">
I'm Yasir Elhadi. Eighteen years running incident desks, CABs, and service catalogues — at Jeddah Airport, on a national government programme, and inside a Big Four regulatory engagement. Rigorvia assesses your service management against ISO/IEC 20000-1, cross-checked to ITIL 4 and COBIT 2019, so the finding holds up whoever in the room is asking.
That's what a scorecard like this one actually is: each practice rated against ISO/IEC 20000-1, cross-checked to ITIL 4 and COBIT 2019, with the evidence behind every number kept on file. When someone in the room asks how you know, there's an answer.
The weak points show up in the first pass. So does what to do about them.
Most organizations I meet have already spent the tooling budget. Incidents still escalate. Changes still fail on a Thursday night. Audits still hurt more than they should. The tool was never the gap.
Rigorvia looks at what's actually happening — the tickets, the CAB minutes, the SLA report nobody reads — and benchmarks it against ISO/IEC 20000-1, ITIL 4, and COBIT 2019. What comes back is a prioritized list of what to fix first, sized to what your team can execute.
Most consultants specialize in one framework and translate the other two as needed. I assess against all three at once, so the compliance lead, the service desk manager, and the board each get an answer in the language they actually use.
This is what gets scored — the international standard for service management, and the basis for certification if that's the road you're on.
This is how the fix gets built. ITIL guidance is what most service desks already half-know, so findings turn into changes that survive contact with the team.
This is how it gets reported upward. COBIT connects the assessment to the objectives a board or audit committee actually cares about.
These are the questions that separate service management that works from service management that's merely documented. Answer them honestly and you'll get a written read, mapped to all three frameworks, in about four minutes.
"Walk me through your last three failed changes. What went wrong — and how did you know?"
"Show me last month's SLA report. Who reviewed it with the customer — and what happened next?"
"Of your last twenty incidents, how many would an earlier root-cause fix have prevented?"
"How many people trust your CMDB enough to make a decision from it?"
Facilitated CABs at 2 a.m. during a major incident. Owned a CMDB nobody trusted until it got rebuilt. Governed SLAs across managed-service contracts and stood in front of auditors defending the score. Every check in this assessment comes from having been on the other side of it.
Every engagement has a defined scope and a fixed price, agreed before work starts. If the picture changes once we're in, we agree a new price first — never after the invoice.
Findings map to NCA ECC controls, with SAMA and PDPL requirements factored in where they apply. Deliverables are structured to survive government-adjacent procurement, not just a boardroom.
Evidence review and report drafting are AI-accelerated, but every finding is validated by a certified practitioner before it reaches you — that's what keeps the turnaround fast without the trust falling apart.
An honest, evidence-based picture of your service management, and a roadmap you'll actually act on.
A region where organizations can prove their service management works, the same way they prove their financials do.
Take the free Diagnostic for a written read on your maturity — or book a 30-minute call and ask anything.
Every Rigorvia service has a fixed scope, timeline, and deliverable, agreed before we start. Start with the free read, and go as far up the ladder as your situation actually needs — nothing more.
Four consultant-grade questions that read your real maturity — no survey, no sales call.
A rapid expert diagnosis — before an audit, after repeated incidents, or ahead of a tooling decision.
The full evidence-based assessment against ISO/IEC 20000-1 — for certification, regulatory review, or transformation.
The Maturity Assessment tells you what's wrong. This is where I stay on to actually help fix it — hands-on, practice by practice, until the scores move.
Light-touch continuous governance after an assessment — so maturity doesn't quietly decay.
The same discipline I applied on national-scale projects and inside a Big Four engagement, compressed into four weeks and shown to you as it happens — not handed over as a black box.
Select the practices that matter. Agree criteria, evidence sources, and the fixed price — in writing.
Documents, ticket samples, SLA data, and interviews. Every score must be traceable to proof.
Clause-level assessment against ISO/IEC 20000-1, informed by ITIL 4 and COBIT 2019 — AI-accelerated, expert-validated.
Findings validated with your team, then a prioritized, costed roadmap and executive briefing. You keep everything.
The four questions on the homepage aren't just conversation-starters — each one is pinned to a specific ISO clause, ITIL practice, and COBIT objective, so a single finding shows up correctly in all three languages.
Anyone can hand you an opinion. Rigorvia hands you a finding — and every finding points to a specific document, ticket sample, SLA report, or interview.
That's what makes the work audit-defensible. When an assessor, regulator, or board member asks "how do you know?", the evidence trail is already there.
Practical thinking on service management maturity, ISO/IEC 20000-1, and the gap between having a process and living it.
The report lands, everyone nods, and nothing changes. The problem usually isn't the findings — it's what the assessment left out.
They're not competitors, and choosing "one or the other" is the wrong question. Here's how they fit together — and where COBIT belongs.
More insights publishing regularly. Follow along on LinkedIn →
Here's a pattern anyone who has run enough assessments will recognize. The engagement goes well. The workshops are energetic. The report is thorough — dozens of findings, neatly scored, professionally bound. The client thanks you. Everyone agrees it was valuable.
Then a month passes, and nothing has changed.
The incidents still escalate the same way. The change process still gets bypassed under pressure. The CMDB is still the thing nobody trusts. The assessment didn't fail because the findings were wrong. It failed because a finding is not a plan.
Most assessments are optimized to demonstrate the assessor's thoroughness. Two hundred pages proves you looked everywhere. But a busy IT leader doesn't need proof that you were thorough — they need to know the three things to do first, why those three, and what "done" looks like.
A report measured in pages is measured by the wrong unit. Measure it in decisions enabled.
When I build a Rigorvia assessment, the scored findings are the input, not the output. The output is a prioritized, sequenced roadmap: what to fix first, what it depends on, roughly what it costs, and how you'll know it worked. The scoring exists to justify the sequence, not to fill a binder.
Service management practices are interdependent. Trying to mature change enablement while your configuration data is untrusted is like renovating a house on a cracked foundation. An assessment that lists every gap without telling you which gap unblocks the others has handed you a to-do list, not a strategy.
The first month after delivery is the moment of truth for any assessment. If your team can pick up the document and act — because it told them exactly where to start — the engagement paid for itself. If they can't, you bought a very expensive description of problems you already suspected.
That's the standard I hold every assessment to. If it doesn't change what you do on Monday, it didn't work.
It's one of the most common questions I hear from IT leaders in the Kingdom: "Should we go with ISO 20000 or ITIL?" It's a reasonable question. It's also the wrong one, because they answer two different needs, and mature organizations use both.
ISO/IEC 20000-1 is a standard. It defines what a service management system must include to be certified — the requirements you'll be audited against. It's written in the language of clauses and conformance. Its natural audience is compliance, and its natural output is a certificate you can show customers and regulators.
ITIL 4 is a body of practice guidance. It doesn't certify your organization; it tells your teams how service management work is actually done well — practices like change enablement, problem management, and service level management. Its natural audience is your operations teams, and its natural output is better day-to-day work.
ISO/IEC 20000-1 is what you're assessed against. ITIL 4 is how you get good enough to pass. COBIT 2019 is how your board knows it's being governed.
There's a third piece that KSA boards increasingly ask about, especially in regulated and government-adjacent entities: governance. COBIT 2019 connects service management to enterprise governance objectives — the language a CIO or audit committee uses to assure the board that IT is under control. It doesn't replace the other two; it sits above them.
So the honest answer to "ISO or ITIL?" is: you'll want the standard to certify against, the practice framework to improve with, and — as you mature — the governance layer to assure leadership. The skill is not choosing between them. It's mapping them to each other so a single finding speaks to compliance, operations, and the board at once.
With Vision 2030 driving digital government and regulators like the NCA raising the bar on cybersecurity governance, service management maturity is no longer just an IT concern — it's an assurance concern. The organizations that will move fastest are the ones that stop treating these frameworks as competing religions and start treating them as one integrated map. That mapping is exactly what a Rigorvia assessment produces.
I'm Yasir Elhadi, founder of Rigorvia. I've spent my career doing this work, not writing about it: facilitating CABs at 2 a.m. during major incidents, owning CMDBs nobody trusted until I rebuilt them, governing SLAs across managed-service contracts, and standing in front of auditors defending every score I gave.
That experience spans aviation IT at Jeddah Airport, a national-scale government project as ITSM Senior Manager, and Big Four delivery as an ITSM consultant on a major regulatory programme. I hold the ITILv5 Master, PMP, ISO/IEC 20000 Lead Implementer, and COBIT 2019 — which is why Rigorvia reads your service management through all three lenses at once.
To give organizations an honest, evidence-based picture of their service management — and a roadmap they'll actually act on — by assessing against ISO/IEC 20000-1, ITIL 4, and COBIT 2019 together, never in isolation.
A region where service management is governed with the same rigor as finance, where an IT leader can put a number on "under control" instead of just asserting it.
Eighteen-plus years accountable for service management outcomes in environments that got audited — airports, national programmes, regulated engagements.
Process maturity assessments and gap analyses across incident, problem, change, and request management; governance review boards; ITIL-aligned standardization for audit defensibility.
Owned enterprise ITSM strategy aligned to ITIL 4 and ISO/IEC 20000-1. Governed Change, Release, Incident, Problem, and Major Incident practices; established CAB/ECAB governance, risk models, and approval authorities.
Led ServiceNow-based ITSM implementation — service catalogue, knowledge, incident, problem, change, and asset management aligned to ITIL, with Performance Analytics dashboards for executive decision-making.
IT management across enterprise, trading, and engineering sectors — ERP rollouts, service desk operations, asset lifecycle, and IT risk — the operational grounding beneath the frameworks.
The triple-framework promise isn't marketing — it's what I'm actually qualified in.
I'm based in Riyadh and deliver across the Kingdom and the wider GCC — remotely, or on-site in Riyadh and Jeddah when an engagement calls for it. For clients outside the region, delivery is entirely remote.
Bilingual by default: English and Arabic, whichever serves the room.
Take the free Diagnostic, or book a 30-minute call to talk through your situation.