Knowledge base
ISO/IEC 20000-1:2018: Documentation and Compliance Requirements
This document explains, clause by clause, what ISO/IEC 20000-1:2018 expects an organisation to have in place and what an auditor may ask to see as evidence.
Prem Kumar Dvivedi · 12 سبتمبر 2026
It covers the requirements across 7 main areas, from understanding the organisation and leadership to service delivery, monitoring, corrective action and continual improvement.
This is not simply a checklist. A checklist asks, “Do you have this?” This guide explains what is required, what it should look like, and what evidence can demonstrate that the requirement is being followed.
________________________________________
4. Organisation and the Services You Provide
Clauses 4.1, 4.2, 4.3 and 4.4
Understanding external issues
You must identify the external factors that can affect your services, such as:
• Customers
• Technology
• Suppliers
• Laws and regulations
• Security threats
• Market conditions
Evidence: A documented list of these external issues and evidence that it is reviewed periodically.
Understanding internal issues
You must also identify internal factors that affect your services, such as:
• Employee skills
• Available tools and technology
• Resources and capacity
• Organisation structure
• Internal processes
Evidence: A documented list of internal issues.
Understanding interested parties
You must identify the people and organisations that are involved in or affected by your services, such as:
• Customers
• Users
• Suppliers
• Business partners
• Regulators
You must also understand their requirements.
Evidence: A list of interested parties and their relevant requirements.
Legal and contractual requirements
You must know the legal, regulatory and contractual requirements that apply to your services.
Evidence: A register or list of applicable legal, regulatory and contractual requirements.
Defining the SMS scope
You must clearly define what is included in your Service Management System (SMS).
This should identify:
• Services covered
• Departments or teams involved
• Locations covered
Evidence: A documented scope statement.
Services provided by other parties
If another organisation, supplier, internal department or customer performs part of a service, you must still maintain control and responsibility for that activity.
Evidence:
• List of external and internal parties involved
• Defined responsibilities
• Evidence that you monitor and control their work
• Evidence that you remain accountable for the process
If a process is completely controlled by another party and you have no evidence of governance or control, you should not claim that process as part of your SMS scope.
Understanding your processes
You must identify the main service management processes and understand how they work together.
Evidence: A process map, process list or documented responsibilities with process owners.
________________________________________
5. Leadership
Clauses 5.1, 5.2 and 5.3
Management involvement
Top management must demonstrate that they are actively involved in service management and have made service-related decisions.
Evidence:
• Management review records
• Investment or budget approvals
• Management decisions
• Records of actions taken
An auditor may also ask management directly about their involvement.
Providing resources
Management must ensure that the SMS has the resources it needs, including:
• People
• Budget
• Technology
• Tools
Evidence: Budgets, staffing records and technology/tool investments.
Service management policy
You must have a documented Service Management Policy.
It should show the organisation's commitment to:
• Meeting applicable requirements
• Managing services effectively
• Continually improving the SMS
Evidence: An approved, dated and controlled policy.
Communicating the policy
The policy must be communicated to employees and relevant suppliers.
Evidence: Website, intranet, training, induction or other communication records.
Roles and responsibilities
You must clearly define who is responsible for:
• Each service
• Each process
• Service management activities
Evidence: Organisation chart, job responsibilities and named service/process owners.
These responsibilities should also be clear for suppliers and other parties involved in delivering the service.
________________________________________
6. Planning
Clauses 6.1, 6.2 and 6.3
Risks and opportunities
You must identify risks and opportunities that could affect your services.
These may include:
• Service risks
• Technology risks
• Supplier risks
• Information security risks
• Capacity risks
• Business continuity risks
Evidence: Risk and opportunity register.
Service management objectives
You must establish measurable service management objectives.
Evidence: Objectives with clear targets and measurable results.
Action plans
For every objective, you should define:
• What needs to be done
• Who will do it
• When it will be completed
• What resources are required
• How success will be measured
Evidence: Documented action plan.
Service Management Plan
You must have a plan explaining how the organisation will achieve its service management objectives.
The plan should consider:
• Services
• People
• Resources
• Suppliers and other parties
• Technology
• Measurement
• Auditing
• Reporting
• Improvement
The plan should be kept updated and actually used.
Evidence: Current plan, revision history and records showing that the plan is being implemented.
________________________________________
7. Support – People, Knowledge and Documents
Clauses 7.1 to 7.6
Resources
You must provide the people, money, infrastructure and tools required to operate the SMS.
Evidence: Budgets, staffing information and technology/tool records.
Competence
You must identify the skills required for different roles and ensure people have the necessary competence.
Evidence:
• Competence requirements
• Skills matrix
• Training records
• Certification records
• Competence assessments
This should also cover supplier personnel when they perform your service management processes.
Awareness
Employees must understand:
• The service management policy
• Their responsibilities
• Their role in achieving service objectives
• What can happen if requirements are not followed
Evidence: Training, induction and awareness records.
Auditors may also ask employees questions to check their understanding.
Communication
You must decide:
• What needs to be communicated
• Who needs the information
• When it should be communicated
• How it will be communicated
Evidence: Communication plan or communication matrix.
Documented information
You must maintain the documents and records required by the standard.
These may include:
• SMS scope
• Policy
• Objectives
• Service Management Plan
• Service Catalogue
• Service Level Agreements
• Process records
Document control
Documents must be reviewed and approved before they are used.
Evidence: Approval records, version numbers and document control information.
Employees and relevant suppliers must be able to access the latest approved version.
Knowledge management
You must capture the knowledge needed to operate and support your services.
This could include:
• Knowledge base
• Runbooks
• Known error records
• Work instructions
• Handover information
The information should be kept current and available to the people who need it.
________________________________________
8. Operating the Services
Clauses 8.1 to 8.7
Service delivery processes
You must establish and operate the processes needed to deliver your services.
Evidence: Documented processes and records showing that they are actually being followed.
Delivering services as agreed
Services must be delivered according to agreed customer requirements.
Evidence: Service requirements, agreements and service delivery records.
Planning new or changed services
When introducing or changing a service, you must consider:
• People
• Technology
• Resources
• Interfaces
• Dependencies
• Service requirements
Evidence: Service planning and design records.
Managing service providers
For every party involved in delivering your services, you must define:
• What they are responsible for
• Expected performance
• How their performance will be monitored
• How you will maintain control
This applies to:
• External suppliers
• Internal departments
• Customers performing supplier-type activities
Service Catalogue
You must maintain a service catalogue that customers and users can access.
It should describe:
• Services available
• What each service provides
• Service requirements
• Dependencies
Asset management
You must know which assets are used to provide your services.
Evidence: Asset records.
Configuration management
You must identify and control important configuration items and maintain accurate records of how they relate to each other.
Evidence:
• Configuration records
• Relationships between configuration items
• Verification checks
• Records of corrections
Customer relationships
A responsible person should be assigned for each customer relationship.
Customer service reviews should take place regularly.
Evidence:
• Named customer contacts
• Meeting agendas
• Minutes
• Action records
Complaints and customer satisfaction
You must have a process for handling complaints and measuring customer satisfaction.
Evidence:
• Complaint procedure
• Complaint register
• Complaint resolution records
• Customer satisfaction results
• Improvement actions
Service Level Agreements
You must establish SLAs with measurable service targets based on customer requirements.
Evidence: SLAs covering services, targets, assumptions and exceptions.
Monitoring service performance
You must regularly report actual performance against agreed targets.
If a target is missed, you should record the reason and take appropriate action.
Evidence: Service performance reports and supporting data.
Supplier management
External suppliers should have agreements defining:
• Services
• Responsibilities
• Performance targets
• Interfaces
• Monitoring requirements
Evidence: Supplier contracts, performance reports and review meetings.
Internal teams and customers performing supplier activities should also have clearly documented responsibilities and performance expectations.
Service budgeting
You must establish budgets for your services and monitor actual costs.
Evidence: Budgets and cost tracking records.
Demand management
You must forecast demand for your services and compare the forecast with actual demand.
Evidence: Demand forecasts and actual demand analysis.
Capacity management
You must ensure that sufficient capacity is available in terms of:
• People
• Technology
• Resources
• Budget
Evidence: Capacity plan, monitoring records and capacity decisions.
The objective is to identify capacity problems before they affect service delivery.
________________________________________
Change Management
Change process
You must have a defined process for managing changes.
It should explain:
• What is considered a change
• Types of changes
• Who can approve changes
• How emergency changes are handled
Assessing changes
Each change must be assessed for:
• Risk
• Impact
• Effect on services
• Effect on customers
Evidence: Change records showing assessment and approval.
Testing and rollback
Changes should be tested before implementation and have a rollback or back-out plan where appropriate.
Evidence:
• Test results
• Rollback plan
• Approval records
• Implementation records
Reviewing changes
After implementation, you should review important changes and analyse:
• Failed changes
• Rolled-back changes
• Unauthorised changes
• Emergency changes
This helps identify weaknesses in the change process.
________________________________________
New and Changed Services
New or significantly changed services must be designed according to agreed requirements before implementation.
Evidence:
• Documented requirements
• Design records
• Resource requirements
• Roles and responsibilities
• Dependencies
• Technology requirements
• SLA requirements
Service acceptance
Before a service goes live, acceptance criteria should be agreed and met.
Evidence:
• Acceptance criteria
• Test results
• Approval
• Live environment verification
• Handover documentation
• Known errors
________________________________________
Incident Management
You must have a process for:
• Recording incidents
• Classifying incidents
• Prioritising incidents
• Resolving incidents
• Keeping users informed
Evidence: Incident records showing classification, priority, communication and resolution.
Major incidents
Major incidents should have a separate process with clear responsibility and management involvement.
Evidence:
• Major incident procedure
• Incident records
• Post-incident review
Service requests
Service requests must be handled within agreed timeframes.
Evidence: Service request records showing actual completion time against the agreed target.
________________________________________
Problem Management
You must analyse recurring incidents to identify their underlying causes.
Where possible, you should remove the root cause rather than repeatedly fixing the same symptom.
Evidence:
• Problem records
• Root cause analysis
• Corrective actions
• Changes made to remove the cause
• Evidence that repeat incidents are reducing
Known errors
Known errors and workarounds should be documented so support teams can use them.
Evidence: An accessible known-error database or knowledge base.
________________________________________
Availability and Service Continuity
Availability
You must define availability requirements and monitor whether the agreed targets are being achieved.
Evidence:
• Availability targets
• Monitoring results
• Records of service interruptions
• Corrective actions
Service continuity
You must identify continuity requirements and establish plans for maintaining or restoring services.
The plans should define:
• Responsibilities
• Recovery requirements
• When the plan should be activated
• Recovery targets
The plans must also be tested.
Evidence: Continuity plans and test records showing dates, results and actions.
________________________________________
Information Security
You must manage information security risks related to your services.
This should include:
• Information security policy
• Security controls
• Security requirements for suppliers
• Security incident management
• Risk-based security measures
Evidence: Security policies, controls, supplier requirements and security incident records.
If the organisation already has ISO/IEC 27001, the information security management system can be used to support this requirement instead of unnecessarily duplicating controls.
________________________________________
9. Checking and Evaluating Performance
Clauses 9.1, 9.2, 9.3 and 9.4
Monitoring and measurement
You must decide:
• What will be measured
• How it will be measured
• How often it will be measured
• Who will review the results
Evidence: Monitoring and measurement plan.
Analysing results
It is not enough to simply collect data. You must analyse the results and take action when necessary.
Evidence: Analysis, evaluation and action records.
Reporting to customers
You should provide customers and other relevant interested parties with service performance information at agreed intervals.
Reports may include:
• Service performance
• SLA achievement
• Major incidents
• Changes
• Continuity events
• Workload
• Nonconformities
• Trends
Evidence: Service reports and agreed reporting schedules.
________________________________________
Internal Audit
You must conduct internal audits of your Service Management System.
The audit programme should cover the requirements of the standard over time.
Evidence:
• Audit programme
• Audit plans
• Audit reports
• Findings
• Corrective actions
Auditors should be competent and sufficiently independent from the activities they audit.
________________________________________
Management Review
Top management must review the SMS at planned intervals.
The review should consider:
• Previous actions
• Changes in internal and external issues
• Service performance
• SMS performance
• Resources
• Risks and opportunities
• Improvement opportunities
Evidence:
• Management review agenda
• Attendance records
• Minutes
• Decisions
• Action plans
A management review should result in clear decisions and actions, not just meeting minutes.
________________________________________
10. Corrective Action and Continual Improvement
Clauses 10.1 and 10.2
Corrective action
When something goes wrong, you must:
1. Identify the problem.
2. Correct it.
3. Find out why it happened.
4. Take action to prevent it from happening again.
5. Check whether the corrective action worked.
Evidence:
• Nonconformity records
• Root cause analysis
• Corrective action records
• Follow-up verification
This can apply to:
• Audit findings
• Service failures
• Missed targets
• Incidents
• Supplier problems
Check for wider impact
When a problem is found, you should also check whether the same problem exists elsewhere.
For example:
• Another service
• Another customer
• Another supplier
• Another department
Evidence: Records showing that this wider check was performed.
Verify corrective actions
You must later confirm that the corrective action was effective.
Evidence: Follow-up review with a defined date and result.
________________________________________
Continual Improvement
You should continuously identify and manage opportunities to improve your services and SMS.
Evidence:
• Improvement register
• Improvement ideas
• Assigned owners
• Priorities
• Status
• Results
You should also measure whether completed improvements actually produced the expected results.
Showing improvement
The organisation should be able to demonstrate improvement over time through trends such as:
• Fewer incidents
• Fewer repeat incidents
• Better change success rates
• Improved SLA performance
• Higher customer satisfaction
• Better service performance
________________________________________
How to Use This Document
ISO/IEC 20000-1:2018 does not simply require you to create a huge manual, hundreds of templates or a complicated filing system.
The main requirement is that the organisation can demonstrate that it has:
• Made the necessary decisions
• Defined responsibilities
• Established appropriate processes
• Implemented those processes
• Monitored their effectiveness
• Kept appropriate records
• Corrected problems
• Continually improved its services
Documentation alone is not compliance
Having a procedure does not automatically mean you are compliant.
If a procedure exists but employees do not follow it, an auditor may identify a gap between what is documented and what actually happens.
The important question is:
Does the documented process reflect the way the organisation actually works?
A simple, practical procedure that people understand and follow is more useful than a lengthy document that nobody uses.
In simple terms, ISO/IEC 20000-1:2018 is about having a controlled Service Management System, using it effectively, keeping evidence of what you do, measuring performance and continuously improving your services.
What this covers
See how this looks as a working system
Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO 20000-1, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.
More reading
- Automotive Suppliers Face Stricter Cybersecurity Assessments
Cybersecurity is becoming a key part of supplier evaluations in the automotive industry. Vehicle manufacturers now check how suppliers protect data and systems alongside quality, cost, and delivery.
13 سبتمبر 2026
- Automotive OEM Vendor Cybersecurity Assessment: Controls, Scoring and ISO Standards Mapping
What does an automotive vendor cybersecurity assessment cover?
13 سبتمبر 2026
- Inside an Automotive OEM Vendor Cybersecurity Assessment: The 19 Control Families and What They Actually Ask For
The nineteen control families in an automotive vendor cybersecurity assessment, where the structure came from, and why good controls still score zero.
13 سبتمبر 2026
