ISO 20000 Managed IT Service Management
ISO 20000-1 managed IT service management certification India. Service levels, incident and change management. Accredited body, three-year cycle.
ISO/IEC 20000-1 managed IT service management system certification in Mumbai, New Delhi and India — service levels, incident, problem and change management audited on a three-year cycle by an accredited body.
ISO/IEC 20000-1 specifies requirements for an IT service management system: defining what services you deliver, agreeing what level of service is committed, running the processes that sustain it, and demonstrating improvement over time. Certification is independent confirmation that the service is managed rather than merely provided.
Why organisations certify
For managed service providers and outsourcers, ISO 20000 is increasingly a condition of tender — particularly in government and financial services procurement, where a client needs assurance that the provider's service management is systematic rather than personality-dependent. For internal IT functions, it is the framework that turns informal practice into something that survives staff turnover.
It is also the standard that pairs with ISO 27001 for technology providers: 27001 covers whether the service is secure, 20000 covers whether it is reliably delivered. Clients frequently ask for both.
What the standard requires
- Service portfolio and catalogueWhat services are delivered, to whom, and on what terms — documented rather than assumed, and kept current as services change.
- Service level managementAgreed, measurable service levels with defined reporting, and performance measured against them rather than against internal convenience.
- Incident and service request managementLogging, prioritisation, escalation and resolution, with evidence that the process is followed under pressure rather than bypassed.
- Problem managementIdentifying underlying causes behind recurring incidents and removing them, which is the process most often documented and least often practised.
- Change managementAssessment, authorisation and controlled release of changes, including emergency changes and the retrospective approval that governs them.
- Configuration managementA configuration management database that reflects reality, since change and incident processes depend on knowing what is actually deployed.
- Capacity and availabilityPlanning to meet agreed demand and availability targets, with monitoring that gives warning before a threshold is breached.
- Service continuityContinuity requirements derived from service commitments, with plans that have been tested rather than written.
- Supplier managementControl of suppliers and their contribution to the service, including cloud and subcontracted components you depend on but do not operate.
- Service reporting and improvementReporting against commitments, and a continual improvement process with evidence of changes actually made.
ISO 20000 and ITIL
The two are frequently confused. ITIL is a body of guidance describing how service management can be done; ISO/IEC 20000-1 is a standard stating what a management system must contain, and it is the one you can be certified against. An organisation working to ITIL is well positioned for certification but is not thereby certified, and the gap is usually in evidence rather than in practice — the processes run but the records demonstrating they run are incomplete.
Where audits find gaps
Change management under pressure is the recurring one: a documented process that is followed for planned work and bypassed for anything urgent, with emergency changes never retrospectively authorised. Configuration data that has drifted from reality is the second. And service reporting produced for the audit rather than used by anyone — a report nobody reads is not evidence of service management.
The certification process
Stage 1 reviews the documented system, confirms the scope and the services covered, and establishes readiness. Stage 2 assesses implementation: incident and change records, service level performance against commitments, problem investigations and their outcomes, and whether personnel describe the process the documentation claims. The certificate runs three years with annual surveillance and recertification before expiry.
Scope
The certificate states which services and locations are covered, and a client will check that the service they buy is inside it. Scope also has to account for services delivered through suppliers — you remain accountable for components you do not operate, and the standard requires you to demonstrate control over them.
Who certifies
- Managed service providers and IT outsourcers
- Data centres and hosting providers
- Software and SaaS companies operating a support function
- Internal IT departments serving a large organisation
- Government technology entities and their suppliers
- Telecommunications and network service operators
Our role and its limits
ITMAD is an accredited certification body. Under ISO/IEC 17021-1 we cannot design, implement or consult on the management system we certify. We provide the audit and the certification decision, plus optional pre-assessment identifying gaps against the standard without prescribing how you close them.
What you receive
- Stage 1 report identifying readiness gaps before the main audit
- Stage 2 audit report with findings supported by objective evidence
- Non-conformities classified by severity with defined response timescales
- Certificate of registration stating your certified scope and services
- Certification mark for use under our mark and seal policy
- Annual surveillance audits and reports through the three-year cycle