Bond prepares ISO/IEC 20000-1 certification in Iraq and Kurdistan.
The IT service management system. It sets how services are agreed, delivered, measured and repaired, and it is the certificate telecom operators, banks and government IT tenders ask a service provider for.
ISO/IEC 20000-1 IT service management systems · IT services
What ISO/IEC 20000-1 is
ISO/IEC 20000-1:2018 is the international standard for a service management system. It asks a company to name the services it delivers, agree measurable targets for each one, control changes and releases, and record how incidents, service requests and problems are handled and closed. It applies to a defined set of services. The certification body issues the certificate to the company.
What the standard requires
- Clauses 1 to 3 cover scope, normative references and terms. Clauses 4 to 10 are the requirements an auditor checks, and clause 8 carries most of them.
- Clause 4, context. Name the parties that matter, fix which services the system covers, and state which parts of those services are delivered by other parties.
- Clause 5, leadership. Management signs the service management policy and names an owner for every process in writing.
- Clause 6, planning. Set service management objectives with numbers and dates, and plan how the services in scope will be delivered.
- Clause 7, support. Competence records for the service desk and the engineers, plus version control over the documented information.
- Clauses 8.2 to 8.4, portfolio and agreements. Service catalogue, service level agreements with measurable targets, supplier contracts, configuration records, budgeting, demand and capacity planning.
- Clause 8.5, design, build and transition. A record for every change, an approval step before production, and controlled release and deployment.
- Clause 8.6, resolution and fulfilment. Incident management, service request handling and problem management, each with a recorded owner, priority and closing time.
- Clause 8.7, service assurance. Availability targets, a service continuity plan that is tested, and information security controls inside the service.
- Clauses 9 and 10, evaluation and improvement. Report performance against the service level targets, run internal audits, hold a management review, and log, correct and close every nonconformity.
Who needs ISO/IEC 20000-1 in Iraq and Kurdistan
The buyers that ask for ISO/IEC 20000-1
| Buyer or list | What they ask for |
|---|---|
| Telecom operators | Zain Iraq, Asiacell and Korek Telecom prequalify managed service and network support contractors, and the service management certificate sits in that file next to ISO/IEC 27001. |
| Banks and payment companies | Electronic payment providers licensed by the Central Bank of Iraq review a supplier's change control, release approval and incident response before granting access. |
| Federal Ministry of Planning | Contractor classification and the federal unified electronic tendering platform. We confirm the current instruction before filing. IT support packages carry a service level section. |
| KRG Approved Suppliers Center | asc.gov.krd. Annual registration. Certificates must come from a recognised conformity body to clear the quality criteria. |
| UN agencies through UNGM | ungm.org. One free registration covers UNDP, UNICEF, WFP, UNHCR, IOM and FAO. IT support contracts are written in English with response times in the schedule. |
| Kurdistan and Basra operators | DNO, Genel Energy, Gulf Keystone, HKN and Basrah Gas Company prequalify IT and communications suppliers, in Kurdistan through the MNR list at mnronline.com/avl. |
| Foreign vendors appointing a local partner | A software or hardware vendor naming an Iraqi partner for first line support asks for ISO/IEC 20000-1 and ISO/IEC 27001 together. |
| Gulf buyers and lenders | Buyers in the UAE, Saudi Arabia and Qatar require a certificate from a body accredited under an IAF member, such as Bureau Veritas, SGS or TUV. |
Two tracks, you choose one
Certificate track
5 daysA company that has to answer a service management clause in a telecom, bank or ministry IT tender before the deadline, or register on the KRG ASC with a recognised certificate. We prepare the compliance system in five working days. The certification body then issues the certificate, and its calendar sits outside the five days.
Steps- We read the tender or the vendor questionnaire on day one and confirm which services the certificate covers and which body the buyer accepts.
- We write the service catalogue and the service level targets with the service manager on day one and day two.
- We write the document set on day two and day three: policy, process descriptions, incident and change procedures, and the report formats.
- We set the service desk tool up on day three to record the fields the standard requires, or build the record forms if there is no tool.
- We train the service desk and the process owners on day four in half day sessions on the records they have to keep.
- We run the first internal audit and the management review on day five, then close the findings.
- We book the certification body at the end of the five days, and the body sets the stage 1 and stage 2 dates on its own calendar. We prepare the site, attend both stages, and answer the findings with your team.
- The service management system, complete in five working days
- Scope statement naming the services and the parties involved
- Service catalogue and service level agreements with measurable targets
- Service management policy, objectives and process descriptions
- Incident, service request, problem and change procedures
- Configuration and release records
- Internal audit report, management review minutes and corrective action records for every finding
- The certification body booking and a three year surveillance and renewal calendar
Implementation track
6 to 14 weeksA company whose service records will be read by a bank, a telecom operator or a foreign vendor, and that wants the service desk running to the targets rather than reporting against them after the fact.
Steps- We analyse what the company does and what its buyers and tenders require, then send a proposal.
- We build the service catalogue and agree the targets with the customers who sign the service level agreements.
- We design each process with the people who run it: incident, request, problem, change, release, capacity and continuity.
- We write the documentation in Arabic, Kurdish or English and configure the tool so the records come out of normal work.
- We train the service desk, the engineers and the process owners, and hand each process to its owner.
- We let the system run live for three to four weeks so the certification body sees real tickets, change records and service reports.
- We run the internal audit programme and the management review, then prepare the site and attend stage 1 and stage 2.
- Service catalogue and signed service level agreements
- Full documented system in the working language
- Configured service desk with the required record fields
- Three to four weeks of live tickets, change records and service reports
- Tested service continuity plan with the test record
- Supplier contracts with matching targets and a supplier review file
- Internal audit programme, reports and management review minutes
- A three year surveillance and renewal calendar we run with you
The certification body issues the certificate.
The implementation track, week by week
| Phase | Weeks | What happens |
|---|---|---|
| Scope and service catalogue | Weeks 1 to 2 | We confirm which services, customers and sites the certificate covers and which body the buyer accepts. Nothing is written before this is fixed. |
| Targets and agreements | Weeks 2 to 4 | We set measurable response, resolution and availability targets, sign them into the service level agreements, and match the supplier contracts to them. |
| Process design and documentation | Weeks 3 to 8 | Incident, service request, problem, change, release, capacity and continuity processes written with the people who run them, in Arabic, Kurdish or English. |
| Tool and record setup | Weeks 6 to 9 | We configure the service desk so priority, owner, timestamps and closing codes are captured, or build the record forms where there is no tool. |
| Training and rollout | Weeks 8 to 10 | A session for the service desk, a session for the engineers, one per process owner, and a session for management on the review and the reports. |
| Records running live | Weeks 9 to 12 | The processes run in daily operations for three to four weeks so there are real tickets, change approvals and service reports for the auditor to sample. |
| Internal audit and management review | Weeks 12 to 13 | We audit every clause, check performance against the agreed targets, log the findings, and hold the management review with the owner. |
| Certification audit | Weeks 13 to 14 | The accredited body runs stage 1 on the documents and stage 2 on site with the live records. We prepare the site, attend both, and answer the findings. |
What we do, what you do
We do
- Confirm which services, which scope and which certification body the buyer accepts, before any work starts.
- Write the service catalogue and set measurable targets with the service manager and the customers.
- Write the whole documented system in the language the company works in.
- Configure the service desk records or build the forms so evidence comes out of normal work.
- Train the service desk, the engineers, the process owners and management on the records they have to keep.
- Run the first internal audit against every clause and chair the management review.
- Select certification bodies, collect their quotes, and book the audit dates.
- Prepare the site, attend stage 1 and stage 2, answer the auditor, and write the corrective actions for every finding.
- Keep the surveillance and recertification dates in a calendar and prepare the company for each audit.
You do
- Name one service manager who can give about six hours a week during process design.
- Give us the current contracts, service level agreements, tool exports and any ticket history you already hold.
- Release each process owner for a half day of training and a half day for the internal audit.
- Give the service desk staff two hours each on the new record fields before the live period starts.
- Run the tested service continuity exercise, which takes about half a day for the technical team.
- Have the owner or general manager attend the management review, which takes about two hours.
- Pay the certification body directly, or through us at cost with the receipts.
- Have the owner or general manager present at the opening and closing meetings of the certification audit.
What moves the price
- Number of services in scope and how different they are from each other.
- Number of sites and whether the auditor has to travel to Erbil, Sulaymaniyah, Baghdad or Basra.
- Effective headcount delivering and supporting the services, which sets the auditor days the body calculates.
- Whether parts of the service are delivered by other parties, because each one has to be controlled and evidenced.
- Whether a service desk tool already exists or the records have to be built from nothing.
- Whether the certificate has to come from a body accredited under an IAF member or a locally accredited body is enough.
- Languages the documentation is written in.
- How much usable process documentation and ticket history already exists in the company.
- Whether ISO/IEC 20000-1 is built alone or together with ISO 9001 and ISO/IEC 27001 as one system, which lowers total auditor days.
The proposal names the scope, the deliverables and the dates before work starts.
ISO/IEC 20000-1 questions we are asked
We prepare the compliance system in five working days on the certificate track. The implementation track runs six to fourteen weeks. The certification body then issues the certificate. Bodies working in Erbil and Baghdad set their own audit dates.
The proposal names the scope, the deliverables and the dates before work starts.
A certificate from a body accredited by IQAS, for example KQC in Erbil, is valid in Iraq and accepted for KRG lists. IQAS is not a member of the IAF Multilateral Recognition Arrangement. Telecom operators, banks, UN agencies and foreign vendors normally require a body accredited under an IAF member, such as Bureau Veritas, SGS or TUV. We confirm which one the buyer accepts before any body is booked.
Zain Iraq, Asiacell and Korek Telecom ask managed service and network support contractors for it. Electronic payment providers licensed by the Central Bank of Iraq check change control before granting production access. Government IT packages run through the Ministry of Planning unified electronic platform under Instruction No. 1 of 2025, in force since February 2026, and KRG ASC registration at asc.gov.krd is renewed every year. Clause 8.7.3 requires information security inside the service, so banks and telecom operators usually ask for ISO/IEC 27001 in the same vendor file.
Three years from the date of issue. The certification body runs a surveillance audit each year and a recertification audit in year three. We keep those dates in a calendar and prepare the company for each one. If a surveillance audit is missed the body can suspend the certificate, and a suspended certificate will not pass a list renewal at the KRG ASC or a telecom operator's annual vendor review.
ITIL is a set of practices and a training scheme for individuals, and a company cannot be certified against it. ISO/IEC 20000-1:2018 is the standard a company is certified against, with 10 clauses and an audit by an accredited body every year. Staff in Erbil and Baghdad often hold ITIL certificates, and that training helps, but a tender asking for a company certificate needs ISO/IEC 20000-1.
Yes. We work anywhere in Iraq, in Basra, Baghdad, Kirkuk, Erbil, Sulaymaniyah and Duhok, and in the Gulf. The office is in Erbil and the team travels to the site.
Business inquiry
Select a target. Two questions follow, and the file reaches the desk on WhatsApp. A reply comes within four working hours.