SOP templatesIT

IT Incident Management SOP Template

A ready-to-use SOP for detecting, classifying, escalating and resolving IT incidents, including major incident handling and post-incident review.

FreeNo sign-upWord, PDF, Excel & CSV
Ilia PirozhenkoReviewed by Ilia Pirozhenko, Founder, Perfect WikiUpdated September 15, 202613 steps4 roles4 min read
Standard operating procedureSOP-IT-002 ยท Rev 1.0
Owner
IT Service Delivery Manager
Effective date
September 15, 2026
Review cycle
Every 12 months

1.Purpose

To restore normal IT service as quickly as possible after an unplanned interruption or degradation, with consistent classification, escalation and communication to affected users.

2.Scope

Applies to incidents reported through the ticketing system, phone or monitoring alerts, from detection through resolution and closure. Standard change requests and planned maintenance are covered by the change management SOP.

Definitions

Incident
An unplanned interruption to an IT service or a reduction in its quality.
Severity level
A rating of an incident's business impact and urgency that determines its priority and response.
Major incident
A high-severity incident affecting many users or a critical system, requiring dedicated coordination.
Known error
A documented root cause and workaround for a previously identified problem.

3.Responsibilities

Service Desk Analyst
Logs, classifies and attempts first-line resolution of incidents, and confirms resolution with the user.
Incident Manager
Declares and coordinates major incidents and manages stakeholder communication.
System Administrator
Diagnoses root cause and implements fixes for escalated incidents.
End User
Reports the incident with relevant details and confirms whether the resolution worked.

RACI matrix

ActivityService Desk AnalystIncident ManagerSystem AdministratorEnd User
Log and classify the incidentR/AIIC
Investigate and resolve the incidentCIR/AI
Declare and manage a major incidentCR/ARI
Communicate status updatesCR/AII
Confirm resolution and close the ticketR/AIIC

R = Responsible, A = Accountable, C = Consulted, I = Informed

4.Materials and PPE

Materials, tools and systems

  • โ†’Ticketing system
  • โ†’Monitoring and alerting tool
  • โ†’Known error database or knowledge base
  • โ†’Severity and priority matrix
  • โ†’Major incident bridge call or chat channel
  • โ†’Escalation contact list

5.Procedure

  1. 5.1

    Log the incident

    Service Desk Analyst

    The Service Desk Analyst logs a ticket capturing the reporter, affected system, symptoms and the time the incident was detected, whether reported by a user or a monitoring alert.

  2. 5.2

    Classify severity and priority

    Service Desk Analyst

    The Service Desk Analyst assigns a severity level using the severity and priority matrix, based on business impact and urgency rather than how upset the reporter sounds.

    Checkpoint: The assigned severity matches the criteria in the matrix for the number of users and systems affected.

  3. 5.3

    Check for a known error

    Service Desk Analyst

    The Service Desk Analyst searches the known error database and knowledge base for a documented fix or workaround matching the symptoms before doing new diagnosis.

  4. 5.4

    Attempt first-line resolution

    Service Desk Analyst

    The Service Desk Analyst applies the documented fix or workaround, if one exists, and confirms with the user whether the issue is resolved.

  5. 5.5

    Escalate to second-line support

    Service Desk Analyst

    If the issue is not resolved at first line, the Service Desk Analyst escalates the ticket to the System Administrator with full notes on what was tried and the results.

  6. 5.6

    Declare a major incident if warranted

    Incident Manager

    The Incident Manager declares a major incident when the severity matrix criteria for wide impact or a critical system are met, and opens a communication bridge for the response team.

    Warning: Delaying a major incident declaration to avoid the coordination overhead usually makes the outage last longer.

  7. 5.7

    Diagnose the root cause

    System Administrator

    The System Administrator investigates logs, recent changes and system health to identify the root cause of the incident.

  8. 5.8

    Implement and test a fix

    System Administrator

    The System Administrator implements a fix or workaround and tests that the affected service is restored before informing the Service Desk Analyst.

    Checkpoint: The fix is verified against the reported symptoms, not just deployed, before the incident is treated as resolved.

  9. 5.9

    Communicate status updates

    Incident Manager

    For major incidents, the Incident Manager sends status updates to affected users and stakeholders at the intervals agreed at the start of the incident.

  10. 5.10

    Confirm resolution with the user

    Service Desk Analyst

    The Service Desk Analyst contacts the original reporter or affected users to confirm the service is working as expected before closing the ticket.

    Checkpoint: The ticket is not closed until the reporter confirms the issue is actually resolved.

  11. 5.11

    Document root cause and resolution

    System Administrator

    The System Administrator records the root cause, the fix applied and any follow-up work needed in the incident ticket.

  12. 5.12

    Close the ticket

    Service Desk Analyst

    The Service Desk Analyst closes the incident ticket once resolution is confirmed and documentation is complete.

  13. 5.13

    Hold a post-incident review

    Incident Manager

    For major incidents, the Incident Manager runs a post-incident review with the response team to capture lessons learned and follow-up actions.

6.Quality checks

  • โ†’Every incident ticket records severity, root cause and confirmed resolution before closure.
  • โ†’Major incidents receive an assigned Incident Manager and a communication bridge promptly after declaration.
  • โ†’Tickets are not closed without the reporter confirming the service is restored.
  • โ†’Root cause is documented for every major incident before the ticket is closed.

7.Records

  • โ†’Incident ticket with classification and resolution
  • โ†’Root cause documentation
  • โ†’Post-incident review notes
  • โ†’Major incident communication log

8.KPIs

  • โ†’Mean time to resolve by severity level
  • โ†’Percentage of incidents resolved within the target timeframe for their severity
  • โ†’Number of major incidents per month
  • โ†’First-contact resolution rate

9.Common mistakes

  • โ†’Under-classifying severity to avoid triggering escalation.
  • โ†’Closing a ticket without confirming the fix with the affected user.
  • โ†’Skipping the known error check and re-diagnosing an issue that already has a documented fix.
  • โ†’Not documenting root cause before closing a major incident.

10.Revision history

RevisionDateDescriptionReviewed by
1.0September 15, 2026Initial releaseIlia Pirozhenko

This is a template. Adapt it to your organization, equipment and local regulations before use.

Ask this SOP

Nobody opens a PDF in the middle of a task. They ask.

Add this SOP to Perfect Wiki and your team gets answers in the chat app they already use, with a link to the exact step. Ask from ChatGPT, Claude or Copilot too.

Perfect Wiki AIExample answer

A single user can't access their email, is that a major incident?

Not usually. Check the severity matrix in step 5.2 against the actual impact and number of users affected; a single-user issue is typically a lower severity handled at first or second line rather than declared as a major incident.Source: step 5.2 ยท Classify severity and priority
Ask your own question about this SOPโ€ฆSign up to keep asking
Word file vs Perfect Wiki

A downloaded SOP starts going out of date the day you save it.

Screen recorders like Scribe and Tango capture clicks. Perfect Wiki holds the whole procedure, including your recorded guides, and answers questions about it.

Word or PDFPerfect Wiki
Finding itDig through folders and email threadsAsk in Teams, Slack, kChat or Mattermost
Keeping it currentEmail a new version and hopeEdit once with AI, everyone sees the update
Everything in one placeText and imagesEmbed Scribe and Tango guides, SharePoint files and videos
Who can change itAnyone with the fileEditors you choose, everyone else reads
Common questions

Frequently asked questions

Didn't find what you're looking for? Contact our support โ†’

Your SOP library

Keep every SOP where your team can ask it.

Perfect Wiki is the knowledge base for Microsoft Teams, Slack, kChat and Mattermost. Store your SOPs, embed your Scribe and Tango guides, and let AI answer questions with a link to the right step.

No credit cardSetup in under 10 minutesCancel anytime