Call Us: 855.476.2701
Follow Us:

News

How to Prepare for ISO 20000 Certification Audit

What is an ISO 20000 certification audit?

An ISO 20000 certification audit is an independent assessment of whether an organization’s service management system conforms to ISO/IEC 20000-1 and operates effectively. The auditor evaluates the services within the certification scope using interviews, observations, documented information, and samples of operational records.

How should an organization prepare for an ISO 20000 certification audit?

This guide explains how to confirm the audit scope, assess readiness, organize objective evidence, complete internal audits and management reviews, prepare employees for interviews, and address common ISO 20000 audit findings.

Preparing for an ISO 20000 certification audit involves more than organizing policies and procedures. The organization must show that responsibilities, controls, service records, performance reviews, and improvement activities form a working service management system.

The current certification standard is ISO/IEC 20000-1:2018, including Amendment 1:2024 on climate action changes. Effective preparation connects these requirements with the organization’s normal service management activities rather than creating a temporary set of records for the auditor.

ISO 20000 audit preparation matters because written procedures alone do not prove that a service management system works. Organizations need reliable evidence that responsibilities are understood, services are controlled, performance is reviewed, problems are corrected, and improvements produce meaningful results.

What Does an ISO 20000 Certification Audit Cover?

The audit focuses on how the organization manages the services included within its certification scope. Auditors test whether required controls have been implemented and whether those controls produce reliable service management outcomes.

The assessment may examine the following areas:

  • Service management governance, policy, and objectives
  • Service management planning
  • Risks and opportunities
  • Service requirements and the service catalog
  • Service-level management and reporting
  • Supplier and internal-provider controls
  • Incident, service-request, and problem management
  • Change, release, and deployment controls
  • Service availability and continuity
  • Performance evaluation and management review
  • Internal auditing, corrective action, and continual improvement

The auditor does not simply confirm that documents exist. Objective evidence must show that processes are understood, followed, monitored, and improved across the services being assessed.

Certification audits must be performed by a qualified certification body. iCertWorks provides training, internal audit support, and audit-readiness assistance but does not issue ISO management-system certifications.

Why Does ISO 20000 Audit Readiness Matter?

Audit readiness helps an organization identify weaknesses that routine operational reporting may not reveal. A service desk could meet its response target, for example, while lacking reliable evidence of trend analysis, corrective action, or management oversight.

A structured readiness review can help the organization:

  • Confirm that the certification scope is accurate
  • Find differences between documented procedures and actual practices
  • Verify that employees understand their responsibilities
  • Identify missing, inconsistent, or unreliable evidence
  • Address nonconformities before the certification assessment
  • Improve coordination across teams, suppliers, and services
  • Demonstrate effective control to customers and interested parties

The aim is not to present a perfect-looking collection of documents. The organization needs to demonstrate that its service management system is controlled, effective, and capable of responding to change.

When Should Audit Preparation Begin?

Preparation should begin once the service management system has been implemented and sufficient operating evidence is available. The organization should be able to demonstrate completed activities, measured results, identified problems, and resulting improvements.

At least one internal audit and management review should be completed before the certification assessment. Important corrective actions should also be closed or progressing under a controlled and credible plan.

Waiting until the audit date is close creates avoidable risk. Missing historical records cannot always be recreated, and employees need time to apply revised processes consistently.

Who Should Participate in Audit Preparation?

Audit preparation is not solely the responsibility of a compliance manager. Everyone whose work affects an in-scope service may need to explain their responsibilities or provide evidence.

Relevant participants commonly include:

  • Senior management and the service management system owner
  • Service and process owners
  • Service desk and operational personnel
  • Change, release, risk, and continuity managers
  • Supplier managers
  • Internal auditors
  • Human resources or training coordinators
  • Technical teams and supporting departments

Employees do not need to memorize ISO/IEC 20000-1. They should understand the processes relevant to their roles, follow those processes consistently, and know where their operational records are retained.

What Happens During Stage 1 and Stage 2?

An initial ISO 20000 certification audit is commonly divided into two stages. Each stage has a different purpose and should be prepared for accordingly.

Stage 1: Readiness Review

Stage 1 evaluates whether the organization is sufficiently prepared for the detailed certification assessment. It also gives the certification body a clearer understanding of the scope, locations, services, and operational complexity.

The Stage 1 review may consider:

  • The service management system scope
  • Service management policies and objectives
  • The service management plan
  • Required documented information
  • Legal, regulatory, contractual, and service requirements
  • Internal audit and management review arrangements
  • Locations and operating conditions
  • The organization’s understanding of ISO/IEC 20000-1

Stage 1 may identify concerns that could become nonconformities during Stage 2. The organization should investigate and address those concerns before the detailed assessment begins.

Stage 2: Implementation and Effectiveness

Stage 2 determines whether the service management system has been implemented and operates effectively. Auditors use interviews, observations, document reviews, and record sampling to test the system.

Evidence examined during Stage 2 may include:

  • Incident and service-request records
  • Change approvals and release records
  • Service performance reports
  • Supplier monitoring and review records
  • Customer feedback and complaints
  • Risk treatment activities
  • Continuity exercises
  • Internal audit findings
  • Management review decisions
  • Corrective actions and improvement results

A documented procedure will not be sufficient when interviews and records show that employees routinely follow a different process.


Review ISO 20000 certification and audit requirements →

ISO 20000 Certification Audit Preparation Checklist

The following checklist focuses on the areas that most directly affect certification readiness. Each activity should produce evidence that can be traced to an accountable owner and an applicable requirement.

1. Confirm the Service Management System Scope

Define the services, organizational units, locations, customers, technologies, and external providers included in the service management system. The scope must reflect how services are actually managed and delivered.

Use the same scope in policies, plans, internal audits, management reviews, and certification communications. Important service dependencies should not disappear simply because they are operated by a supplier or shared department.

2. Map Requirements to Processes and Evidence

Review every applicable ISO/IEC 20000-1 requirement and connect it to an operational process, accountable owner, controlled document, and supporting record.

A useful requirements map should identify:

  • The applicable requirement
  • The responsible process and owner
  • The governing policy, plan, or procedure
  • The records demonstrating implementation
  • The measures used to evaluate effectiveness

The review should include Amendment 1:2024. The organization must determine whether climate change is a relevant issue and consider whether interested parties have relevant climate-related requirements.

3. Perform a Gap Analysis

Compare the current service management system with the applicable requirements. Avoid recording a simple compliant or noncompliant result without explaining the supporting evidence.

For each identified gap, record:

  • The requirement and current practice
  • The missing or ineffective control
  • The operational and certification risk
  • The required action and accountable owner
  • The target completion date
  • The evidence required to confirm closure

Prioritize gaps affecting scope, leadership, service planning, operational control, internal auditing, management review, and corrective action.

4. Review Controlled Documentation

Confirm that policies, procedures, plans, registers, and templates are current, approved, accessible, and protected from unintended change. Obsolete versions should be removed or clearly identified.

Relevant documented information may include:

  • The service management system scope, policy, and objectives
  • The service management plan and service catalog
  • Service-level agreements and performance reports
  • Risk, supplier, incident, problem, change, and release records
  • Service availability and continuity plans
  • Competence and training records
  • Internal audit reports and management review outputs
  • Nonconformity, corrective-action, and improvement records

Documentation should be proportionate to the organization’s size, complexity, risks, and operating needs. Excessive documentation creates its own audit risk when employees cannot maintain or follow it.

5. Test Evidence Across Complete Service Activities

Select representative services and trace activities from beginning to end. This approach tests process handoffs and provides a more realistic view than reviewing each procedure separately.

Useful end-to-end samples include:

  • A major incident from reporting through review and corrective action
  • A service change from request through authorization and deployment
  • A supplier failure from detection through escalation and resolution
  • A missed service target from reporting through management action
  • A continuity exercise from planning through lessons learned
  • An improvement initiative from approval through effectiveness review

End-to-end testing often reveals unclear ownership, inconsistent records, and uncontrolled handoffs between teams.

6. Complete the Internal Audit

The internal audit should evaluate both conformity and effectiveness. Internal auditors should be objective and sufficiently independent of the work being examined.

An effective internal audit should:

  • Sample operational records
  • Interview relevant employees
  • Compare documented and actual practices
  • Evaluate whether controls produce intended results
  • Record findings clearly
  • Track corrective actions to completion
  • Verify the effectiveness of completed actions

A checklist marking every requirement compliant without supporting samples provides little assurance that the service management system works.

7. Conduct the Management Review

Senior management should complete a substantive review of the service management system before the certification audit. The review should lead to decisions, assigned actions, and resource commitments where necessary.

Management should consider:

  • Progress against service management objectives
  • Service and supplier performance
  • Customer and interested-party feedback
  • Risks and opportunities
  • Internal audit results
  • Nonconformities and corrective actions
  • Changes affecting the service management system
  • Resource, competence, and improvement needs

Retain evidence of decisions, owners, resources, and deadlines. Meeting notes that only list discussion topics do not demonstrate effective management control.

8. Close Corrective Actions Properly

Do not close a finding merely because a missing document was created or an employee was reminded of a procedure. Corrective action must address why the problem occurred.

A complete corrective-action process should:

  1. Correct or contain the immediate problem.
  2. Determine the underlying cause.
  3. Check whether similar problems exist elsewhere.
  4. Implement action addressing the cause.
  5. Verify that the action was effective.

Certification auditors may revisit internal findings to determine whether the organization can identify, correct, and prevent recurring problems.

9. Prepare Employees for Audit Interviews

Employees should understand the service management policy, relevant objectives, their responsibilities, and the processes they perform. They should also know where controlled procedures and records are located.

Preparation should help employees understand:

  • Why the audit is taking place
  • Which services and activities are in scope
  • How to locate controlled information
  • How problems and risks are escalated
  • How improvement opportunities are reported
  • Who can assist with evidence requests

Employees should describe normal working practices honestly. Rehearsed answers create risk when supporting records tell a different story.

10. Organize Audit Logistics

Confirm the audit plan, dates, locations, time zones, attendees, confidentiality arrangements, and evidence-sharing method with the certification body.

Practical arrangements should cover:

  • An audit coordinator and available process owners
  • Meeting rooms or remote-conferencing access
  • Secure access to records and system demonstrations
  • Site access where physical observation is required
  • A controlled method for tracking evidence requests

An audit may be on-site, remote, or hybrid. The certification body selects the method after considering risk, objectives, service complexity, evidence access, technology, and the need for physical observation.

What Are the Most Common ISO 20000 Audit Findings?

Audit findings frequently arise where formal processes and operational practices have moved apart. The following weaknesses deserve attention during readiness reviews.

Unclear Scope and Service Dependencies

The scope may not explain how suppliers, shared services, cloud platforms, or supporting departments affect service delivery. Map important dependencies and show how externally performed activities remain controlled.

Inconsistent Roles and Responsibilities

Procedures, job descriptions, and responsibility matrices may identify different owners. Responsibilities should align across controlled information and normal working practices.

Weak Service-Level Monitoring

Some organizations report whether targets were met without investigating recurring failures, customer effects, or necessary actions. Monitoring should support evaluation, decisions, and improvement.

Poor Supplier Control

A signed contract does not provide complete evidence of supplier management. The organization should demonstrate performance monitoring, review meetings, escalations, risk management, and corrective actions.

Risk Management Is Disconnected From Operations

A generic risk register has limited value when identified risks do not influence service planning, supplier oversight, continuity arrangements, or change decisions.

Continual Improvement Cannot Be Demonstrated

Improvements may occur informally without priorities, owners, expected outcomes, or effectiveness reviews. A controlled improvement process should connect identified opportunities with measurable results.

What Happens When an Auditor Finds a Nonconformity?

A nonconformity means that an applicable requirement has not been fulfilled. The certification body may classify the finding according to its significance and whether it indicates an isolated or systemic failure.

The organization will normally need to complete several actions:

  • Correct or contain the immediate issue
  • Analyze the underlying cause
  • Define and implement corrective action
  • Submit evidence within the required timeframe
  • Demonstrate that the action is effective

Significant or unresolved nonconformities may delay certification. The certification body determines whether documentary evidence or additional audit activity is required.

How Can Training Support ISO 20000 Audit Readiness?

Audit readiness depends on people who can interpret requirements, evaluate evidence, manage corrective actions, and integrate the service management system with routine operations.

ISO 20000 Lead Auditor Training supports professionals responsible for planning audits, interviewing personnel, evaluating evidence, documenting findings, and reporting conclusions.

Lead Implementer development is more relevant to professionals responsible for establishing, operating, maintaining, and continually improving the service management system. The two roles are complementary but serve different operational needs.


Build practical ISO 20000 implementation and audit-readiness capability →

Frequently Asked Questions

Is ISO 20000 mandatory?

ISO/IEC 20000-1 certification is generally voluntary. It may become necessary when required by a customer, contract, procurement process, regulator, or other binding commitment. An organization can also implement the standard without pursuing third-party certification.

Will the ISO 20000 auditor question employees?

Yes. Auditors interview employees to determine whether documented processes reflect normal working practices. Employees may be asked about their responsibilities, service objectives, incidents, changes, escalation routes, risks, records, and improvement activities.

How long does ISO 20000 certification last?

Management-system certification commonly follows a three-year cycle, subject to surveillance activities and successful recertification. The selected certification body should confirm the audit schedule and the conditions for maintaining certification.

Can an ISO 20000 certification audit be conducted remotely?

An ISO 20000 audit may be conducted on-site, remotely, or through a hybrid approach. The certification body selects an appropriate method based on the audit objectives, service complexity, risk, access to evidence, available technology, and need for physical observation.

How much does an ISO 20000 certification audit cost?

There is no universal audit price. Cost depends on factors such as the certification scope, employee numbers, service complexity, number of locations, external providers, audit duration, existing certifications, and travel requirements. Organizations should request a written quotation based on an accurately defined scope.

What documents are needed for an ISO 20000 certification audit?

The organization needs the documented information required by ISO/IEC 20000-1 and sufficient records to demonstrate effective operation. Relevant evidence may include the service management system scope, policy, objectives, service management plan, service agreements, risk records, operational records, internal audit reports, management review outputs, and corrective actions.

How long does ISO 20000 audit preparation take?

Preparation time depends on the maturity, size, scope, and complexity of the service management system. An organization with established controls and reliable records may need a focused readiness review, while an organization implementing the system for the first time may require several months or longer.

What is the difference between an internal audit and a certification audit?

An internal audit is conducted for the organization to evaluate its own service management system and identify weaknesses. A certification audit is an independent assessment performed by a certification body to determine whether the applicable certification requirements have been fulfilled.

Can an organization fail an ISO 20000 certification audit?

Certification can be delayed or withheld when unresolved nonconformities prevent the certification body from confirming conformity. The organization will normally need to analyze the causes, complete corrective actions, and provide acceptable evidence under the certification body’s procedures.

Does ISO 20000 apply only to IT departments?

No. ISO/IEC 20000-1 can apply to an organization or part of an organization that manages and delivers services to internal or external customers. Its applicability is determined by the services and service management system included in the defined scope.

Prepare for Your ISO 20000 Certification Audit

Effective preparation brings documentation, operational practice, employee understanding, and objective evidence into alignment. Begin by confirming the scope, mapping requirements to real processes, and testing whether the service management system produces its intended results.

Complete the internal audit and management review before the certification assessment. Address the causes of identified weaknesses, retain credible evidence, and ensure that employees can explain the work they perform.

iCertWorks provides professional training, internal audit support, and audit-readiness assistance. Certification decisions and ISO management-system certificates remain the responsibility of the selected certification body.

Frequently Asked Questions

Is ISO 20000 mandatory?

ISO/IEC 20000-1 certification is generally voluntary. It may become necessary when required by a customer, contract, procurement process, regulator, or other binding commitment. An organization can also implement the standard without pursuing third-party certification.

Will the ISO 20000 auditor question employees?

Yes. Auditors interview employees to determine whether documented processes reflect normal working practices. Employees may be asked about their responsibilities, service objectives, incidents, changes, escalation routes, risks, records, and improvement activities.

How long does ISO 20000 certification last?

Management-system certification commonly follows a three-year cycle, subject to surveillance activities and successful recertification. The selected certification body should confirm the audit schedule and the conditions for maintaining certification.

Can an ISO 20000 certification audit be conducted remotely?

An ISO 20000 audit may be conducted on-site, remotely, or through a hybrid approach. The certification body selects an appropriate method based on the audit objectives, service complexity, risk, access to evidence, available technology, and need for physical observation.

How much does an ISO 20000 certification audit cost?

There is no universal audit price. Cost depends on factors such as the certification scope, employee numbers, service complexity, number of locations, external providers, audit duration, existing certifications, and travel requirements. Organizations should request a written quotation based on an accurately defined scope.

What documents are needed for an ISO 20000 certification audit?

The organization needs the documented information required by ISO/IEC 20000-1 and sufficient records to demonstrate effective operation. Relevant evidence may include the service management system scope, policy, objectives, service management plan, service agreements, risk records, operational records, internal audit reports, management review outputs, and corrective actions.

How long does ISO 20000 audit preparation take?

Preparation time depends on the maturity, size, scope, and complexity of the service management system. An organization with established controls and reliable records may need a focused readiness review, while an organization implementing the system for the first time may require several months or longer.

What is the difference between an internal audit and a certification audit?

An internal audit is conducted for the organization to evaluate its own service management system and identify weaknesses. A certification audit is an independent assessment performed by a certification body to determine whether the applicable certification requirements have been fulfilled.

Can an organization fail an ISO 20000 certification audit?

Certification can be delayed or withheld when unresolved nonconformities prevent the certification body from confirming conformity. The organization will normally need to analyze the causes, complete corrective actions, and provide acceptable evidence under the certification body’s procedures.

Does ISO 20000 apply only to IT departments?

No. ISO/IEC 20000-1 can apply to an organization or part of an organization that manages and delivers services to internal or external customers. Its applicability is determined by the services and service management system included in the defined scope.

Contact us

    TrainingCertification AuditOther GRC Audit

    Looking for

    ISO 27001 Training?

    © 2026 iCertWorks LLC. All right reserved.