How to create a good scope for ISO 9001 or ISO 27001?
When you start implementing a management system, one of the first questions you need to ask yourself is about the scope of your management system. Many organizations see the scope as an administrative mandatory field on the certificate. In practice, however, the scope determines which activities fall under the management system, which risks are managed, and what an auditor will and will not assess.
Nevertheless, auditors often encounter scopes that are too general, too limited, or even misleading. This leads to discussions during an audit, and of course, you want to avoid that. Read this article to preempt the discussion!
What is a scope?
The scope describes the boundaries and applicability of the management system.
For ISO 9001, this means the quality management system (QMS). For ISO 27001, it concerns the information security management system (ISMS).
The scope must answer questions such as:
Which products and services fall under the management system?
Which locations are involved?
Which processes are part of the system?
Which organizational units are included?
Are there activities that are intentionally placed outside the scope?
A good scope gives a reader immediate insight into what is and is not certified. The ultimate goal is, of course, that when a potential customer purchases a service or product from you, they can understand from the scope text whether it falls under the management system.
Why is the scope so important?
The scope forms the basis for:
The risk analysis
The internal audits
The management review
The certification audit
The certificate itself
An incorrect scope can lead to important risks being overlooked or customers getting a wrong impression of the certification.
For example, suppose a software company places its development department outside the scope, while software development is the core activity of the organization. This immediately raises the question of whether the management system is still representative of the organization.
Don't start with the certificate
Many organizations start with the question:
"What do we want to have on the certificate?"
That is exactly the wrong order.
Start with:
The context of the organization.
The products and services being delivered.
The processes that are necessary for that.
The locations where these processes take place.
The relevant internal and external stakeholders.
Only then do you formulate the scope.
The most common mistakes
1. Writing a marketing text
A scope is not an advertisement and should not contain anything promotional. The scope must be written in an objective manner.
An example of how it should not be:
"We are an innovative market leader providing high-quality solutions for the future."
This says nothing about the actual scope.
Better:
"Development, implementation, and management of software solutions for the healthcare sector."
2. Formulating too broadly
Some organizations choose:
"Providing ICT services."
But what does that mean exactly?
Software development?
Hosting?
Service desk?
Consultancy?
The more concrete, the better.
3. Excluding core activities
An auditor will critically examine exclusions.
If an activity is essential for service delivery, it should normally be part of the scope.
The same applies to ISO 27001. For example, an organization cannot simply keep its cloud environment outside the scope if almost all business information is processed there.
4. Forgetting locations
With multiple locations, it must be clear which locations fall under the management system.
Also consider:
Data centers
Outsourced locations
Home offices
Cloud environments
Especially within ISO 27001, cloud platforms are increasingly explicitly mentioned.
Scope for ISO 9001
For ISO 9001, the emphasis is on products and services.
A good scope usually contains:
The primary service delivery
The involved processes
Possibly the relevant locations
Example:
"The design, development, implementation, and management of software solutions for organizations in the healthcare sector."
Short, clear, and verifiable.
Scope for ISO 27001
For ISO 27001, more detail may sometimes be needed.
A good ISMS scope describes, for example:
The business activities
The information being protected
The involved systems
The locations
The organizational units
Example:
"The information security management system to support the development, delivery, management, and support of cloud-based software solutions for healthcare organizations, executed from the location in Arnhem and supported by Microsoft Azure."
When you read this scope, you can assume that there are more locations that are not part of the certification scope. You can also deduce that services are offered from platforms other than Azure; those also fall outside the scope. You might also n
How does an auditor assess the scope?
An auditor looks at, among other things:
Does the scope align with the context analysis?
Does the scope align with the service delivery?
Are exclusions logical and defensible?
Do employees understand what falls within the scope?
Does the scope correspond with reality?
When an organization performs an activity that is not included in the scope, a discussion almost always arises. The certifying body also uses the scope to check the audit program. For example, if the scope includes the verbs development, delivery, management, and support, but no interviews are scheduled for the service desk department in the audit program, then support may not be adequately assessed.
Practical checklist
Before finalizing the scope, check:
✓ Are all core activities included?
✓ Are the main products and services mentioned?
✓ Are relevant locations included?
✓ Is it clear what falls outside the scope?
✓ Does the scope align with the context analysis?
✓ Does the scope align with the risk analysis?
✓ Can an outsider understand what is certified?
More complex situations: the scope of the management system is not always the same as the certification scope
For 90% of organizations, the entire management system is certified. But that doesn't have to be the case! The management system can be broader than the part that is offered for certification. In that case, the scope on the certificate does not correspond with the scope of the entire management system.
For example, suppose an organization has multiple business units. The quality management system is applied organization-wide, including central processes such as HR, Procurement, ICT, and Management. However, the organization decides to certify only the Software Development department.
In that case, we can distinguish between:
Scope of the management system
The entire organization.
All supporting and primary processes.
All locations that are part of the management system.
Scope of certification
Only the activities of the Software Development department.
Possibly one specific location.
Only the products and services provided by this department.
This does not mean that the other parts of the organization fall outside the management system. They can still contribute to the functioning of the system and potentially even be involved during audits when their activities are relevant to the certified part.
When is partial certification acceptable?
A certification body will assess whether the certified part can be sufficiently delineated.
Questions such as:
Is it clear which products and services fall under certification?
Are the boundaries of the certified part objectively determinable?
Are customers not misled about the scope of the certificate?
Are supporting processes sufficiently secured?
When a certificate gives the impression that the entire organization is certified while only a small part has been assessed, there is a risk of misleading. That is not allowed. So also pay attention when information about the certification is shared in news articles and on the website: the impression must not arise that the scope is larger than reality.
A practical example
An international organization has locations in the Netherlands, Germany, and Belgium.
The ISO 27001 management system is implemented across the group. Risk management, policy, supplier management, and incident management are centrally managed.
The organization chooses to certify only the Dutch software services.
In that case:
The ISMS may relate to multiple countries.
The certification scope may be limited to the Netherlands.
Centrally managed processes may still be part of the audit because they influence the certified service delivery.
This distinction is entirely legitimate, provided the scope description is transparent and does not create false expectations.
Practical tip
Ask yourself:
"Does this scope describe the management system, or does this scope describe what will appear on the certificate?"
A good management system has clear boundaries. A good certificate then clarifies which part of that system is actually certified.
Conclusion
A good scope is not a formality but the foundation of the management system.
The best scopes are usually surprisingly simple: clear enough to accurately describe the organization, but specific enough to prevent misunderstandings.
As a rule of thumb:
When a customer understands what is actually certified after reading the scope, you are likely on the right track.