Skip to content

Evidence request lists

ITIL 4

Evidence request list. 53 controls, 53 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Architecture Management

GM-ARC-1
Architecture Management

Provide an understanding of all the different elements that make up an organisation and how those elements interrelate, enabling effective change in pursuit of agreed objectives.

Artefacts an auditor will ask for
  • Business, information, application, and technology architecture views
  • Architecture principles and standards
  • Architecture review board (ARB) minutes and decisions
  • Architecture roadmap and target state
  • Compliance reviews of solution designs
  • Technical debt register
Where this commonly fails
  • Architecture exists on paper but not enforced
  • No ARB or design authority
  • Target state not communicated
  • Technical debt not tracked

Availability Management

SM-AV-1
Availability Management

Ensure that services deliver agreed levels of availability to meet the needs of customers and users by designing, measuring, and improving availability across the service lifecycle.

Artefacts an auditor will ask for
  • Availability targets per service mapped to SLAs
  • Availability monitoring and reporting evidence
  • Availability design documents (redundancy, failover)
  • Unavailability root cause and improvement records
  • Component failure impact analysis (CFIA)
Where this commonly fails
  • Availability measured at component not service level
  • No availability targets defined per service
  • Single points of failure not tracked
  • Planned maintenance excluded inconsistently

Business Analysis

SM-BA-1
Business Analysis

Analyse a business or some element of it, define its associated needs, and recommend solutions to address these needs and solve a business problem, contributing to organisational success.

Artefacts an auditor will ask for
  • Business requirements and user stories
  • Process models (BPMN, value stream maps)
  • Stakeholder analysis artefacts
  • Solution evaluation and recommendation reports
  • Traceability matrices from requirements to test cases
Where this commonly fails
  • Requirements not traced to outcomes
  • Process models outdated
  • Stakeholder coverage incomplete
  • No formal acceptance of requirements

Capacity and Performance Management

SM-CAP-1
Capacity and Performance Management

Ensure that services achieve agreed and expected performance, satisfying current and future demand cost-effectively through capacity planning, modelling, and monitoring.

Artefacts an auditor will ask for
  • Capacity plan covering business, service, and component capacity
  • Performance monitoring dashboards and thresholds
  • Demand forecasts and growth assumptions
  • Capacity-related incident and problem records
  • Tuning and optimisation records
  • Cloud cost and capacity reporting
Where this commonly fails
  • No formal capacity plan, only reactive scaling
  • Cloud autoscaling without cost or limit governance
  • Performance issues not correlated with capacity
  • Forecast assumptions not reviewed

Change Enablement

SM-CHG-1
Change Enablement

Maximise the number of successful service and product changes by ensuring that risks are properly assessed, authorising changes to proceed, and managing the change schedule.

Artefacts an auditor will ask for
  • Change enablement policy with change types (standard, normal, emergency)
  • Change advisory board (CAB) terms of reference and minutes
  • Change authority matrix
  • Change records with risk and impact assessments
  • Forward schedule of change
  • Post-implementation reviews for major and emergency changes
  • Standard change models catalogue
Where this commonly fails
  • Emergency changes bypass review or lack PIR
  • Standard change models not periodically reassessed
  • Change authority misaligned with risk level
  • No segregation between requester, implementer, and approver

Continual Improvement

GM-CI-1
Continual Improvement

Align organisational practices and services with changing business needs through ongoing improvement of products, services, and practices using the continual improvement model and register.

Artefacts an auditor will ask for
  • Continual improvement register (CIR) with prioritised initiatives
  • Improvement initiative business cases and outcomes
  • Post-implementation reviews and lessons learned
  • Service measurement and reporting evidence
  • Improvement governance forum minutes
  • Mapping of improvements to strategic objectives
Where this commonly fails
  • CIR exists but items never closed
  • No baseline measurement before improvement starts
  • Improvements not linked to customer outcomes
  • Lessons learned not fed back into practices

Deployment Management

SM-DEP-1
Deployment Management

Move new or changed hardware, software, documentation, processes, or any other component to live environments, including deployment to test or staging environments.

Artefacts an auditor will ask for
  • Deployment pipeline documentation and tooling configuration
  • Environment promotion controls and approvals
  • Segregation of duties between development and production deployment
  • Deployment verification and smoke test evidence
  • Configuration drift detection records
  • Infrastructure as code and version control evidence
Where this commonly fails
  • Developers with production deploy rights without compensating controls
  • Manual deployment steps not documented
  • No verification of deployed artifact integrity
  • Configuration drift undetected

IT Asset Management

GM-ITAM-1
IT Asset Management

Plan and manage the full lifecycle of all IT assets to maximise value, control costs, manage risks, support decision-making, and meet regulatory and contractual requirements.

Artefacts an auditor will ask for
  • IT asset register covering hardware, software, cloud, and information assets
  • Asset lifecycle policy from acquisition to disposal
  • Software license entitlements and reconciliation reports
  • Secure disposal and data sanitisation records
  • Asset ownership and custodianship assignments
  • Reconciliation between ITAM, finance, and CMDB
Where this commonly fails
  • Shadow IT and cloud SaaS not tracked
  • Software license position not reconciled
  • Disposal certificates missing for retired hardware
  • Asset register not linked to CMDB or finance system

ITIL 4: Continual Improvement

ITIL4-16
Service measurement and reporting

Service measurement and reporting. Control from ITIL 4 framework, domain: ITIL 4: Continual Improvement.

Artefacts an auditor will ask for
  • Service measurement framework with operational, tactical, strategic metrics
  • Service dashboard for each customer/service with trend analysis
  • Balanced scorecard linking IT metrics to business outcomes
  • Quarterly service review pack with insights and improvement actions
  • Customer Experience (XLA) metrics alongside traditional SLA
Where this commonly fails
  • Reports produced but not read, vanity metrics dominate
  • Metrics measure what's easy not what matters to customers
  • No insight commentary, raw data without context
  • Improvement actions not tracked to closure, same issues recur next quarter
ITIL4-17
Continual improvement process

Continual improvement process. Control from ITIL 4 framework, domain: ITIL 4: Continual Improvement.

Artefacts an auditor will ask for
  • Continual Improvement Register (CIR) with status, owner, value estimate
  • Improvement initiative business cases and benefits tracking
  • ITIL CI Model evidence (vision, where are we now, where do we want to be, how do we get there, take action, did we get there, how do we keep momentum)
  • Quarterly improvement review with stakeholders
  • Improvement velocity metrics (initiatives started, completed, abandoned)
Where this commonly fails
  • CIR captures ideas but few become funded initiatives
  • Improvement work is the first sacrificed when operational pressure increases
  • Benefits not measured post-implementation, can't prove improvements work
  • Same improvement themes appear year after year, root causes not addressed
ITIL4-18
Benchmarking and maturity assessment

Benchmarking and maturity assessment. Control from ITIL 4 framework, domain: ITIL 4: Continual Improvement.

Artefacts an auditor will ask for
  • Maturity assessment per practice (ITIL 4 Maturity Model or similar)
  • Benchmarking studies with industry peers or analyst data (Gartner, Forrester)
  • Capability gap analysis with prioritised closure plan
  • External certification or audit reports (ISO 20000, COBIT, ITIL)
  • Process maturity progression evidence over 12-24 months
Where this commonly fails
  • Maturity assessment self-scored, optimistic and unactioned
  • Benchmarking limited to internal comparisons, no external context
  • Capability gaps identified but not converted to funded improvement work
  • Audit findings closed by paperwork update, not real practice change
ITIL4-19
Stakeholder feedback management

Stakeholder feedback management. Control from ITIL 4 framework, domain: ITIL 4: Continual Improvement.

Artefacts an auditor will ask for
  • Stakeholder map and engagement plan per service
  • Customer satisfaction (CSAT, NPS, CES) survey results with trend
  • Voice of Customer (VoC) programme covering structured and unstructured feedback
  • Complaint and compliment log with action tracking
  • Customer journey maps with pain points identified
Where this commonly fails
  • Surveys sent but response rate low, results not representative
  • Detractor feedback not followed up with closed-loop conversation
  • Stakeholder map outdated, key influencers not engaged
  • VoC programme exists but no link to service design or improvement decisions

ITIL 4: Service Operation

ITIL4-11
Incident management

Incident management. Control from ITIL 4 framework, domain: ITIL 4: Service Operation.

Artefacts an auditor will ask for
  • Incident management policy with priority matrix (impact x urgency)
  • Major incident management procedure and on-call escalation tree
  • Incident records with timeline, actions, resolution, root cause
  • MIR (Major Incident Review) reports and improvement actions
  • MTTR, MTBF, first-call resolution KPIs and trend analysis
Where this commonly fails
  • Priority matrix subjective, similar incidents get different priorities
  • Major incident comms delayed, customers learn from social media first
  • Workarounds not promoted to permanent fixes, same incidents recur
  • On-call burden concentrated on small group, burnout risk
ITIL4-12
Problem management

Problem management. Control from ITIL 4 framework, domain: ITIL 4: Service Operation.

Artefacts an auditor will ask for
  • Problem management policy and lifecycle (logged, investigated, known error, resolved)
  • Problem records linked to underlying incidents
  • Root Cause Analysis (RCA) methodology (5 Whys, Ishikawa, fault tree)
  • Known Error Database (KEDB) with documented workarounds
  • Problem trend analysis and proactive problem identification
Where this commonly fails
  • Reactive problem management only, no proactive trend analysis
  • KEDB not surfaced to incident team, same problem reopened repeatedly
  • RCA pressure to finish quickly produces shallow analysis
  • Problem closure not linked to verification that root cause is gone
ITIL4-13
Event management and monitoring

Event management and monitoring. Control from ITIL 4 framework, domain: ITIL 4: Service Operation.

Artefacts an auditor will ask for
  • Monitoring strategy and tooling map (infrastructure, application, synthetic, RUM, logs, traces)
  • Event correlation and alert routing rules
  • Alert tuning records (noise reduction, threshold adjustment)
  • On-call runbooks for each alert class
  • Observability maturity assessment
Where this commonly fails
  • Alert fatigue from too many low-value alerts, real incidents missed
  • Monitoring stops at infrastructure layer, application and user experience blind
  • Synthetic tests cover happy path only, real user issues unnoticed
  • Log aggregation expensive, retention shortened sacrificing forensic capability
ITIL4-14
Request fulfillment

Request fulfillment. Control from ITIL 4 framework, domain: ITIL 4: Service Operation.

Artefacts an auditor will ask for
  • Service request catalogue with fulfillment workflows
  • Self-service portal usage metrics and customer satisfaction
  • Automation evidence for common requests (password reset, access provisioning, software install)
  • Request fulfillment SLA and breach analysis
  • Customer feedback on request experience
Where this commonly fails
  • Request catalogue grew organically, hundreds of items, customers can't find what they need
  • Self-service portal designed for IT not users, low adoption
  • Automation incomplete, human steps in middle of otherwise automated flow create delays
  • Hidden manual processes outside ticketing system bypass governance
ITIL4-15
Access management for services

Access management for services. Control from ITIL 4 framework, domain: ITIL 4: Service Operation.

Artefacts an auditor will ask for
  • IAM policy with role-based access model
  • Joiners/Movers/Leavers (JML) process documentation and integration with HR system
  • Access review reports per system, per role
  • Privileged Access Management (PAM) controls and session recording
  • Segregation of duties matrix and conflict resolution procedure
Where this commonly fails
  • Leavers not de-provisioned promptly, dormant accounts active after termination
  • Access reviews check 'still employed' but not 'still needs this access'
  • Privileged accounts shared, audit trail attributes actions to a role not a person
  • SoD conflicts identified but compensating controls undocumented

ITIL 4: Service Strategy & Design

ITIL4-01
Service portfolio management

Service portfolio management. Control from ITIL 4 framework, domain: ITIL 4: Service Strategy & Design.

Artefacts an auditor will ask for
  • Service portfolio document covering pipeline, catalogue, retired services
  • Service strategy with value propositions per service
  • Investment business cases linked to portfolio review minutes
  • Portfolio review board terms of reference and meeting cadence
  • Retire/replace decisions log
Where this commonly fails
  • Portfolio refreshed annually but no link to enterprise strategy refresh
  • Pipeline items not categorised by stage of maturity
  • Service retirement decisions made informally without portfolio impact analysis
  • Service value drivers not quantified
ITIL4-02
Service level management

Service level management. Control from ITIL 4 framework, domain: ITIL 4: Service Strategy & Design.

Artefacts an auditor will ask for
  • Service Level Agreement (SLA) per customer or service
  • Operational Level Agreement (OLA) per internal team
  • Underpinning Contracts (UC) with third parties
  • SLA achievement reports with breach analysis
  • Customer experience (CX) metrics and feedback loop
Where this commonly fails
  • SLAs measure availability but ignore customer-facing outcomes (XLAs missing)
  • OLAs not aligned to SLA targets, gaps appear under load
  • Breach root cause analysis not feeding into improvement register
  • Service review cadence informal, no documented agenda
ITIL4-03
Capacity and availability management

Capacity and availability management. Control from ITIL 4 framework, domain: ITIL 4: Service Strategy & Design.

Artefacts an auditor will ask for
  • Capacity plan with demand forecasts and tuning actions
  • Availability design specs with redundancy and single-point-of-failure analysis
  • Capacity monitoring dashboards (CPU, memory, network, storage, transactions)
  • Component Failure Impact Analysis (CFIA) per critical service
  • Availability achievement reports vs SLA
Where this commonly fails
  • Capacity planning is reactive after threshold breach, not forward-looking
  • Cloud auto-scaling treated as substitute for capacity planning (cost blow-out)
  • CFIA stale, missed new components added since last review
  • MTBF/MTRS metrics not tracked, only uptime %
ITIL4-04
IT service continuity management

IT service continuity management. Control from ITIL 4 framework, domain: ITIL 4: Service Strategy & Design.

Artefacts an auditor will ask for
  • IT Service Continuity Plan (ITSCP) for each tier-1 service
  • Business Impact Analysis (BIA) with RTO and RPO per service
  • DR test plans, schedule, and results (tabletop, partial, full failover)
  • Recovery runbooks (technical) per critical service
  • Continuity risk register and treatment plan
Where this commonly fails
  • RTO/RPO defined in IT terms not aligned with business BIA
  • DR tests are tabletop only, never an actual failover
  • Recovery runbooks not updated after major architecture changes
  • Third-party recovery dependencies not validated
ITIL4-05
Information security for services

Information security for services. Control from ITIL 4 framework, domain: ITIL 4: Service Strategy & Design.

Artefacts an auditor will ask for
  • Information Security Management System (ISMS) policy and scope
  • Risk assessment results with treatment plans
  • Security controls register aligned to ISO 27001 Annex A or NIST 800-53
  • Security incident management procedure with playbooks
  • Awareness training records and phishing simulation outcomes
Where this commonly fails
  • Security policy not refreshed since initial certification
  • Control owners not documented, accountability unclear when incidents happen
  • Vendor security assessments not tied to procurement gate
  • DevOps pipelines not assessed for security controls (SCA, SAST, secret scanning)

ITIL 4: Service Transition

ITIL4-06
Change management processes

Change management processes. Control from ITIL 4 framework, domain: ITIL 4: Service Transition.

Artefacts an auditor will ask for
  • Change management policy with change types (standard, normal, emergency)
  • Change Advisory Board (CAB) charter and meeting records
  • Change records (RFCs) with risk assessment, rollback plan, post-implementation review
  • Change calendar showing blackout periods and conflicts
  • Change failure rate and lead time KPIs (DORA metrics)
Where this commonly fails
  • Standard change library outdated, every routine change goes through CAB
  • Emergency change process abused to bypass normal review
  • PIR (post-implementation review) skipped for successful changes, learning lost
  • DevOps deployments not visible in change record system
ITIL4-07
Release and deployment management

Release and deployment management. Control from ITIL 4 framework, domain: ITIL 4: Service Transition.

Artefacts an auditor will ask for
  • Release policy with versioning scheme and approval gates
  • Release plan per major version (scope, dates, dependencies)
  • Deployment pipeline configuration and automation evidence
  • Pre-production and production environment inventory with parity assessment
  • Post-deployment validation and rollback log
Where this commonly fails
  • Production and pre-prod environments drift apart, last-minute surprises
  • Feature flags used as substitute for release planning, technical debt accumulates
  • Rollback paths assumed but never tested for new release types
  • Release notes incomplete, support team blindsided
ITIL4-08
Service validation and testing

Service validation and testing. Control from ITIL 4 framework, domain: ITIL 4: Service Transition.

Artefacts an auditor will ask for
  • Test strategy per service or release
  • Test cases mapped to acceptance criteria and risk areas
  • Test environment access and data management procedure
  • Test execution evidence with defect log and fix verification
  • Service acceptance criteria (SAC) sign-off
Where this commonly fails
  • Non-functional testing (performance, security, accessibility) skipped under deadline pressure
  • Test data not anonymised, GDPR risk if breach
  • Test environments differ from production, defects escape
  • User acceptance testing rushed, business sign-off becomes rubber stamp
ITIL4-09
Knowledge management

Knowledge management. Control from ITIL 4 framework, domain: ITIL 4: Service Transition.

Artefacts an auditor will ask for
  • Knowledge Management policy and ownership model
  • Knowledge base with article lifecycle (draft, published, retired)
  • Article quality criteria and review cadence
  • KCS (Knowledge-Centered Service) maturity assessment if adopted
  • Knowledge usage metrics (article reuse rate, deflection rate)
Where this commonly fails
  • Knowledge base populated but articles not maintained, accuracy drops over time
  • Tribal knowledge not captured, single points of failure in staff
  • Customer-facing self-service portal poorly organised, customers prefer phone call
  • Lessons learned from incidents not converted into reusable knowledge
ITIL4-10
Configuration management

Configuration management. Control from ITIL 4 framework, domain: ITIL 4: Service Transition.

Artefacts an auditor will ask for
  • Configuration Management Database (CMDB) scope and data model
  • CI lifecycle states defined (planned, in stock, deployed, retired)
  • Configuration audit reports comparing CMDB to actual environment
  • CMDB integration map with discovery tools, monitoring, ITSM, asset mgmt
  • CI relationship mapping (depends on, runs on, supports)
Where this commonly fails
  • CMDB created during a project but never maintained, data 30%+ stale
  • Discovery tool blind spots (cloud accounts, SaaS) not reconciled
  • CI ownership not assigned, no one accountable for accuracy
  • CMDB used for compliance reporting without verification, leads to audit findings

Incident Management

SM-INC-1
Incident Management

Minimise the negative impact of incidents by restoring normal service operation as quickly as possible, with prioritisation based on business impact and urgency.

Artefacts an auditor will ask for
  • Incident management process and work instructions
  • Priority and severity matrix
  • Incident ticket samples with full lifecycle
  • Major incident procedure and post-incident review records
  • Incident SLA performance reports
  • Escalation paths and on-call schedules
  • Knowledge articles created from incidents
Where this commonly fails
  • Priority assigned inconsistently
  • Major incident reviews delayed or skipped
  • No linkage from incident to problem record
  • Post-resolution communications to customers missing

Information Security Management

GM-ISM-1
Information Security Management

Protect the information needed by the organisation to conduct its business by establishing confidentiality, integrity, availability, authentication, and non-repudiation controls aligned with business risk appetite.

Artefacts an auditor will ask for
  • Information security policy and supporting standards
  • Information security management system (ISMS) scope statement
  • Risk assessment register with treatment plans
  • Security control catalogue mapped to ISO 27001 or NIST CSF
  • Security incident response procedure and runbooks
  • Security awareness training records and phishing simulation results
  • Access control and identity governance procedures
  • Vulnerability management and penetration testing reports
Where this commonly fails
  • Security policy not reviewed annually or after major change
  • No defined risk appetite or tolerance statements
  • Security practice operates in isolation from other ITIL practices
  • Awareness training one-off rather than continuous

Infrastructure and Platform Management

TM-INF-1
Infrastructure and Platform Management

Oversee the infrastructure and platforms used by an organisation, supporting the overall service delivery including hardware, networks, cloud, and platform services with appropriate controls.

Artefacts an auditor will ask for
  • Infrastructure and platform inventory
  • Hardening standards and configuration baselines
  • Patching schedules and compliance reports
  • Cloud landing zone and guardrails documentation
  • Network segmentation and zoning documentation
  • Backup and recovery configuration
Where this commonly fails
  • Patching SLA breached for critical CVEs
  • Hardening baselines drift over time
  • Cloud accounts without guardrails
  • Backups not periodically restored

Knowledge Management

GM-KM-1
Knowledge Management

Maintain and improve the effective, efficient, and convenient use of information and knowledge across the organisation by capturing, sharing, and reusing knowledge.

Artefacts an auditor will ask for
  • Knowledge management policy and standards
  • Knowledge base structure and tagging taxonomy
  • Knowledge article lifecycle (draft, review, retire)
  • Knowledge usage metrics and gap reports
  • Subject matter expert assignments
  • Knowledge-centered service (KCS) practices evidence
Where this commonly fails
  • Knowledge base contains outdated articles
  • No ownership or review cycle for articles
  • Knowledge not captured during incidents
  • Article quality not measured

Measurement and Reporting

GM-MS-1
Measurement and Reporting

Support good decision-making and continual improvement by decreasing levels of uncertainty through the collection of relevant data and its assessment in the appropriate context.

Artefacts an auditor will ask for
  • Measurement framework linking KPIs to objectives and CSFs
  • Metric definitions and data lineage
  • Operational and executive reporting cadence
  • Data quality and validation procedures
  • Decisions log referencing reports and metrics
  • Goal-question-metric (GQM) artefacts
Where this commonly fails
  • Metrics measure activity rather than outcome
  • Reports not used in decisions
  • Data lineage unclear
  • No defined target or threshold per metric

Monitoring and Event Management

SM-MEM-1
Monitoring and Event Management

Systematically observe services and service components and record and report selected changes of state identified as events, distinguishing among informational, warning, and exception events.

Artefacts an auditor will ask for
  • Monitoring coverage matrix per critical service
  • Event classification and threshold definitions
  • Event correlation and noise reduction configuration
  • Alert routing and on-call response evidence
  • Event-to-incident automation records
  • Log retention and access control evidence
Where this commonly fails
  • Alert noise causing fatigue
  • No correlation across infrastructure, application, and security events
  • Monitoring gaps for cloud and SaaS
  • Log retention shorter than regulatory requirement

Organizational Change Management

SM-OCM-1
Organizational Change Management

Ensure that changes in an organisation are smoothly and successfully implemented and that lasting benefits are achieved by managing the people aspects of change.

Artefacts an auditor will ask for
  • Organisational change strategy and plans
  • Stakeholder impact assessments
  • Communication and engagement plans
  • Training and adoption support records
  • Adoption and behavioural change metrics
  • Resistance management actions
Where this commonly fails
  • OCM treated as communications only
  • No baseline of current behaviour
  • Training not linked to adoption metrics
  • Sustainment plan absent post-go-live

Portfolio Management

GM-PFM-1
Portfolio Management

Ensure that the organisation has the right mix of programmes, projects, products, and services to execute its strategy within funding and resource constraints.

Artefacts an auditor will ask for
  • Portfolio inventory of services, products, projects, programmes
  • Prioritisation criteria and scoring
  • Portfolio investment and resource allocation records
  • Portfolio review minutes and decisions
  • Stop, start, continue decisions log
Where this commonly fails
  • No single portfolio view
  • Investments not aligned to strategy
  • Sunsetting services rarely decided
  • Resource capacity not validated

Problem Management

SM-PRB-1
Problem Management

Reduce the likelihood and impact of incidents by identifying actual and potential causes of incidents and managing workarounds and known errors.

Artefacts an auditor will ask for
  • Problem management process documentation
  • Problem records with root cause analysis
  • Known error database (KEDB) with workarounds
  • Proactive problem identification reports (trend analysis)
  • Problem review board minutes
  • Linkage records between incidents, problems, and changes
Where this commonly fails
  • Problems closed without permanent fix
  • KEDB not visible to service desk
  • No proactive analysis of recurring incidents
  • Root cause analysis superficial or missing for major incidents

Project Management

GM-PM-1
Project Management

Ensure that all projects in the organisation are successfully delivered, balancing the constraints of scope, time, cost, quality, and benefits to support strategic objectives.

Artefacts an auditor will ask for
  • Project management methodology (waterfall, agile, hybrid)
  • Project portfolio register and prioritisation criteria
  • Project charters and business cases
  • Project risk and issue registers
  • Project status and steering committee reports
  • Benefits realisation reviews
Where this commonly fails
  • No portfolio view of projects
  • Benefits never measured post-go-live
  • Project risks not integrated with enterprise risk
  • Methodology selection not justified per project

Relationship Management

GM-REL-1
Relationship Management

Establish and nurture the links between the organisation and its stakeholders at strategic and tactical levels, including the identification, analysis, monitoring, and continual improvement of relationships.

Artefacts an auditor will ask for
  • Stakeholder map and register
  • Stakeholder engagement plan
  • Account or relationship manager assignments
  • Customer feedback and NPS or CSAT records
  • Executive sponsor and steering forum minutes
  • Relationship issue and escalation log
Where this commonly fails
  • No defined business relationship manager
  • Stakeholder engagement reactive not planned
  • Feedback collected but not acted on
  • Internal stakeholders not included in map

Release Management

SM-REL-1
Release Management

Make new and changed services and features available for use according to agreed expectations of customers and stakeholders while maintaining control of service quality.

Artefacts an auditor will ask for
  • Release policy and release model definitions
  • Release plans and schedules
  • Release approval and go/no-go records
  • Rollback and backout plans
  • Release notes communicated to stakeholders
  • Post-release review records
Where this commonly fails
  • Release and deployment conflated
  • No rollback plan for major releases
  • Releases not linked to change records
  • Stakeholders unaware of upcoming releases

Risk Management

GM-RSK-1
Risk Management

Ensure that the organisation understands and effectively handles risks by identifying, analysing, evaluating, treating, monitoring, and reporting risks across services and value streams.

Artefacts an auditor will ask for
  • Enterprise risk management framework or policy
  • Risk register with likelihood, impact, owner, and treatment
  • Risk appetite and tolerance statements
  • Risk treatment plans with target dates
  • Risk committee minutes and escalation records
  • Key risk indicator (KRI) dashboards
  • Risk acceptance approvals from accountable executives
Where this commonly fails
  • Risk register out of date or owner unassigned
  • No quantitative risk scoring methodology
  • Treatment actions not tracked to closure
  • Operational risks not linked to service or asset register

Service Catalogue Management

GM-SRV-1
Service Catalogue Management

Provide a single source of consistent information on all services and service offerings, ensuring that it is available to the relevant audience and accurately reflects what is offered.

Artefacts an auditor will ask for
  • Service catalogue with business and technical views
  • Service owner assignments per service
  • Catalogue review and approval cadence
  • Customer-facing service catalogue (portal)
  • Service retirement decisions and notifications
Where this commonly fails
  • Catalogue not in sync with actual services delivered
  • Services missing owners
  • Internal-only catalogue with no customer view
  • Retired services still listed

Service Configuration Management

SM-SCM-1
Service Configuration Management

Ensure that accurate and reliable information about the configuration of services and the CIs that support them is available when and where needed, including relationships between CIs.

Artefacts an auditor will ask for
  • Configuration management database (CMDB) with defined scope
  • Configuration management plan and CI naming standard
  • CI classes, attributes, and relationship model
  • Discovery tool configuration and reconciliation reports
  • CMDB audit results and data quality metrics
  • CI lifecycle states and ownership assignments
Where this commonly fails
  • CMDB stale, with no scheduled verification or audit
  • Relationships between CIs missing or incorrect
  • No defined data owner for CI classes
  • Discovery not reconciled with authoritative sources

Service Continuity Management

SM-SCONT-1
Service Continuity Management

Ensure that service availability and performance are maintained at sufficient levels in case of a disaster, supporting overall business continuity by defining recovery objectives and plans.

Artefacts an auditor will ask for
  • Business impact analysis (BIA) covering critical services
  • Service continuity plans with RTOs and RPOs
  • Disaster recovery test schedule and results
  • Crisis management and communications procedures
  • Recovery site and backup arrangements documentation
  • Lessons learned from continuity exercises
Where this commonly fails
  • BIA outdated or not aligned to current services
  • DR plans never tested end-to-end
  • RTO/RPO not validated against business requirements
  • No coordination with supplier continuity plans

Service Design

SM-SD-DES-1
Service Design

Design products and services that are fit for purpose, fit for use, and that can be delivered by the organisation and its ecosystem, including capacity, availability, security, and continuity considerations.

Artefacts an auditor will ask for
  • Service design packages with requirements traceability
  • Non-functional requirements (security, availability, capacity)
  • Design review and approval records
  • Service acceptance criteria
  • Operational readiness and handover checklists
Where this commonly fails
  • Non-functional requirements added late
  • No operational readiness review before go-live
  • Security and privacy by design not evidenced
  • Handover to operations incomplete

Service Desk

SM-SD-1
Service Desk

Capture demand for incident resolution and service requests, providing a clear path for users to report issues, queries, and requests, and to have them acknowledged and acted upon.

Artefacts an auditor will ask for
  • Service desk operating model and channel matrix (phone, email, portal, chat)
  • Service desk roles, training, and shift schedules
  • Service desk performance metrics (FCR, AHT, CSAT)
  • Self-service portal and knowledge usage statistics
  • User feedback and CSAT survey results
  • Triage and routing procedures
Where this commonly fails
  • Single channel reliance with no portal
  • Knowledge base not maintained by service desk
  • No measurement of customer experience
  • Tier escalation criteria unclear

Service Financial Management

GM-FIN-1
Service Financial Management

Support the organisation's strategies and plans for service management by ensuring that financial resources and investments are used effectively, including budgeting, accounting, and charging.

Artefacts an auditor will ask for
  • IT budget and forecast documents
  • Service cost model and unit costs
  • Chargeback or showback reports
  • Cloud cost (FinOps) reporting
  • Investment business cases with ROI
  • Variance analysis and adjustment records
Where this commonly fails
  • Cloud costs not allocated to services
  • No unit cost per service
  • Budgets not reconciled to actuals
  • ROI of investments not tracked post-go-live

Service Level Management

SM-SLM-1
Service Level Management

Set clear business-based targets for service performance so that the delivery of a service can be properly assessed, monitored, and managed against these targets.

Artefacts an auditor will ask for
  • Service level agreements (SLAs) with customers and OLAs with internal teams
  • SLA target measurement and reporting evidence
  • Service review meeting minutes
  • Service performance dashboards
  • Customer satisfaction measurements linked to services
  • SLA breach root cause and improvement plans
Where this commonly fails
  • Watermelon SLAs (green at SLA, red at user experience)
  • OLAs not aligned to SLAs
  • No regular service review cadence
  • SLAs measure activity not outcome

Service Request Management

SM-SRM-1
Service Request Management

Support the agreed quality of a service by handling all predefined, user-initiated service requests in an effective and user-friendly manner with appropriate approvals.

Artefacts an auditor will ask for
  • Service request catalogue with descriptions, SLAs, and costs
  • Request fulfilment workflows and approval matrices
  • Automation and self-service evidence
  • Request performance metrics
  • Segregation-of-duties checks in approval flows
  • User satisfaction with request fulfilment
Where this commonly fails
  • Requests treated as incidents
  • Approvals not enforced in tooling
  • Catalogue not maintained or out of date
  • No SLA defined per request type

Service Validation and Testing

SM-SVAL-1
Service Validation and Testing

Ensure that new or changed products and services meet defined requirements through structured testing approaches covering utility, warranty, and acceptance criteria.

Artefacts an auditor will ask for
  • Test strategy and test plans
  • Test case repositories and execution evidence
  • User acceptance testing sign-offs
  • Security testing (SAST, DAST, penetration test) results
  • Defect register and resolution tracking
  • Regression test automation evidence
Where this commonly fails
  • UAT performed by IT instead of business
  • Security testing skipped for minor changes
  • Test data contains real production data without masking
  • No regression suite for critical journeys

Software Development and Management

TM-SDM-1
Software Development and Management

Ensure that applications meet stakeholder needs in terms of functionality, reliability, maintainability, compliance, and audibility through structured development and lifecycle management practices.

Artefacts an auditor will ask for
  • Software development lifecycle documentation
  • Secure coding standards and training records
  • Code review and pull request evidence
  • Software composition analysis and SBOM artefacts
  • Source code repository access controls
  • CI/CD pipeline security controls
Where this commonly fails
  • SBOM not maintained for products
  • Open source vulnerabilities not tracked
  • Secrets committed to repositories
  • Code review skipped for hotfixes

Strategy Management

GM-STR-1
Strategy Management

Formulate the goals of the organisation and adopt the courses of action and allocation of resources necessary for achieving these goals, ensuring strategy is communicated and refreshed.

Artefacts an auditor will ask for
  • Documented business and IT strategy
  • Strategy communication evidence (town halls, intranet)
  • Strategic initiative roadmaps
  • Strategic KPIs and balanced scorecard
  • Strategy review and refresh records
Where this commonly fails
  • Strategy not refreshed annually
  • IT strategy disconnected from business strategy
  • Initiatives not tracked against strategic outcomes
  • Frontline staff cannot articulate strategy

Supplier Management

GM-SUP-1
Supplier Management

Ensure that the organisation's suppliers and their performances are managed appropriately to support the seamless provision of quality products and services aligned with strategy.

Artefacts an auditor will ask for
  • Supplier register categorised by strategic, tactical, operational, commodity
  • Contracts and service level agreements with suppliers
  • Supplier performance scorecards and review minutes
  • Supplier risk assessments including concentration risk
  • Supplier onboarding and offboarding procedures
  • Fourth-party (subcontractor) visibility records
Where this commonly fails
  • Critical suppliers not differentiated from commodity
  • No supplier exit plan
  • Contract renewals lapsed
  • Supplier security and continuity not tested

Workforce and Talent Management

GM-WT-1
Workforce and Talent Management

Ensure that the organisation has the right people with the appropriate skills, knowledge, and competencies in the right roles to support its business objectives.

Artefacts an auditor will ask for
  • Workforce plan and headcount forecasts
  • Role descriptions and competency frameworks
  • Training records and certification tracking
  • Skills gap analysis and development plans
  • Succession plans for critical roles
  • Onboarding and offboarding procedures
Where this commonly fails
  • Key person dependency without documented backup
  • Training not aligned to role competencies
  • Onboarding security checks inconsistent
  • Offboarding access removal delayed
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ITIL 4 framework page.