What is ISO/IEC 20000-3 about?
ISO/IEC 20000-3 includes guidance on the scope definition and applicability to the requirements specified in ISO/IEC 20000-1. ISO/IEC 20000-3 assists in establishing whether ISO/IEC 20000-1 is applicable to an organization’s circumstances. ISO/IEC 20000-3 illustrates how the scope of an SMS can be defined, irrespective of whether the organization has experience of defining the scope of other management systems.
The guidance in ISO/IEC 20000-3 can assist an organization in planning and preparing for a conformity assessment against ISO/IEC 20000-1. Annex A contains examples of possible scope statements for an SMS. The examples given use a series of scenarios for organizations ranging from very simple to complex service supply chains. ISO/IEC 20000-3 can be used by personnel responsible for planning the implementation of an SMS, as well as assessors and consultants. It supplements the guidance on the application of an SMS given in ISO/IEC 20000-2. Requirements for bodies providing audit and certification of an SMS can be found in ISO/IEC 20000-6 which recommends the use of ISO/IEC 20000-3.
Who is BS ISO 20000-3 for?
BS ISO 20000-3 on information technology and service management applies to:
- IT project managers
- IT helpdesk services
- Cyber security professionals
- IT hardware and software application engineers
Why should you use ISO/IEC 20000-3?
ISO/IEC 20000-3 helps every business sector in automating their processes and their systems to target objectives, generate revenue and reduce the inefficiency of their work. ISO/IEC 20000-3 provides guidance on scope definition and applicability of ISO/IEC 20000-1. ISO/IEC 20000-3 does not add any requirements to those stated in ISO/IEC 20000-1. Organizations, of any size, type, or area of operations, can provide a range of services to different types of customers, internal and external, and rely on complex service supply chains.
The operation of a service management system (SMS) may involve many parties across legal jurisdictions, national boundaries and time zones. The SMS should include the appropriate controls to facilitate the coordination of all parties participating in the service lifecycle. ISO/IEC 20000-3 takes the form of examples, guidance and recommendations. ISO/IEC 20000-3 should not be quoted as if it were a specification of requirements.
What’s changed since the last update?
BS ISO 20000-3:2019 supersedes BS ISO 20000‑3:2012. BS ISO 20000-3:2019 includes some technical changes with respect to BS ISO 20000‑3:2012. These include:
- BS ISO 20000-3 aligned with the third edition of ISO 20000-1
- Example scenarios in Annex A have been updated to reflect contemporary service management environments, including complex service supply chains

