Look at this from the other side of the table for a moment. An evaluator is assessing six managed services bids against the same criteria. Four of them describe robust ITIL-aligned processes in similar language. Two hold ISO 20000-1 certification.
The evaluator does not have time to audit the four. The certificate resolves a question that would otherwise take reference calls and a site visit, and it does so in a single line of a compliance schedule. That is the honest commercial case for this standard, and it is a good enough one.
What makes it worth doing properly rather than minimally is that the underlying discipline is genuinely useful. An organisation that can define its services, commit to service levels and demonstrate that incidents, changes and problems are managed rather than reacted to is a better supplier. The certificate is evidence of that, not a replacement for it.
ISO 20000-1 or ITIL?
These get treated as interchangeable and they are not. ITIL is a framework of good practice guidance, and certification under it applies to individuals. Your service desk manager can hold an ITIL qualification. Your company cannot.
ISO/IEC 20000-1:2018 is a certifiable management system standard for organisations, audited by a certification body. Plenty of organisations run ITIL-aligned processes and certify to ISO 20000-1, and the two sit together comfortably. But when a tender asks for certification, a folder of ITIL training certificates does not answer the question.
What the standard asks for
ISO/IEC 20000-1:2018 follows the harmonised structure, so Clauses 4 to 10 will look familiar if you hold ISO 9001 or ISO 27001. The service management substance concentrates in Clause 8.
| Area | What it covers | Where organisations fall short |
|---|---|---|
| Service portfolio and planning | Service catalogue, service planning, control of parties involved in the service lifecycle | No genuine catalogue, or one written internally that customers have never seen |
| Relationship and agreement | Business relationship management, service level management, supplier management | SLAs nobody reports against, and supplier arrangements with no service targets |
| Supply and demand | Budgeting and accounting for services, demand management, capacity management | Capacity managed reactively, when something runs out |
| Design, build and transition | Change management, service design and transition, configuration management, release and deployment | Emergency change used as the default path, and a CMDB nobody trusts |
| Resolution and fulfilment | Incident management, service request management, problem management | Incidents closed with no problem record, so the same fault recurs indefinitely |
| Service assurance | Availability management, service continuity, information security management | Continuity planned for infrastructure but not for the service the customer buys |
Where certification actually wins work in Australia
The ISO 27001 pairing
Most of our ISO 20000-1 clients either hold ISO 27001 already or are pursuing both, and there is a practical reason beyond collecting certificates.
The two standards share context, leadership, planning, competence, internal audit, management review and improvement. They also overlap in operations. Information security management appears within the service assurance requirements of ISO 20000-1, and service continuity sits adjacent to ICT continuity under ISO 27001. Building them separately means running two systems that document the same controls in different words and then auditing both.
Where both are in scope we build one system with a single governance structure, one internal audit program and one management review, then scope the certificates separately. Certification bodies discount combined audits because the audit days genuinely overlap.
How we build it
Eighteen to twenty-eight weeks is typical. Organisations with mature service desk practice move faster, and the longest element is usually building genuine problem management and accumulating enough operational evidence for Stage 2.
Which services, customers and delivery locations are in scope. The service catalogue is built here rather than late, and it is written for customers in terms of outcomes rather than infrastructure components.
Current practice assessed clause by clause, then service level agreements with measurable targets, reporting cadence and a defined route for handling breaches. We would rather you commit to targets you can meet than targets that read well in a bid.
Incident, request, problem, change, configuration, release and deployment. Designed inside your existing platform, whether that is ServiceNow, Jira Service Management, Halo, Autotask or something smaller, so the documented process and the real one are the same thing.
Capacity and availability management, and service continuity planned around the service the customer buys rather than only the infrastructure underneath it.
Management of suppliers and any parties involved in delivering the service, with service targets flowed down and monitoring that produces evidence.
Full internal audit, findings closed, documented management review, then Stage 1 and Stage 2 with a JAS-ANZ accredited body. We attend both.
Why providers choose us
| Common approach | Our approach |
|---|---|
| Rebuild your processes to match a reference model | Build around how your service desk actually operates, then close the gaps that matter |
| Treat ITIL certification as equivalent | Be clear that ITIL certifies individuals and ISO 20000-1 certifies organisations |
| Write SLAs that look strong in the bid | Write SLAs you can meet and report against, because the first breach report decides your credibility |
| Deliver process documents and leave you to configure the tool | Design processes inside your existing platform so documentation and practice match |
| Build a CMDB covering everything | Scope configuration management to what you can maintain accurately, because a stale CMDB fails where a small one passes |
| Run ISO 20000-1 and ISO 27001 as separate projects | One integrated system, one audit program, separately scoped certificates |
| Ignore the tender deadline | Sequence backwards from the submission date and tell you early if it is not achievable |
Where we work
Sydney and Melbourne account for most of our ISO 20000-1 work, across managed service providers, cloud and hosting operators, enterprise internal IT functions and platform operations teams. Canberra is disproportionately represented because panel requirements drive demand hardest among suppliers to Commonwealth agencies.
Brisbane work spans MSPs, state government suppliers and ICT providers to the logistics and resources sectors. Perth work is weighted toward providers supporting remote and resources operations. Adelaide work concentrates in defence sector ICT, health and education. We support providers in Hobart, Darwin and regional centres remotely, attending on site for workshops and Stage 2.
FAQ'S
ITIL is a guidance framework whose certifications apply to individuals. ISO/IEC 20000-1 is a certifiable management system standard for organisations. Running ITIL-aligned processes helps considerably, but only ISO 20000-1 produces an organisational certificate a tender can accept.
It depends on the panel and the category. Service management certification appears in Commonwealth and state ICT procurement requirements with some regularity, particularly for managed services. Check the specific arrangement you are bidding into rather than assuming.
If you can only do one, ISO 27001 generally opens more doors in Australian procurement. If both are on the roadmap, build them together, since they share governance, audit and review machinery and combined audits cost less than sequential ones.
Yes. The standard addresses this through requirements for controlling parties involved in the service lifecycle. What you cannot do is exclude subcontracted delivery from your management system while claiming it inside your certificate scope.
No. The standard is tool-agnostic. Certification depends on your processes and evidence, not on which platform you run. We build inside your existing toolset rather than asking you to migrate mid-project.
Detailed enough to support the processes you have committed to, and accurate enough to be trusted. A narrow, accurate configuration management database passes audit where a comprehensive but stale one does not.
Problem management existing on paper only, SLAs with no reporting evidence, emergency change used as a routine bypass, configuration data that does not match reality, and continuity plans covering infrastructure but not the customer-facing service.
Either. Internal IT functions certify where the organisation wants demonstrable service discipline or where a parent company requires it. The service catalogue and service level agreements simply describe services delivered to internal customers.
It includes information security management within its service assurance requirements, but at far less depth than ISO 27001. If security assurance is what your customers are asking about, ISO 27001 is the standard they actually mean.
Sometimes. It depends on the deadline, your current maturity and certification body availability, which is often the binding constraint rather than your readiness. Tell us the submission date first and we will answer honestly before quoting.
Typically 18 to 28 weeks. Organisations with mature service desk practice move faster. The longest element is usually building genuine problem management and accumulating enough operational evidence to satisfy a Stage 2 audit.
All capital cities and regional centres. Our ISO 20000-1 work concentrates in Sydney, Melbourne, Canberra, Brisbane, Perth and Adelaide, with delivery largely remote and on-site attendance for workshops and Stage 2 audits.
Send us the evaluation criteria
If a specific bid is driving this, send us the evaluation criteria and the submission date. That determines whether this is a sprint or a proper build, and we would rather tell you which one it is up front.





















0
Projects
0
Services
0
Clients Serving
0
Countries Serving