Skip to content
General ITAdvanced

ISO/IEC 20000-1:2018 — IT Service Management System (ITSMS) Explained

Quick Answer ISO/IEC 20000-1:2018 is an international standard that specifies requirements for establishing, implementing, maintaining and continually improv...

BI
Bison Technical Team Enterprise IT specialists
Updated 15 May 2026 17 min read 106 total views
Structured technical guidanceSafety notes included where requiredSources listed below

Quick Answer

ISO/IEC 20000-1:2018 is an international standard that specifies requirements for establishing, implementing, maintaining and continually improving a Service Management System (SMS).

It is particularly relevant to organizations that provide or manage IT-enabled services, including IT departments, managed service providers (MSPs), cloud service providers, data centres, software/SaaS providers, help desks and technical support companies.

Advertisement

The standard helps organizations manage the complete service lifecycle in a controlled and measurable way—from planning and service design to transition, delivery, monitoring and continual improvement.

ISO/IEC 20000-1:2018 remains current. ISO states that the 2018 edition was reviewed and confirmed in 2023. A Climate Action Amendment, ISO/IEC 20000-1:2018/Amd 1:2024, was published in February 2024 and applies to the standard.


What Is ISO/IEC 20000-1:2018?

ISO/IEC 20000-1:2018 is formally titled:

Information technology — Service management — Part 1: Service management system requirements

It is the third edition of ISO/IEC 20000-1 and was published in September 2018.

The standard specifies requirements for an organization to establish, implement, maintain and continually improve a Service Management System (SMS). Its requirements cover the planning, design, transition, delivery and improvement of services so that service requirements are met and value is delivered.

In practical terms, ISO/IEC 20000-1 helps an organization answer questions such as:

  • How should IT services be planned and controlled?
  • Who is responsible for each service?
  • How should incidents and service requests be handled?
  • How should changes to IT systems be controlled?
  • How should service levels be agreed and measured?
  • How should suppliers be managed?
  • How should information security risks affecting services be addressed?
  • How should service availability and continuity be maintained?
  • How can recurring problems be identified and reduced?
  • How can IT services be continually improved?

The objective is not simply to create documentation. A conforming SMS should provide a systematic way of managing services and demonstrating that service management processes operate effectively.


What Is an IT Service Management System?

A Service Management System (SMS) is the management framework used by an organization to direct, control and continually improve how services are managed and delivered.

It combines elements such as:

  • Policies
  • Objectives
  • Processes
  • Procedures
  • Responsibilities
  • People
  • Technology
  • Service management tools
  • Documentation
  • Measurements
  • Controls
  • Reviews
  • Improvement activities

For example, an IT support company may have procedures for:

Incident Management
Handling server failures, email problems, network outages and application errors.

Service Request Management
Handling requests such as new user creation, software installation, access permissions and password resets.

Change Management
Controlling upgrades, firewall changes, server migrations, application deployments and infrastructure modifications.

Service Level Management
Defining response times, resolution targets, availability commitments and other service expectations.

Service Continuity Management
Preparing the organization to continue or restore services following major failures or disruptions.

ISO/IEC 20000-1 brings these activities together under a structured management system.


Why Is ISO/IEC 20000-1 Important?

Modern organizations depend heavily on IT services.

An IT failure can affect:

  • Employee productivity
  • Customer service
  • Business applications
  • Email communication
  • Financial transactions
  • Cloud services
  • Websites
  • ERP and accounting applications
  • Security systems
  • Data availability
  • Business continuity

Without structured service management, IT teams may become primarily reactive—solving problems only after users complain.

ISO/IEC 20000-1 encourages organizations to move toward a controlled, measurable and continually improving service management model.


ISO/IEC 20000-1 vs ISO/IEC 20000

These terms are sometimes used interchangeably, but there is an important distinction.

ISO/IEC 20000 refers to a family of standards and guidance documents related to service management.

ISO/IEC 20000-1 is the part containing the formal Service Management System requirements against which conformity can be assessed.

Other documents in the ISO/IEC 20000 family provide supporting guidance.

For example:

Standard Purpose
ISO/IEC 20000-1:2018 Service Management System requirements
ISO/IEC 20000-2:2019 Guidance on applying service management systems
ISO/IEC 20000-3:2019 Guidance on scope definition and applicability
ISO/IEC 20000-10:2018 Concepts and vocabulary

ISO currently lists these documents as part of the ISO/IEC 20000 family.


Who Can Use ISO/IEC 20000-1?

ISO/IEC 20000-1 is not limited to large IT companies.

It can be applicable to organizations or organizational units that manage and deliver services to internal or external customers.

Examples include:

  • IT service providers
  • Managed Service Providers (MSPs)
  • IT support companies
  • Cloud service providers
  • SaaS providers
  • Hosting companies
  • Data centres
  • Network service providers
  • Telecom organizations
  • Software companies
  • IT departments within enterprises
  • Government IT departments
  • Banks and financial organizations
  • Hospitals and healthcare IT departments
  • Educational institutions
  • Outsourcing companies
  • Technical help desks
  • Infrastructure management companies

The organization can also be a department within a larger organization rather than an independent company.


Main Benefits of ISO/IEC 20000-1

Implementing an effective Service Management System can provide several business and operational benefits.

1. Consistent IT Service Delivery

Documented and controlled processes reduce dependence on individual employees and informal working methods.

Customers receive a more predictable service experience.

2. Better Incident Management

Organizations can establish structured methods for:

  • Incident recording
  • Categorization
  • Prioritization
  • Escalation
  • Resolution
  • Communication
  • Closure

This can reduce confusion during major IT incidents.

3. Better Service Availability

Organizations systematically consider service availability requirements and manage services accordingly.

4. Controlled IT Changes

Uncontrolled changes are a common source of IT failures.

Structured change management helps ensure that changes are assessed, authorized, implemented and reviewed appropriately.

5. Improved Customer Satisfaction

Clearly defined service requirements and service levels make expectations easier to understand and manage.

6. Better Supplier Management

Many IT services depend on external providers such as:

  • Internet service providers
  • Cloud providers
  • Software vendors
  • Hardware vendors
  • Data centres
  • Security providers
  • Backup providers

A structured SMS helps ensure that external dependencies are appropriately managed.

7. Measurable Service Performance

Organizations can define and monitor indicators such as:

  • Service availability
  • Incident volumes
  • Response times
  • Resolution times
  • SLA achievement
  • Change success rates
  • Customer complaints
  • Service request completion times

8. Continual Improvement

The organization regularly evaluates performance and identifies opportunities to improve the SMS and services.


Structure of ISO/IEC 20000-1:2018

The standard follows a management-system structure that facilitates alignment with other ISO management system standards.

The major clauses are:

Clause Area
1 Scope
2 Normative references
3 Terms and definitions
4 Context of the organization
5 Leadership
6 Planning
7 Support of the Service Management System
8 Operation of the Service Management System
9 Performance evaluation
10 Improvement

Clauses 4 through 10 contain the core management-system requirements organizations need to address when implementing the SMS.


Understanding the Major ISO/IEC 20000-1 Requirements

Clause 4 — Context of the Organization

An organization needs to understand the environment in which its Service Management System operates.

This includes considering relevant internal and external issues and interested parties.

Interested parties may include:

  • Customers
  • Employees
  • Management
  • Suppliers
  • Regulators
  • Business partners
  • Contractors

The organization must also determine the scope of its SMS.

Example

An IT company may decide that its SMS covers:

Managed server, cloud hosting, network management and remote IT support services delivered from its Delhi operations centre.

A clearly defined scope is important because it establishes which services and organizational areas are included in the SMS.


Clause 5 — Leadership

Successful service management cannot operate solely as an IT technician's responsibility.

Top management needs to demonstrate leadership and commitment.

Important areas include:

  • Service management policy
  • Organizational responsibilities
  • Authorities
  • Resources
  • Alignment between service management and organizational objectives

Management involvement is particularly important because service improvement may require budget, staffing, technology or organizational changes.


Clause 6 — Planning

Organizations need to consider risks and opportunities affecting the SMS.

Planning also includes establishing service management objectives.

Examples could include:

  • Improve SLA compliance to 98%
  • Reduce recurring server incidents
  • Reduce average incident resolution time
  • Improve service availability
  • Improve customer satisfaction
  • Reduce unsuccessful production changes

The standard also requires a service management plan. ISO's service-management committee provides guidance noting that Clause 6.3 requires such a plan and that it should align with the service management policy and objectives.


Clause 7 — Support of the Service Management System

A successful SMS requires adequate support.

This includes areas such as:

Resources

Organizations need sufficient people, technology, infrastructure and financial resources.

Competence

Personnel performing service management activities should have appropriate competence.

Examples include:

  • Help desk technicians
  • Network administrators
  • System administrators
  • Cloud engineers
  • Security personnel
  • Service managers

Awareness

Employees should understand relevant policies, objectives and their contribution to the SMS.

Communication

Organizations should determine what service-management information needs to be communicated, when, to whom and how.

Documented Information

Appropriate documents and records need to be controlled.

Examples may include:

  • Service management policy
  • SMS scope
  • Service management plan
  • SLA records
  • Incident records
  • Change records
  • Service reports
  • Audit reports
  • Corrective actions
  • Continuity documentation

Clause 8 — Operation of the Service Management System

Clause 8 is particularly important because it deals with operational service-management activities.

Service Portfolio

Organizations need to manage the services within the SMS.

This helps ensure that services are understood, controlled and aligned with service requirements.


Relationship and Agreement

Effective service management requires appropriate relationships with customers and other parties.

This includes areas such as:

  • Business relationship management
  • Service level management
  • Supplier management

Example SLA

A server-support agreement might specify:

Measurement Target
Critical incident acknowledgement 15 minutes
High-priority incident acknowledgement 30 minutes
Standard request response 4 business hours
Monthly service availability 99.9%

These numbers are examples only. Actual SLA targets should be based on contractual and business requirements.


Supply and Demand

Organizations should understand service demand and ensure sufficient capacity to meet service requirements.

For example, a cloud provider may monitor:

  • CPU utilization
  • RAM utilization
  • Storage capacity
  • Network bandwidth
  • User growth
  • Database load
  • Backup storage consumption

Capacity planning helps prevent foreseeable performance problems.


Service Design, Build and Transition

New or changed services should not simply be placed into production without appropriate planning and control.

Examples include:

  • Migrating an application to the cloud
  • Deploying a new ERP system
  • Upgrading a Windows Server environment
  • Replacing a firewall
  • Moving email to Microsoft 365 or Google Workspace
  • Implementing a new backup solution

Appropriate planning, testing, authorization and transition activities help reduce service disruption.


Resolution and Fulfilment

This area includes important operational activities such as:

Incident Management

An incident is an interruption or degradation of a service or another event requiring restoration of normal service.

Examples:

  • Internet connection down
  • Email unavailable
  • Server inaccessible
  • Application crashing
  • Printer service unavailable
  • User unable to authenticate

The objective is generally to restore normal service as quickly and effectively as possible.

Service Request Management

Service requests are typically standard user requests rather than unexpected service failures.

Examples:

  • Create a new user
  • Install approved software
  • Reset a password
  • Provide access to a shared folder
  • Configure a printer

Problem Management

Problem management focuses on identifying and addressing causes of incidents, especially recurring incidents.

For example:

Ten users repeatedly losing connectivity every Monday morning should not simply generate ten independently closed tickets each week.

Problem management should investigate the underlying cause.


Service Assurance

Organizations also need to address areas necessary for maintaining dependable services.

These include:

  • Service availability
  • Service continuity
  • Information security

Availability Management

Availability requirements should be understood and service availability should be monitored appropriately.

Service Continuity

Organizations should prepare for serious disruptions.

Examples include:

  • Server hardware failure
  • Data-centre outage
  • Cyberattack
  • Network failure
  • Power failure
  • Natural disaster
  • Major application failure

Continuity arrangements can include:

  • Backup systems
  • Disaster recovery
  • Alternate infrastructure
  • Recovery procedures
  • Emergency contacts
  • Recovery testing

Information Security

Information-security requirements relevant to services need to be appropriately managed.

Organizations may also integrate their service management approach with ISO/IEC 27001 where a more comprehensive Information Security Management System is required.


Clause 9 — Performance Evaluation

An SMS should be measured rather than managed only through assumptions.

Organizations need suitable monitoring, measurement, analysis and evaluation.

Examples of useful metrics include:

Metric Example
Service availability 99.95%
Incidents per month 125
Critical incidents 3
SLA compliance 97%
First-contact resolution 72%
Average resolution time 2.4 hours
Successful changes 96%
Customer satisfaction 4.5/5

The appropriate metrics depend on the organization's services and objectives.


Internal Audits

Organizations need to conduct internal audits at planned intervals.

An internal audit evaluates whether the SMS:

  • Conforms to applicable requirements
  • Is effectively implemented
  • Is maintained appropriately

Audits should identify weaknesses before they become serious operational or certification problems.


Management Review

Top management should periodically review the Service Management System.

A management review may consider:

  • Audit findings
  • Service performance
  • Customer feedback
  • Objectives
  • Risks
  • Nonconformities
  • Corrective actions
  • Resource requirements
  • Opportunities for improvement

Management review helps ensure that service management remains aligned with organizational objectives.


Clause 10 — Improvement

Continual improvement is fundamental to a management system.

When a nonconformity occurs, the organization should appropriately:

  1. React to the problem.
  2. Control and correct it where applicable.
  3. Determine whether action is required to eliminate its cause.
  4. Implement necessary corrective action.
  5. Review whether the action was effective.

The goal is not simply to fix today's incident.

The organization should determine how to reduce the likelihood of the same underlying issue happening again.


ISO/IEC 20000-1:2018 Amendment 1:2024 — Climate Action Changes

Organizations implementing ISO/IEC 20000-1 should be aware of an important update.

In February 2024, ISO published:

ISO/IEC 20000-1:2018/Amd 1:2024 — Amendment 1: Climate action changes

The amendment applies to ISO/IEC 20000-1:2018.

The amendment reflects ISO's broader climate-action changes to management system standards.

For service management, organizations need to consider whether climate change is a relevant issue in the context of their SMS, while recognizing that relevant interested parties can have climate-related requirements. ISO/IEC JTC 1/SC 40 explains that the amendment highlights the importance of identifying and managing climate-change-related requirements relevant to the Service Management System.

This does not mean that every IT organization needs to create a large environmental-management programme under ISO/IEC 20000-1.

Instead, climate-related issues should be considered in the context of the organization and its services where relevant.

For example, an organization might consider:

  • Data-centre cooling risks
  • Extreme-weather disruption
  • Power availability
  • Disaster recovery locations
  • Supplier resilience
  • Customer sustainability requirements
  • Energy-related service dependencies

Organizations preparing for certification or maintaining an existing SMS should therefore account for the 2024 amendment.


ISO/IEC 20000-1 vs ITIL

ISO/IEC 20000-1 and ITIL are related to service management, but they are not the same thing.

ISO/IEC 20000-1 ITIL
International standard IT service management framework/guidance
Specifies SMS requirements Provides practices and guidance
Organization-level conformity/certification possible Individuals can obtain ITIL certifications
Defines what an SMS must achieve Provides extensive guidance on managing services
Auditable requirements Not an organizational certification standard equivalent to ISO/IEC 20000-1

Organizations can use ITIL practices to help design and improve service-management processes while using ISO/IEC 20000-1 as the formal SMS requirements framework.

They can therefore complement each other rather than being direct alternatives.


ISO/IEC 20000-1 vs ISO/IEC 27001

These standards address different management objectives.

ISO/IEC 20000-1 ISO/IEC 27001
Service Management System Information Security Management System
Focuses on managing and delivering services Focuses on managing information-security risks
Strong IT service-management relevance Applies broadly to information security
Covers incidents, changes, service levels, continuity, suppliers and other service-management areas Covers confidentiality, integrity, availability and information-security risk treatment
ITSM-oriented Cybersecurity/information-security-oriented

An IT service provider may implement both.

For example:

ISO/IEC 20000-1 helps demonstrate structured service management.

ISO/IEC 27001 helps demonstrate structured information-security risk management.

Using both can be particularly valuable for managed IT, cloud, hosting, data-centre and SaaS organizations.


ISO/IEC 20000-1 vs ISO 9001

ISO 9001 focuses broadly on quality management, while ISO/IEC 20000-1 focuses specifically on service management.

An IT company could therefore implement:

ISO 9001
for organization-wide quality management,

ISO/IEC 20000-1
for service management,

and

ISO/IEC 27001
for information security.

The appropriate combination depends on business, contractual, regulatory and customer requirements.


How to Implement ISO/IEC 20000-1

A practical implementation programme may follow these stages.

Step 1 — Understand the Standard

Management and implementation personnel should understand the applicable ISO/IEC 20000-1 requirements.

Step 2 — Define the SMS Scope

Clearly determine which:

  • Locations
  • Departments
  • Services
  • Technologies
  • Customers

are included.

Step 3 — Perform a Gap Assessment

Compare existing practices against applicable requirements.

Identify areas that are:

  • Fully implemented
  • Partially implemented
  • Missing
  • Ineffective

Step 4 — Establish Governance

Define:

  • Responsibilities
  • Service-management policy
  • Objectives
  • SMS ownership
  • Management responsibilities

Step 5 — Identify Services and Requirements

Understand the services being delivered and the requirements applying to them.

Step 6 — Develop the Service Management Plan

Create and maintain the required service-management planning information.

Step 7 — Implement Required Processes and Controls

Examples include:

  • Incident management
  • Service request management
  • Problem management
  • Change management
  • Service level management
  • Supplier management
  • Availability management
  • Service continuity
  • Information security management

Step 8 — Implement Measurement

Define useful KPIs and service metrics.

Step 9 — Maintain Documented Information

Ensure required policies, plans, procedures and records are appropriately controlled.

Step 10 — Conduct Internal Audit

Evaluate the SMS against applicable requirements.

Step 11 — Conduct Management Review

Management reviews performance, problems, risks and improvement opportunities.

Step 12 — Correct Nonconformities

Address identified weaknesses and verify corrective actions.

Step 13 — Certification Audit

If certification is desired, engage an appropriate accredited certification body.


Example ISO/IEC 20000-1 Documentation

Depending on the organization's scope and complexity, useful SMS documentation may include:

  • SMS scope
  • Service management policy
  • Service management objectives
  • Service management plan
  • Service catalogue
  • SLA documentation
  • Supplier agreements
  • Incident records
  • Problem records
  • Change records
  • Service request records
  • Availability records
  • Capacity information
  • Service continuity plan
  • Information-security documentation
  • Risk and opportunity records
  • Performance reports
  • Internal audit reports
  • Management review records
  • Corrective-action records
  • Continual-improvement records

A key principle is to maintain documentation that supports effective management and demonstrates conformity—not to create unnecessary paperwork solely for an audit.


Example for an IT Support Company

Consider an MSP providing:

  • Desktop support
  • Server management
  • Network management
  • Cloud backup
  • Microsoft 365 support
  • Google Workspace support
  • Firewall management
  • Remote technical support

An SMS could operate as follows:

Customer reports server problem

↓

Ticket created

↓

Incident categorized and prioritized

↓

SLA timer begins

↓

Engineer assigned

↓

Issue diagnosed

↓

Service restored

↓

Incident closed

↓

Recurring issue identified?

↓

Problem record created

↓

Root cause investigated

↓

Permanent change proposed

↓

Change assessed and authorized

↓

Change implemented and reviewed

↓

Service performance monitored

↓

Improvement recorded

This demonstrates the difference between simply operating a help desk and managing IT services systematically.


Common ISO/IEC 20000-1 Implementation Mistakes

Organizations should avoid treating certification as only a documentation exercise.

Common weaknesses include:

  • Copying generic procedures from the Internet
  • Creating processes employees do not actually follow
  • Poorly defined SMS scope
  • Missing service ownership
  • Weak incident categorization
  • No meaningful SLA measurement
  • Closing recurring incidents without problem analysis
  • Implementing changes without appropriate control
  • Poor supplier monitoring
  • Weak continuity testing
  • Collecting metrics without analysing them
  • Performing internal audits only immediately before certification
  • Lack of management involvement
  • Correcting audit findings without investigating causes

An effective SMS should reflect how the organization actually delivers and improves its services.


Is ISO/IEC 20000-1 Certification Mandatory?

Generally, ISO/IEC 20000-1 certification is voluntary unless a contract, customer, tender, regulatory requirement or other obligation makes it necessary.

Organizations may seek certification because:

  • Customers request it
  • Government tenders specify it
  • Enterprise clients prefer certified providers
  • Management wants stronger ITSM governance
  • The company wants independent assurance of its SMS
  • Certification provides commercial differentiation

Whether certification is worthwhile depends on the organization's customers, services, contracts and business strategy.


Can a Small IT Company Implement ISO/IEC 20000-1?

Yes.

The organization does not need to be a multinational company.

A smaller MSP or IT support company can implement a Service Management System appropriate to its size and complexity.

For example, a smaller organization may use:

  • One ticketing platform
  • A compact service catalogue
  • Standard SLA templates
  • A simple change register
  • A supplier register
  • A risk register
  • Monthly service reports
  • A documented continuity plan

The important point is that the SMS should be appropriate and effective for the services within its scope.


Frequently Asked Questions

What does ISO/IEC 20000-1 stand for?

ISO/IEC 20000-1 is an international standard specifying requirements for a Service Management System.


What is the latest ISO/IEC 20000-1 version?

As of September 2026, ISO/IEC 20000-1:2018 remains the current base edition. ISO states that it was reviewed and confirmed in 2023. It also has Amendment 1:2024 — Climate action changes.


Is ISO/IEC 20000-1 only for IT companies?

No.

It can also apply to an IT or service-management function within a larger organization that manages and delivers services to internal or external customers.


What is SMS in ISO/IEC 20000-1?

SMS means Service Management System.

It is the management system used to establish, implement, maintain and continually improve service management.


Is ISO/IEC 20000-1 the same as ITIL?

No.

ISO/IEC 20000-1 is an international management-system standard containing requirements, while ITIL provides service-management practices and guidance.

They can be used together.


Can an organization be certified to ISO/IEC 20000-1?

Yes.

Organizations can undergo conformity assessment/certification against ISO/IEC 20000-1 requirements.


Does ISO/IEC 20000-1 cover cybersecurity?

It includes information-security requirements relevant to service management, but it is not a replacement for a comprehensive Information Security Management System such as ISO/IEC 27001.


Does ISO/IEC 20000-1 cover incident management?

Yes. Incident management and service request management are important operational elements of the service-management system.


Does ISO/IEC 20000-1 include change management?

Yes. New or changed services and service-management-related changes need appropriate planning and control.


Does ISO/IEC 20000-1 require continual improvement?

Yes.

Evaluation, corrective action and continual improvement are fundamental parts of the management-system approach.


What changed in ISO/IEC 20000-1 in 2024?

ISO published ISO/IEC 20000-1:2018/Amd 1:2024, introducing climate-action changes to the management-system requirements. Organizations should consider whether climate change is a relevant issue for their SMS and recognize that interested parties may have climate-related requirements.


Final Recommendation / Conclusion

ISO/IEC 20000-1:2018 provides a structured international framework for organizations that want to manage IT and other services consistently, measurably and with a strong focus on continual improvement.

For IT service providers, MSPs, cloud companies, SaaS providers and internal IT departments, the standard can help transform service management from an informal, reactive support model into a controlled management system.

Organizations considering implementation should start by:

  1. Defining their services and SMS scope.
  2. Understanding customer and service requirements.
  3. Performing a gap assessment.
  4. Establishing policies, responsibilities and measurable objectives.
  5. Implementing practical service-management processes.
  6. Measuring actual service performance.
  7. Conducting internal audits and management reviews.
  8. Continually correcting and improving the SMS.

Organizations already working with the 2018 standard should also ensure that the ISO/IEC 20000-1:2018/Amd 1:2024 Climate Action Amendment has been considered.

For authoritative requirements and updates, always refer to the official ISO publication rather than relying solely on third-party checklists or certification guides.

Official reference: ISO — ISO/IEC 20000-1:2018

 

YOUR FEEDBACK

Was this guide useful?

Your answer helps us keep BISONKB accurate and practical.

THE BISON BRIEF

Practical IT knowledge, once a week.

New troubleshooting guides, scripts and infrastructure notes. No noise.

By subscribing, you agree to our privacy policy. Unsubscribe at any time.