Exemplar Global Certified Courses from USD 99. Ending Soon!

Audit Tips for ISO 45001 Clause 4.3: Verifying Scope

AW

Team @ Audit Workshop

13 min read
Audit Tips for ISO 45001 Clause 4.3: Verifying Scope

Why Clause 4.3 Scope Verification Matters More Than Most Auditors Realise

Scope is the foundation of every OH&S management system. Get it wrong and nothing else in the system can be trusted. If the scope excludes workers, sites, or activities that carry real risk, the entire OHSMS is built on a false premise. Yet in practice, Clause 4.3 of ISO 45001 is one of the most superficially audited clauses in the standard.

Many auditors treat scope verification as a five minute document check. They read the scope statement on the wall or in the manual, confirm it mentions the organisation by name, tick the box, and move on. That approach misses the point entirely. Verifying scope under ISO 45001 requires you to test whether the documented scope accurately reflects the physical, operational, and organisational reality of the OH&S management system.

This article walks through exactly how to do that, including what evidence to gather, what questions to ask, and where the common nonconformities hide.

What Clause 4.3 Actually Requires

ISO 45001 Clause 4.3 requires the organisation to determine the boundaries and applicability of the OHSMS in order to establish its scope. When doing so, the organisation must consider the external and internal issues identified under Clause 4.1, the requirements of interested parties identified under Clause 4.2 (with particular attention to workers and their representatives), and the work related activities of the organisation.

The clause also requires that the scope be available as documented information and be available to interested parties. Critically, the standard states that once something is within the scope, the organisation must include it in the OHSMS. You cannot scope in an activity and then ignore it in your hazard identification or risk controls.

Three things are worth noting from an auditor's perspective. First, the standard does not permit arbitrary exclusions of high risk activities simply because they are inconvenient to manage. Second, the scope must be consistent with what was determined in Clauses 4.1 and 4.2. Third, unlike ISO 9001 which allows exclusions of certain clauses, ISO 45001 does not have an exclusions mechanism. If an activity is within scope, all applicable requirements of the standard apply to it.

Starting the Audit: Document Review Before You Step on Site

Before the site visit, request and review the scope statement as documented information. Look for the following during your desktop review.

What the Scope Statement Should Describe

A well written scope statement for ISO 45001 should clearly identify the physical locations covered, the types of work activities included, the categories of workers covered (employees, contractors, labour hire, volunteers), and any relevant organisational boundaries such as business units or divisions.

Watch for scope statements that are deliberately vague. Phrases like all operations at our facilities sound comprehensive but tell you nothing about whether remote workers, contractor managed sites, or off site activities are actually included. A vague scope is often a warning sign that the organisation has not thought carefully about its boundaries.

Cross Reference the Scope Against Clauses 4.1 and 4.2

Pull the context analysis and interested party register before the audit. The scope should be consistent with both. If Clause 4.1 identified that the organisation operates across three states, but the scope only mentions the head office location, that inconsistency needs to be explored. If Clause 4.2 identified labour hire workers as a significant interested party, but the scope is silent on contractor and labour hire activities, that is a red flag worth investigating on site.

This cross referencing step is something many auditors skip because it requires reading three documents together rather than in isolation. Do not skip it. It is where the most significant scope gaps are usually found.

On Site Audit Techniques for Clause 4.3

Document review tells you what the organisation claims. The site visit tells you whether that claim holds up. Here is how to approach the on site component of scope verification.

Walk the Physical Boundaries

Ask to be taken through the physical areas covered by the OHSMS. As you walk, compare what you see against what the scope statement describes. Pay attention to areas that seem to be in use but were not mentioned in the scope. Warehouses, maintenance workshops, car parks, loading docks, and remote work areas are commonly omitted from scope statements even when workers are regularly exposed to hazards in those locations.

If you see an activity happening that involves workers and carries obvious risk, ask whether it is covered by the OHSMS. If the answer is uncertain, that uncertainty is itself a finding worth recording.

Interview Workers at Different Levels

Talk to workers, not just managers. Ask a frontline worker whether they are aware of the OH&S management system and whether it covers their work. Ask a supervisor whether any of their team's activities fall outside the scope. Ask a contractor representative whether the OHSMS applies to their work on site.

These conversations often surface gaps that no document would reveal. A worker who says that safety system is for the office staff, not us is telling you something important about the real boundaries of the system.

Test the Scope Against the Hazard Register

One of the most effective techniques for scope verification is to trace the scope statement through to the hazard identification records. If the scope includes a particular work activity, there should be evidence that hazards associated with that activity have been identified, assessed, and controlled.

Pick three or four activities mentioned in the scope and ask to see the corresponding hazard identification records. Then pick one or two activities you observed on site that are not explicitly mentioned in the scope and ask the same question. If hazard records exist for activities that are outside the documented scope, the scope is probably understated. If hazard records are missing for activities that are within the scope, there may be a Clause 6.1 issue as well.

For more detail on auditing hazard identification specifically, see Auditing Hazard Identification: Is the Process Ongoing and Proactive?

Check Whether Contractors Are Within Scope

Contractor management is a persistent problem area in ISO 45001 audits. Many organisations define their scope in a way that implicitly or explicitly excludes contractors, then discover during an audit that this creates a significant gap.

Under ISO 45001, the organisation is responsible for the OH&S of workers, which includes contractors working under the organisation's control. The scope should reflect this. Ask to see the list of current contractors on site and check whether the OHSMS addresses their activities. Check whether contractors are mentioned in the hazard identification process, whether they receive inductions, and whether their work is subject to the same operational controls as employees.

If the scope statement says all employees at our Brisbane facility but says nothing about contractors, and contractors are regularly on site performing high risk work, that is a scope gap that could support a nonconformity.

Common Nonconformities Found When Auditing Clause 4.3

Based on real audit experience, these are the nonconformities that appear most frequently when auditors properly test scope under ISO 45001.

Scope Excludes High Risk Activities Without Justification

Some organisations attempt to limit their scope to low risk activities in order to simplify certification. For example, a construction company might scope in only the office function and exclude site based construction activities. This is not a legitimate use of scope boundaries. The scope must reflect where workers are actually exposed to OH&S risks. An auditor who finds that the highest risk activities in the business are outside the OHSMS scope should raise this as a major nonconformity.

Scope Is Inconsistent with Clause 4.1 and 4.2 Outputs

As discussed above, the scope must be informed by the context analysis and interested party identification. If those earlier processes identified issues or parties that should have influenced the scope, but the scope statement does not reflect them, the linkage between clauses has broken down. This is a systemic issue, not just a documentation gap.

Scope Has Not Been Updated After Organisational Changes

Organisations change. They open new sites, take on new types of work, change their workforce composition, or restructure their operations. When this happens, the scope should be reviewed and updated if necessary. A common finding is that the scope was written at the time of initial certification and has not been touched since, even though the organisation looks quite different now.

Ask when the scope was last reviewed and what triggered that review. If the answer is we set it up when we got certified and have not looked at it since, that is worth probing further.

Scope Is Not Available to Interested Parties

Clause 4.3 requires that the scope be available as documented information and available to interested parties. Check where the scope is documented, how workers can access it, and whether contractors and other relevant parties have been informed of it. A scope buried in a quality manual that workers have never seen does not meet this requirement.

Linking Scope to the Rest of the OHSMS

One of the most important things an auditor can do during a Clause 4.3 audit is to test the downstream consistency of the scope. The scope is not just a declaration. It is a commitment that everything within those boundaries will be managed under the OHSMS. That means the hazard identification process, the risk assessment, the operational controls, the competence requirements, the emergency preparedness arrangements, and the internal audit programme should all reflect the same boundaries.

If the scope says the system covers three sites but the internal audit programme only covers one, something is wrong. If the scope includes maintenance activities but the hazard register only covers production, something is wrong. These inconsistencies are best found by tracing the scope forward through the system rather than treating it as a standalone clause.

For a broader look at how ISO 45001 audits are structured, Auditing Occupational Health and Safety Under ISO 45001 provides useful context on how the clauses connect.

Practical Audit Questions for Clause 4.3

Here are specific questions you can use when auditing scope under ISO 45001. These are designed to go beyond document review and surface real information.

  • Can you walk me through the physical boundaries of your OHSMS scope?
  • How was the scope determined, and who was involved in that decision?
  • When was the scope last reviewed, and what prompted that review?
  • Are there any work activities, locations, or worker groups that are deliberately excluded from the scope? If so, why?
  • How does the scope connect to the issues and interested parties you identified in Clauses 4.1 and 4.2?
  • How do contractors and labour hire workers fit within the scope?
  • Where is the scope documented, and how can workers access it?
  • Has anything changed in the organisation since the scope was last reviewed?
  • Can you show me a hazard that was identified for an activity at the edge of your scope boundary?

These questions are designed to be open ended and to invite explanation rather than yes or no answers. The goal is to understand how the organisation thinks about its scope, not just what it has written down.

Writing Findings for Clause 4.3 Nonconformities

When you identify a scope gap, write your finding with precision. A vague finding like the scope does not fully reflect the organisation's activities is not useful. A well written finding specifies what was observed, what was expected under the standard, and why the gap matters.

For example: The documented scope states that the OHSMS applies to all employees at the Brisbane warehouse. During the site walkthrough, it was observed that a team of four labour hire workers from [supplier name] are engaged in forklift operations in the despatch area on a daily basis. These workers were not included in the hazard identification records, had not received the site induction, and were not referenced in the OHSMS scope. This is inconsistent with Clause 4.3, which requires the scope to reflect the work related activities of the organisation, and with the definition of worker under ISO 45001, which includes persons performing work under the control of the organisation.

That level of specificity gives the organisation something concrete to act on and makes the finding defensible if challenged.

For guidance on writing findings that hold up, see How to Write Nonconformities That Hold Up.

Tips for Internal Auditors Auditing Their Own Organisation

Internal auditors face a particular challenge with scope verification because they are often already familiar with the organisation's boundaries. That familiarity can create blind spots. You might not question whether the scope covers the maintenance workshop because you have always known it is there, even if it is not mentioned in the scope statement.

A useful technique is to approach the scope audit as if you are seeing the organisation for the first time. Look at the scope statement cold and ask whether it accurately describes what you know to be true about the organisation. Then deliberately look for things that are missing rather than confirming what is present.

It also helps to involve workers from different parts of the organisation in the scope review process. Ask people who work in areas at the edges of the scope whether they feel the OHSMS applies to their work. Their answers can surface gaps that an auditor sitting in a meeting room would never find.

If you are building your internal audit skills and want to go deeper on ISO 45001 auditing techniques, the ISO 45001 Internal Audit Checklist is a practical starting point for structuring your audit coverage across all clauses.

A Note for Lead Auditors and Certification Auditors

If you are conducting a Stage 1 certification audit, Clause 4.3 scope verification is one of your primary objectives. The Stage 1 audit exists partly to confirm that the scope is appropriate before the Stage 2 audit proceeds. If you find at Stage 1 that the scope is materially incomplete, that is a significant finding that should be resolved before Stage 2 begins.

At surveillance and recertification audits, scope should be revisited to check for changes. Ask directly whether there have been any changes to the organisation's locations, activities, workforce, or structure since the last audit. If there have been, check whether the scope has been reviewed and updated accordingly.

Lead auditors managing a team should ensure that scope verification is not delegated to the most junior team member as a warm up task. It is a substantive audit activity that requires judgement and cross referencing across multiple clauses.

Frequently Asked Questions

No. ISO 45001 does not include an exclusions mechanism equivalent to what exists in ISO 9001. While an organisation can define the boundaries of its OHSMS, those boundaries must reflect the work related activities of the organisation. Deliberately excluding high risk activities to simplify certification is not consistent with the intent of the standard and would typically result in a major nonconformity during a certification audit.
Start Learning

Ready to Build Real Audit Skills?

Join practitioners training with ISO auditors who've conducted 500+ external certification audits.

ISO 9001:2015 Lead Auditor Training Course
  • Lead Auditor
  • Self-Paced Online
  • Exemplar Global
  • USD 199USD 789
ISO 45001:2018 Lead Auditor Training Course
  • Lead Auditor
  • Self-Paced Online
  • Exemplar Global
  • USD 199USD 789
ISO 14001:2026 Lead Auditor Training Course
  • Lead Auditor
  • Self-Paced Online
  • Exemplar Global
  • USD 199USD 789
Exemplar Global Recognised Training Provider digital badge

Audit Workshop is an Exemplar Global Recognised Training Provider

Globally Recognised, Certified Training

Pass an Exemplar Global Certified course and you earn a Certificate of Attainment and an Exemplar Global digital badge. Audit Workshop graduates can apply for third-party Personnel Certification through Exemplar Global.

  • 12 months of Graduate certification
  • Access to Exemplar Global Community
  • Access to self-coaching assessment
  • Access to webinars, events, and online resources
Learn Anytime

No fixed schedule. Start, pause, and pick up exactly where you left off.

Instant Certificate

Download your digital certificate the moment you complete the course.

Practical Content

Every lesson is built from real-world ISO auditing experience.

Lifetime Access

Course materials are yours to keep and revisit long after you complete.