ISO27K

ISMS scope builder for ISO 27001 clause 4.3

Clause 4.3 asks for a boundary, not a description of the company. Six questions produce a drafted scope statement, the exclusions you can defend, and the list of interfaces and dependencies the certification body will ask you to show.

Last reviewed 2026-09-14Written by Jacob Masse, TrazTech Inc.

Scope is the first decision in an ISO 27001 project and the one that prices everything after it. Clause 4.3 wants three things settled: the boundary, what sits outside it, and the interfaces and dependencies between work you do and work other organizations do on your behalf. Most first drafts settle the first and skip the third, and the third is what a certification body reads first.

This works the boundary out from six answers and hands back a drafted scope statement you can edit. The result appears on this page. Nothing is emailed anywhere unless you ask for it at the end.

How much of the business goes inside the boundary?

A narrow scope is legitimate and common. What is not legitimate is a scope so narrow that the certificate no longer covers the thing your customer asked about.

What physical locations are inside it?

Inside the scope, not inside the company. Where in-scope work actually happens is the test, and a home office is a location the standard has an answer for.

Where do the in-scope systems run?

Who else touches in-scope work?

Tick everything that applies. Each one is an interface clause 4.3 expects you to have written down, and each one is a question at the documentation review.

What do you want to leave outside?

Every exclusion needs a reason that survives being read aloud. Tick what you intend to exclude and the result will tell you which of those reasons hold.

How many people work there?

When does the certificate need to exist?

What clause 4.3 actually asks for

The clause is four lines long and it asks the organization to determine the boundaries and applicability of the management system, and while doing so to consider the external and internal issues from 4.1, the requirements of interested parties from 4.2, and the interfaces and dependencies between activities it performs and activities performed by other organizations. The scope has to be available as documented information. That is the whole requirement.

The third item is the one that gets skipped. A cloud provider runs the data centre, a payroll service holds employee records, a managed service provider pushes patches to laptops, an agency writes code. Each of those is an activity performed by another organization that in-scope work depends on, and each needs naming and describing rather than assuming. The scope statement page walks through the sentence structure; this tool works out what belongs in it.

What the scope decision changes downstream
DecisionWhat it moves
Whole entity rather than one productEvery team is in the internal audit program and every employee is in the awareness training evidence. Audit days go up, and so does the evidence you maintain forever.
No premises inside the boundaryRoughly seven of the fourteen physical controls become arguable to exclude, and a remote audit becomes easier to agree.
Corporate IT left outsideThe hardest exclusion to defend, because the laptop that reaches the in-scope system is part of the path to it.
A parent company providing shared servicesAn interface, a supplier relationship, and usually a written agreement the auditor will ask to read.
Offshore developmentA location question, a personnel screening question, and a data transfer question, all three of which the certification body raises at scoping.

A scope is a promise to a reader, not a boundary drawn for the auditor

The certificate carries the scope statement on its face. Whoever asked you for the certificate will read that sentence and decide whether it covers the service they buy from you. A scope that certifies an internal platform nobody buys is technically valid and commercially worthless, and it is the failure mode nobody catches until a procurement team reads the certificate.

Common questions

Do I have to give an email address to see the result?

No. The drafted scope statement, the exclusions and the interface list render on this page as soon as you finish the questions. The field underneath sends a written version with the justifications set out, which is useful when several people have to agree the boundary. Skipping it costs you nothing.

Can we widen the scope later?

Yes, and it is the normal path. A scope change is handled at the next surveillance audit or through a separate extension audit, and it costs audit days rather than a fresh certification. Narrowing later is harder, because a customer who has seen the wider certificate will ask why it shrank.

Is a one-product scope seen as weaker?

Not by an auditor. The standard is indifferent to how much of the company is inside, as long as the boundary is coherent and the interfaces are documented. Buyers are less indifferent. The question to ask before you narrow is whether the sentence on the certificate will name the thing your customer is buying.

Can we exclude the office if most people work from home?

Only if no in-scope work happens there, which is a higher bar than it sounds. If a laptop that reaches production is ever used in that office, or a customer meeting happens there, the exclusion is thin. Companies that hold an office and exclude it usually end up putting it back after stage 1.

What comes after the scope is settled?

The risk assessment, because the boundary decides which assets and processes are in play, and then the control decisions that follow from it. The Annex A control selector takes the scope answers and works out which controls stay applicable.

Get the scope reviewed before it is priced

Tell us the boundary you are considering and we will put it in front of Canadian firms doing ISO 27001 work.

Get matched