Skip to content

Evidence request lists

ISO 20000-1

Evidence request list. 22 controls, 22 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

ISO 20000-1: Continual Improvement

ISO20000-16
Service measurement and reporting

Service measurement and reporting. Control from ISO 20000-1 framework, domain: ISO 20000-1: Continual Improvement.

Artefacts an auditor will ask for
  • SLA documentation
  • change management records
  • incident tickets
  • configuration management database extract
  • service review minutes
  • service catalogue
Where this commonly fails
  • insufficient problem closure evidence
  • gaps in service measurement reporting
  • incomplete service catalogue
  • weak SLA tracking
ISO20000-17
Continual improvement process

Continual improvement process. Control from ISO 20000-1 framework, domain: ISO 20000-1: Continual Improvement.

Artefacts an auditor will ask for
  • service catalogue
  • SLA documentation
  • change management records
Where this commonly fails
  • gaps in service measurement reporting
  • incomplete service catalogue
  • weak SLA tracking
ISO20000-18
Benchmarking and maturity assessment

Benchmarking and maturity assessment. Control from ISO 20000-1 framework, domain: ISO 20000-1: Continual Improvement.

Artefacts an auditor will ask for
  • incident tickets
  • configuration management database extract
  • service review minutes
  • service catalogue
  • SLA documentation
  • change management records
Where this commonly fails
  • insufficient problem closure evidence
  • gaps in service measurement reporting
  • incomplete service catalogue
ISO20000-19
Stakeholder feedback management

Stakeholder feedback management. Control from ISO 20000-1 framework, domain: ISO 20000-1: Continual Improvement.

Artefacts an auditor will ask for
  • configuration management database extract
  • service review minutes
  • service catalogue
  • SLA documentation
Where this commonly fails
  • incomplete service catalogue
  • weak SLA tracking
  • missing change advisory board records
  • insufficient problem closure evidence

ISO 20000-1: Service Operation

ISO20000-11
Incident management

Incident management. Control from ISO 20000-1 framework, domain: ISO 20000-1: Service Operation.

Artefacts an auditor will ask for
  • change management records
  • incident tickets
  • configuration management database extract
Where this commonly fails
  • missing change advisory board records
  • insufficient problem closure evidence
  • gaps in service measurement reporting
ISO20000-12
Problem management

Problem management. Control from ISO 20000-1 framework, domain: ISO 20000-1: Service Operation.

Artefacts an auditor will ask for
  • service review minutes
  • service catalogue
  • SLA documentation
  • change management records
  • incident tickets
Where this commonly fails
  • incomplete service catalogue
  • weak SLA tracking
  • missing change advisory board records
  • insufficient problem closure evidence
  • gaps in service measurement reporting
ISO20000-13
Event management and monitoring

Event management and monitoring. Control from ISO 20000-1 framework, domain: ISO 20000-1: Service Operation.

Artefacts an auditor will ask for
  • incident tickets
  • configuration management database extract
  • service review minutes
  • service catalogue
  • SLA documentation
  • change management records
Where this commonly fails
  • weak SLA tracking
  • missing change advisory board records
  • insufficient problem closure evidence
  • gaps in service measurement reporting
ISO20000-14
Request fulfillment

Request fulfillment. Control from ISO 20000-1 framework, domain: ISO 20000-1: Service Operation.

Artefacts an auditor will ask for
  • service catalogue
  • SLA documentation
  • change management records
Where this commonly fails
  • gaps in service measurement reporting
  • incomplete service catalogue
  • weak SLA tracking
ISO20000-15
Access management for services

Access management for services. Control from ISO 20000-1 framework, domain: ISO 20000-1: Service Operation.

Artefacts an auditor will ask for
  • service review minutes
  • service catalogue
  • SLA documentation
  • change management records
  • incident tickets
  • configuration management database extract
Where this commonly fails
  • gaps in service measurement reporting
  • incomplete service catalogue
  • weak SLA tracking
  • missing change advisory board records
  • insufficient problem closure evidence

ISO 20000-1: Service Strategy & Design

ISO20000-01
Service portfolio management

Service portfolio management. Control from ISO 20000-1 framework, domain: ISO 20000-1: Service Strategy & Design.

Artefacts an auditor will ask for
  • configuration management database extract
  • service review minutes
  • service catalogue
Where this commonly fails
  • weak SLA tracking
  • missing change advisory board records
  • insufficient problem closure evidence
  • gaps in service measurement reporting
  • incomplete service catalogue
ISO20000-02
Service level management

Service level management. Control from ISO 20000-1 framework, domain: ISO 20000-1: Service Strategy & Design.

Artefacts an auditor will ask for
  • service review minutes
  • service catalogue
  • SLA documentation
  • change management records
  • incident tickets
  • configuration management database extract
Where this commonly fails
  • missing change advisory board records
  • insufficient problem closure evidence
  • gaps in service measurement reporting
  • incomplete service catalogue
  • weak SLA tracking
ISO20000-03
Capacity and availability management

Capacity and availability management. Control from ISO 20000-1 framework, domain: ISO 20000-1: Service Strategy & Design.

Artefacts an auditor will ask for
  • configuration management database extract
  • service review minutes
  • service catalogue
  • SLA documentation
  • change management records
  • incident tickets
Where this commonly fails
  • weak SLA tracking
  • missing change advisory board records
  • insufficient problem closure evidence
ISO20000-04
IT service continuity management

IT service continuity management. Control from ISO 20000-1 framework, domain: ISO 20000-1: Service Strategy & Design.

Artefacts an auditor will ask for
  • configuration management database extract
  • service review minutes
  • service catalogue
  • SLA documentation
  • change management records
  • incident tickets
Where this commonly fails
  • incomplete service catalogue
  • weak SLA tracking
  • missing change advisory board records
  • insufficient problem closure evidence
ISO20000-05
Information security for services

Information security for services. Control from ISO 20000-1 framework, domain: ISO 20000-1: Service Strategy & Design.

Artefacts an auditor will ask for
  • SLA documentation
  • change management records
  • incident tickets
  • configuration management database extract
  • service review minutes
  • service catalogue
Where this commonly fails
  • incomplete service catalogue
  • weak SLA tracking
  • missing change advisory board records

ISO 20000-1: Service Transition

ISO20000-06
Change management processes

Change management processes. Control from ISO 20000-1 framework, domain: ISO 20000-1: Service Transition.

Artefacts an auditor will ask for
  • SLA documentation
  • change management records
  • incident tickets
  • configuration management database extract
Where this commonly fails
  • insufficient problem closure evidence
  • gaps in service measurement reporting
  • incomplete service catalogue
ISO20000-07
Release and deployment management

Release and deployment management. Control from ISO 20000-1 framework, domain: ISO 20000-1: Service Transition.

Artefacts an auditor will ask for
  • incident tickets
  • configuration management database extract
  • service review minutes
  • service catalogue
Where this commonly fails
  • incomplete service catalogue
  • weak SLA tracking
  • missing change advisory board records
  • insufficient problem closure evidence
ISO20000-08
Service validation and testing

Service validation and testing. Control from ISO 20000-1 framework, domain: ISO 20000-1: Service Transition.

Artefacts an auditor will ask for
  • change management records
  • incident tickets
  • configuration management database extract
  • service review minutes
  • service catalogue
  • SLA documentation
Where this commonly fails
  • insufficient problem closure evidence
  • gaps in service measurement reporting
  • incomplete service catalogue
ISO20000-09
Knowledge management

Knowledge management. Control from ISO 20000-1 framework, domain: ISO 20000-1: Service Transition.

Artefacts an auditor will ask for
  • incident tickets
  • configuration management database extract
  • service review minutes
  • service catalogue
  • SLA documentation
Where this commonly fails
  • weak SLA tracking
  • missing change advisory board records
  • insufficient problem closure evidence
  • gaps in service measurement reporting
  • incomplete service catalogue
ISO20000-10
Configuration management

Configuration management. Control from ISO 20000-1 framework, domain: ISO 20000-1: Service Transition.

Artefacts an auditor will ask for
  • incident tickets
  • configuration management database extract
  • service review minutes
  • service catalogue
Where this commonly fails
  • gaps in service measurement reporting
  • incomplete service catalogue
  • weak SLA tracking
  • missing change advisory board records
  • insufficient problem closure evidence

Operation - Service Assurance

8.7.1
Service Availability Management

Service availability is planned, measured and improved to meet agreed requirements.

Artefacts an auditor will ask for
  • Availability plan document
  • Uptime reports
  • Improvement log
Where this commonly fails
  • Availability measured technically not business-aligned
  • No single point of failure analysis
8.7.2
Service Continuity Management

Service continuity plans ensure ability to restore agreed services within agreed timeframes after disruption.

Artefacts an auditor will ask for
  • SCM plan
  • BIA document
  • Test reports
Where this commonly fails
  • Plans not tested annually
  • RTO/RPO not aligned with SLA
8.7.3
Information Security Management

Information security is managed for services including controls, incidents and risk assessment.

Artefacts an auditor will ask for
  • InfoSec policy
  • Risk register
  • Security incident reports
Where this commonly fails
  • Security separate from SMS
  • No ISMS-SMS interface defined
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO 20000-1 framework page.