Knowledge base

ISO/IEC 20000-1:2018: Documentation and Compliance Requirements

This document explains, clause by clause, what ISO/IEC 20000-1:2018 expects an organisation to have in place and what an auditor may ask to see as evidence.

Prem Kumar Dvivedi · 12 September 2026

It covers the requirements across 7 main areas, from understanding the organisation and leadership to service delivery, monitoring, corrective action and continual improvement.

This is not simply a checklist. A checklist asks, “Do you have this?” This guide explains what is required, what it should look like, and what evidence can demonstrate that the requirement is being followed.

________________________________________

4. Organisation and the Services You Provide

Clauses 4.1, 4.2, 4.3 and 4.4

Understanding external issues

You must identify the external factors that can affect your services, such as:

• Customers

• Technology

• Suppliers

• Laws and regulations

• Security threats

• Market conditions

Evidence: A documented list of these external issues and evidence that it is reviewed periodically.

Understanding internal issues

You must also identify internal factors that affect your services, such as:

• Employee skills

• Available tools and technology

• Resources and capacity

• Organisation structure

• Internal processes

Evidence: A documented list of internal issues.

Understanding interested parties

You must identify the people and organisations that are involved in or affected by your services, such as:

• Customers

• Users

• Suppliers

• Business partners

• Regulators

You must also understand their requirements.

Evidence: A list of interested parties and their relevant requirements.

Legal and contractual requirements

You must know the legal, regulatory and contractual requirements that apply to your services.

Evidence: A register or list of applicable legal, regulatory and contractual requirements.

Defining the SMS scope

You must clearly define what is included in your Service Management System (SMS).

This should identify:

• Services covered

• Departments or teams involved

• Locations covered

Evidence: A documented scope statement.

Services provided by other parties

If another organisation, supplier, internal department or customer performs part of a service, you must still maintain control and responsibility for that activity.

Evidence:

• List of external and internal parties involved

• Defined responsibilities

• Evidence that you monitor and control their work

• Evidence that you remain accountable for the process

If a process is completely controlled by another party and you have no evidence of governance or control, you should not claim that process as part of your SMS scope.

Understanding your processes

You must identify the main service management processes and understand how they work together.

Evidence: A process map, process list or documented responsibilities with process owners.

________________________________________

5. Leadership

Clauses 5.1, 5.2 and 5.3

Management involvement

Top management must demonstrate that they are actively involved in service management and have made service-related decisions.

Evidence:

• Management review records

• Investment or budget approvals

• Management decisions

• Records of actions taken

An auditor may also ask management directly about their involvement.

Providing resources

Management must ensure that the SMS has the resources it needs, including:

• People

• Budget

• Technology

• Tools

Evidence: Budgets, staffing records and technology/tool investments.

Service management policy

You must have a documented Service Management Policy.

It should show the organisation's commitment to:

• Meeting applicable requirements

• Managing services effectively

• Continually improving the SMS

Evidence: An approved, dated and controlled policy.

Communicating the policy

The policy must be communicated to employees and relevant suppliers.

Evidence: Website, intranet, training, induction or other communication records.

Roles and responsibilities

You must clearly define who is responsible for:

• Each service

• Each process

• Service management activities

Evidence: Organisation chart, job responsibilities and named service/process owners.

These responsibilities should also be clear for suppliers and other parties involved in delivering the service.

________________________________________

6. Planning

Clauses 6.1, 6.2 and 6.3

Risks and opportunities

You must identify risks and opportunities that could affect your services.

These may include:

• Service risks

• Technology risks

• Supplier risks

• Information security risks

• Capacity risks

• Business continuity risks

Evidence: Risk and opportunity register.

Service management objectives

You must establish measurable service management objectives.

Evidence: Objectives with clear targets and measurable results.

Action plans

For every objective, you should define:

• What needs to be done

• Who will do it

• When it will be completed

• What resources are required

• How success will be measured

Evidence: Documented action plan.

Service Management Plan

You must have a plan explaining how the organisation will achieve its service management objectives.

The plan should consider:

• Services

• People

• Resources

• Suppliers and other parties

• Technology

• Measurement

• Auditing

• Reporting

• Improvement

The plan should be kept updated and actually used.

Evidence: Current plan, revision history and records showing that the plan is being implemented.

________________________________________

7. Support – People, Knowledge and Documents

Clauses 7.1 to 7.6

Resources

You must provide the people, money, infrastructure and tools required to operate the SMS.

Evidence: Budgets, staffing information and technology/tool records.

Competence

You must identify the skills required for different roles and ensure people have the necessary competence.

Evidence:

• Competence requirements

• Skills matrix

• Training records

• Certification records

• Competence assessments

This should also cover supplier personnel when they perform your service management processes.

Awareness

Employees must understand:

• The service management policy

• Their responsibilities

• Their role in achieving service objectives

• What can happen if requirements are not followed

Evidence: Training, induction and awareness records.

Auditors may also ask employees questions to check their understanding.

Communication

You must decide:

• What needs to be communicated

• Who needs the information

• When it should be communicated

• How it will be communicated

Evidence: Communication plan or communication matrix.

Documented information

You must maintain the documents and records required by the standard.

These may include:

• SMS scope

• Policy

• Objectives

• Service Management Plan

• Service Catalogue

• Service Level Agreements

• Process records

Document control

Documents must be reviewed and approved before they are used.

Evidence: Approval records, version numbers and document control information.

Employees and relevant suppliers must be able to access the latest approved version.

Knowledge management

You must capture the knowledge needed to operate and support your services.

This could include:

• Knowledge base

• Runbooks

• Known error records

• Work instructions

• Handover information

The information should be kept current and available to the people who need it.

________________________________________

8. Operating the Services

Clauses 8.1 to 8.7

Service delivery processes

You must establish and operate the processes needed to deliver your services.

Evidence: Documented processes and records showing that they are actually being followed.

Delivering services as agreed

Services must be delivered according to agreed customer requirements.

Evidence: Service requirements, agreements and service delivery records.

Planning new or changed services

When introducing or changing a service, you must consider:

• People

• Technology

• Resources

• Interfaces

• Dependencies

• Service requirements

Evidence: Service planning and design records.

Managing service providers

For every party involved in delivering your services, you must define:

• What they are responsible for

• Expected performance

• How their performance will be monitored

• How you will maintain control

This applies to:

• External suppliers

• Internal departments

• Customers performing supplier-type activities

Service Catalogue

You must maintain a service catalogue that customers and users can access.

It should describe:

• Services available

• What each service provides

• Service requirements

• Dependencies

Asset management

You must know which assets are used to provide your services.

Evidence: Asset records.

Configuration management

You must identify and control important configuration items and maintain accurate records of how they relate to each other.

Evidence:

• Configuration records

• Relationships between configuration items

• Verification checks

• Records of corrections

Customer relationships

A responsible person should be assigned for each customer relationship.

Customer service reviews should take place regularly.

Evidence:

• Named customer contacts

• Meeting agendas

• Minutes

• Action records

Complaints and customer satisfaction

You must have a process for handling complaints and measuring customer satisfaction.

Evidence:

• Complaint procedure

• Complaint register

• Complaint resolution records

• Customer satisfaction results

• Improvement actions

Service Level Agreements

You must establish SLAs with measurable service targets based on customer requirements.

Evidence: SLAs covering services, targets, assumptions and exceptions.

Monitoring service performance

You must regularly report actual performance against agreed targets.

If a target is missed, you should record the reason and take appropriate action.

Evidence: Service performance reports and supporting data.

Supplier management

External suppliers should have agreements defining:

• Services

• Responsibilities

• Performance targets

• Interfaces

• Monitoring requirements

Evidence: Supplier contracts, performance reports and review meetings.

Internal teams and customers performing supplier activities should also have clearly documented responsibilities and performance expectations.

Service budgeting

You must establish budgets for your services and monitor actual costs.

Evidence: Budgets and cost tracking records.

Demand management

You must forecast demand for your services and compare the forecast with actual demand.

Evidence: Demand forecasts and actual demand analysis.

Capacity management

You must ensure that sufficient capacity is available in terms of:

• People

• Technology

• Resources

• Budget

Evidence: Capacity plan, monitoring records and capacity decisions.

The objective is to identify capacity problems before they affect service delivery.

________________________________________

Change Management

Change process

You must have a defined process for managing changes.

It should explain:

• What is considered a change

• Types of changes

• Who can approve changes

• How emergency changes are handled

Assessing changes

Each change must be assessed for:

• Risk

• Impact

• Effect on services

• Effect on customers

Evidence: Change records showing assessment and approval.

Testing and rollback

Changes should be tested before implementation and have a rollback or back-out plan where appropriate.

Evidence:

• Test results

• Rollback plan

• Approval records

• Implementation records

Reviewing changes

After implementation, you should review important changes and analyse:

• Failed changes

• Rolled-back changes

• Unauthorised changes

• Emergency changes

This helps identify weaknesses in the change process.

________________________________________

New and Changed Services

New or significantly changed services must be designed according to agreed requirements before implementation.

Evidence:

• Documented requirements

• Design records

• Resource requirements

• Roles and responsibilities

• Dependencies

• Technology requirements

• SLA requirements

Service acceptance

Before a service goes live, acceptance criteria should be agreed and met.

Evidence:

• Acceptance criteria

• Test results

• Approval

• Live environment verification

• Handover documentation

• Known errors

________________________________________

Incident Management

You must have a process for:

• Recording incidents

• Classifying incidents

• Prioritising incidents

• Resolving incidents

• Keeping users informed

Evidence: Incident records showing classification, priority, communication and resolution.

Major incidents

Major incidents should have a separate process with clear responsibility and management involvement.

Evidence:

• Major incident procedure

• Incident records

• Post-incident review

Service requests

Service requests must be handled within agreed timeframes.

Evidence: Service request records showing actual completion time against the agreed target.

________________________________________

Problem Management

You must analyse recurring incidents to identify their underlying causes.

Where possible, you should remove the root cause rather than repeatedly fixing the same symptom.

Evidence:

• Problem records

• Root cause analysis

• Corrective actions

• Changes made to remove the cause

• Evidence that repeat incidents are reducing

Known errors

Known errors and workarounds should be documented so support teams can use them.

Evidence: An accessible known-error database or knowledge base.

________________________________________

Availability and Service Continuity

Availability

You must define availability requirements and monitor whether the agreed targets are being achieved.

Evidence:

• Availability targets

• Monitoring results

• Records of service interruptions

• Corrective actions

Service continuity

You must identify continuity requirements and establish plans for maintaining or restoring services.

The plans should define:

• Responsibilities

• Recovery requirements

• When the plan should be activated

• Recovery targets

The plans must also be tested.

Evidence: Continuity plans and test records showing dates, results and actions.

________________________________________

Information Security

You must manage information security risks related to your services.

This should include:

• Information security policy

• Security controls

• Security requirements for suppliers

• Security incident management

• Risk-based security measures

Evidence: Security policies, controls, supplier requirements and security incident records.

If the organisation already has ISO/IEC 27001, the information security management system can be used to support this requirement instead of unnecessarily duplicating controls.

________________________________________

9. Checking and Evaluating Performance

Clauses 9.1, 9.2, 9.3 and 9.4

Monitoring and measurement

You must decide:

• What will be measured

• How it will be measured

• How often it will be measured

• Who will review the results

Evidence: Monitoring and measurement plan.

Analysing results

It is not enough to simply collect data. You must analyse the results and take action when necessary.

Evidence: Analysis, evaluation and action records.

Reporting to customers

You should provide customers and other relevant interested parties with service performance information at agreed intervals.

Reports may include:

• Service performance

• SLA achievement

• Major incidents

• Changes

• Continuity events

• Workload

• Nonconformities

• Trends

Evidence: Service reports and agreed reporting schedules.

________________________________________

Internal Audit

You must conduct internal audits of your Service Management System.

The audit programme should cover the requirements of the standard over time.

Evidence:

• Audit programme

• Audit plans

• Audit reports

• Findings

• Corrective actions

Auditors should be competent and sufficiently independent from the activities they audit.

________________________________________

Management Review

Top management must review the SMS at planned intervals.

The review should consider:

• Previous actions

• Changes in internal and external issues

• Service performance

• SMS performance

• Resources

• Risks and opportunities

• Improvement opportunities

Evidence:

• Management review agenda

• Attendance records

• Minutes

• Decisions

• Action plans

A management review should result in clear decisions and actions, not just meeting minutes.

________________________________________

10. Corrective Action and Continual Improvement

Clauses 10.1 and 10.2

Corrective action

When something goes wrong, you must:

1. Identify the problem.

2. Correct it.

3. Find out why it happened.

4. Take action to prevent it from happening again.

5. Check whether the corrective action worked.

Evidence:

• Nonconformity records

• Root cause analysis

• Corrective action records

• Follow-up verification

This can apply to:

• Audit findings

• Service failures

• Missed targets

• Incidents

• Supplier problems

Check for wider impact

When a problem is found, you should also check whether the same problem exists elsewhere.

For example:

• Another service

• Another customer

• Another supplier

• Another department

Evidence: Records showing that this wider check was performed.

Verify corrective actions

You must later confirm that the corrective action was effective.

Evidence: Follow-up review with a defined date and result.

________________________________________

Continual Improvement

You should continuously identify and manage opportunities to improve your services and SMS.

Evidence:

• Improvement register

• Improvement ideas

• Assigned owners

• Priorities

• Status

• Results

You should also measure whether completed improvements actually produced the expected results.

Showing improvement

The organisation should be able to demonstrate improvement over time through trends such as:

• Fewer incidents

• Fewer repeat incidents

• Better change success rates

• Improved SLA performance

• Higher customer satisfaction

• Better service performance

________________________________________

How to Use This Document

ISO/IEC 20000-1:2018 does not simply require you to create a huge manual, hundreds of templates or a complicated filing system.

The main requirement is that the organisation can demonstrate that it has:

• Made the necessary decisions

• Defined responsibilities

• Established appropriate processes

• Implemented those processes

• Monitored their effectiveness

• Kept appropriate records

• Corrected problems

• Continually improved its services

Documentation alone is not compliance

Having a procedure does not automatically mean you are compliant.

If a procedure exists but employees do not follow it, an auditor may identify a gap between what is documented and what actually happens.

The important question is:

Does the documented process reflect the way the organisation actually works?

A simple, practical procedure that people understand and follow is more useful than a lengthy document that nobody uses.

In simple terms, ISO/IEC 20000-1:2018 is about having a controlled Service Management System, using it effectively, keeping evidence of what you do, measuring performance and continuously improving your services.


What this covers

See how this looks as a working system

Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO 20000-1, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.

Ask us about this

Tell us what is being asked of you and by whom.

What are you looking for?

We reply within one working day. Your details stay with our consultants.

More reading

All articles