# Management System Scope Statement

> Mandatory document – ISO 9001:2015 cl.4.3 / ISO 27001:2022 cl.4.3.
> The scope defines what the management system covers and is the first
> document auditors ask for.

| Field | Value |
|-------|-------|
| Document ID | DOC-[QMS|ISMS]-001 |
| Standard | ISO XXXXX:YYYY |
| Version | N.N |
| Approved by | Top management |
| Effective date | YYYY-MM-DD |

## 1. Organization

Legal entity name, locations covered.

## 2. Scope statement

One paragraph, quotable verbatim in the certificate:

> The [QMS/ISMS] of [organization] covers [products/services/processes]
> delivered by [sites/departments], including [key activities and
> information types].

## 3. Boundaries

- **Included**: sites, processes, products, information assets
- **Interfaces**: dependencies on external parties at the boundary

## 4. Exclusions & justification

| Excluded item | Clause | Justification |
|---------------|--------|---------------|
| Process/site not covered | e.g., 8.3 design | Why exclusion does not affect conformity |

## 5. Applicable requirements

- Statutory/regulatory requirements applying to the scope
- Contractual requirements
- Internal policies

## 6. Context & interested parties (ref cl.4.1/4.2)

| Interested party | Need/expectation | Addressed how |
|------------------|-------------------|---------------|
| Customers | quality/security | processes |
| Regulators | compliance | controls |
| Staff | clarity | procedures |
