IT is no longer just a support function sitting behind the scenes. It runs the systems customers touch directly, the platforms employees depend on every hour of the day, and the infrastructure that keeps a business operating at all. As that responsibility has grown, so has the need for a structured, repeatable way to manage it. That is what ITIL (Information Technology Infrastructure Library) was built to provide, and in 2026 the framework itself went through its biggest update since 2019.
This guide covers what ITIL actually is, how its practices and principles fit together, what changed with the recent move to ITIL 5, and how a team can start applying any of it without getting lost in certification jargon.
What Is ITIL?
ITIL is a framework for IT service management (ITSM): a shared set of concepts, practices, and guiding principles for planning, delivering, and improving IT services. It does not prescribe a rigid set of steps to follow. Instead, it gives organizations a common vocabulary and a proven set of practices to adapt to their own size, industry, and maturity level.
ITIL began in the 1980s as a set of published books commissioned by the UK government’s Central Computer and Telecommunications Agency, aimed at standardizing how IT services were run across public sector projects. It has since gone through several major revisions, each one reflecting how IT itself changed.
Figure 1. ITIL has been revised roughly once per decade. ITIL 5, published by PeopleCert in 2026, is the first major revision since ITIL 4 in 2019.
The ITIL Service Value System
Everything in ITIL sits inside what the framework calls the Service Value System (SVS): the overall model for how an organization turns demand into value, whatever that value looks like for its customers. The SVS has five parts working together.
- Guiding principles, seven recommendations that shape decision-making in any situation.
- Governance, the mechanisms by which an organization is directed and controlled.
- The service value chain, the set of activities an organization performs to create and deliver services and products.
- Practices, 34 sets of organizational resources built for specific purposes, from incident management to supplier management.
- Continual improvement, the practice and mindset of improving everything, all the time.
None of these parts work in isolation. Governance shapes how the value chain runs, practices supply the specific capabilities the value chain draws on, and continual improvement touches all of it. That interdependence is the main reason ITIL resists being treated as a linear checklist. It is closer to an operating model than a workflow diagram.
The Four Dimensions of Service Management
ITIL asks organizations to look at every service through four dimensions at once, so that a fix in one area does not quietly create a problem in another. This model carried over from ITIL 4 into ITIL 5 without change.
Figure 2. Every service should be evaluated across all four dimensions, not just the technology one. A tool rollout that ignores the people or supplier dimension usually stalls in adoption, not in the software itself.
The Seven Guiding Principles
The guiding principles are the part of ITIL meant to travel with a person regardless of which practice they are working in. They are recommendations, not rules, and PeopleCert has kept all seven unchanged in ITIL 5.
Figure 3. The seven guiding principles apply across every practice and every dimension. They are the one part of ITIL meant to be memorized rather than looked up.
The 34 Management Practices
Practices are where ITIL gets specific. Each one is a defined set of organizational resources (people, processes, information, and tools) built to achieve a particular objective, such as handling incidents, managing changes, or tracking configuration items. ITIL 4 organized all 34 practices into three groups. ITIL 5 keeps the same 34 practices but reorganizes them into two.
Figure 4. ITIL 5 keeps the same 34 practices carried over from ITIL 4, but retires the separate technical management group and folds those practices into a combined product and service management group. PeopleCert describes the individual practices as staying largely the same, with some adjustments.
The practices themselves are grouped by what they help with rather than by which department owns them. Familiar ones include incident management, problem management, change enablement, service desk, and configuration management, alongside practices that get less attention but matter just as much, like workforce and talent management, supplier management, and continual improvement itself.
What ITIL 5 Actually Changes
ITIL 5 was published by PeopleCert, the company that now owns the ITIL trademark after acquiring AXELOS, and it is described as an evolution of ITIL 4 rather than a replacement of it. The guiding principles and the underlying value system carry forward, so a team that has already invested in ITIL 4 is not starting over. The changes that matter most are these:
- Products and services are treated as one model. Earlier versions of ITIL focused on services. ITIL 5 explicitly extends that scope to digital products, reflecting how much of modern IT delivery is now productized rather than delivered as a one-off service engagement.
- AI is addressed directly rather than left as an afterthought. ITIL 5 is described by PeopleCert as built for an AI-native and increasingly complex environment, with guidance on where AI fits into governance and operating models instead of treating it purely as a tool choice.
- Practice groups were simplified from three to two, as shown above, without reducing the number of practices themselves.
- Digital experience gets more explicit attention, reflecting the reality that how a service feels to use has become as important as whether it technically works.
- The certification pathway was restructured around three designations: ITIL Practice Manager, ITIL Managing Professional, and ITIL Strategic Leader, with an ITIL Master designation for those who complete all three.
Some of the finer detail, such as exactly how individual value chain activities are being renamed or how specific practices will shift between the two new groups, is still settling as PeopleCert rolls out training material and different providers publish their own interpretations. Organizations do not need to wait for every detail to be finalized before acting. The direction is already clear enough to plan around: treat products and services together, put real governance around AI use, and keep the practices that already work.
Where AI Actually Fits Into ITIL Work Today
Most of the AI conversation around ITSM tools focuses on chatbots answering tickets, which is real but narrow. The more useful shifts are happening in a few specific places.
- Triage and categorization. Incoming incidents and requests can be classified and routed automatically, which speeds up the early minutes of incident management without changing the practice itself.
- Knowledge and problem management. Pattern recognition across historical incidents can surface likely root causes and related knowledge articles faster than a person searching manually.
- Change risk assessment. Some platforms now flag changes that resemble past changes which caused incidents, adding a layer of risk scoring to change enablement rather than replacing the approval process.
- Governance, not just execution. This is the part ITIL 5 calls out directly. Using AI inside a practice is a tooling decision. Deciding who is accountable when an AI-assisted decision goes wrong is a governance decision, and that is the part organizations tend to skip.
None of this replaces the discipline ITIL asks for. It changes how fast some steps happen and raises the bar on how clearly accountability needs to be defined before automation is layered on top of a practice.
How to Actually Start Using ITIL
Adopting ITIL does not mean implementing all 34 practices at once, and no organization should try. A more realistic starting sequence looks like this.
- Assess where you actually are. Before changing anything, get an honest, evidence-based read on current maturity across people, process, tools, and governance. Guessing at this step is the most common reason ITIL initiatives stall later.
- Pick two or three practices that matter most right now. Incident management and change enablement are common starting points because they are visible and their impact is easy to measure.
- Map the four dimensions for each practice you touch. Confirm the people, the tooling, the supplier relationships, and the actual process are all being addressed together, not just the tooling.
- Apply the guiding principles as a filter, especially “start where you are” and “keep it simple and practical,” to avoid rebuilding processes that already work reasonably well.
- Build in continual improvement from day one rather than treating it as a phase that happens after the “real” implementation is finished.
Check Your Own ITSM and ITOM Maturity
If you are trying to figure out where your own organization actually stands before committing to an ITIL 5 upgrade path or a new tool purchase, Desqcon Consulting’s ITSM & ITOM Maturity Assessment gives you a structured, evidence-based read on that. Start with a free trial across one process area, or request the full deep-dive assessment across people, process, tools, automation, AI, and governance.
