Why Scope Matters More Than Most People Think
When organisations implement ISO 45001, Clause 4.3 often gets treated as an administrative task. Someone writes a sentence or two describing the business, attaches it to the manual, and moves on. That is a mistake.
On this page
The scope of your occupational health and safety management system is not a formality. It defines what your system actually covers, which workers and activities are protected, which locations fall under the system, and which obligations apply. Get it wrong and you end up with a system that looks complete on paper but leaves real hazards outside its boundaries.
This article walks through what Clause 4.3 actually requires, how to determine scope in practice, the common errors organisations make, and what auditors check when they review your scope statement.
What Clause 4.3 Says
ISO 45001 Clause 4.3 requires the organisation to determine the boundaries and applicability of the OH&S management system in order to establish its scope. The clause is short, but what it points to is significant.
To determine the scope, the standard says you must consider:
- The external and internal issues referred to in Clause 4.1
- The requirements of relevant interested parties referred to in Clause 4.2
- The planned or performed work-related activities
Once determined, the scope must be available as documented information. It must also be available to interested parties.
That last point matters. The scope is not just an internal document. It is something workers, contractors, regulators, customers, and certification bodies may need to see. It needs to be clear, accurate, and honest about what the system covers.
Exemplar Global Recognised Training ProviderRTP No. 310970The Link Between Clause 4.1, 4.2, and 4.3
Clause 4.3 does not stand alone. It sits at the end of a sequence that begins with understanding context and interested parties. That sequence is deliberate.
Clause 4.1 asks you to identify the internal and external issues that are relevant to your organisation's purpose and that affect your ability to achieve the intended outcomes of the OH&S management system. These issues shape your scope because they define the environment in which your system operates.
For example, if your organisation operates across multiple states with different WHS legislation, that is an external issue. If you have a high turnover of labour hire workers, that is an internal issue. Both should influence how you define the boundaries of your system.
Clause 4.2 asks you to identify workers and other interested parties, and to understand their needs and expectations. Workers are explicitly listed as the primary interested party in ISO 45001, which is a deliberate shift from older frameworks. If certain groups of workers are excluded from your system, that exclusion needs to be justified, not assumed.
The scope you write in Clause 4.3 should reflect what you learned from Clauses 4.1 and 4.2. If those earlier clauses are shallow, your scope will be too.
What “Boundaries and Applicability” Actually Means
The standard uses the phrase “boundaries and applicability.” These are two different things and it is worth separating them.
Boundaries
Boundaries are the physical and organisational limits of the system. This includes:
- Which sites or locations are covered
- Which legal entities are included
- Which activities and operations fall within the system
A construction company might have a head office, multiple project sites, and a depot. The scope should make clear whether all of these are included or whether some are excluded and why.
Applicability
Applicability is about which activities and functions the system applies to. This is particularly relevant when an organisation has activities that are performed by workers under different arrangements, such as direct employees, contractors, subcontractors, and labour hire workers.
ISO 45001 uses the term “workers” broadly. It includes not only employees but also contractors and subcontractors who are under the organisation's control. The scope should reflect this. If you manage contractors on your site, those contractor activities are generally within the scope of your system even if the workers are not your employees.
How to Determine Your Scope in Practice
There is no template that works for every organisation. Scope determination requires judgement. Here is a practical approach that works in the field.
Step 1: Map Your Work-Related Activities
Start with a complete picture of what the organisation actually does. List every type of work performed, every location where work happens, and every category of worker involved. Include activities that are performed infrequently, such as maintenance shutdowns or seasonal operations. These are often the highest risk activities and they belong in scope.
Step 2: Review Your Context and Interested Party Analysis
Go back to what you documented under Clauses 4.1 and 4.2. Are there external issues, such as regulatory requirements or industry codes, that affect which activities need to be covered? Are there interested party requirements that define what the system must address?
For example, if a major client requires that your system cover all work performed on their premises, that is an interested party requirement that affects your scope.
Step 3: Identify Any Proposed Exclusions
ISO 45001 does not list permitted exclusions the way ISO 9001 does. However, organisations sometimes have genuine reasons to exclude certain activities or locations. If you are going to exclude something, you need to be able to justify it, and the exclusion must not result in leaving workers unprotected.
A common error is excluding activities because they seem low risk. Risk level is not a valid basis for excluding something from scope. If workers perform an activity, it is generally in scope.
Step 4: Write the Scope Statement
The scope statement should be clear and specific. It should describe:
- The nature of the organisation and its activities
- The locations covered
- The types of workers covered
- Any relevant exclusions with justification
Avoid vague statements like “all operations of the organisation.” That tells an auditor nothing about what the system actually covers. Be specific about locations, activities, and worker categories.
Common Mistakes When Defining Scope
After conducting hundreds of OH&S audits, certain scope errors come up repeatedly. Here are the ones worth watching for.
Copying the QMS Scope
Many organisations have an existing ISO 9001 quality management system and simply copy that scope statement into their OH&S documentation. The problem is that the QMS scope is written to address product and service delivery, not worker safety. The activities, locations, and worker categories relevant to OH&S may be quite different.
Excluding Contractors Without Justification
Some scope statements say the system applies to “employees only.” Under ISO 45001, this is almost always inadequate. If contractors work on your site or under your direction, they are workers under the standard and their safety is your concern. Excluding them from scope without a clear rationale is a finding waiting to happen.
Listing Locations That Are Not Actually Covered
The opposite problem also occurs. An organisation lists all of its locations in the scope but has not actually implemented the system at all of them. During an audit, it becomes apparent that one of the listed sites has no hazard identification process, no incident reporting, and no worker consultation. The scope says it is covered. The evidence says it is not.
Failing to Update the Scope After Organisational Changes
Organisations grow, acquire new sites, add new activities, or change their workforce arrangements. The scope needs to be reviewed when these changes occur. A scope that was accurate three years ago may now misrepresent what the system covers.
What Auditors Check Under Clause 4.3
When an auditor reviews your scope, they are not just reading the document. They are testing whether the scope accurately reflects the system that is actually operating. Here is what they look for.
Is the Scope Documented and Available?
This is the basic conformance check. The scope must exist as documented information and must be available to interested parties. If the scope is buried in a manual that no one can find, or if it exists only in the quality manager's head, that is a problem.
Does the Scope Reflect the Context and Interested Party Analysis?
An auditor will compare the scope to what was documented under Clauses 4.1 and 4.2. If the context analysis identified significant issues related to a particular site or activity, those should be reflected in the scope. If they are not, the auditor will ask why.
Are Excluded Activities Justified?
If the scope excludes any activities or locations, the auditor will probe the justification. The key question is whether the exclusion results in any workers being left without OH&S protection. If it does, the exclusion is not acceptable.
Does the System Actually Cover What the Scope Claims?
This is the most important check. The auditor will follow the scope into the system. If the scope says all three sites are covered, the auditor will look for evidence that hazard identification, risk assessment, incident reporting, and worker consultation are happening at all three sites. A scope that overstates coverage is a nonconformity.
Is the Scope Consistent With the Certificate?
For organisations seeking or maintaining certification, the scope statement must be consistent with the scope of certification. If the certificate says the system covers construction activities at metropolitan project sites, the scope document should say the same thing. Inconsistencies between the two create confusion and can affect the validity of the certificate.
Scope in Multi-Site and Multi-Entity Organisations
For larger organisations, scope determination becomes more complex. A company that operates across multiple states, or that has separate legal entities sharing common OH&S arrangements, needs to think carefully about what is included and how the system applies across those structures.
In multi-site situations, it is worth asking whether each site has the same activities and hazard profile. A head office with administrative staff has a very different risk profile from a manufacturing plant or a remote construction site. The scope should acknowledge this, and the system should be calibrated accordingly.
For integrated management systems that combine ISO 9001, ISO 14001, and ISO 45001, the scope of each standard does not have to be identical. The scope of the OH&S system should be determined based on OH&S considerations, not simply mirrored from the quality or environmental system. In practice, they often align, but the alignment should be deliberate rather than automatic.
If you want to understand how the scope clauses compare across these three standards, the article on ISO 9001 Clause 4.3 and the companion piece on defining your EMS scope under ISO 14001:2026 are worth reading alongside this one.
Scope and Worker Participation
One aspect of scope that is sometimes overlooked is the connection to worker participation. ISO 45001 places significant emphasis on consulting workers and involving them in the OH&S management system. If your scope excludes categories of workers, those workers are also excluded from participation.
This can create a situation where the workers who face the highest risks, such as contractors performing hazardous tasks, have no voice in the system that is supposed to protect them. That is inconsistent with the intent of the standard.
When defining scope, consider which worker groups will be brought into the consultation and participation processes. If certain groups are excluded from scope, be clear about who is responsible for their safety and how that responsibility is managed.
Practical Tips for Getting Scope Right
Here are a few practical points that come from real audit experience.
- Walk the site before writing the scope. You cannot write an accurate scope from a desk. Go to the locations, observe the activities, and talk to workers about what they actually do.
- Review the scope annually at minimum. Tie the scope review to your management review process so it is not overlooked.
- Cross-reference the scope with your hazard register. If your hazard register includes activities or locations that are not in scope, that is a red flag. Either the scope needs updating or the hazard register is wrong.
- Make the scope accessible. Post it on your intranet, include it in worker induction materials, and make sure contractors can access it. The standard says it must be available to interested parties.
- Be honest about what is not yet covered. If you are implementing the system in stages, say so. Do not claim coverage you have not yet established. A phased implementation is legitimate. Misrepresenting coverage is not.
Exemplar Global Recognised Training ProviderRTP No. 310970Auditing Clause 4.3 as an Internal Auditor
If you are conducting an internal audit of your own organisation's OH&S management system, Clause 4.3 is worth spending time on. It is a foundation clause. If the scope is wrong, everything built on it is potentially compromised.
Start by reviewing the documented scope. Then test it against reality. Visit the locations listed. Check whether the system is actually operating there. Review the hazard register and ask whether all activities in scope are represented. Talk to workers and ask whether they understand what the system covers.
For more on how auditors verify scope in practice, the article on audit tips for ISO 45001 Clause 4.3 goes deeper into the evidence-gathering side of this clause.
You might also find it useful to review the broader context of auditing occupational health and safety under ISO 45001, which covers how the standard's requirements connect across all clauses during an audit.
Building Your Competence in ISO 45001 Auditing
Understanding Clause 4.3 in isolation is useful. Understanding how it connects to the rest of the standard, and how to audit it effectively, requires a deeper level of competence.
Audit Workshop offers ISO 45001 internal auditor and lead auditor training that covers every clause of the standard in practical terms. The training is built around real audit scenarios, not just theory. Whether you are new to OH&S auditing or looking to formalise your skills, the courses provide the knowledge and confidence to conduct audits that are genuinely useful to your organisation.
If you are working toward auditor certification, the ISO 45001 training at Audit Workshop is recognised by Exemplar Global, which means the training counts toward your professional certification pathway.










