In this guide you will learn how to implement ISO 27001 Clause 4.3 Determining the Scope of the Information Security Management System and pass your audit from ISO 27001 Lead Auditor Stuart Barker – author of the ultimate ISO 27001 Toolkit.
ISO 27001 Clause 4.3 Determining The Scope Of The Information Security Management System is an ISO 27001 clause that requires you to define the scope of your information security management system.
Table of contents
- Key Takeaways
- Purpose & Definition
- FREE ISO 27001 Clause 4.3 Training Video
- Implementation Guidance
- How to define ISO 27001 Scope
- How to document scope
- ISO 27001 Scope Template
- How to approve your ISO 27001 Scope
- ISO 27001 Scope Statement Example
- 10 real-world ISO 27001 Scope Statement examples
- How to legally de-scope to reduce audit costs
- Why Climate Change matters for ISO 27001 Clause 4.3
- How to pass the ISO 27001 Clause 4.3 audit
- What an auditor looks for
- Top 3 mistakes and how to fix them
Key Takeaways
- The scope should reflect what you want to be shown on your ISO 27001 certificate
- Narrowing scope will remove undue cost and bureaucracy
- Getting the scope wrong can cost a lot of time and lot of money
Purpose & Definition
The purpose of ISO 27001 Clause 4.3 Determining The Scope Of The Information Security Management is to ensure a clear and well-defined scope for your Information Security Management System (ISMS) and your subsequent ISO 27001 certification. This clarity helps establish:
- Which parts of the organisation are included within the boundaries of the ISMS.
- The specific areas that will be assessed during the ISO 27001 certification audit.
By defining the scope, you can ensure that your ISMS is focused on the most critical areas and that your certification accurately reflects the extent of your information security efforts.
The ISO 27001 standard defines ISO 27001 Clause 4.3 as:
The organization shall determine the boundaries and applicability of the information security
ISO27001:2022 Clause 4.3 Determining The Scope Of The Information Security Management System
management system to establish its scope.
When determining this scope, the organization shall consider:
a) the external and internal issues referred to in 4.1;
b) the requirements referred to in 4.2;
c) interfaces and dependencies between activities performed by the organization, and those that are
performed by other organizations.
The scope shall be available as documented information.
ISO 27001 Starter Kit
Instant download of mandatory ISMS core policies and documentation. Verified by Lead Auditors and used by 5,000+ businesses worldwide to pass Stage 1 certification first time.
FREE ISO 27001 Clause 4.3 Training Video
In this free training video I show you how to implement ISO 27001 Clause 4.3 Scope and how to pass your audit.
Implementation Guidance
- Establish scope by determining the boundaries and applicability of the information security management system: There is a cost in time, resource and money to implement ISO 27001 so it makes sense to concentrate on protecting the things that your clients are expecting to you to protect and the things that represent the biggest risk to you. I will show you how to do this later in the article.
- Consider your internal and external issues: When you set the scope you are making sure that you have addressed the internal and external issues that we covered in ISO 27001 Clause 4.1 Understanding the Organisation and It’s Context.
- Consider the needs an expectations of interested parties: The interested parties and their requirements which we covered in ISO 27001 clause 4.2 Understanding the Needs and Expectations of Interested Parties will be reviewed on if, and how, they affect the scope you are setting.
- Consider what you do verses what other people do for you: Third parties will be used a lot and those third parties will be responsible for the areas that they control so you will define the interfaces and dependencies between activities you do and activities that they do.
How to define ISO 27001 Scope
Scope is vitally important for your ISO 27001 Certification. It clearly sets out what we are going to apply our information security management system to and more importantly it defines what will go on our ISO 27001 certificate.
Determining your scope effectively can be challenging. To assist you, we’ve created a comprehensive guide: How To Define ISO 27001 Scope.This guide provides clear, step-by-step instructions to help you establish a well-defined scope.
We’ve included an ISO 27001 Scope Statement Template within our ISO 27001 Toolkit. This template can be used as a valuable resource to assist in the development of your official scope statement.
Based on practical, real world implementations and experience this is how to implement ISO 27001 Clause 4.3 Determining The Scope Of The Information Security Management System (ISMS):
Define Organisational Boundaries
Clearly identify where the organisation’s boundaries lie, especially in complex or multi-national organisations.
- Utilise organisational charts, legal documents, and stakeholder interviews to define the organisational structure.
- Consider third-party relationships and their impact on information security.
List all your products and services
List out all of the products and services that you have and document them.
- Conduct workshops with key interested parties (e.g., management, product owners, sales) to identify and document core offerings.
- Utilise process mapping and data flow diagrams to visualise the flow of products and services.
Ask your customers which products and services they expect to be in scope
From your list of products and services ask your customers which of them they expect to be in scope. Review current contracts for any scope requirements.
Ask your leadership team which products and services they expect to be in scope
From your list of products and services ask your leadership team which of them they expect to be in scope.
Ask the list of interested parties which products and services they expect to be in scope
From your list of products and services ask your interested parties which of them they expect to be in scope.
Document the list of products and services that are in scope
Taking the input from customers, leadership and interested parties document the list of products and services that are in scope.
Review your internal and external issues
Review the products and services that are in scope against the list of internal and external issues to determine if their are any direct issues or changes to issues.
Confirm the list of of products and services that are in scope
Agree and sign off the scope with the senior leadership team and document the agreement.
Identify Supporting Functions
Determine which departments and functions are critical to the delivery of core products and services.
- Analyse organisational structure and identify departments that directly or indirectly support core business functions.
- Consider departments like IT, HR, finance, legal, and facilities.
Determine Scope Exclusions
Identify activities, departments, or systems that will be explicitly excluded from the scope of the ISMS.
- Clearly document the rationale for any exclusions.
- Ensure that excluded areas do not pose significant risks to the organisation’s information security.
Document and understand the ISO 27001 Scope Boundaries
Identifying the people, premises, technology, and suppliers that directly support the in-scope products and services and understand the interfaces between in scope entities and out of scope entities as well as with third party organisations.
Write your ISO 27001 Scope Statement
Summarise your scope in the required ISO 27001 scope statement.
- Use clear and concise language.
- Obtain input and approval from key interested parties.
- Regularly review and update the scope statement to reflect changes in the organisation or its environment.
Communicate Scope to Stakeholders
Ensure that all relevant stakeholders understand the scope of the ISMS and their roles and responsibilities within it.
- Conduct training sessions and awareness campaigns.
- Distribute the scope statement to all employees.
- Include the scope statement in relevant policies and procedures.
Obtain Management Approval
Secure management approval for the defined scope of the ISMS.
- Present the proposed scope to management and address any concerns or questions.
- Obtain formal approval from top management.
Verify the scope statement with the certification body (optional)
Share your ISO 27001 scope statement with the external ISO 27001 certification body auditor for feedback and confirmation.
Check Your Work?
You buit it yourself. Maybe with AI. But will it pass the audit?
Don’t gamble – let a trained ISO 27001 auditor check your work.

How to document scope
Your scope statement is the heart of your certification. It is the text that will eventually be printed on your ISO 27001 certificate. If it is poorly documented, you risk misleading your customers or, worse, failing your Stage 1 audit because the auditor cannot identify what they are supposed to be testing.
A professionally documented scope statement must include four key elements:
- The Legal Entity: Clearly state the name of the company or the specific business unit being certified.
- The Services/Products: Define exactly what the ISMS protects (e.g., “The provision of cloud-based payroll services”).
- The Physical and Logical Boundaries: Mention your primary locations and your core infrastructure (e.g., “Operating from the Leeds head office and utilizing AWS Dublin regions”).
- The Exclusions: If you are excluding a department or a location, you must document the justification. “We just didn’t want to include them” is not a valid justification.
ISO 27001 Scope Template
The ISO 27001 Scope Template provides a structured framework for defining the scope of your Information Security Management System (ISMS), fully meeting the requirements of ISO 27001 Clause 4.3.
It was designed and built with these key features:
- Pre-filled with common scope examples: Provides a solid foundation and saves you time.
- Available as an individual download: Offers flexibility for specific needs.
- Included in the internationally acclaimed ISO 27001 Toolkit: Access a comprehensive suite of templates and resources to streamline your entire implementation process.

How to approve your ISO 27001 Scope
Approval is not just a signature on a page; it is the moment your leadership team accepts the risk and responsibility for the boundaries you have drawn. Under Clause 5.1 (Leadership and Commitment), top management must demonstrate they are ‘all in.’ If they haven’t formally approved the scope defined in Clause 4.3, your certification will fail at the first hurdle.
To get your scope approved correctly, follow these three non-negotiable steps:
- The Scoping Workshop: Present the draft boundaries to the board or senior leadership. Explain exactly what is IN and what is OUT. If they don’t understand the exclusions, they can’t approve them.
- Formal Minute Recording: Approval should happen during a Management Review Meeting or a dedicated Security Steering Group. Ensure the decision is recorded in the minutes. An auditor will ask to see these.
- The Versioned Sign-Off: Your Scope Statement should have a version history and an approval block. I expect to see a name, a role (typically the CEO or CISO), and a date.
ISO 27001 Scope Statement Example
An example ISO 27001 Scope Statement:
The scope of this Information Security Management System (ISMS) encompasses all products and services offered by [Organisation Name], as outlined in [link to product/service catalogue or relevant document]. The implementation of controls is detailed within the Statement of Applicability, version [version number].
In practice:
A practical example, taken directly from our ISO 27001 certification, is:
Information security consultancy and virtual chief information security officer services in accordance with the statement of applicability version 2.1
High Table ISO 27001 Scope Statement
White Label ISO 27001 for Consultants
Custom-brandable ISO 27001 documentation for consultants. Easily rebrand, reduce project time, and deliver professional, high-value security systems. Focus on delivery, not drafting.
10 real-world ISO 27001 Scope Statement examples
To help you draft your own documented information, here are 10 examples of scope statements across various industries. Remember, clarity is the priority.
- Software as a Service (SaaS): “The scope of the ISMS includes the development, maintenance, and hosting of the [Product Name] platform, including all customer data stored within the AWS Production Environment.”
- Professional Services: “Provision of legal and consultancy services, including all supporting IT infrastructure and physical offices located at [Address].”
- Managed Service Provider (MSP): “Management and monitoring of client infrastructure, including the helpdesk operations, remote management tools, and onsite support staff.”
- FinTech Startup: “The ISMS encompasses the [App Name] mobile application, the underlying API architecture, and the payment processing gateway interfaces.”
- E-commerce: “Security of the online retail platform, including the checkout process, warehouse management systems, and customer database.”
- Healthcare Provider: “Protection of patient records and diagnostic data within the [System Name], including all medical devices connected to the internal hospital network.”
- Manufacturing: “The ISMS covers the design and production of [Product], specifically protecting the intellectual property on the CAD servers and the PLC controllers on the factory floor.”
- Education: “The administration of student records and the delivery of online learning modules via the University Virtual Learning Environment (VLE).”
- AI Development: “The lifecycle of AI model training, including data ingestion pipelines, GPU compute clusters, and the proprietary algorithm repository.”
- HR & Payroll Outsourcing: “Processing of employee payroll data and benefits administration, including the secure transfer of data to HMRC and third-party pension providers.”
How to legally de-scope to reduce audit costs
One of the biggest secrets in ISO 27001 implementation is that a smaller scope usually leads to a more effective system and a significantly lower audit fee. As a Lead Auditor, I see many organisations pay for five days of auditing when they only needed three. Strategic de-scoping is the art of removing non-critical business units without compromising your security posture.
Why Climate Change matters for ISO 27001 Clause 4.3
As an ISO 27001 Lead Auditor, I see too many organisations treating Clause 4.3 as a “set and forget” exercise. That is a mistake that will lead to a minor non-conformity in your next audit. Following the February 2024 Amendment 1, you are now mandated to consider climate change when determining your scope.
If your Clause 4.1 context identifies climate risks but your Clause 4.3 scope statement ignores them, your Management System is disconnected. You cannot claim to have an effective ISMS if the boundaries of your security do not account for the very real physical and transition risks posed by a changing climate.
The standard now requires you to determine if climate change is a relevant issue. If it is, that relevance must flow directly into your scope. You are defining the “where” and the “what” of your security. If your “where” is a flood zone or an area with an unstable power grid due to extreme heat, your scope must reflect that reality.
Strategic Impact of Climate Change on ISMS Boundaries
| Climate Factor | Impact on Clause 4.3 Scope | Auditor’s Expectation |
|---|---|---|
| Physical Risk (Flooding/Fire) | Mandatory inclusion of specific geographic locations or data centres in high risk zones. | I want to see that your “Premises” boundary includes the specific physical protections for those sites. |
| Resource Scarcity (Power/Water) | Scope must extend to include backup power systems and cooling infrastructure for server rooms. | You cannot exclude “Facilities Management” from your scope if climate change threatens your server uptime. |
| Supply Chain Volatility | Expanded “Interface” boundaries to include alternative SaaS or hosting providers in different regions. | Your scope statement must acknowledge the dependencies on third parties that are themselves at risk. |
| Regulatory Shifts | Inclusion of “Legal and Regulatory Compliance” as a primary driver for the ISMS boundary. | If new green laws require data residency changes, your scope must adjust to those new territories. |
How to Update Your Scope for Amendment 1
To pass your audit, you must demonstrate that you have performed a “Climate Sanity Check” on your boundaries. Use the following list to verify your Clause 4.3 documentation is compliant.
- Review your Clause 4.1 Output: Look at the internal and external issues you identified regarding climate.
- Identify Geographic Vulnerabilities: If you have shifted to “Remote First” because your main office is in a high risk heatwave zone, your scope must now focus on the “Endpoint” rather than the “Office.”
- Adjust Interface Definitions: Clearly define the boundary between your organisation and your utilities providers if climate change makes power or connectivity a high risk dependency.
- Document the Decision: Even if you decide climate change does not affect your scope, you must document that you considered it. Silence is not a defence during a Stage 2 audit.
- Update the Scope Statement: Ensure the final version of your documented information mentions that climate considerations have been factored into the boundary definitions.
How to pass the ISO 27001 Clause 4.3 audit
To successfully pass an audit of ISO 27001 Clause 4.3, a crucial step in achieving ISO 27001 Certification, you must ensure you have implemented the mandatory ISO 27001 documents and ISO 27001 polices. You are going to need to put in place ISO 27001 controls to:
- Document an ISO 27001 Scope Statement
- Implement the ISO 27001 standard
What an auditor looks for
The ISO 27001 certification body auditor will ensure:
- That you have documented your ISO 27001 scope: You must have a documented scope for your Information Security Management System (ISMS). The auditor will check for the existence of a documented scope statement. Utilising the ISO 27001 Scope Template can simplify this process.
- That you have implemented the scope: You must have implemented the ISO 27001 standard within the defined scope. The auditor will assess whether the requirements of the ISO 27001 standard have been applied effectively to the identified products, services, and areas included within the scope.
- That the scope was approved: Your documented scope must be formally approved. The auditor will check for evidence of scope approval, such as documented approvals and signatures from relevant management personnel.
Top 3 mistakes and how to fix them
These are the top 3 mistakes people make for ISO 27001 Scope:
- Defining an Overly Broad Scope: Including unnecessary areas within the scope of your ISMS can lead to wasted time, resources, and unnecessary costs. Carefully consider and document the specific products, services, and areas that require information security controls.
- Neglecting Client Expectations: Failing to consider client expectations and requirements within the scope of your ISMS can diminish the value of your certification. Involve clients in the scope definition process to ensure your ISMS addresses their specific needs and concerns.
- Poor Scope Management: Inadequate documentation, version control, and review of the scope statement can lead to confusion and non-compliance. Maintain accurate and up-to-date records of the scope statement, implement a robust version control system and regularly review and update the scope statement to reflect changes in the organisation or its environment.

