Home · Compliance · ISO/IEC 20000-1
ISO certification · ISO/IEC 20000-1IT services

Keybridge prepares ISO/IEC 20000-1 certification in Iraq and Kurdistan.

Define, deliver, monitor and improve the services within your service-management scope. We confirm the scope and the buyer’s stated requirements before preparation starts. Buyer acceptance depends on the certificate scope, issuing body and the requirements set by the buyer. We review those requirements before preparation.

ISO/IEC 20000-1 IT service management systems

ISO/IEC 20000-1 at a glance

Published
September 2018. ISO/IEC 20000-1:2018 is the current edition. It replaced the 2011 edition and moved the standard onto the Annex SL structure.
Structure
Annex SL high level structure. 10 clauses, and clauses 4 to 10 carry the auditable requirements. Clause 8 holds the service management processes and is the longest clause in the standard.
Certifiable
Yes. The company is certified for a named set of services. There is no certificate for a product, a tool or a person under this standard.
Certificate validity
The assessment body confirms the applicable schedule and continuing requirements for your scope.
Surveillance
The assessment body confirms the applicable schedule and continuing requirements for your scope.
Audit days, 10 to 50 people
The assessment body confirms the applicable schedule and continuing requirements for your scope.
What the scope covers
Only the sites and activities written into the scope. Anything left out of it is not covered.
What the certificate says
The company name, the standard, the scope and the dates the certificate runs.
Language of the system
We write the policies and procedures in Arabic, Kurdish or English. Service desk tickets, change records and service reports are usually kept in English because the tools are in English.

What ISO/IEC 20000-1 is

ISO/IEC 20000-1:2018 is the international standard for a service management system. It asks a company to name the services it delivers, agree measurable targets for each one, control changes and releases, and record how incidents, service requests and problems are handled and closed. It applies to a defined set of services.

What the standard requires

  1. Clauses 1 to 3 cover scope, normative references and terms. Clauses 4 to 10 are the requirements an auditor checks, and clause 8 carries most of them.
  2. Clause 4, context. Name the parties that matter, fix which services the system covers, and state which parts of those services are delivered by other parties.
  3. Clause 5, leadership. Management signs the service management policy and names an owner for every process in writing.
  4. Clause 6, planning. Set service management objectives with numbers and dates, and plan how the services in scope will be delivered.
  5. Clause 7, support. Competence records for the service desk and the engineers, plus version control over the documented information.
  6. Clauses 8.2 to 8.4, portfolio and agreements. Service catalogue, service level agreements with measurable targets, supplier contracts, configuration records, budgeting, demand and capacity planning.
  7. Clause 8.5, design, build and transition. A record for every change, an approval step before production, and controlled release and deployment.
  8. Clause 8.6, resolution and fulfilment. Incident management, service request handling and problem management, each with a recorded owner, priority and closing time.
  9. Clause 8.7, service assurance. Availability targets, a service continuity plan that is tested, and information security controls inside the service.
  10. Clauses 9 and 10, evaluation and improvement. Report performance against the service level targets, run internal audits, hold a management review, and log, correct and close every nonconformity.

Who needs ISO/IEC 20000-1 in Iraq and Kurdistan

IT and managed service providersISO/IEC 20000-1 may be relevant to the management of this activity. Confirm the applicable scope and any buyer requirement before seeking certification.
Hosting and data centre operatorsISO/IEC 20000-1 may be relevant to the management of this activity. Confirm the applicable scope and any buyer requirement before seeking certification.
Government IT suppliersMinistry and KRG tenders for systems and support ask how an incident is logged, escalated and closed inside an agreed time.
Banking and payment technology companiesA bank's vendor review starts with change management and asks who approved each release into production.
Telecom support and network contractorsZain Iraq, Asiacell and Korek Telecom measure their contractors on response and resolution times and audit the records behind them.
Software companies selling support contractsISO/IEC 20000-1 may be relevant to the management of this activity. Confirm the applicable scope and any buyer requirement before seeking certification.
Oil and gas IT and communications contractorsISO/IEC 20000-1 may be relevant to the management of this activity. Confirm the applicable scope and any buyer requirement before seeking certification.
Hospitals and private universities with in-house ITSystems holding patient or student records need a service desk with recorded response times and a tested recovery plan.

The buyers that ask for ISO/IEC 20000-1

Buyer or listWhat they ask for
Telecom operatorsReview this buyer’s current supplier criteria for the products or services offered. Certificate scope, buyer acceptance and tender eligibility need to be checked separately.
Banks and payment companiesCheck the financing or procurement conditions for the relevant project. Confirm whether certification is requested rather than assuming it from the sector.
Federal Ministry of PlanningCheck the current registration instructions for your activity and category. Confirm whether this standard is requested and which issuing bodies are accepted.
KRG Approved Suppliers CenterCheck the current registration instructions for your activity and category. Confirm whether this standard is requested and which issuing bodies are accepted.
UN agencies through UNGMCheck the individual procurement notice for the required certificate and scope. Registration on UNGM does not replace the tender’s qualification criteria.
Kurdistan and Basra operatorsReview this buyer’s current supplier criteria for the products or services offered. Certificate scope, buyer acceptance and tender eligibility need to be checked separately.
Foreign vendors appointing a local partnerReview this buyer’s current supplier criteria for the products or services offered. Certificate scope, buyer acceptance and tender eligibility need to be checked separately.
Gulf buyers and lendersCheck the financing or procurement conditions for the relevant project. Confirm whether certification is requested rather than assuming it from the sector.

What shapes your investment

  • Number of services in scope and how different they are from each other.
  • Number of sites and whether the auditor has to travel to Erbil, Sulaymaniyah, Baghdad or Basra.
  • Headcount delivering and supporting the services, which sets how many auditor days the audit takes.
  • Whether parts of the service are delivered by other parties, because each one has to be controlled and evidenced.
  • Whether a service desk tool already exists or the records have to be built from nothing.
  • Languages the documentation is written in.
  • How much usable process documentation and ticket history already exists in the company.
  • Whether ISO/IEC 20000-1 is built alone or together with ISO 9001 and ISO/IEC 27001 as one system; the certification body determines the audit time.

The proposal names the scope, the deliverables and the dates before work starts.