WhatsApp contact icon for Nathan ISO Consulting
WhatsApp contact icon for Nathan ISO Consulting

Look at this from the other side of the table for a moment. An evaluator is assessing six managed services bids against the same criteria. Four of them describe robust ITIL-aligned processes in similar language. Two hold ISO 20000-1 certification.

The evaluator does not have time to audit the four. The certificate resolves a question that would otherwise take reference calls and a site visit, and it does so in a single line of a compliance schedule. That is the honest commercial case for this standard, and it is a good enough one.

What makes it worth doing properly rather than minimally is that the underlying discipline is genuinely useful. An organisation that can define its services, commit to service levels and demonstrate that incidents, changes and problems are managed rather than reacted to is a better supplier. The certificate is evidence of that, not a replacement for it.

ISO 20000-1 or ITIL?

These get treated as interchangeable and they are not. ITIL is a framework of good practice guidance, and certification under it applies to individuals. Your service desk manager can hold an ITIL qualification. Your company cannot.

ISO/IEC 20000-1:2018 is a certifiable management system standard for organisations, audited by a certification body. Plenty of organisations run ITIL-aligned processes and certify to ISO 20000-1, and the two sit together comfortably. But when a tender asks for certification, a folder of ITIL training certificates does not answer the question.

What the standard asks for

ISO/IEC 20000-1:2018 follows the harmonised structure, so Clauses 4 to 10 will look familiar if you hold ISO 9001 or ISO 27001. The service management substance concentrates in Clause 8.

AreaWhat it coversWhere organisations fall short
Service portfolio and planningService catalogue, service planning, control of parties involved in the service lifecycleNo genuine catalogue, or one written internally that customers have never seen
Relationship and agreementBusiness relationship management, service level management, supplier managementSLAs nobody reports against, and supplier arrangements with no service targets
Supply and demandBudgeting and accounting for services, demand management, capacity managementCapacity managed reactively, when something runs out
Design, build and transitionChange management, service design and transition, configuration management, release and deploymentEmergency change used as the default path, and a CMDB nobody trusts
Resolution and fulfilmentIncident management, service request management, problem managementIncidents closed with no problem record, so the same fault recurs indefinitely
Service assuranceAvailability management, service continuity, information security managementContinuity planned for infrastructure but not for the service the customer buys

Where certification actually wins work in Australia

  • Government ICT panels and marketplaces. Commonwealth and state ICT procurement arrangements list service management certification among evaluation criteria or mandatory requirements for managed services categories with some regularity.
  • Enterprise managed services contracts. Large private buyers use certification as a screening mechanism, particularly where the service supports regulated operations.
  • Health, education and utilities procurement. Sectors carrying regulated service obligations push service management requirements down to their ICT suppliers.
  • Financial services supplier assessments. Where you are a material service provider under APRA CPS 230, service management evidence forms part of the assurance the regulated entity is obliged to obtain from you.
  • Separating from a tied field. In panels where several bidders meet the technical requirements, certification is a clean way to differentiate from an uncertified competitor.

The ISO 27001 pairing

Most of our ISO 20000-1 clients either hold ISO 27001 already or are pursuing both, and there is a practical reason beyond collecting certificates.

The two standards share context, leadership, planning, competence, internal audit, management review and improvement. They also overlap in operations. Information security management appears within the service assurance requirements of ISO 20000-1, and service continuity sits adjacent to ICT continuity under ISO 27001. Building them separately means running two systems that document the same controls in different words and then auditing both.

Where both are in scope we build one system with a single governance structure, one internal audit program and one management review, then scope the certificates separately. Certification bodies discount combined audits because the audit days genuinely overlap.

How we build it

Eighteen to twenty-eight weeks is typical. Organisations with mature service desk practice move faster, and the longest element is usually building genuine problem management and accumulating enough operational evidence for Stage 2.

Weeks 1–5 Scope and service definition

Which services, customers and delivery locations are in scope. The service catalogue is built here rather than late, and it is written for customers in terms of outcomes rather than infrastructure components.

Weeks 3–8 Gap analysis and service level framework

Current practice assessed clause by clause, then service level agreements with measurable targets, reporting cadence and a defined route for handling breaches. We would rather you commit to targets you can meet than targets that read well in a bid.

Weeks 6–16 Core process build

Incident, request, problem, change, configuration, release and deployment. Designed inside your existing platform, whether that is ServiceNow, Jira Service Management, Halo, Autotask or something smaller, so the documented process and the real one are the same thing.

Weeks 12–20 Capacity, availability and continuity

Capacity and availability management, and service continuity planned around the service the customer buys rather than only the infrastructure underneath it.

Weeks 16–22 Supplier and party control

Management of suppliers and any parties involved in delivering the service, with service targets flowed down and monitoring that produces evidence.

Weeks 20–28 Audit and certification

Full internal audit, findings closed, documented management review, then Stage 1 and Stage 2 with a JAS-ANZ accredited body. We attend both.

Why providers choose us

Common approachOur approach
Rebuild your processes to match a reference modelBuild around how your service desk actually operates, then close the gaps that matter
Treat ITIL certification as equivalentBe clear that ITIL certifies individuals and ISO 20000-1 certifies organisations
Write SLAs that look strong in the bidWrite SLAs you can meet and report against, because the first breach report decides your credibility
Deliver process documents and leave you to configure the toolDesign processes inside your existing platform so documentation and practice match
Build a CMDB covering everythingScope configuration management to what you can maintain accurately, because a stale CMDB fails where a small one passes
Run ISO 20000-1 and ISO 27001 as separate projectsOne integrated system, one audit program, separately scoped certificates
Ignore the tender deadlineSequence backwards from the submission date and tell you early if it is not achievable

Where we work

Sydney and Melbourne account for most of our ISO 20000-1 work, across managed service providers, cloud and hosting operators, enterprise internal IT functions and platform operations teams. Canberra is disproportionately represented because panel requirements drive demand hardest among suppliers to Commonwealth agencies.

Brisbane work spans MSPs, state government suppliers and ICT providers to the logistics and resources sectors. Perth work is weighted toward providers supporting remote and resources operations. Adelaide work concentrates in defence sector ICT, health and education. We support providers in Hobart, Darwin and regional centres remotely, attending on site for workshops and Stage 2.

FAQ'S

ITIL is a guidance framework whose certifications apply to individuals. ISO/IEC 20000-1 is a certifiable management system standard for organisations. Running ITIL-aligned processes helps considerably, but only ISO 20000-1 produces an organisational certificate a tender can accept.

It depends on the panel and the category. Service management certification appears in Commonwealth and state ICT procurement requirements with some regularity, particularly for managed services. Check the specific arrangement you are bidding into rather than assuming.

If you can only do one, ISO 27001 generally opens more doors in Australian procurement. If both are on the roadmap, build them together, since they share governance, audit and review machinery and combined audits cost less than sequential ones.

Yes. The standard addresses this through requirements for controlling parties involved in the service lifecycle. What you cannot do is exclude subcontracted delivery from your management system while claiming it inside your certificate scope.

No. The standard is tool-agnostic. Certification depends on your processes and evidence, not on which platform you run. We build inside your existing toolset rather than asking you to migrate mid-project.

Detailed enough to support the processes you have committed to, and accurate enough to be trusted. A narrow, accurate configuration management database passes audit where a comprehensive but stale one does not.

Problem management existing on paper only, SLAs with no reporting evidence, emergency change used as a routine bypass, configuration data that does not match reality, and continuity plans covering infrastructure but not the customer-facing service.

Either. Internal IT functions certify where the organisation wants demonstrable service discipline or where a parent company requires it. The service catalogue and service level agreements simply describe services delivered to internal customers.

It includes information security management within its service assurance requirements, but at far less depth than ISO 27001. If security assurance is what your customers are asking about, ISO 27001 is the standard they actually mean.

Sometimes. It depends on the deadline, your current maturity and certification body availability, which is often the binding constraint rather than your readiness. Tell us the submission date first and we will answer honestly before quoting.

Typically 18 to 28 weeks. Organisations with mature service desk practice move faster. The longest element is usually building genuine problem management and accumulating enough operational evidence to satisfy a Stage 2 audit.

All capital cities and regional centres. Our ISO 20000-1 work concentrates in Sydney, Melbourne, Canberra, Brisbane, Perth and Adelaide, with delivery largely remote and on-site attendance for workshops and Stage 2 audits.

Send us the evaluation criteria

If a specific bid is driving this, send us the evaluation criteria and the submission date. That determines whether this is a sprint or a proper build, and we would rather tell you which one it is up front.

CONTACT
Reach out to us for any inquiries, collaborations,
or just to say hello!

Contact information for Nathan ISO Consulting

CLIENTELE
Our Valuable Client

WHEN NUMBERS MATTER
Empowering Insights into our Business Performance