Skip to main content
Version: 0.7.0

SAF and ISO/IEC 20000-1

Nature and status of the approach

ISO/IEC 20000-1:2018 is an international standard specifying requirements for a service management system (SMS). ISO confirmed the third edition in 2023, and it remains current; Amendment 1:2024 adds changes related to climate action. The standard specifies organizational requirements, not a metamodel of architectural objects.

Purpose and audience

The standard is intended for organizations that plan, design, transition, deliver, and improve services, as well as for customers, auditors, consultants, and conformity-assessment bodies. SAF addresses organizational modeling and may provide part of the controlled information used by an SMS, but it does not implement a management system by itself.

Management scope and unit

The subject is an SMS within a defined scope and the services it manages. Relevant concerns include organizational context, interested parties, leadership, planning, support, operations, performance evaluation, and improvement. SAF's primary unit is an architectural object, so most correspondence between the standard and SAF is indirect.

Concepts and SAF mappings

ISO/IEC 20000-1Nearest concept in SAFType / confidenceBoundary
ServiceServiceDirect / highWithin an SMS, a service is subject to management-system requirements.
Organization / service providerActor or group of actorsPartial / mediumSAF does not model the legal scope of an SMS as a separate type.
Customer and interested partyActor with a rolePartial / highA role is captured by an attribute or external reference data.
Service requirementsService attributes and an external requirementPartial / mediumRequirement is not a SAF core type.
Processes and documented informationProcess and Information ObjectPartial / mediumDocumented information includes management evidence, not only business data.
Technology supporting servicesSystems, Components, Deployments, and resourcesComposite / mediumThe standard does not define SAF's architectural decomposition.

Relationships

An SMS connects interested-party requirements, scope, services, processes, resources, responsibilities, risks, measures, and improvements. SAF can substantiate the architectural part of the chain “consumer — Service — Process — Capability — System — infrastructure,” while conformity, control, audit, and corrective-action relationships remain in the SMS.

Lifecycle and organization of work

The official summary of the standard covers planning, design, transition, delivery, and improvement of services. SAF stores facts before and after a change and can support impact analysis. Management of the transition itself, evidence of execution, and nonconformities remains outside the architecture repository.

Roles and governance

An organization within the SMS scope must define responsibilities and authorities. SAF shows an owner for a significant object, but it does not prove fulfillment of requirements for leadership, competence, communication, internal audit, or management review.

Measures, maturity, and adaptation

ISO/IEC 20000-1 requires monitoring, measurement, analysis, evaluation, and continual improvement of the SMS and services. These are performance requirements, not a SAF maturity scale. A company profile may reduce SAF depth, but it does not alter the standard's requirements within a declared certification scope.

Using the approaches together

SAF is useful as a controlled map of the service scope and supporting architecture. Joint use requires SMS links to service_id, the owner, processes, and critical dependencies; SAF quality rules can provide evidence of currency. Other documents, risks, audits, and corrective actions remain in the management system.

Mapping limitations

The full standard is licensed by ISO. This analysis is limited to the official catalog and public materials and is not an interpretation of requirements for a certification audit. SAF is not claimed to conform to ISO/IEC 20000-1.

Sources for the approach