ISO/IEC 20000-1 IT Service Management Systems

Confirms that an organisation delivers IT services at the level it promised, and restores them by a defined procedure when they fail.

ITS own scheme

This standard is not covered by our IAS or UAF accreditation scopes. ITS certifies it under its own scheme. See our accreditations →

What this certification proves

ISO/IEC 20000-1 does not certify that nothing will break. It will. What it examines is whether, when an incident or request arrives, who receives it, within what time, and in what order it is handled are already defined, and whether records are kept.

One distinction matters more than any other here: incident versus problem. Incident management restores what has stopped. Problem management finds why it stopped and removes the cause. Most organisations do the first and skip the second, which is why the same outage keeps returning. An audit looks for problem management records first.

It also checks that service levels (SLAs) are defined as numbers and that achievement against them is reported to the customer.

Who this is for

  • Organisations operating IT systems for clients
  • System integration, managed service and cloud operations businesses
  • Organisations bidding for public-sector IT operations contracts
  • Internal IT functions expected to meet service levels

🌱 How this relates to ESG

Foundation for an ESG management system

ISO/IEC 20000-1 is not a direct indicator for E, S or G. It is groundwork that makes IT operations dependable. We do not dress it up as an ESG credential.

  • Same character as ISO 9001 — organising the way work is done makes other certifications easier, but does not itself raise an ESG score
  • However clause 8.7 service assurance (availability, continuity, security) leads into ISO 22301 and ISO/IEC 27001. If you need ESG evidence, those two are the direct sources
  • Public-sector and large-enterprise IT tenders often require it as a basic qualification, ahead of any ESG assessment
  • ⚠️ Do not write «we addressed ESG through 20000-1 certification» in a report — assessors will not accept it

What certification gives you

How the requirements are structured

This is the overall shape of what the standard asks for. Working through it in this order is a sensible way to prepare.

ISO/IEC 20000-1IT Service Management SystemsP · 조항 4 · 5 · 6PlanSet the servicescope, objectives…D · 조항 8DoHandle incidents,requests, problems,…C · 조항 9CheckMeasure SLAachievement; audit…A · 조항 10ActRemove the root ofrepeat outages…
계획 → 실행 → 점검 → 개선이 한 번으로 끝나지 않고 계속 돕니다. 심사에서 보는 것도 «이 바퀴가 실제로 도는가» 입니다.
ClauseTitleIn plain terms
4ContextIdentify which IT services you deliver and to whom, and set the scope.
5LeadershipTop management sets the service management policy and assigns roles.
6PlanningService objectives, risk actions and the service management plan.
7SupportPeople, technology, knowledge (operational documentation) and communication.
8Operation of the SMSThe heart of the standard — service levels · supplier management · capacity · change and release · incident and problem · availability, continuity and security.
9Performance evaluationMeasure SLA achievement and handling times; audit internally and review.
10ImprovementRemove the causes of recurring failures and revise procedures.

※ This is a summary written to help you, not the text of the standard. Please refer to the published standard for the exact requirements.

Before you apply, please check

Having these in place makes the audit considerably smoother. If you are not ready yet, you are still welcome to get in touch — we will set out what to do first, with a timeline.

  • Is there a service catalogue listing the services you deliver?
  • Are SLAs agreed with customers as numbers — response time, restoration time, availability?
  • Is there a service desk through which all requests are received?
  • Are incident records kept — receipt, priority, handling time?
  • 🔴 Are there problem management records showing root causes of recurring failures? This is the most commonly missing item
  • Is there change management, so that production systems cannot be changed without approval?
  • Are capacity and availability monitored against defined thresholds?
  • Do contracts with suppliers (subcontractors, cloud) state service levels?
  • Have you carried out at least one internal audit yourselves? (required before the audit)
See the 8-step certification process →

You can apply for ISO/IEC 20000-1 certification here

Tell us your organisation’s size and the standards you need, and we will send you the audit duration and a fee proposal. You are free to decide after seeing it.

Tel 02-786-9242Email info@itscert.or.krFax 02-6940-9317

※ ITS Certification Body does not provide management system consultancy. Auditing and consultancy must remain separate. What we can do is explain the certification process and what you need to have in place.

Which audit division handles this

Audits against this standard are carried out by our 정보보안심사본부. See the organisation chart →