ISO 20000 Certification in USA
A client has asked for your certificate. IAS audits IT service management systems across the United States and issues ISO 20000 certification against ISO/IEC 20000-1. Talk to an assessor about scope before you commit to anything — contact the IAS team.
ISO/IEC 20000-1 is the standard for a service management system. It is not a tool, not a framework you install, and not a badge you buy. It describes how a provider plans, delivers, monitors and improves services. ISO 20000 certification means an independent body looked at your system and found it working.
Most people arrive here because a customer, a parent company or a bid document asked for it. That is a fine reason. It also means you have a deadline, and the fastest way to lose months is to get the scope wrong. This page explains what the ISO 20000 audit covers, who accredits the body doing the auditing, and where service providers usually trip. If you are weighing it against the rest of the IAS range, the IAS home page is the wider starting point.
Who IAS is, and who assesses IAS
IAS — Integrated Assessment Services — is the body that performs the audit. When IAS issues you a certificate, IAS is the organization standing behind it.
IAS is accredited by UQAS. UQAS is the accreditation body. Its job is to assess IAS — the competence of the auditors, the impartiality controls, the way certification decisions are made, the handling of complaints and appeals. UQAS does not audit your service desk. It audits the people who audit your service desk.
That distinction matters more than it sounds. Accreditation is an assessment of IAS. It confers no approval on the service providers IAS certifies. Your certificate says your service management system met the standard on the days it was assessed. It does not say an accreditation body has inspected, approved or blessed your company.

If a client asks you who accredits your certificate, the answer is short. UQAS accredits IAS. IAS certified your service management system. You can read more about the organization on the IAS about page.
What ISO 20000 certification actually asks for
The standard is written around a service management system, usually shortened to SMS. Buyers often call it ITSM certification; the certificate itself names the service management system. Either way, think of it as the management layer over your delivery work.
It asks you to agree what services you provide and to whom. It asks for planning — capacity, demand, continuity. It asks for control of what you hand to customers: incidents, requests, problems, changes, releases. It asks for measurement, internal audit, management review and correction when something goes wrong.
Some of this will already exist. Most service providers already run incident tickets and a change calendar. What is usually missing is the connecting tissue: documented service requirements, agreed targets, evidence of review, and a record showing that the review changed something.
Scope is the thing people get wrong
Scope is the single biggest cause of delay, rework and awkward conversations with clients. Get it settled first.
Scope for ISO 20000 has to name the services, not just the company. “IT services provided by Acme Inc.” is not a scope. “Managed end-user support, server monitoring and backup services delivered from the Dallas and Phoenix operations centers” is a scope.
Two traps show up again and again.
The first is including services you do not control. If you resell a platform and have no ability to govern its delivery, you cannot certify it as yours. The standard expects you to demonstrate control over the parties in the service chain — through contracts, agreed interfaces and monitoring. If you cannot show that, take it out of scope or fix the control first.
The second is location. If three sites run three different toolsets and three different escalation paths, that is three sets of evidence, not one. Either harmonize the process or name only the sites you can actually evidence. Certifying one site and quietly implying all of them is how disputes start.
| Scope decision | Include it | Leave it out | What decides |
|---|---|---|---|
| Service you deliver in-house | Yes | — | You control the process end to end |
| Service delivered by a subcontractor you govern | Yes, if governed | — | Contract, agreed targets, monitoring evidence |
| Cloud platform you resell with no control | — | Yes | You cannot demonstrate control of delivery |
| Second site on a different toolset | Only if evidenced | Yes, if not | Same documented process, same records |
| New service launching next quarter | — | Yes, for now | Add at the next audit once it has history |
| Internal service with no customer agreement | Only if defined | Yes, if undefined | A service needs agreed requirements |
Write the scope statement early and read it aloud to someone in delivery. If they wince, it is wrong.
The ISO 20000 certification pathway
The route is the same one used across system certification in the USA. It runs in stages, and each stage exists for a reason.
You apply and agree scope. The body reviews what you have sent and confirms the application. Stage 1 is a readiness review — documentation, scope, whether your internal audit and management review have actually happened. Stage 2 is the full assessment against the standard, on site or remote as agreed, with interviews and records. Findings are raised, you correct them, and the body makes a certification decision. Surveillance follows during the certification cycle, then recertification.

The general sequence, the paperwork and the review points are set out in the certification process page, and the way audits are conducted is described in the ISO audit procedure.
One thing surprises people. Stage 1 is not a formality. If your internal audit has not run, or your management review is a calendar invite with no minutes, Stage 2 will not go well. Stage 1 is where you find that out cheaply.
What the audit looks for, and what weak evidence looks like
Auditors work from records. Intentions do not audit well. Here is the difference between something that holds up and something that does not.
| Area | Sound practice | Practice that gets a finding |
|---|---|---|
| Service scope | Named services, named sites, agreed with customers | “All IT services” with no service catalog |
| Service targets | Targets agreed in writing, measured, reported | Targets in a slide deck nobody reports against |
| Incident handling | Priority rules applied consistently, records complete | Priorities set by whoever shouts, half the tickets unclassified |
| Problem management | Recurring incidents traced, root causes closed out | Problem queue exists but nothing has closed in months |
| Change control | Changes assessed, approved, backed out when needed | Emergency changes are the norm, no post-review |
| Supplier control | Contracts with targets, supplier performance reviewed | Supplier named, no agreed targets, no reviews |
| Continuity | Plan tested, results recorded, plan updated after test | Plan written once, never exercised |
| Internal audit | Full coverage over the cycle, findings closed | One audit of one process, findings still open |
| Management review | Minutes, decisions, owners, dates | A standing meeting with no output |
| Improvement | Changes traceable to a trigger and an outcome | An improvement register with no closed entries |
If you read the right-hand column and recognize yourself, that is useful. Fix it before Stage 1 rather than explaining it at Stage 2. The same evidence habits carry over to every audit IAS runs, whether that is ISO 45001 certification for occupational health and safety or ISO 14001 certification for environmental management.
✓ Audits by assessors who work in service delivery | ✓ Scope agreed before you commit | ✓ IAS is accredited by UQAS | ✓ Clear findings, plain language reports
Getting ready without stopping the day job
Preparation does not need to be a project with its own budget line. It needs sequence.
Start with the service catalog. List what you deliver, to whom, with what targets. Then check each target is actually measured by something, not estimated at month end. Then run one honest internal audit against the standard and let it find things. Then hold a real management review, take minutes, and record the decisions.
That order matters. Teams that write documents first end up with a manual that describes a company they do not work for. Teams that start from the catalog end up with documents that match what happens.
If you want your own people to run the internal audits, internal auditor training is the usual route, and lead auditor training suits those running the program. People new to management systems often start with foundation training before anything else. Course dates are listed on the training schedule, and the wider catalog sits under ISO training in the USA, including ISO 9001 internal auditor training and ISO 9001 training online for teams that cannot leave the desk.
Where ISO 20000 certification meets your other certificates
Most service providers do not hold this one alone. Clients often ask for information security alongside service management, and the two systems share a lot of plumbing — supplier control, incident handling, internal audit, management review.
If you already hold ISO 27001 certification, reuse the machinery. One internal audit program, one management review agenda, one corrective action process. Where continuity is a customer requirement, ISO 22301 certification covers it, and ISO 9001 certification covers the general quality system many bidders ask for. Data-center power and cost pressure sometimes brings ISO 50001 certification into the same conversation. Technical testing is a separate matter — see VAPT certification.
If you are the person running several of these programs, the auditor courses stack the same way: ISO 27001 lead auditor training and ISO 22301 lead auditor training cover the two standards most often paired with service management.
Keep the systems joined at the management layer and separate in the detail. Do not try to write one document that satisfies everything.
Who does what
Certification is a shared job with clear boundaries. Confusion here creates friction during the audit.
| Task | Your organization | IAS | UQAS |
|---|---|---|---|
| Define services and scope | Owns it | Reviews and agrees | No role |
| Build and run the SMS | Owns it | No role | No role |
| Internal audit | Owns it | Checks it happened | No role |
| Stage 1 and Stage 2 assessment | Provides evidence | Conducts it | No role |
| Certification decision | No role | Makes it | No role |
| Correcting findings | Owns it | Verifies closure | No role |
| Assessing the certification body | No role | Is assessed | Accredits IAS |
| Using the certificate and marks | Owns it, within the rules | Sets the rules | No role |
Mark and logo use has its own rules. They are set out in the guideline for usage of logos, and it is worth reading before your marketing team puts the certificate on a proposal template.
The improvement cycle after certification
The certificate is not the finish line. Surveillance exists because a service management system that stops being maintained stops being real.

What surveillance looks at, in practice: whether your measurements are still being taken, whether findings from last time were closed and stayed closed, whether the scope still matches what you deliver, and whether anything significant changed — a new site, a major subcontractor, a merged service desk. Tell the body about changes when they happen rather than at the next audit.
Reading the scope on an ISO 20000 certificate
Be precise about this, especially in bids.
A certificate means an independent body assessed your service management system against ISO/IEC 20000-1, within the stated scope, and found it conforming at the time of assessment. That is a substantive claim, and it is worth making.
It does not mean every ticket was handled well. It does not cover services outside the scope, sites not named, or work done after the assessment. It is not a guarantee of service quality, uptime or customer satisfaction, and it is not a warranty on any outcome. It does not certify your people, your products or your tools — only the management system named on the certificate.
State the scope when you cite the certificate. A client who reads the scope line and finds it narrower than your claim will remember it.
A note on legal duties
This page makes no claim about the law in any country, state or city. Nothing here should be read as legal advice, and nothing here says that certification satisfies any statutory or contractual duty.
Certification is voluntary and contractual. Whether any law, regulation or customer contract applies to your services is a question for your own attorneys and advisers. Ask them, not us.
Common ISO 20000 certification mistakes worth avoiding
Scope written by marketing rather than delivery. Targets that nobody measures. A supplier in the chain with no agreed service targets. An internal audit done the week before Stage 2. Documents describing a process the team abandoned two tool migrations ago. A management review with no minutes.
None of these are exotic. All of them are found at Stage 1 or Stage 2, and all of them are cheaper to fix now.
Working with IAS
IAS assesses service management systems for providers across the United States, from internal IT functions to managed service firms. The starting point is a conversation about scope — what services, which sites, which suppliers sit in the chain.
You can see the full range on the ISO certification in USA page, read background material on the IAS blog, or look at how the standard developed. General questions are answered on the FAQ page. Providers outside our direct coverage often work through the IAS associate partners, and assessors who want to do this work themselves can look at the IAS job openings.
Frequently asked questions
Who accredits IAS?
IAS is accredited by UQAS. UQAS assesses IAS as a certification body — auditor competence, impartiality and how certification decisions are made.
Does accreditation mean my company has been approved by UQAS?
No. Accreditation is an assessment of IAS, not of the organizations IAS certifies. Your certificate covers your service management system, within its stated scope.
What exactly gets certified in ISO 20000 certification?
The service management system for the services named in the scope, at the sites named in the scope. Not the company as a whole, and not services you left out.
How do I write the scope statement?
Name the services, the sites and the delivery model. Check that you can evidence the same process everywhere you name. If you cannot, narrow it.
Can I certify a service that a subcontractor delivers?
Only if you can demonstrate control — a contract with agreed targets, monitored performance and a record of review. Without that, leave it out.
What happens at Stage 1?
A readiness review. The auditor checks your documentation, your scope, and whether internal audit and management review have genuinely run. It is where gaps surface before the full assessment.
What is a nonconformity?
A finding that something required by the standard is missing or not working. You propose a correction and a cause analysis, then the body verifies closure before the decision.
Do we need our own trained auditors?
The standard requires internal audits by competent people. Many providers train their own staff; others use external auditors. Either works.
We already hold ISO 27001. Does that help?
Yes. Internal audit, management review, corrective action and supplier control can serve both systems. The service-specific requirements still need their own evidence.
What happens between audits?
Surveillance. The body checks the system is still running, findings stayed closed, and the scope still matches reality. Tell IAS about major changes when they happen.
Can an ISO 20000 certification be withdrawn?
Yes. If the system stops meeting the standard, surveillance is refused, or the marks are misused, the body can suspend or withdraw certification.
Where do I start with ISO 20000 certification?
With your service catalog and a scope conversation. Contact IAS and describe what you deliver and where.
What happens at an ISO 20000 audit if we also hold other certificates?
Shared evidence — internal audit, management review, supplier control — can be looked at once and used for both, provided the records cover the service-specific requirements too. Say so at application and the audit can be planned that way.
Start with scope, not paperwork. Tell IAS which services and which sites you want assessed, and get a straight answer on what the audit will cover — get in touch or read the ISO 20000 certification page.
