ISO 20000 Certification in USA

A client has asked for your certificate. IAS audits IT service management systems across the United States and issues ISO 20000 certification against ISO/IEC 20000-1. Talk to an assessor about scope before you commit to anything — contact the IAS team.

ISO/IEC 20000-1 is the standard for a service management system. It is not a tool, not a framework you install, and not a badge you buy. It describes how a provider plans, delivers, monitors and improves services. ISO 20000 certification means an independent body looked at your system and found it working.

Most people arrive here because a customer, a parent company or a bid document asked for it. That is a fine reason. It also means you have a deadline, and the fastest way to lose months is to get the scope wrong. This page explains what the ISO 20000 audit covers, who accredits the body doing the auditing, and where service providers usually trip. If you are weighing it against the rest of the IAS range, the IAS home page is the wider starting point.

Who IAS is, and who assesses IAS

IAS — Integrated Assessment Services — is the body that performs the audit. When IAS issues you a certificate, IAS is the organization standing behind it.

IAS is accredited by UQAS. UQAS is the accreditation body. Its job is to assess IAS — the competence of the auditors, the impartiality controls, the way certification decisions are made, the handling of complaints and appeals. UQAS does not audit your service desk. It audits the people who audit your service desk.

That distinction matters more than it sounds. Accreditation is an assessment of IAS. It confers no approval on the service providers IAS certifies. Your certificate says your service management system met the standard on the days it was assessed. It does not say an accreditation body has inspected, approved or blessed your company.

Diagram of the accreditation chain: UQAS accredits IAS as a certification body, IAS audits and certifies the service provider, and the service provide
Diagram of the accreditation chain: UQAS accredits IAS as a certification body, IAS audits and certifies the service provider, and the service provider delivers services to its customers — with a note that the accreditation applies to IAS, not to the certified organization.

If a client asks you who accredits your certificate, the answer is short. UQAS accredits IAS. IAS certified your service management system. You can read more about the organization on the IAS about page.

What ISO 20000 certification actually asks for

The standard is written around a service management system, usually shortened to SMS. Buyers often call it ITSM certification; the certificate itself names the service management system. Either way, think of it as the management layer over your delivery work.

It asks you to agree what services you provide and to whom. It asks for planning — capacity, demand, continuity. It asks for control of what you hand to customers: incidents, requests, problems, changes, releases. It asks for measurement, internal audit, management review and correction when something goes wrong.

Some of this will already exist. Most service providers already run incident tickets and a change calendar. What is usually missing is the connecting tissue: documented service requirements, agreed targets, evidence of review, and a record showing that the review changed something.

Scope is the thing people get wrong

Scope is the single biggest cause of delay, rework and awkward conversations with clients. Get it settled first.

Scope for ISO 20000 has to name the services, not just the company. “IT services provided by Acme Inc.” is not a scope. “Managed end-user support, server monitoring and backup services delivered from the Dallas and Phoenix operations centers” is a scope.

Two traps show up again and again.

The first is including services you do not control. If you resell a platform and have no ability to govern its delivery, you cannot certify it as yours. The standard expects you to demonstrate control over the parties in the service chain — through contracts, agreed interfaces and monitoring. If you cannot show that, take it out of scope or fix the control first.

The second is location. If three sites run three different toolsets and three different escalation paths, that is three sets of evidence, not one. Either harmonize the process or name only the sites you can actually evidence. Certifying one site and quietly implying all of them is how disputes start.

Scope decisionInclude itLeave it outWhat decides
Service you deliver in-houseYes—You control the process end to end
Service delivered by a subcontractor you governYes, if governed—Contract, agreed targets, monitoring evidence
Cloud platform you resell with no control—YesYou cannot demonstrate control of delivery
Second site on a different toolsetOnly if evidencedYes, if notSame documented process, same records
New service launching next quarter—Yes, for nowAdd at the next audit once it has history
Internal service with no customer agreementOnly if definedYes, if undefinedA service needs agreed requirements

Write the scope statement early and read it aloud to someone in delivery. If they wince, it is wrong.

The ISO 20000 certification pathway

The route is the same one used across system certification in the USA. It runs in stages, and each stage exists for a reason.

You apply and agree scope. The body reviews what you have sent and confirms the application. Stage 1 is a readiness review — documentation, scope, whether your internal audit and management review have actually happened. Stage 2 is the full assessment against the standard, on site or remote as agreed, with interviews and records. Findings are raised, you correct them, and the body makes a certification decision. Surveillance follows during the certification cycle, then recertification.

Flow diagram of the ISO 20000 certification pathway from application and scope agreement, through Stage 1 readiness review and Stage 2 assessment, to
Flow diagram of the ISO 20000 certification pathway from application and scope agreement, through Stage 1 readiness review and Stage 2 assessment, to findings and correction, the certification decision, surveillance visits and recertification at the end of the cycle.

The general sequence, the paperwork and the review points are set out in the certification process page, and the way audits are conducted is described in the ISO audit procedure.

One thing surprises people. Stage 1 is not a formality. If your internal audit has not run, or your management review is a calendar invite with no minutes, Stage 2 will not go well. Stage 1 is where you find that out cheaply.

What the audit looks for, and what weak evidence looks like

Auditors work from records. Intentions do not audit well. Here is the difference between something that holds up and something that does not.

AreaSound practicePractice that gets a finding
Service scopeNamed services, named sites, agreed with customers“All IT services” with no service catalog
Service targetsTargets agreed in writing, measured, reportedTargets in a slide deck nobody reports against
Incident handlingPriority rules applied consistently, records completePriorities set by whoever shouts, half the tickets unclassified
Problem managementRecurring incidents traced, root causes closed outProblem queue exists but nothing has closed in months
Change controlChanges assessed, approved, backed out when neededEmergency changes are the norm, no post-review
Supplier controlContracts with targets, supplier performance reviewedSupplier named, no agreed targets, no reviews
ContinuityPlan tested, results recorded, plan updated after testPlan written once, never exercised
Internal auditFull coverage over the cycle, findings closedOne audit of one process, findings still open
Management reviewMinutes, decisions, owners, datesA standing meeting with no output
ImprovementChanges traceable to a trigger and an outcomeAn improvement register with no closed entries

If you read the right-hand column and recognize yourself, that is useful. Fix it before Stage 1 rather than explaining it at Stage 2. The same evidence habits carry over to every audit IAS runs, whether that is ISO 45001 certification for occupational health and safety or ISO 14001 certification for environmental management.

✓ Audits by assessors who work in service delivery | ✓ Scope agreed before you commit | ✓ IAS is accredited by UQAS | ✓ Clear findings, plain language reports

Getting ready without stopping the day job

Preparation does not need to be a project with its own budget line. It needs sequence.

Start with the service catalog. List what you deliver, to whom, with what targets. Then check each target is actually measured by something, not estimated at month end. Then run one honest internal audit against the standard and let it find things. Then hold a real management review, take minutes, and record the decisions.

That order matters. Teams that write documents first end up with a manual that describes a company they do not work for. Teams that start from the catalog end up with documents that match what happens.

If you want your own people to run the internal audits, internal auditor training is the usual route, and lead auditor training suits those running the program. People new to management systems often start with foundation training before anything else. Course dates are listed on the training schedule, and the wider catalog sits under ISO training in the USA, including ISO 9001 internal auditor training and ISO 9001 training online for teams that cannot leave the desk.

Where ISO 20000 certification meets your other certificates

Most service providers do not hold this one alone. Clients often ask for information security alongside service management, and the two systems share a lot of plumbing — supplier control, incident handling, internal audit, management review.

If you already hold ISO 27001 certification, reuse the machinery. One internal audit program, one management review agenda, one corrective action process. Where continuity is a customer requirement, ISO 22301 certification covers it, and ISO 9001 certification covers the general quality system many bidders ask for. Data-center power and cost pressure sometimes brings ISO 50001 certification into the same conversation. Technical testing is a separate matter — see VAPT certification.

If you are the person running several of these programs, the auditor courses stack the same way: ISO 27001 lead auditor training and ISO 22301 lead auditor training cover the two standards most often paired with service management.

Keep the systems joined at the management layer and separate in the detail. Do not try to write one document that satisfies everything.

Who does what

Certification is a shared job with clear boundaries. Confusion here creates friction during the audit.

TaskYour organizationIASUQAS
Define services and scopeOwns itReviews and agreesNo role
Build and run the SMSOwns itNo roleNo role
Internal auditOwns itChecks it happenedNo role
Stage 1 and Stage 2 assessmentProvides evidenceConducts itNo role
Certification decisionNo roleMakes itNo role
Correcting findingsOwns itVerifies closureNo role
Assessing the certification bodyNo roleIs assessedAccredits IAS
Using the certificate and marksOwns it, within the rulesSets the rulesNo role

Mark and logo use has its own rules. They are set out in the guideline for usage of logos, and it is worth reading before your marketing team puts the certificate on a proposal template.

The improvement cycle after certification

The certificate is not the finish line. Surveillance exists because a service management system that stops being maintained stops being real.

Diagram of the continual cycle after certification: plan the service management system, deliver and operate services, monitor and measure against agre
Diagram of the continual cycle after certification: plan the service management system, deliver and operate services, monitor and measure against agreed targets, review and correct — feeding back into planning, with surveillance audits checking the cycle is running.

What surveillance looks at, in practice: whether your measurements are still being taken, whether findings from last time were closed and stayed closed, whether the scope still matches what you deliver, and whether anything significant changed — a new site, a major subcontractor, a merged service desk. Tell the body about changes when they happen rather than at the next audit.

Reading the scope on an ISO 20000 certificate

Be precise about this, especially in bids.

A certificate means an independent body assessed your service management system against ISO/IEC 20000-1, within the stated scope, and found it conforming at the time of assessment. That is a substantive claim, and it is worth making.

It does not mean every ticket was handled well. It does not cover services outside the scope, sites not named, or work done after the assessment. It is not a guarantee of service quality, uptime or customer satisfaction, and it is not a warranty on any outcome. It does not certify your people, your products or your tools — only the management system named on the certificate.

State the scope when you cite the certificate. A client who reads the scope line and finds it narrower than your claim will remember it.

A note on legal duties

This page makes no claim about the law in any country, state or city. Nothing here should be read as legal advice, and nothing here says that certification satisfies any statutory or contractual duty.

Certification is voluntary and contractual. Whether any law, regulation or customer contract applies to your services is a question for your own attorneys and advisers. Ask them, not us.

Common ISO 20000 certification mistakes worth avoiding

Scope written by marketing rather than delivery. Targets that nobody measures. A supplier in the chain with no agreed service targets. An internal audit done the week before Stage 2. Documents describing a process the team abandoned two tool migrations ago. A management review with no minutes.

None of these are exotic. All of them are found at Stage 1 or Stage 2, and all of them are cheaper to fix now.

Working with IAS

IAS assesses service management systems for providers across the United States, from internal IT functions to managed service firms. The starting point is a conversation about scope — what services, which sites, which suppliers sit in the chain.

You can see the full range on the ISO certification in USA page, read background material on the IAS blog, or look at how the standard developed. General questions are answered on the FAQ page. Providers outside our direct coverage often work through the IAS associate partners, and assessors who want to do this work themselves can look at the IAS job openings.

Frequently asked questions

Who accredits IAS?

IAS is accredited by UQAS. UQAS assesses IAS as a certification body — auditor competence, impartiality and how certification decisions are made.

Does accreditation mean my company has been approved by UQAS?

No. Accreditation is an assessment of IAS, not of the organizations IAS certifies. Your certificate covers your service management system, within its stated scope.

What exactly gets certified in ISO 20000 certification?

The service management system for the services named in the scope, at the sites named in the scope. Not the company as a whole, and not services you left out.

How do I write the scope statement?

Name the services, the sites and the delivery model. Check that you can evidence the same process everywhere you name. If you cannot, narrow it.

Can I certify a service that a subcontractor delivers?

Only if you can demonstrate control — a contract with agreed targets, monitored performance and a record of review. Without that, leave it out.

What happens at Stage 1?

A readiness review. The auditor checks your documentation, your scope, and whether internal audit and management review have genuinely run. It is where gaps surface before the full assessment.

What is a nonconformity?

A finding that something required by the standard is missing or not working. You propose a correction and a cause analysis, then the body verifies closure before the decision.

Do we need our own trained auditors?

The standard requires internal audits by competent people. Many providers train their own staff; others use external auditors. Either works.

We already hold ISO 27001. Does that help?

Yes. Internal audit, management review, corrective action and supplier control can serve both systems. The service-specific requirements still need their own evidence.

What happens between audits?

Surveillance. The body checks the system is still running, findings stayed closed, and the scope still matches reality. Tell IAS about major changes when they happen.

Can an ISO 20000 certification be withdrawn?

Yes. If the system stops meeting the standard, surveillance is refused, or the marks are misused, the body can suspend or withdraw certification.

Where do I start with ISO 20000 certification?

With your service catalog and a scope conversation. Contact IAS and describe what you deliver and where.

What happens at an ISO 20000 audit if we also hold other certificates?

Shared evidence — internal audit, management review, supplier control — can be looked at once and used for both, provided the records cover the service-specific requirements too. Say so at application and the audit can be planned that way.

Start with scope, not paperwork. Tell IAS which services and which sites you want assessed, and get a straight answer on what the audit will cover — get in touch or read the ISO 20000 certification page.