Preparation for ISO Certification 08 Feb 2025

Scope of the Management System on the Certificate – How to Define It Correctly?

How to correctly define the ISO certification scope to avoid mistakes and pass the audit? Find out how to formulate the scope, when it can be changed, and what the most common mistakes are.

Introduction

The scope of the management system is a key element of an ISO certificate, defining which areas of an organization are covered by the implemented and certified management system. The scope indicates which processes, services, or products the system applies to and which standard requirements are being followed. Properly defining the scope is essential for a successful certification audit and the effective maintenance of the management system.

How to Define the Scope of a Management System Correctly?

The scope of a management system should be precise and should clearly specify:

  • Which activities the management system covers,
  • Which locations are included,
  • Which products, services, or processes are part of the system,
  • For ISO 27001 – a reference to the Statement of Applicability (SoA), which identifies selected security controls in accordance with Annex A of ISO 27001. The Statement of Applicability specifies which controls are implemented in the organization and how they are applied.

The scope should reflect reality to avoid issues during the certification audit.

The initial draft of the scope is first submitted by the client to the certification body in the quotation request form. This preliminary scope is then thoroughly reviewed during the first stage of the audit. In some cases, for example, when exclusions or limitations apply to the full range of services, the auditor may need to consult additional individuals within the organization. At the end of the audit, the auditor confirms the final version of the scope.

What If the Auditor Questions the Scope of the Management System?

During the certification audit, the auditor may challenge the proposed scope if they determine that:

  • It does not cover key organizational processes,
  • It is too broad compared to actual operations,
  • It includes services, products, or processes that are not covered by the implemented system.

In such cases, the organization may:

  1. Modify the scope, eliminating or adding elements in accordance with the auditor’s recommendations.
  2. Demonstrate that the scope is accurate, for example, by providing additional evidence (procedures, records, policies).
  3. Take additional actions, such as implementing missing processes or updating documentation.

It is advisable to consult the scope with the certification body before the audit to avoid potential issues.

Real-life Examples of Certification Scopes Issued by Certification Bodies

Company: Schüco International KG – ISO 9001 (Quality Management System)
“Design, development, and sales of aluminum and PVC-U systems for construction, as well as production of PVC-U and aluminum systems.”
Certification body: DQS GmbH
Source: https://www.schueco.com/pl/firma/zrownowazony-rozwoj/certyfikaty/systemy-zarzadzania 

Company: PW Krystian – ISO 14001 (Environmental Management System)
“Design, production, and sales of professional and protective clothing, distribution of personal protective equipment, and cleaning products.”
Certification body: TÜV Rheinland
Source: https://www.krystian.com.pl/pw-krystian-z-certyfikatem-srodowiskowym-iso-14001/ 

Company: Asseco Poland – ISO 22301 (Business Continuity Management System)
*“Business Continuity Management System in the scope of:

  • Developing, implementing, and providing IT services,
  • Managing IT projects,
  • Designing, developing, implementing, administrating, maintaining, and integrating IT solutions, carried out by the Systems Maintenance Division.”*
    Certification body: Alcumus ISOQAR
    Source: https://pl.asseco.com/dokumenty 

Company: IBM – ISO 27001 (Information Security Management System)
*“The design, development, and support of Infrastructure Management System (IMS) and IaaS cloud offerings, using local and global capabilities. Customer-managed options delivered from within IMS include:

  • IBM Cloud Bare Metal, IBM Cloud Virtual Servers,
  • SAP-Certified Cloud Infrastructure, IBM Cloud Hardware Security Module (HSM),
  • IBM Cloud Load Balancer, IBM Cloud Direct Link '1.0' (Connect, Dedicated Hosting, Exchange),
  • Hardware Firewall, Gateway Appliance,
  • IPSec VPN, Fortigate Security Appliance,
  • IBM Cloud Block Storage, IBM Cloud File Storage,
  • IBM Cloud Backup, IBM Cloud Object Storage (IaaS).
    Consolidated Statement of Applicability V1.26 dated 5/8/2023.”*
    Certification body: Bureau Veritas
    Source: https://www.ibm.com/support/pages/ibm-iso-27001-certifications-cloud 

Can the Scope of Certification Be Changed During the Certificate’s Validity Period?

Changing the certification scope during the validity of the certificate is possible, but it requires additional audit activities. Depending on the nature of the changes, they may:

  • Extend or shorten the audit duration,
  • Require an additional special audit,
  • Cover an expansion of the scope to include new processes, services, or locations,
  • Reduce the scope if some areas are no longer relevant.

The best time to introduce changes is during a surveillance or recertification audit, as this minimizes additional costs associated with audit time extensions. The organization should contact the certification body to discuss the scope changes and obtain information on requirements and the implementation process.

Frequently Asked Questions (FAQ) About Certification Scope

1. What is the scope of ISO certification?
The scope of ISO certification defines the specific areas, processes, products, or services of an organization that are covered by a management system compliant with a given ISO standard. A well-defined scope is essential for a successful certification process.

2. How do I determine the correct scope for my organization?
To define the appropriate scope, you should:

  • Identify the key processes, products, and services within your organization,
  • Determine which locations are included,
  • Consider customer requirements and applicable legal regulations,
  • Consult a certification body or ISO expert to verify scope accuracy.

3. Can I change the certification scope after it has been established?
Yes, it is possible to change the certification scope during the certificate’s validity period. However, it requires an additional audit. The best time for changes is during a surveillance or recertification audit to minimize additional costs.

4. What happens if the auditor questions the proposed scope?
If the auditor finds that the scope does not cover key processes or is too broad compared to actual operations, the organization can:

  • Adjust the scope according to the auditor’s recommendations,
  • Provide additional evidence proving the scope’s accuracy,
  • Implement missing processes or update documentation.

5. What are the most common mistakes in defining the certification scope?
The most common mistakes include:

  • A scope that is too narrow, omitting important processes or services,
  • A scope that is too broad, including non-relevant areas,
  • Lack of precision, leading to misunderstandings during the audit,
  • Not aligning the scope with the organization’s actual activities.

6. Does the certification scope need to cover all processes in the organization?
No, the scope does not have to cover all organizational processes. However, key processes that affect the quality of products or services must be included. Exclusions should be clearly justified and must not affect the organization’s ability to meet standard requirements.

7. What are the benefits of a well-defined certification scope?
A properly defined scope allows for:

  • Focusing on key operational areas during the audit,
  • Avoiding misunderstandings with the certification body,
  • Optimizing audit costs and duration,
  • Increasing the credibility of the certificate among customers and business partners.

Share this article