ISO 20000
Definition
ISO 20000
ISO 20000 is the international standard for IT service management, setting requirements for how an organisation plans, delivers and improves the services it runs. Buyers use it to test whether a provider runs a real system rather than a set of habits.
The distinction is the whole point of the standard.
Plenty of providers deliver competently through the knowledge of a few long-serving staff. That works until those people leave — and it produces no evidence an auditor can inspect.
ISO 20000 asks for the opposite: documented processes, defined measurement, and a management system that survives turnover. Whether that translates into better service is a separate question.
Key takeaways
- ISO 20000 is the certifiable standard for IT service management systems.
- ITIL is a body of guidance, not a standard, and organisations cannot be certified against it.
- Certification covers a declared service scope, not the provider’s entire operation.
- The standard tests whether a system exists, not whether the service is good.
How it works
ISO 20000 requires an organisation to run a service management system across the service lifecycle. DNV describes the standard as covering how organisations plan, design, transition, deliver and improve their IT services.
That sequence is the shape of the standard. Each stage carries requirements for documentation, measurement and review, and an auditor tests whether the organisation does what its own documents say.
The relationship with ITIL confuses almost every buyer who encounters both. ITIL is guidance describing good practice; ISO 20000 is a specification an organisation can be audited and certified against.
An organisation can adopt ITIL practices and never certify. It can also certify to ISO 20000 without using ITIL vocabulary at all. PeopleCert, which owns ITIL, now markets version 5 as the current release — a reminder that guidance moves faster than standards do.
| ISO 20000 | ITIL | |
|---|---|---|
| Type | Certifiable standard | Guidance framework |
| Who is certified | The organisation | Individual practitioners |
| Audited by | An accredited certification body | Nobody |
| Evidence produced | A scoped certificate | Training records |
| Useful to a buyer for | Proving a system exists | Proving staff know the vocabulary |
The column that matters is the last one. A provider with many ITIL-certified staff and no ISO 20000 certificate has trained people — and unproven processes.
Examples
Service management certification shows up in procurement more often than it shows up in delivery, and the gap between the two is where buyers get caught. Each case here involves somebody who had to answer the question in writing.
A government buyer makes ISO 20000 a tender requirement for its service desk contract. That is common in government outsourcing, where auditable process counts more than speed.
A managed service provider certifies only its network operations centre. Its application support team, which the client actually uses daily, falls outside the scope entirely.
A financial services client pairs the certificate with its own service credits, having concluded the standard proves process discipline but says nothing about performance. Those credits live in the service level agreement (SLA).
A retailer drops the requirement after finding every shortlisted provider held the certificate. When everyone qualifies, the filter has stopped filtering.
Related terms
Service management sits in a crowded field of standards, frameworks and contractual instruments that overlap awkwardly. The definitions that follow are narrow on purpose, since overlap is what misleads buyers.
- ITIL 4: the edition of the ITIL guidance most organisations still run on.
- ITIL Foundation: the entry-level individual certification, which certifies vocabulary rather than capability.
- COBIT 2019: governance of enterprise IT, sitting above service management rather than inside it.
- Service level agreement (SLA): the contractual performance commitment, which the standard does not set.
- ISO certification: the general audit process behind any ISO management standard.
- Quality assurance outsourcing: buying the checking function as a service line.
- Vendor management outsourcing: running the supplier relationship itself, including certificate verification.
FAQ
Is ISO 20000 the same as ITIL?
No. ITIL is guidance that individuals get certified in; ISO 20000 is a standard that organisations get certified against. They are complementary rather than interchangeable.
Can a person be ISO 20000 certified?
Not in the way they can be ITIL certified. Individuals can hold auditor or practitioner qualifications, but the certificate itself belongs to the organisation.
Does certification mean good service?
No. It means a documented management system exists and is followed. Service quality is measured by your service levels, not by the standard.
What scope should I ask about?
The specific services and locations named on the certificate. A provider may certify one delivery tower and leave the one you buy uncovered.
Which edition is current?
ISO/IEC 20000-1:2018 remains the current edition of the requirements part, having been reviewed and confirmed rather than replaced.
Is it worth requiring in a tender?
It is, until every bidder has it. At that point it stops discriminating and you need a sharper requirement.
Review source partners in the Outsource Accelerator hubs directory and check the service scope before you check the certificate.







Independent




