ISO9001 Clause Deep Interpretation (4) | 4.3 Determining the Scope of the QMS: Draw the Boundary Right, Then the System Lands

By: QTank Published: 9/3/2026 Views: 71
Current rating: ★★★☆☆ Rate this Equivalent to 8 ratings

1. Key Points of the Clause

ISO 9001:2015 Clause 4.3 requires organizations to "determine the boundaries and applicability of the quality management system (QMS) to establish its scope." When determining the scope, the organization should consider three inputs: the internal and external factors described in Clause 4.1, the requirements of interested parties described in Clause 4.2, and the organization's products and services. Once the scope is determined, it should be maintained as documented information and be available for retrieval, meaning it must be documented and verifiable. The clause also includes two often-overlooked limitations: first, all requirements applicable to the determined scope must be implemented without selective execution; second, if the organization believes that certain requirements of this standard are not applicable to its scope, it must provide justification, and only when such non-applicability "does not affect the organization's ability or responsibility to ensure the conformity of its products and services and enhance customer satisfaction" can it claim compliance with the standard. In other words, exclusions are not discretionary but require justification as exceptions.

2. Interpretation of Intent

The scope clause, though brief, is the "first foundation" of the entire system. The 2015 edition deliberately places it alongside Clauses 4.1 and 4.2 in Chapter 4, with a clear logic: first understand the environment, then identify the interested parties, next define the system boundaries, and finally plan the processes. The scope must address three questions: where the system applies (geographical and organizational boundaries, such as plant sites, branch companies, and off-site project locations), what it covers (types of products and services), and which requirements are not applicable (e.g., excluding Clause 8.3 if there are no design responsibilities). If the boundaries are unclear, all subsequent clauses will be unsupported—process lists, responsibility allocation, resource allocation, and internal audit coverage will all lack a basis. The scope also serves as the foundation for certification contracts: the scope description on the certificate directly determines the sampling boundaries and audit frequency. A scope that is too broad, without corresponding evidence, will put the organization at a disadvantage during audits; a scope that is too narrow, excluding actual business activities, may lead to questions of "operating beyond the scope" during bidding. The "non-applicability statement" provided by the standard is a conditional freedom—exclusions must also remove responsibility, and if they cannot, they should not be made. This is the most easily misunderstood aspect of the deeper logic of Clause 4.3.

3. Implementation Practices

Step 1: Inventory Products, Services, and Sites

List all products and services currently provided by the organization, all processes required to achieve these products, and the locations where each process occurs, including multi-site branches, on-site service points at customer locations, and outsourced processes controlled by the organization. Create a comprehensive list without pre-judging which items to include or exclude.

Step 2: Integrate Environmental and Stakeholder Analysis Conclusions

Use the outputs from Clauses 4.1 and 4.2 as inputs: identify which internal and external factors will substantially impact the boundaries (such as industry access regulations, group control requirements, and plans for building new facilities in different locations), and which stakeholder requirements must be covered by the system (such as customer-specified on-site audits and local jurisdictional oversight). Based on this, determine whether a single system or multiple systems, and a single site or multiple sites, are necessary.

Step 3: Compare and Justify Non-Applicability

Compare each requirement of the standard to your products and services, asking, "Does this requirement apply to my products and services?" For any requirement deemed non-applicable, document the reasons in writing and have management confirm that the exclusion does not affect the organization's ability to ensure product conformity and customer satisfaction. Common reasonable exclusions in practice include Clause 8.3 (no design and development activities), while Clauses 8.4, 8.7, and 10.2 generally do not allow for exclusions. Justification can be done using a simple review form to check each requirement, ensuring that "the process of judgment is traceable and the conclusions are signed."

Step 4: Document and Approve for Release

Write the conclusions into a "QMS Scope Statement," clearly defining the covered product/service types, site boundaries, non-applicable clauses, and reasons. After approval by the highest management, release it as a controlled document and ensure consistency with the quality manual, process list, and certification certificate. This document serves multiple purposes: it is the basis for certification applications and surveillance audits, and a proof of system coverage during bidding. The language must be robust enough to withstand external scrutiny.

Step 5: Establish a Change Trigger Mechanism

Incorporate scope reviews into regular management reviews and define trigger conditions: when business expands or contracts, organizational structure changes, new regulations are implemented, or a scope change application for certification is made, promptly re-evaluate and update the scope document, ensuring that changes are documented.

4. Auditor's Perspective

  1. Common Nonconformities: Scope is disconnected from operational reality. For example, a company's scope only states "mechanical parts processing," but the actual workshop also handles surface treatment and outsourced assembly. An auditor can quickly identify out-of-scope activities during a site visit, leading to a determination that the system scope is inaccurately defined.
  2. Common Nonconformities: Justification for exclusions does not withstand questioning. A customized equipment company excludes Clause 8.3, claiming "design is completed by the customer," but cannot provide evidence of complete design input from the customer or a justification for the exclusion's impact. The auditor will issue a nonconformity based on this.
  3. Common Nonconformities: Missing or uncontrolled scope documents. Some organizations believe that "the scope can just be copied from the certification application," without creating an independent document or updating it after revisions, leading to inconsistencies between the on-site version and the certificate scope.
  4. Common Misunderstandings: Equating outsourcing with exclusion. Some organizations assume that outsourcing a process means it can be excluded from the system boundaries, but external processes, products, and services still need to be controlled according to Clause 8.4, and the organization's responsibility does not transfer with outsourcing.
  5. Frequent Questions: "Which clauses have you excluded, and what are the reasons? Who approved these exclusions? When was the last scope change, and what was the process?"

5. Self-Inspection Checklist

  • Have you formed a scope statement document that covers all product/service types and sites (including outsourced, on-site, and temporary sites) and is controlled and released?
  • Was the scope determination based on the analysis conclusions of the internal and external factors in Clause 4.1 and the requirements of interested parties in Clause 4.2, rather than arbitrary decisions?
  • Do you have a written list of non-applicable clauses with detailed reasons for each, and have these been justified as not affecting product conformity and customer satisfaction?
  • Are the scope statements in the scope document, quality manual, process list, and certification certificate consistent?
  • After significant changes in business or organization, have you promptly reviewed and updated the scope, and are these changes documented?

Accurate boundaries ensure a solid system

Knowledge code: 2.1.1

Version: v20260903

Author: QTank QTank is dedicated to providing systematic professional knowledge, methodologies, and practical tools for quality management practitioners, helping companies continuously improve their quality capabilities.