">">">
Rigorvia · ITSM Consulting

The rigor your service management has been missing.

I'm Yasir Elhadi. Eighteen years running incident desks, CABs, and service catalogues — at Jeddah Airport, on a national government programme, and inside a Big Four regulatory engagement. Rigorvia assesses your service management against ISO/IEC 20000-1, cross-checked to ITIL 4 and COBIT 2019, so the finding holds up whoever in the room is asking.

ISO/IEC 20000 Lead Implementer · ITILv5 Master · PMP · COBIT 2019
Yasir Elhadi
Founder & Principal Consultant
ISO/IEC 20000 Lead ImplementerITILv5 MasterPMPCOBIT 201918+ years · Aviation, national projects, Big Four
What You Get

Every score in this report traces back to a document, a ticket, or an interview.

That's what a scorecard like this one actually is: each practice rated against ISO/IEC 20000-1, cross-checked to ITIL 4 and COBIT 2019, with the evidence behind every number kept on file. When someone in the room asks how you know, there's an answer.

The weak points show up in the first pass. So does what to do about them.

Maturity Scorecard · ISO/IEC 20000-1
OVERALL 0.0 / 5
RGV-01
Incident Management
3.6
RGV-02
Change Enablement
2.1
RGV-03
Problem Management
2.8
RGV-04
Service Configuration
1.9
RGV-05
Service Level Mgmt.
3.2
CLAUSES 8.2–8.6 · ITIL 4 · COBIT 20192 CRITICAL GAPS IDENTIFIED
The Problem

A ServiceNow licence tells you the software runs. It doesn't tell you whether the process behind it works.

Most organizations I meet have already spent the tooling budget. Incidents still escalate. Changes still fail on a Thursday night. Audits still hurt more than they should. The tool was never the gap.

Rigorvia looks at what's actually happening — the tickets, the CAB minutes, the SLA report nobody reads — and benchmarks it against ISO/IEC 20000-1, ITIL 4, and COBIT 2019. What comes back is a prioritized list of what to fix first, sized to what your team can execute.

Evidence-based
Every rating traces to a document, a ticket sample, or an interview on file.
Fixed-price
Scope and cost are agreed before I start. If the picture changes mid-engagement, we agree a new price first — not after the invoice.
Regulator-aware
Findings map to ISO/IEC 20000-1 clauses and NCA ECC controls, for entities that answer to a Saudi regulator.
One Assessment, Three Lenses

Standard, practice, and governance, read together.

Most consultants specialize in one framework and translate the other two as needed. I assess against all three at once, so the compliance lead, the service desk manager, and the board each get an answer in the language they actually use.

The Standard

ISO/IEC 20000-1

This is what gets scored — the international standard for service management, and the basis for certification if that's the road you're on.

FOR: compliance & certification leads
The Practice

ITIL 4

This is how the fix gets built. ITIL guidance is what most service desks already half-know, so findings turn into changes that survive contact with the team.

FOR: IT & service operations teams
The Governance

COBIT 2019

This is how it gets reported upward. COBIT connects the assessment to the objectives a board or audit committee actually cares about.

FOR: CIOs, boards & audit committees
The Rigorvia Diagnostic

Four questions I'd ask in the first hour of any engagement.

These are the questions that separate service management that works from service management that's merely documented. Answer them honestly and you'll get a written read, mapped to all three frameworks, in about four minutes.

01 · CHANGE FAILURE

What your last three failed changes reveal

"Walk me through your last three failed changes. What went wrong — and how did you know?"

ISO CL 8.5.1 · ITIL Change Enablement · COBIT BAI06
02 · SLA REPORTING

Whether your SLA report gets read, or just sent

"Show me last month's SLA report. Who reviewed it with the customer — and what happened next?"

ISO CL 8.3.3 · ITIL Service Level Mgmt · COBIT APO09
03 · PROBLEM RECURRENCE

Whether you solve incidents, or keep re-living them

"Of your last twenty incidents, how many would an earlier root-cause fix have prevented?"

ISO CL 8.6.3 · ITIL Problem Mgmt · COBIT DSS03
04 · CONFIGURATION TRUST

Whether anyone trusts your CMDB enough to use it

"How many people trust your CMDB enough to make a decision from it?"

ISO CL 8.2.6 · ITIL Service Config Mgmt · COBIT BAI10
Why Rigorvia

The rigor of a consulting firm, without the consulting-firm timeline.

Practitioner-built

I've sat in the room this was built for

Facilitated CABs at 2 a.m. during a major incident. Owned a CMDB nobody trusted until it got rebuilt. Governed SLAs across managed-service contracts and stood in front of auditors defending the score. Every check in this assessment comes from having been on the other side of it.

Fixed price, fixed scope

You know the cost before we start

Every engagement has a defined scope and a fixed price, agreed before work starts. If the picture changes once we're in, we agree a new price first — never after the invoice.

Regulator-aware

Built for KSA and GCC realities

Findings map to NCA ECC controls, with SAMA and PDPL requirements factored in where they apply. Deliverables are structured to survive government-adjacent procurement, not just a boardroom.

AI-accelerated, human-signed

AI speeds up the analysis. I still sign off on every finding.

Evidence review and report drafting are AI-accelerated, but every finding is validated by a certified practitioner before it reaches you — that's what keeps the turnaround fast without the trust falling apart.

Our Mission

An honest, evidence-based picture of your service management, and a roadmap you'll actually act on.

Our Vision

A region where organizations can prove their service management works, the same way they prove their financials do.

Start Here

Not sure where to start? The Diagnostic will tell you.

Take the free Diagnostic for a written read on your maturity — or book a 30-minute call and ask anything.

yasir@rigorvia.com · Replies within one business day
Services

Five engagements, structured as one ladder.

Every Rigorvia service has a fixed scope, timeline, and deliverable, agreed before we start. Start with the free read, and go as far up the ladder as your situation actually needs — nothing more.

TIER 0

The Diagnostic

Free · 4 minutes · Instant verdict

Four consultant-grade questions that read your real maturity — no survey, no sales call.

  • Written diagnostic verdict
  • Posture across four core practices
  • Mapped to ISO, ITIL & COBIT
  • Recommended next step
Take the Diagnostic
TIER 1

Health Check

Fixed fee · 2 weeks · Remote or on-site

A rapid expert diagnosis — before an audit, after repeated incidents, or ahead of a tooling decision.

  • Structured intake + document review
  • 90-minute workshop with your IT leads
  • 15-page findings report, risk-ranked
  • Prioritized 90-day action plan
Request a quote
TIER 2

Maturity Assessment

Fixed fee · 4 weeks · Board-ready

The full evidence-based assessment against ISO/IEC 20000-1 — for certification, regulatory review, or transformation.

  • Clause-level scoring with evidence refs
  • ISO × ITIL × COBIT × NCA ECC mapping
  • Gap analysis + improvement roadmap
  • Executive briefing for leadership
Request a scoping call
TIER 3

Improvement Program

Fixed fee · 8–12 weeks · Hands-on delivery

The Maturity Assessment tells you what's wrong. This is where I stay on to actually help fix it — hands-on, practice by practice, until the scores move.

  • Remediation of assessment findings
  • Process & documentation rebuild
  • Re-scoring at completion
  • Evidence pack for audit or certification
Discuss your gaps
TIER 4

Rigorvia Retainer

Monthly · Ongoing · 4–8 hrs/month

Light-touch continuous governance after an assessment — so maturity doesn't quietly decay.

  • Quarterly re-scoring against the same clause map
  • On-call advisory for CAB & major incidents
  • COBIT governance reporting support
  • Cancel anytime, no lock-in
Ask about the Retainer
 
Diagnostic
Health Check
Maturity Assessment
Improvement Program
Retainer
Duration
4 minutes
2 weeks
4 weeks
8–12 weeks
Ongoing monthly
Output
Written verdict
15-page report + plan
Full workbook + roadmap
Closed gaps + evidence pack
Quarterly re-score + advisory
Evidence
Self-reported
Document review
Verified evidence
Remediated & re-verified
Continuously monitored
Frameworks
ISO/ITIL/COBIT
ISO/ITIL/COBIT
+ NCA ECC
+ NCA ECC
ISO/ITIL/COBIT
Price
Free
Fixed quote
Fixed after scoping
Fixed after scoping
Monthly, no lock-in
Best for
A fast, honest read
Rapid diagnosis
Certification & board assurance
Actually closing gaps
Staying mature long-term
Engagement FAQ

Straight answers.

Do you implement tools like ServiceNow or Jira?
Rigorvia assesses and designs; implementation partners can be recommended. This independence means our findings are never biased toward selling you software.
Can you work with government-adjacent entities?
Yes. Deliverables can be structured to your procurement, confidentiality, and data-residency requirements.
Is everything really fixed-price?
Yes for project work. If scope grows, we agree a new fixed price before any additional work begins. The Retainer is the one exception — it's a simple monthly rate with no lock-in.
Which languages do you deliver in?
English and Arabic. Reports and workshops in either language, or bilingual on request.
Method

How Rigorvia reads maturity.

The same discipline I applied on national-scale projects and inside a Big Four engagement, compressed into four weeks and shown to you as it happens — not handed over as a black box.

The Four-Step Method

Four steps, and nothing you can't see happening.

STEP 01

Scope

Select the practices that matter. Agree criteria, evidence sources, and the fixed price — in writing.

STEP 02

Evidence

Documents, ticket samples, SLA data, and interviews. Every score must be traceable to proof.

STEP 03

Score

Clause-level assessment against ISO/IEC 20000-1, informed by ITIL 4 and COBIT 2019 — AI-accelerated, expert-validated.

STEP 04

Roadmap

Findings validated with your team, then a prioritized, costed roadmap and executive briefing. You keep everything.

The Rigorvia Diagnostic Framework

Every test maps to all three frameworks at once.

The four questions on the homepage aren't just conversation-starters — each one is pinned to a specific ISO clause, ITIL practice, and COBIT objective, so a single finding shows up correctly in all three languages.

Rigorvia Test
ISO/IEC 20000-1
ITIL 4 Practice
COBIT 2019
Change Failure
Clause 8.5.1
Change Enablement
BAI06 Managed IT Changes
SLA Reporting
Clause 8.3.3
Service Level Management
APO09 Managed Service Agreements
Problem Recurrence
Clause 8.6.3
Problem Management
DSS03 Managed Problems
Configuration Trust
Clause 8.2.6
Service Configuration Management
BAI10 Managed Configuration
Evidence Standard

If we can't trace it, we don't score it.

Anyone can hand you an opinion. Rigorvia hands you a finding — and every finding points to a specific document, ticket sample, SLA report, or interview.

That's what makes the work audit-defensible. When an assessor, regulator, or board member asks "how do you know?", the evidence trail is already there.

Traceable
Every maturity score references the evidence that justifies it.
Reproducible
A different assessor, same evidence, reaches the same score.
Defensible
Findings survive the second and third follow-up question.
Insights

Field notes on ITSM that actually works.

Practical thinking on service management maturity, ISO/IEC 20000-1, and the gap between having a process and living it.

ASSESSMENT6 MIN READ

Why most ITSM assessments fail in the first month after delivery

The report lands, everyone nods, and nothing changes. The problem usually isn't the findings — it's what the assessment left out.

Read article →
STANDARDS7 MIN READ

ISO/IEC 20000 vs ITIL 4: what KSA organizations actually need

They're not competitors, and choosing "one or the other" is the wrong question. Here's how they fit together — and where COBIT belongs.

Read article →

More insights publishing regularly. Follow along on LinkedIn →

← All insights
ASSESSMENT · 6 MIN READ

Why most ITSM assessments fail in the first month after delivery

Here's a pattern anyone who has run enough assessments will recognize. The engagement goes well. The workshops are energetic. The report is thorough — dozens of findings, neatly scored, professionally bound. The client thanks you. Everyone agrees it was valuable.

Then a month passes, and nothing has changed.

The incidents still escalate the same way. The change process still gets bypassed under pressure. The CMDB is still the thing nobody trusts. The assessment didn't fail because the findings were wrong. It failed because a finding is not a plan.

The gap between knowing and doing

Most assessments are optimized to demonstrate the assessor's thoroughness. Two hundred pages proves you looked everywhere. But a busy IT leader doesn't need proof that you were thorough — they need to know the three things to do first, why those three, and what "done" looks like.

A report measured in pages is measured by the wrong unit. Measure it in decisions enabled.

When I build a Rigorvia assessment, the scored findings are the input, not the output. The output is a prioritized, sequenced roadmap: what to fix first, what it depends on, roughly what it costs, and how you'll know it worked. The scoring exists to justify the sequence, not to fill a binder.

Why sequence beats completeness

Service management practices are interdependent. Trying to mature change enablement while your configuration data is untrusted is like renovating a house on a cracked foundation. An assessment that lists every gap without telling you which gap unblocks the others has handed you a to-do list, not a strategy.

The first month after delivery is the moment of truth for any assessment. If your team can pick up the document and act — because it told them exactly where to start — the engagement paid for itself. If they can't, you bought a very expensive description of problems you already suspected.

That's the standard I hold every assessment to. If it doesn't change what you do on Monday, it didn't work.

← All insights
STANDARDS · 7 MIN READ

ISO/IEC 20000 vs ITIL 4: what KSA organizations actually need

It's one of the most common questions I hear from IT leaders in the Kingdom: "Should we go with ISO 20000 or ITIL?" It's a reasonable question. It's also the wrong one, because they answer two different needs, and mature organizations use both.

Different tools for different jobs

ISO/IEC 20000-1 is a standard. It defines what a service management system must include to be certified — the requirements you'll be audited against. It's written in the language of clauses and conformance. Its natural audience is compliance, and its natural output is a certificate you can show customers and regulators.

ITIL 4 is a body of practice guidance. It doesn't certify your organization; it tells your teams how service management work is actually done well — practices like change enablement, problem management, and service level management. Its natural audience is your operations teams, and its natural output is better day-to-day work.

ISO/IEC 20000-1 is what you're assessed against. ITIL 4 is how you get good enough to pass. COBIT 2019 is how your board knows it's being governed.

Where COBIT fits

There's a third piece that KSA boards increasingly ask about, especially in regulated and government-adjacent entities: governance. COBIT 2019 connects service management to enterprise governance objectives — the language a CIO or audit committee uses to assure the board that IT is under control. It doesn't replace the other two; it sits above them.

So the honest answer to "ISO or ITIL?" is: you'll want the standard to certify against, the practice framework to improve with, and — as you mature — the governance layer to assure leadership. The skill is not choosing between them. It's mapping them to each other so a single finding speaks to compliance, operations, and the board at once.

What this means for a Saudi organization today

With Vision 2030 driving digital government and regulators like the NCA raising the bar on cybersecurity governance, service management maturity is no longer just an IT concern — it's an assurance concern. The organizations that will move fastest are the ones that stop treating these frameworks as competing religions and start treating them as one integrated map. That mapping is exactly what a Rigorvia assessment produces.

About

Eighteen years inside service management. Now available outside it.

I'm Yasir Elhadi, founder of Rigorvia. I've spent my career doing this work, not writing about it: facilitating CABs at 2 a.m. during major incidents, owning CMDBs nobody trusted until I rebuilt them, governing SLAs across managed-service contracts, and standing in front of auditors defending every score I gave.

That experience spans aviation IT at Jeddah Airport, a national-scale government project as ITSM Senior Manager, and Big Four delivery as an ITSM consultant on a major regulatory programme. I hold the ITILv5 Master, PMP, ISO/IEC 20000 Lead Implementer, and COBIT 2019 — which is why Rigorvia reads your service management through all three lenses at once.

Connect with me on LinkedIn →

Yasir Elhadi
Founder & Principal Consultant
Mission

Why Rigorvia exists

To give organizations an honest, evidence-based picture of their service management — and a roadmap they'll actually act on — by assessing against ISO/IEC 20000-1, ITIL 4, and COBIT 2019 together, never in isolation.

Vision

The future I'm building toward

A region where service management is governed with the same rigor as finance, where an IT leader can put a number on "under control" instead of just asserting it.

01
Evidence over opinion
If it can't be traced, it doesn't get scored.
02
Clarity over volume
A roadmap you'll act on beats a report you won't read.
03
Rigor over theater
Fixed scope, fixed price, findings that survive scrutiny.
Track Record

Where the rigor comes from.

Eighteen-plus years accountable for service management outcomes in environments that got audited — airports, national programmes, regulated engagements.

2026 →

ITSM Consultant · Big Four (KSA regulatory programme)

Process maturity assessments and gap analyses across incident, problem, change, and request management; governance review boards; ITIL-aligned standardization for audit defensibility.

2025–26

ITSM Senior Manager · National Address Project

Owned enterprise ITSM strategy aligned to ITIL 4 and ISO/IEC 20000-1. Governed Change, Release, Incident, Problem, and Major Incident practices; established CAB/ECAB governance, risk models, and approval authorities.

2023–25

Head of ITSM · Jeddah Airport

Led ServiceNow-based ITSM implementation — service catalogue, knowledge, incident, problem, change, and asset management aligned to ITIL, with Performance Analytics dashboards for executive decision-making.

2006–23

17 years in IT leadership & operations

IT management across enterprise, trading, and engineering sectors — ERP rollouts, service desk operations, asset lifecycle, and IT risk — the operational grounding beneath the frameworks.

Credentials

Certified across all three frameworks.

The triple-framework promise isn't marketing — it's what I'm actually qualified in.

ISO/IEC 20000 Lead ImplementerPECB
ITILv5 MasterPEOPLECERT
Project Management Professional (PMP)PMI
COBIT 2019 FoundationISACA
PRINCE2 Agile ExpertPEOPLECERT
ITIL 4 Specialist · ITAM, Sustainability, BRMPEOPLECERT
Where I Work

Riyadh-based, with reach across the GCC and beyond.

I'm based in Riyadh and deliver across the Kingdom and the wider GCC — remotely, or on-site in Riyadh and Jeddah when an engagement calls for it. For clients outside the region, delivery is entirely remote.

Bilingual by default: English and Arabic, whichever serves the room.

KSA & GCC
Primary market — Riyadh, Jeddah, and across the Gulf.
Remote worldwide
Fully remote delivery for international clients.
EN / العربية
Workshops and reports in either language, or both.
Work With Me

Let's find out how ready you really are.

Take the free Diagnostic, or book a 30-minute call to talk through your situation.

yasir@rigorvia.com · Riyadh, Saudi Arabia