{"id":6852,"date":"2017-02-07T19:38:24","date_gmt":"2017-02-07T19:38:24","guid":{"rendered":"https:\/\/multiacademstg.wpengine.com\/20000academy\/?p=6852"},"modified":"2024-12-12T16:54:49","modified_gmt":"2024-12-12T16:54:49","slug":"itil-underpinning-contract-vs-iso-20000-supplier-contract-similarities-and-differences","status":"publish","type":"post","link":"https:\/\/staging.advisera.com\/20000academy\/blog\/2017\/02\/07\/itil-underpinning-contract-vs-iso-20000-supplier-contract-similarities-and-differences\/","title":{"rendered":"ITIL Underpinning Contract vs. ISO 20000 Supplier Contract \u2013 Similarities and differences"},"content":{"rendered":"<p>Most of the clients I work with are focused on their customers and the services they deliver to them. Accordingly, I always receive a bunch of questions related to the Service Level Agreement (SLA; i.e., the contract an organization has with its customers), which is reasonable. But, what I often witness is that many companies get into trouble with their suppliers because they quite often take them for granted and don\u2019t pay much attention while defining relationships with them.<\/p>\n<p>What does that mean? Well, the fact is that there are situations when your company can\u2019t do everything by itself \u2013 you need someone to \u201cjump in.\u201d And, that\u2019s OK. But, to be sure that you are managing third parties, there are a lot of elements that require a serious approach. Both <a href=\"https:\/\/staging.advisera.com\/20000academy\/what-is-itil\/\" target=\"_blank\" rel=\"noopener noreferrer\">ITIL<\/a> and <a href=\"https:\/\/staging.advisera.com\/20000academy\/what-is-iso-20000\/\" target=\"_blank\" rel=\"noopener noreferrer\">ISO 20000<\/a> can help you define (and document) your relationships with third parties (or, we usually say \u2013 suppliers). There are many common elements, but also some differences between ITIL and ISO 20000.<\/p>\n<h2>The motivational factor<\/h2>\n<p>First of all, you can have the best people managing your IT services throughout their lifecycle (from idea up to operational support in the live environment), including excellent relationships with suppliers, but experience says that sooner or later you will get into a dispute. For example, your understanding of requirements could be different, or the requirements for <a href=\"https:\/\/staging.advisera.com\/20000academy\/iso-20000-documentation-toolkit\/?rel=relationship-and-agreement-processes&#038;doc=supplier-contract\" target=\"_blank\" rel=\"noopener\">suppliers<\/a> are not in line with the company\u2019s responsibilities towards their customers\u2026 So, having a written agreement will define the \u201crules of the game\u201d between you and your suppliers, as well as what to do if someone doesn\u2019t stick to the rules.<\/p>\n<p>Besides the fact that your agreement with a supplier defines your relationship with them, as well as related roles, responsibilities, activities, etc., it is also your basis for further evaluation. For example, if you need a supplier to deliver a certain functionality, check the database with all relevant data about all your suppliers and process the information. It will give you an idea of whom to work with and whom to avoid. Or, talk to colleagues who have experience with a targeted supplier. A prerequisite should be to have a documented agreement and, if possible, feedback or measurements of the supplier\u2019s performance. When I say feedback, I remember a case when quality management inside my company sent a supplier satisfaction survey. Once all the feedback was gathered, we could access the results and gain useful information while evaluating a potential supplier.<br \/>\n<div id=\"middle-banner\" class=\"banner-shortcode\"><\/div><script>loadMiddleBanner();<\/script><br \/>\n<div id=\"side-banner-trigger\" class=\"banner-shortcode\"><\/div><\/p>\n<h2>Similarities and differences<\/h2>\n<p>ITIL and ISO 20000 have many common requirements (in the case of ISO 20000-1:2011, i.e., Service Management System requirements) and recommendations (in the case of ITIL best practice implementation). Here are few areas covered by both ITIL and ISO 20000, as an example:<\/p>\n<ul>\n<li><strong>Service<\/strong> \u2013 includes a description of (service-related) requirements towards suppliers, scope of what needs to be delivered by the supplier, and service targets<\/li>\n<li><strong>Organization and communication<\/strong> \u2013includes a communication matrix, interfaces between the two companies, and integration of activities of both parties<\/li>\n<li><strong>Management and finances<\/strong> \u2013 includes charging and measurement<\/li>\n<\/ul>\n<p>Well, when we talk about differences, the biggest one is \u2013 naming. ITIL uses \u201c<a href=\"https:\/\/staging.advisera.com\/20000academy\/documentation\/underpinning-contract\/\" target=\"_blank\" rel=\"noopener noreferrer\">Underpinning Contract<\/a>\u201d as the document name (for the document that regulates relationships between IT service providers and suppliers), whereas ISO 20000 uses \u201cContract\u201d (which is, according to its application, named \u201cSupplier Contract\u201d). Additionally, ITIL emphasizes integration of the\u00a0<a href=\"https:\/\/staging.advisera.com\/20000academy\/documentation\/supplier-management-process-iso-20000\/\" target=\"_blank\" rel=\"noopener noreferrer\">Supplier Management process<\/a>\u00a0(and, consequently, the appropriate contract) with other processes in the scope of ITSM, while ISO 20000 does not. Additionally, ISO 20000 emphasizes the role of sub-suppliers and the IT organization\u2019s obligation to control them.<\/p>\n<h2>The content<\/h2>\n<p>Let\u2019s see what would be the usual content of the Supplier Agreement. As usual, ISO 20000 sets quite direct requirements about the content of such an agreement (which you need to include if you want to be ISO 20000 certified), while ITIL gives reasoning and details on how to implement it. Besides the ISO 20000 requirements and ITIL recommendations, experience shows that the usual content of the supplier agreement is as follows:<\/p>\n<ul>\n<li><strong>Operational processes<\/strong> \u2013 if your supplier is involved in your ITSM processes \u2013 define the process. That could be, e.g., the Incident Management process or the Change Management process.<\/li>\n<li><strong>Contacts and communication<\/strong> \u2013 as already stated, ISO 20000 and ITIL are quite demanding in having a clear picture of who is doing what, i.e., who is responsible for what. After all, it\u2019s in everyone\u2019s best interest to have clear definition of roles and related responsibilities.<\/li>\n<li><strong>Performance (evaluation)<\/strong> \u2013 when we are talking about <a href=\"https:\/\/staging.advisera.com\/20000academy\/documentation\/supplier-performance-report-iso-20000\/\" target=\"_blank\" rel=\"noopener noreferrer\">performance<\/a>, the guideline would be \u2013 whatever you signed in the SLA, you need to be even stricter towards your supplier. Of course, only if that\u2019s possible. For example, if you agreed with your customer (in the SLA) that incidents of priority 2 will be resolved in 4 hours, then you need to require from your supplier to resolve the same incidents in, e.g., 3 hours. Just as you are obliged towards your customers to deliver certain performance \u2013 so you need to require that from your suppliers. Measure and review the results.<\/li>\n<li><strong>Contract review<\/strong> \u2013 that could occur regularly (as mentioned above \u2013 measuring the performance of the supplier and comparing it to the agreement), or upon the contract\u2019s extension date. If you are reviewing your supplier regularly, you can include the supplier\u2019s performance or fulfillment of any other terms and obligations. On renewal of the contract, scope of cooperation and scope of the service supported will be reviewed first (together with feedback on that particular supplier).<\/li>\n<li><strong>Formal meetings<\/strong> \u2013 just as you do with your customer, you will regularly meet with your supplier. If it\u2019s included in the agreement \u2013 it\u2019s official.<\/li>\n<\/ul>\n<h2>Customer, in the background<\/h2>\n<p>Why bother with all these details, someone could ask? Well, if you have a supplier who is cooperating with you for a longer time, then an <a href=\"https:\/\/staging.advisera.com\/20000academy\/documentation\/supplier-agreement-portfolio-iso-20000\/\" target=\"_blank\" rel=\"noopener noreferrer\">agreement<\/a> may seem obsolete. But, even in that situation, you should have in mind that your company is on the front line towards your customers. If everything is OK with the services you deliver \u2013 no one will complain. But, if something goes wrong, your customers will not care whose fault it really is. For them, the answer is clear \u2013 it\u2019s yours. And that\u2019s logical because they have the agreement with you.<\/p>\n<p>Whether you can do everything by yourselves, or you need someone else \u2013 they don\u2019t care. So, it\u2019s your job and responsibility to protect the services you deliver, and certainly your company\u2019s. An agreement with your suppliers is the right approach. And, sometimes, the only thing you can do.<\/p>\n<p><em>To implement ISO 20000 easily and efficiently, use our<\/em> <a href=\"https:\/\/staging.advisera.com\/20000academy\/iso-20000-documentation-toolkit\/\" target=\"_blank\" rel=\"noopener\">ISO 20000 Documentation Toolkit<\/a> <em>that provides step-by-step guidance for full ISO 20000 compliance.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Most of the clients I work with are focused on their customers and the services they deliver to them. Accordingly, I always receive a bunch of questions related to the Service Level Agreement (SLA; i.e., the contract an organization has with its customers), which is reasonable. But, what I often witness is that many companies &#8230;<\/p>\n","protected":false},"author":32,"featured_media":6854,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[564,366,344,405,565],"class_list":["post-6852","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-contract","tag-iso-20000","tag-itil","tag-supplier","tag-underpinning-contract"],"acf":[],"_links":{"self":[{"href":"https:\/\/staging.advisera.com\/20000academy\/wp-json\/wp\/v2\/posts\/6852","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/staging.advisera.com\/20000academy\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/staging.advisera.com\/20000academy\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/staging.advisera.com\/20000academy\/wp-json\/wp\/v2\/users\/32"}],"replies":[{"embeddable":true,"href":"https:\/\/staging.advisera.com\/20000academy\/wp-json\/wp\/v2\/comments?post=6852"}],"version-history":[{"count":3,"href":"https:\/\/staging.advisera.com\/20000academy\/wp-json\/wp\/v2\/posts\/6852\/revisions"}],"predecessor-version":[{"id":17960,"href":"https:\/\/staging.advisera.com\/20000academy\/wp-json\/wp\/v2\/posts\/6852\/revisions\/17960"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/staging.advisera.com\/20000academy\/wp-json\/wp\/v2\/media\/6854"}],"wp:attachment":[{"href":"https:\/\/staging.advisera.com\/20000academy\/wp-json\/wp\/v2\/media?parent=6852"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/staging.advisera.com\/20000academy\/wp-json\/wp\/v2\/categories?post=6852"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/staging.advisera.com\/20000academy\/wp-json\/wp\/v2\/tags?post=6852"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}