ISO Certifications · IT Service Management
ISO 20000-1 certification that proves your IT service delivery holds up.
We build and stress-test your service management system, run the readiness and internal audit, and stand beside you through the accredited certification audit that puts the certificate in your hands.
ISO/IEC 20000-1 is the international standard for a service management system, or SMS — the way you plan, deliver, and improve IT services. FinAudit CPA prepares your SMS, aligns it with ITIL practice, runs the readiness review and internal audit, then works alongside an accredited certification body that performs the audit and issues the certificate your enterprise clients trust.
Reviewed by Debraj Hazra, CPA (USA), ACA (ICAEW, ICAI)
Last updated July 2026
What is ISO 20000-1, really?
ISO/IEC 20000-1 is the international standard for a service management system, usually shortened to SMS. It sets out what an organization must have in place to plan, deliver, monitor, and improve IT services that other people depend on. If your customers pay you to keep systems running, resolve incidents, and ship changes without breaking things, this is the standard that describes how a disciplined operation does that work.
The word "system" matters here. ISO 20000-1 certification does not judge a single help desk or one clever automation. It judges the whole management machine: how you agree service levels, how you record and resolve incidents, how you stop the same problem recurring, how you approve and release changes, and how you keep services available when something goes wrong. Certification says that machine is defined, followed, measured, and improved on a cycle, not held together by a few heroes who remember how everything works.
Anyone who has run a modern IT shop will recognize the vocabulary, because ISO 20000-1 and ITIL grew up together. ITIL is a library of good practice — a detailed description of how service management can be done well. ISO 20000-1 is the certifiable standard that says you actually do it and can prove it to an independent auditor. You can adopt ITIL without ever certifying. You cannot earn an ISO 20000-1 certificate without a system an accredited body can inspect.
ITIL tells you how good IT service management looks. ISO 20000-1 is the certificate that proves you run that way every day, checked by someone who does not work for you.
Who needs ISO 20000-1, and when?
ISO 20000-1 earns its keep when the way you deliver a service is the product a client is buying. A few situations push it to the front of the queue:
- You are a managed service provider bidding for enterprise work. Large buyers and public tenders increasingly list ISO 20000-1 as a requirement or a scoring criterion. Without it, you are explaining why you should be trusted. With it, an accredited body has already vouched for how you operate.
- You run IT outsourcing or a shared service center. When another company hands you their operations, they want evidence that service levels, escalations, and change control are governed rather than improvised. The certificate answers that before the questionnaire lands.
- You are a SaaS or platform operations team scaling past the founder-knows-everything stage. As you add customers and engineers, informal processes stop scaling. Certifying your SMS forces the definitions, ownership, and metrics that keep quality steady while you grow.
If any of these fit, start before a contract forces your hand. Building a service management system that survives an audit takes real work, and rushing it under a deal deadline is the expensive way to do it. The teams that certify calmly are the ones who began while the certificate was still a plan rather than a blocker.
ISO 20000-1 vs ITIL: what is the difference?
People use the two names almost interchangeably, and they are related, but they do different jobs. ITIL is guidance you adopt. ISO 20000-1 is a standard you certify against. Here is how they line up so you can decide what you actually need.
| ISO 20000-1 | ITIL | |
|---|---|---|
| What it is | A certifiable international standard for a service management system | A library of good-practice guidance for IT service management |
| Can you be certified | Yes, an accredited certification body issues a certificate for the organization | No organization certificate; individuals earn ITIL qualifications |
| What it requires | Defined, followed, measured, and improved processes an auditor can inspect | Recommended practices you choose how far to adopt |
| How buyers read it | Independent proof your service delivery meets a recognized bar | Evidence your people know the practice, but not that you run it |
| How they work together | Gives ITIL practice a certifiable, audited backbone | Supplies the detailed how-to behind the standard’s requirements |
How our ISO 20000-1 process runs
You always know where you are and what comes next. We prepare the system; an accredited certification body performs the formal audit. No black box, no surprise invoices.
-
01
Scoping
We agree which services, teams, and locations sit inside the SMS, map your current practice against the standard, and set a fixed fee before we start. Clear scope keeps the audit honest and the cost predictable.
-
02
Gap assessment
We measure your service management against every clause — service level management, incident, problem, change, release, continuity, and the governance around them — and hand you a plain-language list of what to build or tighten.
-
03
Build and remediation
You close the gaps with our support. We help you define service levels, workflows, and metrics that reflect how your team actually works, so the system is real rather than shelfware written for the auditor.
-
04
Internal audit
We run a full internal audit against the standard, exactly as the certification body will, so you find and fix weaknesses before they cost you a nonconformity in the audit that counts.
-
05
Certification audit
An accredited certification body performs the Stage 1 documentation review and the Stage 2 on-site audit. We prepare your team, sit with you through it, and help you respond to any findings.
-
06
Surveillance and improvement
After the certificate is issued, we help you keep the system running through the annual surveillance audits and the improvement cycle that keep it valid across the 3-year term.
What you get, and how long it takes
You end this engagement with a service management system your team runs day to day and an ISO 20000-1 certificate issued by an accredited certification body. Along the way you get the documented service catalog, service level agreements, and the incident, problem, change, and continuity processes that the standard requires — written to fit your operation rather than lifted from a template. You also get the internal audit records and management review that prove the system is alive, not decorative.
The service lifecycle is the thread running through all of it. Service level management sets the promises and the measures. Incident management restores service fast when something breaks. Problem management hunts down root causes so the same failure stops repeating. Change and release management move updates into production without gambling on stability. ISO 20000-1 asks you to connect these into one governed cycle, and that connection is what convinces an enterprise client you can be relied on.
Timing depends on where you begin. A team with mature ITIL-aligned processes can often reach the certification audit in a few months. A team building much of this for the first time should plan for longer, because the standard expects the system to have operated for a while before an auditor can see it working. We give you a realistic schedule at scoping, not an optimistic one you later have to explain away.
What actually drives the cost
We quote a fixed preparation fee, so you will not see a surprise hourly bill from us. The certification body sets its own audit fee separately. The number depends on real factors, not guesswork:
Scope of the SMS
The more services, teams, and locations inside the certificate, the more there is to define, audit, and maintain. A tight, honest scope costs less than an everything-at-once one.
Process maturity
If your incident, change, and service level management already run cleanly and are documented, preparation moves fast. If much of it lives in people’s heads, building the system is where the effort goes.
Tooling and evidence
A single service desk that produces clean records is easier to audit than a patchwork of tools and spreadsheets that you have to reconcile by hand.
Certification body audit fees
The accredited body charges its own fee for the Stage 1 and Stage 2 audits and the annual surveillance audits, based on your size and scope. We are transparent that this sits outside our preparation fee.
Why run your ISO 20000-1 with FinAudit CPA
Here is the honest structure, because it protects the value of your certificate. FinAudit CPA prepares your service management system, runs the readiness work, and performs the internal audit. We do not issue the certificate, and no credible firm that prepares you should. Under the accreditation rules that give the certificate its worth, the body that audits and certifies you must be independent of the body that built your system. We work alongside an accredited certification body that performs the formal audit and issues the certificate. That separation is not a limitation; it is the reason a buyer trusts the result.
What you get from us is a preparer who reads more than the process diagrams. As a licensed CPA firm, we look at service management the way an auditor looks at a control environment — where the evidence is thin, where a metric is being gamed, where a process exists on paper but not in practice. That perspective is exactly what carries you through a Stage 2 audit without unpleasant surprises. You also get senior attention that does not thin out as the work grows, fixed scope you can budget around, and controls mapped so the effort you spend here carries over to ISO 27001, ISO 22301, or ISO 9001 instead of being rebuilt from scratch.
Pair your ISO 20000-1 with
- ISO 27001, when clients want proof you secure the services you deliver, not just run them well
- ISO 22301, when enterprise buyers ask how you keep services available through a disruption
- ISO 9001, when you want one management system that governs quality across the whole business
- SOC 2, when North American SaaS buyers want a CPA-signed report alongside your certificate
ISO/IEC 20000-1 (IT Service Management) · questions buyers ask
No, though they are closely related. ITIL is a library of good-practice guidance for IT service management that you choose how far to adopt. ISO 20000-1 is a certifiable international standard your organization can be audited and certified against. Most teams use ITIL as the detailed how-to and ISO 20000-1 as the certificate that proves an independent auditor confirmed they actually run that way.
No, and no credible preparer should. The accreditation rules that give the certificate its value require the certification body to be independent of whoever built your system. FinAudit CPA prepares your service management system, runs the readiness review, and performs the internal audit. An accredited certification body then performs the formal Stage 1 and Stage 2 audits and issues the certificate, which is what makes it trustworthy to your clients.
It depends on where you start. A team with mature, documented, ITIL-aligned processes can often reach the certification audit in a few months. A team building much of the system for the first time should plan for longer, because the standard expects the system to have operated for a period before an auditor can confirm it works. We give you a realistic schedule at scoping rather than an optimistic one.
Cost depends on the scope of your service management system, how mature your processes already are, how clean your tooling and records are, and the certification body’s own audit fees. We quote a fixed preparation fee up front, and we are transparent that the accredited body charges separately for the Stage 1, Stage 2, and annual surveillance audits based on your size and scope.
The standard covers the core of IT service management: service level management, incident management, problem management, change and release management, service continuity and availability, and the governance that ties them together. It expects these to run as one connected lifecycle — promises set and measured, incidents resolved, root causes removed, and changes released safely — rather than as separate teams working in isolation.
The certificate is valid for 3 years once an accredited certification body issues it. To keep it valid, you pass annual surveillance audits during that term, and you recertify at the end of the cycle. This is why ISO 20000-1 rewards a system that genuinely runs day to day. A program built only to pass one audit rarely survives the surveillance that follows.
Usually less than you fear, but more than nothing. Strong ITIL practice gives you most of the raw material, since the processes and vocabulary already match. What ISO 20000-1 adds is proof: documented scope, service levels, records, internal audit, and management review that an auditor can inspect. We map what you already run against the standard and focus the work on the gaps between good practice and certifiable evidence.
Yes, and it should. All three share the same management-system backbone: defined scope, risk thinking, internal audit, management review, and continual improvement. We map your ISO 20000-1 system so the governance you build carries over to ISO 27001 for security or ISO 22301 for continuity. You build the shared foundation once and extend it, instead of standing up separate programs that overlap heavily.
Pair it with
Audit once, comply many.
ISO 22301 (Business Continuity)
Prove your service keeps running when things go wrong — with certified business continuity.
ISO/IEC 27001 Certification
The international security certificate your global customers recognize on sight.
ISO 9001 (Quality)
The quality certificate procurement teams check before they let you bid.