ITIL Adoption in Brazil Since 2015
Brazil's ITIL adoption since 2015 has followed two distinct paths. Multinationals inherited maturity from their parent companies. Mid-sized organisations built it, unevenly, from a much lower base.
Core Competencies
- Assessment of ITSM practice maturity against ITIL 4's practice-based model and Service Value System
- Analysis of regulatory drivers, including LGPD, and their mapping onto specific ITIL practices such as access, change, and incident management
- Comparative evaluation of ITSM tooling and governance models across multinational subsidiaries and mid-market organisations
The Situation
Brazilian organisations adopting ITIL since 2015 have followed two distinct paths depending on where they started. Multinational subsidiaries typically inherited a global ITSM platform, whether ServiceNow, BMC Helix, or an equivalent, along with the service catalogue, CMDB structure, and SLA targets their parent company had already defined. Mid-sized Brazilian organisations, whether privately held companies, cooperatives, or regional service providers, had no such inheritance. Adoption had to be justified locally, funded locally, and staffed by people learning ITSM concepts and Brazilian Portuguese process terminology at the same time.
The shape of Brazilian ITIL certification reflects this divide. For much of the period since 2015, the overwhelming majority of certified professionals in the country have held only the entry-level ITIL Foundation qualification, with intermediate and expert-level credentials remaining comparatively rare. That distribution points to a market where organisations wanted staff conversant with ITIL’s vocabulary, incident, problem, change, service request, but had far less appetite or budget for the deeper investment required to reach process maturity.
What the Framework Defines
ITIL 4, launched globally in February 2019, replaced ITIL v3’s 26 discrete processes with 34 flexible practices organised under a Service Value System rather than a fixed lifecycle. Its guiding principle of starting where you are, rather than replacing what exists, asks an organisation to formalise the practices its operations actually need, typically incident management, service request management, and change enablement, without committing to the full apparatus a large enterprise runs. A conformant implementation stops short of measurable improvement when it treats Foundation-level awareness as the endpoint rather than the starting point, a pattern that recurs across the research into ITIL adoption in mid-sized organisations: early gains in structuring incident intake and service requests, followed by a plateau once the harder, less visible work of proactive problem identification and continual improvement is reached.
Regulation has done more than the framework itself to close that gap in Brazil. The Lei Geral de Proteção de Dados, enacted in August 2018 and enforced from September 2020, never references ITIL, but its requirements land squarely on practices the framework had already defined. Access management determines who can reach personal data. Change management determines how systems handling that data are modified. Incident management determines how a breach is detected, contained, and reported, with the law’s 72-hour notification expectation to the ANPD adding real urgency to a process many organisations had previously treated as a formality.
A Gap Analysis Approach for New Clients
Our consultants begin by establishing where an organisation’s ITSM practice actually sits, not where its certification records suggest it sits. A Foundation-heavy certification base, a service desk running on GLPI, OTRS, Tiflux, Desk Manager, or Zenvia Service, and a set of ad hoc incident workflows are common starting points for mid-sized Brazilian organisations, and each tells us something different about where the gap to target maturity lies. The distance to close is measured against the specific commitments the organisation has made, whether that is an LGPD compliance obligation around access and change control, a Plano Diretor de Tecnologia da Informação in the public sector, or a service level a cooperative has promised its members.
From there, the gap analysis identifies the specific practices to formalise first, typically incident management, request fulfilment, and change enablement, and the measures that show whether the change has taken hold: ticket categorisation consistency, change failure rate, first-contact resolution. Tooling choice follows the gap analysis rather than preceding it. An organisation without a global parent to underwrite an enterprise-grade licence is often better served by a correctly configured open-source or domestic platform than by an underused enterprise one.
Working with Typeface
Typeface helps IT organisations raise the maturity of their service management practice. Our consultants have worked across financial cooperatives, multinational subsidiaries, and mid-sized Brazilian companies, assessing where a practice sits today and setting out what it takes to reach the maturity a service commitment requires.
Key Takeaways
- Brazilian ITIL certification has long skewed heavily towards Foundation level, signalling breadth of awareness rather than depth of practice
- LGPD became an unplanned driver of ITSM discipline, pushing organisations towards documented change, access, and incident management
- Multinational subsidiaries inherit ITSM maturity from parent companies, while mid-sized Brazilian organisations must build it themselves, often through open-source or domestic tooling and specialist consultancy support
Bring Structure to Your Transition
If your organisation is approaching a period of significant operational change and would benefit from structured, experienced advisory and/or hands-on support, we would welcome a conversation about where we might help.
Schedule a Consultation