ITIL 4
Evidence request list. 53 controls, 53 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Architecture Management
Provide an understanding of all the different elements that make up an organisation and how those elements interrelate, enabling effective change in pursuit of agreed objectives.
- Business, information, application, and technology architecture views
- Architecture principles and standards
- Architecture review board (ARB) minutes and decisions
- Architecture roadmap and target state
- Compliance reviews of solution designs
- Technical debt register
- Architecture exists on paper but not enforced
- No ARB or design authority
- Target state not communicated
- Technical debt not tracked
Availability Management
Ensure that services deliver agreed levels of availability to meet the needs of customers and users by designing, measuring, and improving availability across the service lifecycle.
- Availability targets per service mapped to SLAs
- Availability monitoring and reporting evidence
- Availability design documents (redundancy, failover)
- Unavailability root cause and improvement records
- Component failure impact analysis (CFIA)
- Availability measured at component not service level
- No availability targets defined per service
- Single points of failure not tracked
- Planned maintenance excluded inconsistently
Business Analysis
Analyse a business or some element of it, define its associated needs, and recommend solutions to address these needs and solve a business problem, contributing to organisational success.
- Business requirements and user stories
- Process models (BPMN, value stream maps)
- Stakeholder analysis artefacts
- Solution evaluation and recommendation reports
- Traceability matrices from requirements to test cases
- Requirements not traced to outcomes
- Process models outdated
- Stakeholder coverage incomplete
- No formal acceptance of requirements
Capacity and Performance Management
Ensure that services achieve agreed and expected performance, satisfying current and future demand cost-effectively through capacity planning, modelling, and monitoring.
- Capacity plan covering business, service, and component capacity
- Performance monitoring dashboards and thresholds
- Demand forecasts and growth assumptions
- Capacity-related incident and problem records
- Tuning and optimisation records
- Cloud cost and capacity reporting
- No formal capacity plan, only reactive scaling
- Cloud autoscaling without cost or limit governance
- Performance issues not correlated with capacity
- Forecast assumptions not reviewed
Change Enablement
Maximise the number of successful service and product changes by ensuring that risks are properly assessed, authorising changes to proceed, and managing the change schedule.
- Change enablement policy with change types (standard, normal, emergency)
- Change advisory board (CAB) terms of reference and minutes
- Change authority matrix
- Change records with risk and impact assessments
- Forward schedule of change
- Post-implementation reviews for major and emergency changes
- Standard change models catalogue
- Emergency changes bypass review or lack PIR
- Standard change models not periodically reassessed
- Change authority misaligned with risk level
- No segregation between requester, implementer, and approver
Continual Improvement
Align organisational practices and services with changing business needs through ongoing improvement of products, services, and practices using the continual improvement model and register.
- Continual improvement register (CIR) with prioritised initiatives
- Improvement initiative business cases and outcomes
- Post-implementation reviews and lessons learned
- Service measurement and reporting evidence
- Improvement governance forum minutes
- Mapping of improvements to strategic objectives
- CIR exists but items never closed
- No baseline measurement before improvement starts
- Improvements not linked to customer outcomes
- Lessons learned not fed back into practices
Deployment Management
Move new or changed hardware, software, documentation, processes, or any other component to live environments, including deployment to test or staging environments.
- Deployment pipeline documentation and tooling configuration
- Environment promotion controls and approvals
- Segregation of duties between development and production deployment
- Deployment verification and smoke test evidence
- Configuration drift detection records
- Infrastructure as code and version control evidence
- Developers with production deploy rights without compensating controls
- Manual deployment steps not documented
- No verification of deployed artifact integrity
- Configuration drift undetected
IT Asset Management
Plan and manage the full lifecycle of all IT assets to maximise value, control costs, manage risks, support decision-making, and meet regulatory and contractual requirements.
- IT asset register covering hardware, software, cloud, and information assets
- Asset lifecycle policy from acquisition to disposal
- Software license entitlements and reconciliation reports
- Secure disposal and data sanitisation records
- Asset ownership and custodianship assignments
- Reconciliation between ITAM, finance, and CMDB
- Shadow IT and cloud SaaS not tracked
- Software license position not reconciled
- Disposal certificates missing for retired hardware
- Asset register not linked to CMDB or finance system
ITIL 4: Continual Improvement
Service measurement and reporting. Control from ITIL 4 framework, domain: ITIL 4: Continual Improvement.
- Service measurement framework with operational, tactical, strategic metrics
- Service dashboard for each customer/service with trend analysis
- Balanced scorecard linking IT metrics to business outcomes
- Quarterly service review pack with insights and improvement actions
- Customer Experience (XLA) metrics alongside traditional SLA
- Reports produced but not read, vanity metrics dominate
- Metrics measure what's easy not what matters to customers
- No insight commentary, raw data without context
- Improvement actions not tracked to closure, same issues recur next quarter
Continual improvement process. Control from ITIL 4 framework, domain: ITIL 4: Continual Improvement.
- Continual Improvement Register (CIR) with status, owner, value estimate
- Improvement initiative business cases and benefits tracking
- ITIL CI Model evidence (vision, where are we now, where do we want to be, how do we get there, take action, did we get there, how do we keep momentum)
- Quarterly improvement review with stakeholders
- Improvement velocity metrics (initiatives started, completed, abandoned)
- CIR captures ideas but few become funded initiatives
- Improvement work is the first sacrificed when operational pressure increases
- Benefits not measured post-implementation, can't prove improvements work
- Same improvement themes appear year after year, root causes not addressed
Benchmarking and maturity assessment. Control from ITIL 4 framework, domain: ITIL 4: Continual Improvement.
- Maturity assessment per practice (ITIL 4 Maturity Model or similar)
- Benchmarking studies with industry peers or analyst data (Gartner, Forrester)
- Capability gap analysis with prioritised closure plan
- External certification or audit reports (ISO 20000, COBIT, ITIL)
- Process maturity progression evidence over 12-24 months
- Maturity assessment self-scored, optimistic and unactioned
- Benchmarking limited to internal comparisons, no external context
- Capability gaps identified but not converted to funded improvement work
- Audit findings closed by paperwork update, not real practice change
Stakeholder feedback management. Control from ITIL 4 framework, domain: ITIL 4: Continual Improvement.
- Stakeholder map and engagement plan per service
- Customer satisfaction (CSAT, NPS, CES) survey results with trend
- Voice of Customer (VoC) programme covering structured and unstructured feedback
- Complaint and compliment log with action tracking
- Customer journey maps with pain points identified
- Surveys sent but response rate low, results not representative
- Detractor feedback not followed up with closed-loop conversation
- Stakeholder map outdated, key influencers not engaged
- VoC programme exists but no link to service design or improvement decisions
ITIL 4: Service Operation
Incident management. Control from ITIL 4 framework, domain: ITIL 4: Service Operation.
- Incident management policy with priority matrix (impact x urgency)
- Major incident management procedure and on-call escalation tree
- Incident records with timeline, actions, resolution, root cause
- MIR (Major Incident Review) reports and improvement actions
- MTTR, MTBF, first-call resolution KPIs and trend analysis
- Priority matrix subjective, similar incidents get different priorities
- Major incident comms delayed, customers learn from social media first
- Workarounds not promoted to permanent fixes, same incidents recur
- On-call burden concentrated on small group, burnout risk
Problem management. Control from ITIL 4 framework, domain: ITIL 4: Service Operation.
- Problem management policy and lifecycle (logged, investigated, known error, resolved)
- Problem records linked to underlying incidents
- Root Cause Analysis (RCA) methodology (5 Whys, Ishikawa, fault tree)
- Known Error Database (KEDB) with documented workarounds
- Problem trend analysis and proactive problem identification
- Reactive problem management only, no proactive trend analysis
- KEDB not surfaced to incident team, same problem reopened repeatedly
- RCA pressure to finish quickly produces shallow analysis
- Problem closure not linked to verification that root cause is gone
Event management and monitoring. Control from ITIL 4 framework, domain: ITIL 4: Service Operation.
- Monitoring strategy and tooling map (infrastructure, application, synthetic, RUM, logs, traces)
- Event correlation and alert routing rules
- Alert tuning records (noise reduction, threshold adjustment)
- On-call runbooks for each alert class
- Observability maturity assessment
- Alert fatigue from too many low-value alerts, real incidents missed
- Monitoring stops at infrastructure layer, application and user experience blind
- Synthetic tests cover happy path only, real user issues unnoticed
- Log aggregation expensive, retention shortened sacrificing forensic capability
Request fulfillment. Control from ITIL 4 framework, domain: ITIL 4: Service Operation.
- Service request catalogue with fulfillment workflows
- Self-service portal usage metrics and customer satisfaction
- Automation evidence for common requests (password reset, access provisioning, software install)
- Request fulfillment SLA and breach analysis
- Customer feedback on request experience
- Request catalogue grew organically, hundreds of items, customers can't find what they need
- Self-service portal designed for IT not users, low adoption
- Automation incomplete, human steps in middle of otherwise automated flow create delays
- Hidden manual processes outside ticketing system bypass governance
Access management for services. Control from ITIL 4 framework, domain: ITIL 4: Service Operation.
- IAM policy with role-based access model
- Joiners/Movers/Leavers (JML) process documentation and integration with HR system
- Access review reports per system, per role
- Privileged Access Management (PAM) controls and session recording
- Segregation of duties matrix and conflict resolution procedure
- Leavers not de-provisioned promptly, dormant accounts active after termination
- Access reviews check 'still employed' but not 'still needs this access'
- Privileged accounts shared, audit trail attributes actions to a role not a person
- SoD conflicts identified but compensating controls undocumented
ITIL 4: Service Strategy & Design
Service portfolio management. Control from ITIL 4 framework, domain: ITIL 4: Service Strategy & Design.
- Service portfolio document covering pipeline, catalogue, retired services
- Service strategy with value propositions per service
- Investment business cases linked to portfolio review minutes
- Portfolio review board terms of reference and meeting cadence
- Retire/replace decisions log
- Portfolio refreshed annually but no link to enterprise strategy refresh
- Pipeline items not categorised by stage of maturity
- Service retirement decisions made informally without portfolio impact analysis
- Service value drivers not quantified
Service level management. Control from ITIL 4 framework, domain: ITIL 4: Service Strategy & Design.
- Service Level Agreement (SLA) per customer or service
- Operational Level Agreement (OLA) per internal team
- Underpinning Contracts (UC) with third parties
- SLA achievement reports with breach analysis
- Customer experience (CX) metrics and feedback loop
- SLAs measure availability but ignore customer-facing outcomes (XLAs missing)
- OLAs not aligned to SLA targets, gaps appear under load
- Breach root cause analysis not feeding into improvement register
- Service review cadence informal, no documented agenda
Capacity and availability management. Control from ITIL 4 framework, domain: ITIL 4: Service Strategy & Design.
- Capacity plan with demand forecasts and tuning actions
- Availability design specs with redundancy and single-point-of-failure analysis
- Capacity monitoring dashboards (CPU, memory, network, storage, transactions)
- Component Failure Impact Analysis (CFIA) per critical service
- Availability achievement reports vs SLA
- Capacity planning is reactive after threshold breach, not forward-looking
- Cloud auto-scaling treated as substitute for capacity planning (cost blow-out)
- CFIA stale, missed new components added since last review
- MTBF/MTRS metrics not tracked, only uptime %
IT service continuity management. Control from ITIL 4 framework, domain: ITIL 4: Service Strategy & Design.
- IT Service Continuity Plan (ITSCP) for each tier-1 service
- Business Impact Analysis (BIA) with RTO and RPO per service
- DR test plans, schedule, and results (tabletop, partial, full failover)
- Recovery runbooks (technical) per critical service
- Continuity risk register and treatment plan
- RTO/RPO defined in IT terms not aligned with business BIA
- DR tests are tabletop only, never an actual failover
- Recovery runbooks not updated after major architecture changes
- Third-party recovery dependencies not validated
Information security for services. Control from ITIL 4 framework, domain: ITIL 4: Service Strategy & Design.
- Information Security Management System (ISMS) policy and scope
- Risk assessment results with treatment plans
- Security controls register aligned to ISO 27001 Annex A or NIST 800-53
- Security incident management procedure with playbooks
- Awareness training records and phishing simulation outcomes
- Security policy not refreshed since initial certification
- Control owners not documented, accountability unclear when incidents happen
- Vendor security assessments not tied to procurement gate
- DevOps pipelines not assessed for security controls (SCA, SAST, secret scanning)
ITIL 4: Service Transition
Change management processes. Control from ITIL 4 framework, domain: ITIL 4: Service Transition.
- Change management policy with change types (standard, normal, emergency)
- Change Advisory Board (CAB) charter and meeting records
- Change records (RFCs) with risk assessment, rollback plan, post-implementation review
- Change calendar showing blackout periods and conflicts
- Change failure rate and lead time KPIs (DORA metrics)
- Standard change library outdated, every routine change goes through CAB
- Emergency change process abused to bypass normal review
- PIR (post-implementation review) skipped for successful changes, learning lost
- DevOps deployments not visible in change record system
Release and deployment management. Control from ITIL 4 framework, domain: ITIL 4: Service Transition.
- Release policy with versioning scheme and approval gates
- Release plan per major version (scope, dates, dependencies)
- Deployment pipeline configuration and automation evidence
- Pre-production and production environment inventory with parity assessment
- Post-deployment validation and rollback log
- Production and pre-prod environments drift apart, last-minute surprises
- Feature flags used as substitute for release planning, technical debt accumulates
- Rollback paths assumed but never tested for new release types
- Release notes incomplete, support team blindsided
Service validation and testing. Control from ITIL 4 framework, domain: ITIL 4: Service Transition.
- Test strategy per service or release
- Test cases mapped to acceptance criteria and risk areas
- Test environment access and data management procedure
- Test execution evidence with defect log and fix verification
- Service acceptance criteria (SAC) sign-off
- Non-functional testing (performance, security, accessibility) skipped under deadline pressure
- Test data not anonymised, GDPR risk if breach
- Test environments differ from production, defects escape
- User acceptance testing rushed, business sign-off becomes rubber stamp
Knowledge management. Control from ITIL 4 framework, domain: ITIL 4: Service Transition.
- Knowledge Management policy and ownership model
- Knowledge base with article lifecycle (draft, published, retired)
- Article quality criteria and review cadence
- KCS (Knowledge-Centered Service) maturity assessment if adopted
- Knowledge usage metrics (article reuse rate, deflection rate)
- Knowledge base populated but articles not maintained, accuracy drops over time
- Tribal knowledge not captured, single points of failure in staff
- Customer-facing self-service portal poorly organised, customers prefer phone call
- Lessons learned from incidents not converted into reusable knowledge
Configuration management. Control from ITIL 4 framework, domain: ITIL 4: Service Transition.
- Configuration Management Database (CMDB) scope and data model
- CI lifecycle states defined (planned, in stock, deployed, retired)
- Configuration audit reports comparing CMDB to actual environment
- CMDB integration map with discovery tools, monitoring, ITSM, asset mgmt
- CI relationship mapping (depends on, runs on, supports)
- CMDB created during a project but never maintained, data 30%+ stale
- Discovery tool blind spots (cloud accounts, SaaS) not reconciled
- CI ownership not assigned, no one accountable for accuracy
- CMDB used for compliance reporting without verification, leads to audit findings
Incident Management
Minimise the negative impact of incidents by restoring normal service operation as quickly as possible, with prioritisation based on business impact and urgency.
- Incident management process and work instructions
- Priority and severity matrix
- Incident ticket samples with full lifecycle
- Major incident procedure and post-incident review records
- Incident SLA performance reports
- Escalation paths and on-call schedules
- Knowledge articles created from incidents
- Priority assigned inconsistently
- Major incident reviews delayed or skipped
- No linkage from incident to problem record
- Post-resolution communications to customers missing
Information Security Management
Protect the information needed by the organisation to conduct its business by establishing confidentiality, integrity, availability, authentication, and non-repudiation controls aligned with business risk appetite.
- Information security policy and supporting standards
- Information security management system (ISMS) scope statement
- Risk assessment register with treatment plans
- Security control catalogue mapped to ISO 27001 or NIST CSF
- Security incident response procedure and runbooks
- Security awareness training records and phishing simulation results
- Access control and identity governance procedures
- Vulnerability management and penetration testing reports
- Security policy not reviewed annually or after major change
- No defined risk appetite or tolerance statements
- Security practice operates in isolation from other ITIL practices
- Awareness training one-off rather than continuous
Infrastructure and Platform Management
Oversee the infrastructure and platforms used by an organisation, supporting the overall service delivery including hardware, networks, cloud, and platform services with appropriate controls.
- Infrastructure and platform inventory
- Hardening standards and configuration baselines
- Patching schedules and compliance reports
- Cloud landing zone and guardrails documentation
- Network segmentation and zoning documentation
- Backup and recovery configuration
- Patching SLA breached for critical CVEs
- Hardening baselines drift over time
- Cloud accounts without guardrails
- Backups not periodically restored
Knowledge Management
Maintain and improve the effective, efficient, and convenient use of information and knowledge across the organisation by capturing, sharing, and reusing knowledge.
- Knowledge management policy and standards
- Knowledge base structure and tagging taxonomy
- Knowledge article lifecycle (draft, review, retire)
- Knowledge usage metrics and gap reports
- Subject matter expert assignments
- Knowledge-centered service (KCS) practices evidence
- Knowledge base contains outdated articles
- No ownership or review cycle for articles
- Knowledge not captured during incidents
- Article quality not measured
Measurement and Reporting
Support good decision-making and continual improvement by decreasing levels of uncertainty through the collection of relevant data and its assessment in the appropriate context.
- Measurement framework linking KPIs to objectives and CSFs
- Metric definitions and data lineage
- Operational and executive reporting cadence
- Data quality and validation procedures
- Decisions log referencing reports and metrics
- Goal-question-metric (GQM) artefacts
- Metrics measure activity rather than outcome
- Reports not used in decisions
- Data lineage unclear
- No defined target or threshold per metric
Monitoring and Event Management
Systematically observe services and service components and record and report selected changes of state identified as events, distinguishing among informational, warning, and exception events.
- Monitoring coverage matrix per critical service
- Event classification and threshold definitions
- Event correlation and noise reduction configuration
- Alert routing and on-call response evidence
- Event-to-incident automation records
- Log retention and access control evidence
- Alert noise causing fatigue
- No correlation across infrastructure, application, and security events
- Monitoring gaps for cloud and SaaS
- Log retention shorter than regulatory requirement
Organizational Change Management
Ensure that changes in an organisation are smoothly and successfully implemented and that lasting benefits are achieved by managing the people aspects of change.
- Organisational change strategy and plans
- Stakeholder impact assessments
- Communication and engagement plans
- Training and adoption support records
- Adoption and behavioural change metrics
- Resistance management actions
- OCM treated as communications only
- No baseline of current behaviour
- Training not linked to adoption metrics
- Sustainment plan absent post-go-live
Portfolio Management
Ensure that the organisation has the right mix of programmes, projects, products, and services to execute its strategy within funding and resource constraints.
- Portfolio inventory of services, products, projects, programmes
- Prioritisation criteria and scoring
- Portfolio investment and resource allocation records
- Portfolio review minutes and decisions
- Stop, start, continue decisions log
- No single portfolio view
- Investments not aligned to strategy
- Sunsetting services rarely decided
- Resource capacity not validated
Problem Management
Reduce the likelihood and impact of incidents by identifying actual and potential causes of incidents and managing workarounds and known errors.
- Problem management process documentation
- Problem records with root cause analysis
- Known error database (KEDB) with workarounds
- Proactive problem identification reports (trend analysis)
- Problem review board minutes
- Linkage records between incidents, problems, and changes
- Problems closed without permanent fix
- KEDB not visible to service desk
- No proactive analysis of recurring incidents
- Root cause analysis superficial or missing for major incidents
Project Management
Ensure that all projects in the organisation are successfully delivered, balancing the constraints of scope, time, cost, quality, and benefits to support strategic objectives.
- Project management methodology (waterfall, agile, hybrid)
- Project portfolio register and prioritisation criteria
- Project charters and business cases
- Project risk and issue registers
- Project status and steering committee reports
- Benefits realisation reviews
- No portfolio view of projects
- Benefits never measured post-go-live
- Project risks not integrated with enterprise risk
- Methodology selection not justified per project
Relationship Management
Establish and nurture the links between the organisation and its stakeholders at strategic and tactical levels, including the identification, analysis, monitoring, and continual improvement of relationships.
- Stakeholder map and register
- Stakeholder engagement plan
- Account or relationship manager assignments
- Customer feedback and NPS or CSAT records
- Executive sponsor and steering forum minutes
- Relationship issue and escalation log
- No defined business relationship manager
- Stakeholder engagement reactive not planned
- Feedback collected but not acted on
- Internal stakeholders not included in map
Release Management
Make new and changed services and features available for use according to agreed expectations of customers and stakeholders while maintaining control of service quality.
- Release policy and release model definitions
- Release plans and schedules
- Release approval and go/no-go records
- Rollback and backout plans
- Release notes communicated to stakeholders
- Post-release review records
- Release and deployment conflated
- No rollback plan for major releases
- Releases not linked to change records
- Stakeholders unaware of upcoming releases
Risk Management
Ensure that the organisation understands and effectively handles risks by identifying, analysing, evaluating, treating, monitoring, and reporting risks across services and value streams.
- Enterprise risk management framework or policy
- Risk register with likelihood, impact, owner, and treatment
- Risk appetite and tolerance statements
- Risk treatment plans with target dates
- Risk committee minutes and escalation records
- Key risk indicator (KRI) dashboards
- Risk acceptance approvals from accountable executives
- Risk register out of date or owner unassigned
- No quantitative risk scoring methodology
- Treatment actions not tracked to closure
- Operational risks not linked to service or asset register
Service Catalogue Management
Provide a single source of consistent information on all services and service offerings, ensuring that it is available to the relevant audience and accurately reflects what is offered.
- Service catalogue with business and technical views
- Service owner assignments per service
- Catalogue review and approval cadence
- Customer-facing service catalogue (portal)
- Service retirement decisions and notifications
- Catalogue not in sync with actual services delivered
- Services missing owners
- Internal-only catalogue with no customer view
- Retired services still listed
Service Configuration Management
Ensure that accurate and reliable information about the configuration of services and the CIs that support them is available when and where needed, including relationships between CIs.
- Configuration management database (CMDB) with defined scope
- Configuration management plan and CI naming standard
- CI classes, attributes, and relationship model
- Discovery tool configuration and reconciliation reports
- CMDB audit results and data quality metrics
- CI lifecycle states and ownership assignments
- CMDB stale, with no scheduled verification or audit
- Relationships between CIs missing or incorrect
- No defined data owner for CI classes
- Discovery not reconciled with authoritative sources
Service Continuity Management
Ensure that service availability and performance are maintained at sufficient levels in case of a disaster, supporting overall business continuity by defining recovery objectives and plans.
- Business impact analysis (BIA) covering critical services
- Service continuity plans with RTOs and RPOs
- Disaster recovery test schedule and results
- Crisis management and communications procedures
- Recovery site and backup arrangements documentation
- Lessons learned from continuity exercises
- BIA outdated or not aligned to current services
- DR plans never tested end-to-end
- RTO/RPO not validated against business requirements
- No coordination with supplier continuity plans
Service Design
Design products and services that are fit for purpose, fit for use, and that can be delivered by the organisation and its ecosystem, including capacity, availability, security, and continuity considerations.
- Service design packages with requirements traceability
- Non-functional requirements (security, availability, capacity)
- Design review and approval records
- Service acceptance criteria
- Operational readiness and handover checklists
- Non-functional requirements added late
- No operational readiness review before go-live
- Security and privacy by design not evidenced
- Handover to operations incomplete
Service Desk
Capture demand for incident resolution and service requests, providing a clear path for users to report issues, queries, and requests, and to have them acknowledged and acted upon.
- Service desk operating model and channel matrix (phone, email, portal, chat)
- Service desk roles, training, and shift schedules
- Service desk performance metrics (FCR, AHT, CSAT)
- Self-service portal and knowledge usage statistics
- User feedback and CSAT survey results
- Triage and routing procedures
- Single channel reliance with no portal
- Knowledge base not maintained by service desk
- No measurement of customer experience
- Tier escalation criteria unclear
Service Financial Management
Support the organisation's strategies and plans for service management by ensuring that financial resources and investments are used effectively, including budgeting, accounting, and charging.
- IT budget and forecast documents
- Service cost model and unit costs
- Chargeback or showback reports
- Cloud cost (FinOps) reporting
- Investment business cases with ROI
- Variance analysis and adjustment records
- Cloud costs not allocated to services
- No unit cost per service
- Budgets not reconciled to actuals
- ROI of investments not tracked post-go-live
Service Level Management
Set clear business-based targets for service performance so that the delivery of a service can be properly assessed, monitored, and managed against these targets.
- Service level agreements (SLAs) with customers and OLAs with internal teams
- SLA target measurement and reporting evidence
- Service review meeting minutes
- Service performance dashboards
- Customer satisfaction measurements linked to services
- SLA breach root cause and improvement plans
- Watermelon SLAs (green at SLA, red at user experience)
- OLAs not aligned to SLAs
- No regular service review cadence
- SLAs measure activity not outcome
Service Request Management
Support the agreed quality of a service by handling all predefined, user-initiated service requests in an effective and user-friendly manner with appropriate approvals.
- Service request catalogue with descriptions, SLAs, and costs
- Request fulfilment workflows and approval matrices
- Automation and self-service evidence
- Request performance metrics
- Segregation-of-duties checks in approval flows
- User satisfaction with request fulfilment
- Requests treated as incidents
- Approvals not enforced in tooling
- Catalogue not maintained or out of date
- No SLA defined per request type
Service Validation and Testing
Ensure that new or changed products and services meet defined requirements through structured testing approaches covering utility, warranty, and acceptance criteria.
- Test strategy and test plans
- Test case repositories and execution evidence
- User acceptance testing sign-offs
- Security testing (SAST, DAST, penetration test) results
- Defect register and resolution tracking
- Regression test automation evidence
- UAT performed by IT instead of business
- Security testing skipped for minor changes
- Test data contains real production data without masking
- No regression suite for critical journeys
Software Development and Management
Ensure that applications meet stakeholder needs in terms of functionality, reliability, maintainability, compliance, and audibility through structured development and lifecycle management practices.
- Software development lifecycle documentation
- Secure coding standards and training records
- Code review and pull request evidence
- Software composition analysis and SBOM artefacts
- Source code repository access controls
- CI/CD pipeline security controls
- SBOM not maintained for products
- Open source vulnerabilities not tracked
- Secrets committed to repositories
- Code review skipped for hotfixes
Strategy Management
Formulate the goals of the organisation and adopt the courses of action and allocation of resources necessary for achieving these goals, ensuring strategy is communicated and refreshed.
- Documented business and IT strategy
- Strategy communication evidence (town halls, intranet)
- Strategic initiative roadmaps
- Strategic KPIs and balanced scorecard
- Strategy review and refresh records
- Strategy not refreshed annually
- IT strategy disconnected from business strategy
- Initiatives not tracked against strategic outcomes
- Frontline staff cannot articulate strategy
Supplier Management
Ensure that the organisation's suppliers and their performances are managed appropriately to support the seamless provision of quality products and services aligned with strategy.
- Supplier register categorised by strategic, tactical, operational, commodity
- Contracts and service level agreements with suppliers
- Supplier performance scorecards and review minutes
- Supplier risk assessments including concentration risk
- Supplier onboarding and offboarding procedures
- Fourth-party (subcontractor) visibility records
- Critical suppliers not differentiated from commodity
- No supplier exit plan
- Contract renewals lapsed
- Supplier security and continuity not tested
Workforce and Talent Management
Ensure that the organisation has the right people with the appropriate skills, knowledge, and competencies in the right roles to support its business objectives.
- Workforce plan and headcount forecasts
- Role descriptions and competency frameworks
- Training records and certification tracking
- Skills gap analysis and development plans
- Succession plans for critical roles
- Onboarding and offboarding procedures
- Key person dependency without documented backup
- Training not aligned to role competencies
- Onboarding security checks inconsistent
- Offboarding access removal delayed
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ITIL 4 framework page.