ISO/IEC 19770-1:2017 certification demonstrates an organisation's commitment to standardised, efficient and compliant IT asset management. Being certified offers business benefits such as continued C-level attention for ITAM, improved data security and compliance, better vendor relationships and continuous improvement. It also facilitates interoperability with other important IT functions, communication and knowledge sharing.
Obtaining ISO 19770-1 certification is not something that’s done “on the side”. There’s no set time frame, it will depend on your organisation’s prior preparation, specific needs, and scale. If you are starting from scratch or need an overhaul of your systems, it will take longer than an organisation that already has a strong management system in place for another ISO standard, for example for ISO 27001.
It will probably take more time than expected, so make sure to start early.
In general, the process can be divided into these steps:
Getting started – how to prepare
Get (re-)acquainted with the standard
First, make sure to be informed! You need to understand the business, management, and performance standards that the ISO certification for ITAM is based on. Specifically:
Note: certification is valid for 3 years, even if the standard changes in the meantime.
Did your organisation go through reorganisations, mergers, personnel changes? Or did you switch your tooling- or platform partner? Then it is important to ask yourself the following questions:
Consult your peers
After getting (re)acquainted with the ISO standard, you can consult your peers. After all, they might be going through the same process, and you might learn from them.
Pre-audit activities
Before you start and dive into the audit, you can prepare your team and organisation. Here are some tips we wholeheartedly recommend.
Perform you own Internal Assessment: Once your company understands the benchmark for certification, the company should hold an in-depth internal audits of current processes, RACI matrices and team roles. (By the way, a yearly assessment is mandatory for certification, so that’s an easy box to tick)
Enlist external expertise: Another way to prepare for an audit is working with an external ITAM specialist who performs an assessment as a "dress rehearsal" for the real thing. Being new to the company’s way of working, chances are this can be done as a one-off project or as part of a service.
Prepare Your Team: This is the moment to make sure you have the right people on board. Can they answer the questions? Do you know where the ITAM roles are delegated? It’s best you find out for yourself, and not during the actual audit.
Result / adaptation – Setting up for success
Next to assessing your status, you need to make sure that you fix what needs to be fixed before the next phase of the audit. Make sure that all the differences you found, are addressed in an ITAM improvement plan.
The assessment
After the assessment by an external, independent auditor, two things can happen:
Congratulations! You have been certified! And then?
ISO/IEC 19770-1 certificates are valid for three years. During this time, two surveillance audits are performed and then, the re-certification process will occur.
Having a hard time getting started?
Are you unsure where to start? For example, because you don’t have the manpower to handle it all, or lack the experience? Just give us a call!
Having been on 3 different sides of the process, Softline offers a 360° approach to ISO 19770 certification. Next to co-writing the certification method and supporting companies in implementing the ISO management framework, we also went through our own certification process. Resulting in Softline being the first company worldwide to be ISO/IEC 19770-1 certified.