I took the ITIL Foundation (Version 5) exam a few months after it became available. Forty questions, sixty minutes, closed book. I have sat every version of this exam since the framework was three coloured books and a training room with an overhead projector, and I will say at the outset what I told the people who asked me afterwards: this is a real update, it is not a revolution, and the most interesting thing about it is not in the syllabus at all.
Let me deal with the trivial question first, because it will not go away.
The name nobody is going to use
PeopleCert’s official brand is ITIL (Version 5). Parentheses and all. When ITSM.tools polled the community on what people would actually call it, ninety-two respondents split like this: ITIL 5 at 41 per cent, ITIL v5 at 26 per cent, the official ITIL (Version 5) at 22 per cent, and plain ITIL at 9 per cent. Stephen Mann’s verdict was that “ITIL 5 and ITIL v5 have already won.”
That is a small thing, but it tells you something about the relationship between the framework’s owner and the people who use it. A community that will not adopt your brand name after six months is a community that is reserving judgement. Keep that in mind as you read the rest.
What genuinely changed
Four things, and they are not trivial.
The scope moved from service management to digital product and service management. ITIL now describes itself as guidance for DPSM. The official framing of the arc is: IT infrastructure management, then IT service management, then service management, and now product and service management. The reasoning given is that “the traditional separation of product and service silos has become a liability for organizations.” I think that is correct, and I think most organisations I walk into are living proof of it — the team that builds the thing and the team that runs the thing report to different people, are measured on opposing numbers, and meet properly only during a Sev 1.
A new eight-stage lifecycle model. Discover, Design, Acquire, Build, Transition, Operate, Deliver, Support. This replaces — or restates, depending on which commentator you read — ITIL 4’s six value chain activities. Two of the changes are genuinely useful. ITIL 4 collapsed design and transition into a single activity, which never matched how anyone works; they are now separate. And “Deliver & Support” has been pulled apart into Operate, Deliver and Support, which finally distinguishes keeping the infrastructure running from making the service available to a user from fixing it when it breaks. The trainer Ben Kalland called this “a clear improvement,” and he is right.
AI is treated as first-class. ITIL 5 describes itself as “AI-native” and “complexity-native.” There is a new AI Capability Model — the six Cs: Creation, Curation, Clarification, Cognition, Communication and Coordination — and an entire separate publication and certification for AI Governance, with no prerequisites. There is a new subsection on “Organizations, people and AI” inside the four dimensions. For anyone who has spent the last two years being asked by a board what the organisation’s position on AI is, having a service management framework that acknowledges the question is welcome.
The practices were recategorised. The thirty-four practices are now twenty-two Product and Service Management practices and twelve General Management practices. The Technical Management category is gone. Deployment Management, Infrastructure and Platform Management, and Software Development and Management moved out of Technical; Information Security Management and Service Financial Management moved out of General. The arithmetic reconciles exactly, which is the kind of small thing I check.
What did not change
Now the other half of the ledger, which the launch material is quieter about.
All thirty-four practice names are unchanged. Not one added, not one removed, not one renamed.
The seven guiding principles are unchanged. Focus on value. Start where you are. Progress iteratively with feedback. Collaborate and promote visibility. Think and work holistically. Keep it simple and practical. Optimise and automate. Word for word what you learned in ITIL 4.
The four dimensions are unchanged in name — organisations and people, value streams and processes, information and technology, partners and suppliers. The diagram has been redrawn and they are now described as the four dimensions of product and service management rather than of service management.
The Practice Manager modules are identical. Monitor, Support and Fulfil; Plan, Implement and Control; Collaborate, Assure and Improve — same three names, same five practices in each, as ITIL 4.
And the practice guides themselves have not been rewritten yet. This is the fact I would most want a training buyer to understand. The thirty-four practice publications currently in circulation are still the ITIL 4 documents. PeopleCert has scheduled their update for the second half of 2026, with three stated changes: terminology alignment across all practices, addition of established AI use in selected practices, and additional product focus in selected practices. So at the time of writing, the practice reorganisation is a change of category and vocabulary at Foundation level. The substantive body of practice guidance is the one you already own.
The awkward question
Put those two lists side by side and you can see why some serious practitioners are unimpressed.
Gil Regev of itecor put it most sharply: “ITIL v5 is a major overhaul of ITIL, but not from the service management perspective. The essence of service management has already been proposed in ITIL v3.” He also made an observation about the new lifecycle that I have not seen anyone answer: “The lifecycle view is not a complete cradle to grave sequence. It misses the crucial activity of Decommissioning.” That is a fair hit. Anyone who has tried to work out what an application actually costs, or to close a data centre, knows that decommissioning is where organisations go to fail.
Jeroen van Craaikamp, who sat and passed the Foundation exam and wrote it up honestly, concluded that “ITIL Version 5, IMHO is an update of the ITIL 4 practice, but it is not quite a game-changer,” and noted that practical guidance for operationalising the new lifecycle stages is missing — the same criticism that dogged ITIL 4. His line about the courseware is the one I keep coming back to: “Kudos to Peoplecert on the HOW!!” Good delivery, thin substance.
The bluntest summary came from Michael Inhoff Nielsen: “Could have been ITIL4.1.”
Meanwhile, the certification scheme has been rebuilt entirely. Nine modules. New exams at every level. A paid Foundation Bridge for existing ITIL 4 holders. A paid Managing Professional Transition. And a stated plan to sunset all ITIL 4 modules on 31 December 2027.
High certification churn, low framework churn. That is the sceptics’ case, and it can be made entirely from PeopleCert’s own published pages.
I will give the counter-case fairly, because I think it is stronger than the sceptics allow. The eight-stage lifecycle fixes a real defect in ITIL 4. The product and service unification is a genuine scope expansion, not a relabelling. And the AI Governance material has no ITIL 4 equivalent at all — it is new content addressing a question every board is now asking. Barclay Rae, who has watched this framework longer than most, called it “an evolutionary step forward” while adding the caveat that matters: “the key elements are people, culture and management, not what ITIL says or what version is used.”
That caveat deserves a case study.
What a framework cannot do for you: TSB, April 2018
In April 2018, TSB Bank migrated approximately five million customers off Lloyds Banking Group’s platform onto a new core banking system built by its parent’s IT subsidiary. It was a largely single-event migration — a big bang, over one weekend.
TSB was not an organisation without frameworks. It was a UK retail bank, regulated by the FCA and the PRA, with a programme office, a testing regime, third-party contracts and a board. Every artefact you would look for in a maturity assessment existed.
Here is what the independent review by Slaughter and May and the regulators’ Final Notices established.
The two data centres were specified to be configured identically so that the platform could run active-active. They were not. Performance testing had been conducted against one data centre only, so the asymmetry was invisible before go-live. Load targets were reduced after early tests failed. Some non-functional testing was carried out in the production environment because no dedicated environment existed. Non-functional testing concluded the day before the migration decision was taken.
Across the programme, 34,671 defects had been identified. 4,424 were still open at go-live. The review found that TSB’s own, lower defect count had been reached “by inappropriately excluding a number of major categories of defect.”
When the platform failed, the contact channels failed with it. Telephony was running at 25 per cent of intended line capacity. Wait times reached one hour twenty minutes, with a 70 per cent call abandonment rate. Branch technology — chip and PIN, voucher readers, cash handling — failed. Around 600 customers could see other customers’ account information. Phishing attacks against TSB customers peaked at seventy times normal levels.
The FCA treats the disruption as running from 22 April to 10 December 2018. Seven and a half months. There were 225,492 complaints. Customer redress came to £32,705,762. The total 2018 cost to TSB was £330.2 million, turning a £162.7 million profit into a £105.4 million loss. In December 2022 the FCA and PRA fined the bank £48.65 million between them.
The review’s summary of the position on the morning of the migration is one sentence long: “The platform was not ready to support TSB’s full customer base and Sabis was not ready to operate the platform.”
And the governance finding is the one I would put in front of any board: the board did not sufficiently challenge the timetable, was not independently advised on the programme as a whole, and did not substantively discuss whether a single-event migration was the right choice at all.
None of that is a framework problem. TSB did not fail because it was on ITIL 4 rather than ITIL 5, or because its change enablement practice sat in the wrong category. It failed because a date was committed publicly before the plan supported it, because testing was compressed to fit the date, because open defects were reclassified rather than fixed, and because nobody with the authority to stop it asked the question loudly enough.
Mark Steward of the FCA summarised it as: “The failings in this case were widespread and serious.”
So what should you actually do about ITIL 5?
Five things, in the order I would do them.
1. Do not rip anything out. Your ITIL 4 certifications remain valid and are accepted as prerequisites for every higher-level Version 5 certification. Your process documentation is still correct — the practice guides have not been rewritten. Nothing you built last year is now wrong.
2. Diarise the sunset, then wait. The stated plan is to retire all ITIL 4 modules on 31 December 2027. Note the word “plan”; PeopleCert has hedged it. If you have people mid-pathway on ITIL 4, they have time. If you are starting fresh, start on Version 5.
3. Send one person to Foundation, not the department. Find out what the eight-stage lifecycle actually gives you before you buy forty seats. One accredited Foundation course and one honest debrief will tell you more than any vendor briefing.
4. Take the AI Governance module seriously, separately. It has no prerequisites, it is genuinely new content, and it maps onto a question your audit committee is going to ask within the year. If you are also looking at ISO/IEC 42001, the two reinforce each other.
5. Then close the ITIL 5 tab and go and read your own change records. How many changes failed last quarter? How many were emergency changes that were emergencies only because somebody missed a deadline? How many open defects would your last major release have carried into production if the date had been immovable? Those questions are worth more than any version number.
The framework was never the thing. The framework was only ever a way of writing down what competent organisations already do. TSB had access to all of it and still lost £330 million, because the pressure to hit a date beat the evidence that the platform was not ready — and no edition of ITIL has ever contained a practice that stops that happening.
Adopt and adapt. That advice has survived every version, and it will survive this one.
What this means if you are reading from India
Three practical notes for an Indian audience, because the global commentary largely ignores them.
Accredited training availability lags the announcement. PeopleCert released the modules progressively through 2026, and accredited training organisations pick them up at different speeds. Foundation is widely available. The advanced modules — where accredited training is mandatory, since exam results are not released without proof of course completion — arrive later in a given market. Before you plan a pathway for a team, confirm that the specific module is actually deliverable here, in the language and format you need, on the dates you need it.
The cost conversation is different. Published prices sit in US dollars: a Foundation exam bundle around $690, eLearning packages higher, the advanced modules higher again. For an Indian organisation putting twenty people through a pathway, the arithmetic is materially different from the same decision in London or Chicago — and the certification is the smaller half of the cost, because accredited training and the working days it consumes are the larger half. Judge it against the value of the capability, not the headline exam fee.
The vocabulary now aligns with what your regulator already expects. This is the part I find most useful. RBI’s Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices, effective 1 April 2024, requires regulated financial entities to have IT service management processes, change and patch management, incident management, and business continuity capability, with information systems audit overseen by the Audit Committee of the Board. When the RBI restricted Kotak Mahindra Bank in April 2024, its stated reasons named “IT inventory management, patch and change management, user access management, vendor risk management, data security and data leak prevention strategy, business continuity and disaster recovery rigour and drill.”
Read that list again. Every item is an ITIL practice. The regulator did not use ITIL’s vocabulary, but it audited against ITIL’s territory.
That is the strongest argument I know for investing in service management capability in an Indian regulated entity, and it has nothing to do with which version number is current. The supervisor is already examining these disciplines. A framework is simply a coherent way to organise your answer.
Sources
- PeopleCert, ITIL (Version 5) explained — peoplecert.org
- PeopleCert, ITIL framework — qualification scheme — peoplecert.org
- PeopleCert, ITIL FAQ (ITIL 4 sunset, prerequisites, renewal) — peoplecert.org
- ITIL.com, ITIL Foundation (Version 5): what’s new (eight-stage lifecycle, AI-native framing) — itil.com
- ITSM.tools, ITIL (Version 5) management practices (22/12 split, category moves) — itsm.tools
- ITSM.tools, ITIL (Version 5) vs ITIL 4: key changes — itsm.tools
- ITSM.tools, ITIL 5 vs ITIL v5 vs ITIL (Version 5) (naming poll) — itsm.tools
- Gil Regev, itecor, A new ITIL, so what? — itecor.com
- Jeroen van Craaikamp, JAVC, ITIL Version 5 Foundation released — javc.nl
- Barclay Rae, ITIL Version 5 launch takeaways — barclayrae.com
- Slaughter and May, Independent Review of the 2018 TSB Migration (2019)
- Financial Conduct Authority, Final Notice: TSB Bank plc (December 2022)
- Prudential Regulation Authority, Final Notice: TSB Bank plc (December 2022)
- TSB Bank plc, Annual Report and Accounts 2018