SCRM Supplier Compliance & Risk Management

Home

ISO/IEC 20000-1:2018 · clauses 8.2.3 and 8.3.4

Your service level is only as solid as your sub-supplier’s.

The IT service management standard requires supplier governance in its own right: documented agreements, defined interfaces and continuous performance monitoring – for external and internal suppliers alike.

ISO/IEC 20000-1 addresses organisations delivering IT services. Because such services are almost never delivered entirely in-house, the standard explicitly covers the parties involved: external suppliers, internal suppliers and customers acting as suppliers.

For providers this is both a sales argument and an audit point. Committing to a service level means showing that the underlying supply contracts can carry it – otherwise the commitment is a bet.

Who this concerns

  • IT providers and managed service providers, certified or not.
  • Internal IT functions delivering services to business units.
  • Providers whose customers require ISO 20000 or comparable terms contractually.
  • Anyone passing work to subcontractors – data centre, support, development.

What the standard requires

8.2.3
Control the parties involved in the service lifecycle: who delivers which part, through which interface.
8.3.4.1
Documented agreements with external suppliers, including performance targets.
8.3.4.1
Monitor and evaluate supplier performance against those targets.
8.3.4.2
Internal suppliers and customers acting as suppliers need agreed interfaces too.
8.7
Keep incidents and service requests traceable across organisational boundaries.

How SCRM covers it

Service mapping per supplier

Which provider underpins which service – the basis of any outage analysis.

Agreements with targets

Service levels and response times as checked fields, not a PDF attachment.

Performance monitoring

Reviews on fixed cycles, deviations recorded.

Chain visible

Your provider’s subcontractors as part of the record.

Frequently asked

We are not certified. Why bother?

Because customers increasingly ask, and because DORA and NIS2 point the same way: documented agreements and monitored performance.

What is an internal supplier?

Another unit of the same company delivering part of the service. The standard requires agreed interfaces there too – the commonly overlooked part.

How does this relate to ITIL?

ITIL is a framework of guidance, ISO/IEC 20000-1 a certifiable standard with requirements. In practice they complement each other.

Contact

Request a consultation

A few details is all we need. We reply within one working day with an honest read on whether SCRM fits your situation.

  • A free seven-day demo account on request
  • Reply within one working day
  • No newsletter, no sharing with third parties
  • An honest read, including when we are not the fit
What drives your supply chain monitoring? *

Select all that apply

How can we reach you? *

Either one of the two is enough.

No leading zero, e.g. 79 123 45 67

* Required