Why Clause 4.3 Matters More Than Most People Realise
When organisations first implement ISO 9001, they often treat Clause 4.3 as a formality. Write a scope statement, get it approved, move on. That approach almost always creates problems later, either during internal audits or, worse, during a certification audit when the auditor starts asking questions about what is actually included in the quality management system and what is not.
On this page
Clause 4.3 is not a box to tick. It is the foundation that determines which processes, locations, products, services, and functions your QMS actually governs. Get it wrong and you end up with a system that either over promises and under delivers, or one that quietly excludes things a customer or certification body would reasonably expect to be covered.
This article walks through what Clause 4.3 actually requires, how to approach the scoping decision practically, what exclusions are and are not permissible, and what auditors look for when they review your scope. If you are a quality manager, an ISO consultant, or someone preparing for a certification audit, this is worth reading carefully.
What Clause 4.3 Actually Says
The clause is relatively short. ISO 9001:2015 requires the organisation to determine the boundaries and applicability of the quality management system to establish its scope. In doing so, the organisation must consider the external and internal issues identified under Clause 4.1, the requirements of relevant interested parties identified under Clause 4.2, and the products and services of the organisation.
The scope must be maintained as documented information and must be available to relevant interested parties. Where a requirement of the standard cannot be applied, the organisation must be able to justify that, and the justification must not affect the ability to ensure conformity of products and services or enhance customer satisfaction.
That last sentence is important. Exclusions are not automatic. They require justification, and that justification has to hold up to scrutiny.
Exemplar Global Recognised Training ProviderRTP No. 310970The Three Inputs You Must Consider
Internal and External Issues from Clause 4.1
Your scope decision should be informed by what you identified when analysing the context of your organisation. If you identified that regulatory compliance in a particular jurisdiction is a significant external issue, and your organisation operates in that jurisdiction, it would be difficult to justify excluding the relevant operations from scope.
Similarly, if an internal issue is that your organisation is growing through acquisition and now operates multiple sites, the scope decision needs to address whether all sites are included, and if not, why not. Auditors will cross reference your Clause 4.1 context analysis against your scope statement. Inconsistencies between the two are a common source of nonconformities. You can read more about how auditors approach this in our article on how to audit organisational context under ISO 9001 Clause 4.1.
Interested Party Requirements from Clause 4.2
If a significant customer requires that all your manufacturing sites be covered by the QMS, that requirement shapes your scope. You cannot simply exclude a site because it is inconvenient if a relevant interested party has a legitimate expectation that it is included.
This is where scope decisions can become commercially sensitive. Some organisations want to limit scope to avoid scrutiny of certain operations. That is understandable, but if a major customer or a regulatory body expects those operations to be covered, the scope decision needs to reflect reality, not wishful thinking.
Products and Services
The scope must describe the products and services covered by the QMS. This is where many scope statements fall short. Vague descriptions like provision of services or manufacturing of products tell an auditor very little. A well written scope statement names the actual products or service categories, the relevant locations, and the applicable functions.
If your organisation provides both consulting services and software development, and only the consulting services are in scope, that needs to be stated explicitly. If your Sydney office is in scope but your Brisbane office is not, that distinction must be clear and justified.
Writing a Scope Statement That Actually Works
A good scope statement answers four questions clearly. What does the organisation do? Where does it do it? Which products or services are covered? And what, if anything, has been excluded and why?
Here is an example of a weak scope statement that would attract audit questions:
The quality management system covers the design, manufacture, and supply of products at our Australian operations.
Compare that to a stronger version:
The quality management system covers the design, manufacture, and supply of industrial filtration equipment at the organisation’s facility located in Dandenong, Victoria. The scope includes product design, procurement, production, testing, and customer delivery. Installation services conducted at customer sites are excluded from scope as these are subcontracted to third parties who maintain their own certified management systems.
The second version is specific, locates the operations, names the product category, lists the functions covered, and explains the exclusion with a rationale. That is what auditors want to see.
Permissible Exclusions Under ISO 9001
This is one of the most misunderstood areas of Clause 4.3. ISO 9001:2015 significantly tightened the exclusion rules compared to the 2008 version. Under the 2008 edition, organisations could routinely exclude Clause 7 requirements. The 2015 version does not have an equivalent blanket exclusion provision.
Under the current standard, an exclusion is only permissible when a requirement is genuinely not applicable to the organisation. The test is whether applying that requirement is necessary to ensure conformity of products and services, or to enhance customer satisfaction. If it is, you cannot exclude it.
Common Legitimate Exclusions
The most frequently excluded clause is 8.3, which covers design and development. If your organisation manufactures products to customer specifications and does not perform any design activity, this clause may genuinely not apply. A contract manufacturer who produces to drawings supplied by the customer is a common example.
However, if your organisation modifies those designs, selects materials, or makes any technical decisions that affect the final product, you are likely performing design and development activities, even if you do not call them that. Auditors will probe this. They will ask about engineering change requests, material substitutions, and product modifications. If those activities exist, the exclusion does not hold.
Clause 8.5.4, covering customer property, is sometimes excluded by organisations that never take custody of anything belonging to customers. That can be legitimate. But if your technicians work on customer equipment, or if customer supplied materials are used in production, the exclusion is not appropriate.
What You Cannot Exclude
You cannot exclude a clause simply because it is difficult to implement, because you have not yet set up the relevant processes, or because management does not want the scrutiny. Those are not valid justifications.
Auditors are trained to identify scope limitations that appear designed to hide weaknesses rather than reflect genuine inapplicability. If an exclusion looks suspicious, they will investigate further. A poorly justified exclusion can result in a nonconformity against Clause 4.3 itself.
Multi Site Scope Decisions
Organisations with multiple sites face additional complexity. The scope decision must address whether all sites are included, and if not, which ones are covered and why others are not.
There are legitimate reasons to limit scope to certain sites. A head office might be included while a small regional depot is not, particularly if the depot performs no quality affecting activities. But if the depot handles customer orders, stores finished goods, or interacts with customers, it is harder to justify its exclusion.
Certification bodies handle multi site certification differently. Some issue a single certificate covering all sites, while others issue separate certificates per site. Your scope statement needs to be consistent with whatever arrangement you have with your certification body. If you are preparing for certification and have multiple sites, this is worth discussing with your certification body early in the process.
The Relationship Between Scope and Clause 4.4
Clause 4.4 requires the organisation to establish, implement, maintain, and continually improve the QMS, including the processes needed and their interactions. The scope you define in Clause 4.3 determines which processes fall under Clause 4.4.
This means that if a process is within scope, it must be identified, managed, and subject to the requirements of the standard. You cannot include a function in your scope statement and then fail to address it in your process framework. Auditors will map your scope against your process documentation and will expect to find coverage of everything you have claimed is included.
Our article on auditing the process approach in ISO 9001 Clause 4.4 covers how auditors verify that the processes within scope are properly defined and managed.
How Auditors Evaluate Your Scope
At Stage 1
The Stage 1 audit, sometimes called the document review or readiness review, is where auditors first examine your scope in detail. They will read your scope statement, compare it against your Clause 4.1 context analysis and your Clause 4.2 interested party register, and assess whether the scope is realistic and complete.
Common Stage 1 findings related to scope include scope statements that do not match the organisation’s actual activities, exclusions that are not documented or justified, and inconsistencies between the scope and the documented process framework.
If the auditor identifies significant concerns about scope at Stage 1, they may require the organisation to address these before Stage 2 proceeds. This is not a failure, but it does delay the certification timeline and can create pressure on everyone involved.
At Stage 2 and Surveillance Audits
At Stage 2, auditors verify that the QMS actually operates within the boundaries stated in the scope. They will visit locations named in the scope, interview people in functions described in the scope, and sample evidence from processes that should be covered.
If they find activities that appear to be within scope but are not managed under the QMS, that is a problem. Equally, if they find that the scope statement describes activities that do not actually occur, they will question the accuracy of the scope.
At surveillance audits, auditors will check whether the scope has changed and whether any changes have been documented and justified. Organisations that grow, acquire new businesses, or change their product and service mix need to update their scope accordingly. Failing to do so is a common source of surveillance audit nonconformities.
Scope Changes and How to Manage Them
Scope is not static. Organisations change. Products are added or discontinued. New sites open. Functions are outsourced or brought in house. Each of these changes potentially affects the scope of the QMS.
When a change occurs that affects scope, the organisation needs to assess whether the current scope statement remains accurate. If it does not, the scope must be updated. This update requires the same level of consideration as the original scope decision, meaning you need to revisit the Clause 4.1 and 4.2 inputs, assess whether any exclusions remain valid, and update the documented scope statement.
If the scope change is significant, you may need to notify your certification body. Adding a new site or a new product category to scope may require an extension audit. Removing something from scope may require documentation of why it is no longer applicable. Either way, the change needs to be managed deliberately, not left to drift.
Our article on how to audit QMS scope and exclusions in ISO 9001 provides additional guidance on how auditors approach scope verification in practice.
Common Mistakes to Avoid
The most frequent mistake is writing a scope statement in isolation, without reference to the Clause 4.1 and 4.2 analysis. The scope should be a logical output of those inputs, not a separate exercise.
Another common mistake is using generic language that could apply to almost any organisation. A scope statement that reads design and manufacture of products without naming the products, the location, or the relevant functions is not specific enough. It will attract questions from auditors and may indicate that the scoping exercise was not done with sufficient rigour.
Organisations also sometimes exclude clauses without documenting the justification. The justification must be part of the documented scope information. Verbal explanations offered during an audit are not a substitute for documented justification.
Finally, some organisations set a scope that is aspirational rather than reflective of current reality. If your scope describes activities you intend to implement but have not yet established, your QMS is not ready for certification. The scope must describe what is actually in place and operating.
Exemplar Global Recognised Training ProviderRTP No. 310970Practical Steps for Getting Clause 4.3 Right
- Start with your Clause 4.1 analysis. Review the internal and external issues you have identified and consider which of your operations are affected by those issues.
- Review your Clause 4.2 register. Identify any interested party requirements that have implications for what must be included in scope.
- List your products and services. Be specific. Name the product categories or service types, and identify the locations and functions involved in delivering them.
- Assess potential exclusions honestly. For each clause that might be excluded, ask whether the exclusion is genuinely justified or whether it is a convenience. If you are not sure, include it.
- Document the scope clearly. Write the scope statement in plain language. Name the locations, products, services, and functions. State any exclusions and explain why they apply.
- Review the scope whenever your organisation changes. Build scope review into your management review agenda so it is considered at least annually.
If you are building or reviewing your QMS and want to understand how the clause structure fits together, our article on ISO 9001 clauses explained in plain English provides a useful overview of how each clause connects to the others.
Building the Skills to Get This Right
Understanding Clause 4.3 at a conceptual level is one thing. Applying it in a real organisation, where business pressures, competing priorities, and incomplete information all come into play, is another. The ability to make sound scoping decisions, identify unjustified exclusions, and write scope statements that hold up to audit scrutiny comes from structured training and practical experience.
At Audit Workshop, our ISO 9001 internal auditor and lead auditor courses cover Clause 4.3 in the context of real audit scenarios. You will learn how to evaluate scope statements, identify weaknesses in exclusion justifications, and approach scoping decisions with the same rigour that certification body auditors apply. Whether you are implementing a QMS for the first time or preparing to audit one, that practical grounding makes a genuine difference.










