a service provider of any size and with any kind of service. What matters is that you deliver a defined service to a customer under agreed terms.

Can an internal IT department be certified?

Yes. The provider can be a department that serves the rest of its own organization. The scope then names the internal customers, and documented service levels agreed with them take the place of a contract. They are measured and reviewed in the same way.

More questions about certification

Ask about ISO/IEC 20000-1 for your organization.

Tell us your scope, your sites and how many people work in them. We will tell you what the audit involves.