ISO 9001 · Clause 4 · 4.3
The scope
In plain words
The scope is the shortest mandatory exercise in the standard: a written statement of what your QMS covers — which products and services, which sites — and which requirements of the standard you declare not applicable, with reasons. It is one of the few places where the standard explicitly demands a documented, available result.
Half a page is enough. The statement rests on what came before it: the context (4.1), the interested parties (4.2) and your actual range of work. And it has one hard boundary: you may only exclude what does not touch your ability to deliver conforming products — and you must justify it.
The scope is also what later appears word for word on your certificate. It is less an internal view than a promise to the outside: for exactly this range, we let ourselves be audited.
Why this requirement exists
Without a defined boundary, a management system cannot be audited — not by you, not by anyone. The scope fixes where the rules apply, and it prevents cherry-picking: defining the inconvenient part of the business out of the system although it co-determines product quality.
The justification duty for non-applicability serves the same purpose. The classic example is design (clause 8.3): whoever manufactures exclusively to customer drawings does not design — the exclusion is honest and common. But whoever quietly co-designs and excludes 8.3 anyway has a gap exactly where errors are most expensive.
What good looks like
In a company of 12 people: half a page, three paragraphs. First: what we do and for whom — concrete enough that a stranger understands the business. Second: where — sites, off-site stores or mobile work if any. Third: what is not applicable, with a one-sentence reason. Worded like the future certificate text, because that is what it becomes.
The scope is maintained on occasion: a new line of work, a new site, changed manufacturing depth → a new version. Between occasions it rests — a scope that changes monthly describes not a company but a building site.
What changes as you grow: little — and that is the point of this clause. More sites and business lines make the statement longer, not different. Only the delineation gets more demanding: with several sites or a group, someone must consciously decide which units sit inside the certification scope — at the latest then, the scope belongs on the table once per management-review year.
The minimum to pass
- A released, available written statement — intent is not enough here; the document is mandatory.
- It names the products and services and the sites the QMS applies to.
- Every non-applicability is individually justified — and the justification survives the question of whether the excluded requirement really plays no role in your product conformity.
- The statement matches reality — and what the certificate is supposed to say.
What an auditor asks for
- The released scope document itself — usually one of the first an auditor opens.
- Its agreement with the certificate text and with your actual appearance (website, offers).
- The justifications of the exclusions — and, on the shop-floor tour, the cross-check: is there really no designing happening here?
- The derivation: does the scope fit the context (4.1) and the interested parties (4.2)?
- After changes in the company: was the scope brought along (a new version), or does it describe the state of two years ago?
Common traps
- The marketing text. “We stand for the highest quality and customer satisfaction” is a slogan, not a scope. What is asked for is the sober answer: what, for whom, where.
- The unjustified exclusion. “8.3 not applicable” without the sentence to go with it — the most common formal finding in first audits. The justification costs one line.
- The dishonest exclusion. Design excluded, but the offer says “engineering to customer requirements”. Auditors read websites.
- Cut too narrow. Keeping the complaint-prone unit out of the QMS does not work if it touches product quality — and it shows at the latest on the tour.
- The forgotten site. The off-site store, the second building, permanent work at a customer’s — whatever belongs to delivering the service belongs in the statement.
- Never brought along. A new line of business for a year, a scope from the day before yesterday — an avoidable finding, because the change would have been one line.
Worked example
The scope of Berger Präzisionsteile GmbH is three paragraphs. In essence: Manufacture of precision turned and milled parts to customer drawings for medical technology and machine building, including inspection and dispatch, at the Musterstadt site. Then the exclusion: Clause 8.3 (design and development) is not applicable, as manufacture is exclusively to customer-supplied drawings; feasibility checks take place within order review (8.2). The second sentence is the valuable one: it shows the auditor the boundary was thought through, not convenient.
A year later, the opportunity “assembly work” (from the risk and opportunity overview, clause 6.1) becomes a pilot order — and the scope gets a new version: … and assembly of simple sub-assemblies. One line of change, cleanly versioned, and the certificate grows with it at the next surveillance audit. That is how scope and lived business belong together.
How easo covers it
The scope is mandatory documented information — in easo a row in the readiness denominator (clause 4.3), with everything that belongs to it:
- The scope starter template brings the structure — what/for whom/where, context and parties as sections, exclusions with a justification sentence — and easo’s honest scaffolding prevents placeholder text from ever being released.
- Every change is a new, signed version with history — the auditor sees when the scope was last brought up to reality.
- Justified non-applicability exists in readiness itself too: requirements like design (8.3) can be marked not applicable with a reason — they leave the denominator auditable, not silently. Document exclusion and readiness exclusion tell the same story in two places.
Stay in the loop
easo is available for macOS — the Windows version is coming soon. Leave us a note and we'll reach out the moment it lands.