Overview
ISO/IEC 19770-11:2021 specifies requirements and guidance for certification bodies that audit and certify an IT asset management system (ITAMS) in accordance with ISO/IEC 19770-1. It supplements ISO/IEC 17021-1 by providing ITAM‑specific expectations for impartiality, competence, audit processes and documentation. The document can also be used by accreditation bodies when assessing certification bodies, though it does not itself set requirements for how accreditation bodies audit certification bodies.
Key topics and technical requirements
This standard focuses on practical, conformity‑assessment topics tailored to IT asset management and includes (but is not limited to):
- Principles and general requirements for certification bodies auditing ITAMS
- Legal, contractual and liability considerations relevant to certification activities
- Impartiality management and specific handling of conflicts of interest (SM5.2.2)
- Structural and resource requirements, including competence of personnel and evaluation processes
- Personnel management: records, use of external auditors/technical experts, and outsourcing controls
- Information requirements: public information, certification documentation, scope definition, confidentiality and information exchange
- Process requirements for the full certification lifecycle: pre‑certification, audit planning, audit conduct (opening/closing meetings, evidence collection, reporting), certification decision, maintenance, appeals and complaints
- Audit specifics such as determining audit time, multi‑site sampling, multi‑standard integrations and cause analysis for nonconformities
- Management system requirements for certification bodies and an annex on knowledge and skills for ITAMS auditing
These topics align with ISO/IEC 17021-1 while adding ITAM‑specific guidance to ensure consistent, competent ITAMS audits.
Applications and who should use it
ISO/IEC 19770-11 is intended for:
- Certification bodies that issue ITAMS certifications and need to demonstrate compliance with ITAM‑specific auditing practices.
- Accreditation bodies assessing certification bodies for ITAMS audit competence (as guidance).
- Organizations seeking ITAMS certification, procurement or compliance teams who want to understand audit expectations and certification scope.
- ITAM consultants and auditors developing audit programs, competence matrices, or training aligned to international audit requirements.
Practical benefits include harmonized audit approaches, clear competence criteria for auditors, improved impartiality and confidentiality controls, and better predictability of certification outcomes.
Related standards
- ISO/IEC 19770-1 - IT asset management systems - Requirements (audit target)
- ISO/IEC 17021-1 - Requirements for bodies providing audit and certification of management systems (base criteria)
- ISO/IEC 19770-5 - Overview and vocabulary
- ISO/IEC 20000-1 - Service management system requirements (related IT management context)
Keywords: ISO/IEC 19770-11, IT asset management, ITAMS certification, certification bodies, audit and certification, ISO/IEC 19770-1, ISO/IEC 17021-1, accreditation bodies.