You likely know that Iran is an oil-rich country. It’s a God-given windfall of wealth that, because it is not managed properly, goes to waste. In my opinion, our obsession with oil and gas, along with poor governance, has made information technology in Iran less impressive than in India, the United States, and other countries. Nevertheless, despite sanctions, pressure, and market difficulties, technology has made significant progress thanks to the efforts of some capable players. And ITIL has played a role.
Why ITIL Matters More Than Ever in Modern IT
Many services and systems have been implemented in Iran. Although the range of choices has always been limited and, in my opinion, still is. These companies are ultimately government-managed, tying everyone’s hands and restricting their freedom to act. Still, people do their best to prove themselves.
Under these circumstances, trying to establish ITIL concepts in Iran, which was one of our missions, was extremely difficult. Who assigned this mission? Nobody! It was simply a human feeling, running perpendicular to my business instincts, that came over me, and I felt that I should spread everything I had learned. My intention was to improve the chaotic state of services in these organizations. As things progressed, my business instinct also took shape, and I began earning income from it.
Why Buying Technology Isn’t Enough
At first, whenever I spoke about the ITIL framework, everyone ignored it. But today, after 20 years of continuous effort, much of which was carried out by my team and me, I am happy that others and companies have also joined this cause and that some degree of understanding and maturity in service management has been achieved. Today, many oil, gas, and petrochemical companies are on our customer list.
Despite sanctions, market limitations, difficulties in obtaining equipment, and limited choices, Iran’s IT industry has not come to a standstill. Major services, infrastructures, and systems have been implemented in banks, oil and gas companies, petrochemical companies, steel industries, universities, operators, government organizations, and private companies. Today, the main issue is no longer merely “buying and installing technology”; it’s properly managing what has already been purchased and implemented.
This is where ITIL adoption is important.
IT and ITIL in Iran
Organizations in Iran are highly inclined to purchase equipment without providing even the slightest proper service. I tried to change this mindset: after all, a fool with a tool is still a fool!
I repeatedly said that, contrary to common belief, ITIL is not a collection of forms, complicated terminology, or requirements for obtaining a certificate. ITIL helps an organization understand whom it serves, what services it delivers, and what value it creates. Having servers, software, networks, a data center, or an advanced IT service desk does not, by itself, mean that an organization provides desirable IT services.
In the oil, gas, and petrochemical industries, a single system failure may disrupt production. In a bank, an interruption lasting only a few minutes may affect thousands of transactions. At a university, losing a service can disrupt the educational process for thousands of students. In manufacturing companies, system unavailability may disrupt the supply chain, sales, or factory operations.
In such environments, concepts such as incident management, service request management, change management (or change enablement), problem management, IT asset management, service configuration management, service level management, knowledge management, and service continuity are not ceremonial matters. They are mechanisms for reducing disruption, controlling risk, preventing error recurrence, and protecting the organization’s investments.
ITIL vs ISO/IEC 20000: Understanding the Difference
Once, an information technology manager asked me, “I wish ITIL could also become a standard, rather than merely being a best practice.” It seems that unless there is an audit or some form of force, nobody is interested in it!
I’ve also thought about this. In my opinion, he was right. Had ITIL not merely been a set of “best practices,” perhaps it would have gained a more compulsory position. My experiences have shown that many organizations have little motivation to improve their service management unless they face an audit, a contractual obligation, pressure from a higher authority, or the risk of losing a certificate.
Everyone speaks about continual improvement, value creation, and customer centricity. But when implementation is optional, budgets and attention usually go to matters that seem more urgent.
Of course, ISO/IEC 20000 exists for auditing and certification. ITIL itself, however, is not an auditable standard and mainly serves as guidance and a collection of best practices. From one perspective, this freedom may be an advantage because it does not trap organizations in a rigid and identical model. But in a culture where doing the right thing often happens only through force (like in Iran), this same flexibility may become an excuse for doing nothing at all.
The Risks of Treating ITIL as “Just Guidance”
The bitter reality is that some organizations do not understand the necessity of service management until a major incident occurs, critical information is lost, a service stops working, or an auditor raises a nonconformity. It is as though prevention, service ownership, documentation, change management, and continual improvement are still considered “additional expenses.” Meanwhile, the much higher costs of disruption and disorder are completely accepted.
ITIL may not be implementable by force, but without some form of managerial obligation, performance indicators, contractual commitment, and clear accountability, (based on my experiences in Iran) it will not progress beyond a few training courses and a number of terms in many organizations.
Nevertheless, being a best practice is both an advantage and a limitation; it depends on what we expect from ITIL. However, we must ask why ITIL did not become an auditable standard.
Why ITIL isn’t a Standard
ITIL isn’t meant to tell every organization exactly what structure it should have or what forms it must complete. Instead, ITIL is a framework and a collection of best practices that an organization must adapt to its own size, industry, risks, culture, and maturity. PeopleCert’s official resources also emphasize “adapting practices to the organization’s real environment,” rather than implementing an identical model for everyone.
An auditable standard must include clear, demonstrable requirements. It must specify what an organization must create, document, maintain, and review. This role is fulfilled by ISO/IEC 20000-1 – a service management standard that defines the requirements for establishing, implementing, maintaining, and continually improving a “service management system.”
Simply put, ISO/IEC 20000 specifies the management system that must exist, while ITIL helps us understand how to implement it effectively and appropriately.
How ITIL Reduces Risk and Protects IT Investments
The advantage of ITIL as a best practice is that an organization is not forced to create useless, burdensome processes merely to obtain a certificate. A small company, a bank, a university, or a refinery can use the same shared concept while implementing it in line with its own risks and complexity.
This flexibility means that ITIL:
- Is not tool-oriented or product-oriented
- Does not inherently conflict with Agile, DevOps, or modern working models
- Allows an organization to start with its real pain points
- Allows improvement to occur gradually and continually rather than through a single large project.
If ITIL had been completely transformed into a rigid standard, it would have risked being reduced to a set of forms, documents, and checklists. The organization could pass the audit while its services remained poor.
ITIL’s Flexibility Can Be an Issue (in Iran)
In my opinion, the issue begins when flexibility is mistaken for permission to do nothing. Without an audit or external obligation, some managers might simply say: “ITIL is only a recommendation; we have more important work to do right now.”
As a result, training courses are held, software is purchased, and a few English terms are introduced into meetings. But service ownership, change management, the analysis of recurring incidents, a knowledge base, service level agreements (SLAs), and continual improvement never take shape.
The absence of an official criterion for an “ITIL-compliant organization” also means almost any organization or vendor can describe itself as ITIL-based without having its maturity level or the actual quality of its services independently assessed. Of course, PeopleCert has a separate validation system for certain tools aligned with ITIL practices, but this is not the same as certifying an organization’s service management system.
Do Audits Help?
The more important question, in my opinion, is whether auditing solves the issue. I have also seen ISO audits, but it is still the same old story – an audit can compel an organization to comply with minimum requirements. Still, it does not create value on its own.
It can verify that:
- A change management process exists
- Incidents are recorded
- Responsibilities have been assigned
- Objectives and indicators are reviewed.
However, it cannot guarantee that changes have genuinely become less risky, that end-users have a better experience, or that IT creates more value for the business. Even a certified organization may become trapped in paperwork, artificial performance indicators, and inefficient processes.
The Right ITIL Approach (including for Iranian Industries)
In my opinion, we do not need to turn ITIL into a compulsory collection of clauses. A two-layer model would be better:
- The obligation layer: ISO/IEC 20000, industry regulations, contractual requirements, internal audits, and governance controls.
- The improvement layer: ITIL practices, principles, and guidance for the genuine design and improvement of services.
For Iran’s critical industries and, of course, for similar countries, minimum requirements such as identifying critical services, assigning service owners, managing incidents and changes, ensuring service continuity, recording assets and dependencies, defining SLAs, managing suppliers, and reporting meaningful indicators must become managerial or contractual obligations. However, organizations can select an implementation method using ITIL and adapt it to their needs.
The Pros and Cons of ITIL as Best Practices
Therefore, my conclusion is that ITIL not being a standard is an advantage by design. But in organizations with weak managerial maturity and accountability, it becomes a weakness.
The main issue is not ITIL. The issue is that some organizations only take something seriously when an auditor writes a “nonconformity” against it. The art of service management is understanding the cost of disorder before an auditor forces us to.
Of course, ITIL is not a compulsory standard or a one-size-fits-all model for every organization. You shouldn’t implement all its practices without considering the organization’s size, culture, and maturity. Correct ITIL adoption means selecting and adapting practices that solve the organization’s real problems.
Iran and ITIL: Why ITSM Projects Should Start with Services, Not Tools
Many service management projects in Iran start with the tool rather than the service. They buy software, create forms, and define statuses. But nobody asks who the service customer is, what the expected outcome is, what creates value for the business, or who truly owns the service.
At MedaNet, we have tried to take the opposite path.
In our projects, we try to balance the three dimensions of “people, process, and technology.” IT service management (ITSM) tools such as ServiceDesk Plus are valuable when configured around a proper service model. For this reason, alongside tool implementation, we have focused on designing the service catalog, defining SLAs, managing assets and the configuration management database (CMDB), controlling changes, designing workflows, creating management dashboards, training specialists, and supporting continual improvement.
Adapting ITIL to Local (Iranian) Business and Industry Challenges
We have also learned that the Iranian version of service management must recognize the country’s real constraints: sanctions, limited direct access to specific manufacturers, budget constraints, exchange rate fluctuations, a lack of skilled professionals, and reliance on suppliers. All of which affect the quality of IT services. Therefore, an Iranian organization cannot implement a foreign model exactly as it is without adaptation and localization.
Unfortunately, domestic products are also produced by copying foreign models, and they are very weak. Because government agencies cover these manufacturers, many organizations also use them. But we tried to change this view. That is, in addition to localizing a foreign product, we tried to adapt the processes and needs of Iranian organizations to ITIL. In other words, we implemented the theoretical concepts of ITIL with a suitable, not necessarily perfect, tool in a practical way.
Making ITIL Practical Instead of Theoretical
ITIL becomes practical in Iranian industries when it leaves training slides and enters everyday decisions: when the risks of every change are assessed in advance; recurring incidents are root-cause analyzed; assets and service dependencies are identified; knowledge is not left in the minds of only a few specialists; and IT can demonstrate its value through indicators that business managers can understand.
The Future of IT Service Management in Iran Requires Better Governance
A country that fails to manage its natural resources properly should not repeat the same mistake with its digital resources, data, infrastructure, and human capital.
ITIL is not supposed to solve every issue in Iran’s IT industry. However, it can help us manage what we have built at great expense more rationally, waste less, and transform IT from a reactive technical unit into a genuine business partner. This is the path we at MedaNet have pursued for years: transforming technology into service, service into value, and experience into a repeatable method for improvement.
ITIL in Iran FAQs
Organizations there are highly inclined to purchase equipment without providing even the slightest proper service. The article is blunt about this: a fool with a tool is still a fool. Having servers, software, networks, or an advanced IT service desk doesn’t by itself mean an organization delivers desirable IT services.
ISO/IEC 20000-1 is the auditable standard. It specifies the requirements for establishing, maintaining, and continually improving a service management system. ITIL isn’t auditable; it’s guidance on how to implement that system effectively, adapted to an organization’s own size, industry, risk, and maturity.
Because it’s designed as flexible best practice rather than a fixed set of requirements, so an organization isn’t forced into a rigid, identical model just to pass an audit. The trade-off is that in cultures where things only get taken seriously under external pressure, that same flexibility can become an excuse to do nothing.
No. An audit can confirm that a change management process exists, incidents are recorded, responsibilities are assigned, and objectives are reviewed. It can’t guarantee that changes have actually become less risky, that end-users have a better experience, or that IT creates more value for the business.
By starting with the service rather than the tool. Instead of buying software and defining statuses first, the MedaNet approach balances people, process, and technology, with tools such as ServiceDesk Plus configured around a proper service model, service catalog, SLAs, CMDB, and change control already in place.
Hadi Ahmadi (Soroush)
Soroush is a ITSM consultant and helping organizations to start, implement and develop effective services strategies. He is a leader, ITIL lecturer, and consultant with +15 years of activity to business strategy. Also, Soroush is a storyteller, poet and novelist and wrote and published a few books about specialized fields: ITSM,ITOM,ITAM, ESM and Digital transformation in Persian language.
