ISO 20000 History: The Genesis, Origins & Evolution of the Standard
ISO 20000 is the international standard for an IT Service Management System (ITSMS), and its story begins with the British Standard BS 15000, which was shaped by ITIL best practice before being adopted worldwide as ISO/IEC 20000 in 2005. Understanding the history of ISO 20000 is more than an academic exercise. It explains why the standard is structured the way it is, how it relates to frameworks like ITIL, and why it remains one of the most trusted benchmarks for organizations that deliver IT services. This article traces the genesis, origins, and evolution of ISO 20000, then explains what the standard looks like today and why it still matters for IT service providers.
What Is ISO/IEC 20000?
ISO/IEC 20000 is the international standard that specifies the requirements for an IT Service Management System, often abbreviated as ITSMS or simply SMS. In plain terms, it defines what an organization must do to plan, design, deliver, operate, and continually improve its IT services so that they consistently meet the needs of the business and its customers.
The standard is published in parts. Part 1 sets out the certifiable requirements, the things an IT service provider must demonstrate to earn certification. Part 2 is a code of practice that offers guidance on how to apply those requirements. Because it is a management system standard, ISO/IEC 20000 focuses on establishing repeatable, measurable processes rather than prescribing specific technologies. That makes it applicable to in-house IT departments, managed service providers, cloud vendors, and outsourcing firms alike.
Crucially, ISO/IEC 20000 is certified to organizations, specifically to the IT service providers that operate the service management system, not to individuals. When a provider says it is “ISO 20000 certified,” it means an accredited certification body has independently assessed its service management system and confirmed it meets the requirements of the standard.
The Origins of ISO 20000: BS 15000 and ITIL
Every international standard has a lineage, and the roots of ISO 20000 reach back to the United Kingdom. The direct ancestor of the standard is BS 15000, the British Standard for IT service management. BS 15000 was first published in 2000 and then revised in 2002 and 2003 as practitioners refined its approach.
BS 15000 did not appear from nowhere. It was heavily influenced by ITIL, the IT Infrastructure Library, a collection of best-practice guidance for IT service management that had been developed in the UK. ITIL described how IT services could be managed effectively through defined processes covering areas such as incident, problem, change, and service level management. BS 15000 took that body of best practice and distilled it into a formal, auditable specification, something an organization could actually be certified against.
This distinction is the key to the whole story. ITIL offered guidance on good practice, but guidance alone cannot be certified. BS 15000 turned those principles into a set of requirements, creating the template that would soon become an international standard.
Adoption as ISO/IEC 20000 in 2005
The success and clarity of BS 15000 attracted international attention. In 2005, the standard was adopted at the international level and published as ISO/IEC 20000, developed jointly under the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC).
The first edition mirrored the structure that had proven effective in Britain. It was released in two parts:
- ISO/IEC 20000-1:2005 — the specification, containing the formal requirements for an IT service management system that an organization could be certified against.
- ISO/IEC 20000-2:2005 — the code of practice, providing guidance and recommendations on how to meet those requirements.
With this move, IT service management gained its first truly global, certifiable standard. Organizations anywhere in the world could now be assessed against a common, internationally recognized benchmark, rather than relying on a national standard or on best-practice guidance that carried no certificate.
The 2011 Revision
Standards are living documents, and ISO/IEC 20000 was revised in 2011 to keep pace with how IT service management had matured. The revision refined and sharpened the requirements of Part 1, improving the alignment between the specification and the way modern service providers actually worked.
This update reinforced the process-based, continual-improvement philosophy at the heart of the standard. It kept ISO/IEC 20000 relevant as IT environments grew more complex and as customers demanded greater consistency, accountability, and transparency from their service providers.
The Current Version: ISO/IEC 20000-1:2018
The current edition of Part 1 is ISO/IEC 20000-1:2018. This is the version organizations are certified against today, and it represents the most recent step in the standard’s evolution.
The 2018 edition continues to define requirements for planning, designing, delivering, and improving IT services, all within a structured management system. It emphasizes leadership, risk-based thinking, and the ongoing improvement of services, reflecting the wider evolution of ISO management system standards toward a common, business-focused structure. For an IT service provider, achieving ISO/IEC 20000-1:2018 certification signals that its service management system meets a rigorous, up-to-date international benchmark.
An ISO 20000 Timeline at a Glance
The evolution of ISO 20000 is easiest to grasp as a timeline:
- 2000 — BS 15000, the British Standard for IT service management, is first published, influenced by ITIL best practice.
- 2002 / 2003 — BS 15000 is revised as the approach is refined in practice.
- 2005 — BS 15000 is adopted internationally and published as ISO/IEC 20000 (Part 1: specification; Part 2: code of practice).
- 2011 — ISO/IEC 20000 is revised, sharpening the requirements of Part 1.
- 2018 — ISO/IEC 20000-1:2018, the current version of Part 1, is published.
This progression, from national standard to global benchmark, shows how a single, well-designed specification can shape IT service management across the world.
ISO 20000 vs ITIL: Complementary, Not Interchangeable
Because ISO 20000 grew out of a standard influenced by ITIL, the two are often mentioned together, and sometimes confused. They are closely related but serve different purposes.
ITIL is a framework of best-practice guidance. It describes how IT service management can be done well, offering detailed advice, terminology, and process descriptions. However, ITIL is guidance, and an organization cannot be formally certified against it as a management system.
ISO/IEC 20000 is the certifiable standard. It sets out requirements that an IT service provider must meet, and an accredited certification body can independently audit an organization against those requirements and issue a certificate.
In practice, the two complement each other. Many organizations use ITIL guidance to help build and refine their service management processes, then use ISO/IEC 20000 to formally demonstrate, through independent certification, that those processes meet an internationally recognized standard. ITIL helps you get there; ISO 20000 proves you have arrived.
Why ISO 20000 Matters Today
The history of ISO 20000 explains its structure, but its present-day value is what makes it worth pursuing. For modern IT service providers, certification delivers several concrete benefits.
- Consistent, reliable service. The standard drives defined, repeatable processes that reduce variability and improve the quality of IT services.
- Independent credibility. Certification by an accredited body offers objective proof that an organization’s service management system meets a global benchmark, which is valuable in competitive tenders and customer due diligence. Our guide to ISO certification benefits explores this value in more detail.
- A culture of continual improvement. ISO/IEC 20000 embeds ongoing measurement and improvement, helping providers adapt as technology and customer expectations change.
- Better alignment with the business. By focusing on services that meet defined requirements, the standard helps IT deliver measurable value rather than just technical output.
- Compatibility with other standards. Its management-system structure makes it easier to integrate with other frameworks a provider may already operate, such as information security or quality management systems.
For any provider whose reputation depends on the dependability of its IT services, ISO 20000 remains a powerful way to demonstrate maturity and earn trust.
Getting ISO 20000 Certified With IAS
At Integrated Assessment Services (IAS), we help IT service providers pursue ISO 20000 certification against the current requirements of the standard. As an established certification body, IAS assesses your service management system independently and transparently, so your certificate carries genuine weight with customers and partners.
If you are new to the world of ISO standards, our ISO certification hub explains the broader landscape, and our system certification page covers management system standards more generally. To understand what an assessment involves from start to finish, review our certification process, our blog on the ISO certification process, and, if your team needs to build knowledge first, take a look at our training schedule. It also helps to understand the role of ISO certification bodies before you begin.
To discuss ISO 20000 certification for your organization, simply contact us and our team will guide you through the next steps. IAS is part of a global network of assessment and certification organizations, including EAS, giving clients confidence in a well-connected, internationally minded body.


