Scope is the part of an ISO certificate that decides what it is worth, and it is the part most people give the least thought to. It is also a word doing two jobs at once, which is where most of the confusion comes from.
Two things are called scope
The first is the scope of your management system, which is what clause 4.3 of ISO 9001 actually requires. It is a documented statement of the boundaries and applicability of the system: which activities, products and services it covers, and any requirements of the standard you are not applying, with the reasons.
The second is the certificate scope, the short statement printed on your certificate describing what your organisation does. It is what a customer reads when they ask for evidence of certification.
The two should align. They are not the same document. Your internal scope will carry detail about exclusions, justifications and boundaries that has no place on a certificate, and the certificate carries a concise plain-language description that would be too brief to satisfy clause 4.3 on its own.
What clause 4.3 asks you to decide
The standard asks you to determine the boundaries and applicability of the management system, taking three things into account: the internal and external issues you identified under clause 4.1, the requirements of interested parties under clause 4.2, and the products and services you provide. The result has to be documented and available.
That is a shorter list than it sounds. It amounts to deciding what the system is for, who it has to satisfy, and what you actually sell, then writing down where the system starts and stops.
The certificate scope is written for someone else
A certificate scope is a plain description of the business, along the lines of "provides commercial cleaning services to offices and retail premises". The wording is agreed with your certification body, and there is no single format prescribed by the standard. Some bodies prefer a fuller description, others keep it short.
Write it in the words your customers would use for what you do. A scope full of internal language is technically accurate and commercially useless, because the person reading it is trying to answer one question: does this cover the work I am placing with them?
Exclusions and the design clause
Where a requirement of the standard genuinely does not apply to what you do, you can state it as not applicable and exclude it, provided the exclusion is justified and does not affect your ability to deliver conforming products and services.
The clause most often excluded is 8.3, design and development. For an organisation that manufactures to a customer's specification, or delivers a defined service with no design input, the plain reading of the standard is that 8.3 does not apply.
This is handled inconsistently across the certification industry. Some bodies accept the exclusion where it is clearly justified. Others take the position that 8.3 can never be excluded, on the argument that any decision about how a product or service is configured amounts to design. The standard does not support that reading, but it is applied often enough to cause real problems.
Our own position is straightforward. Where the exclusion is obvious, we accept it. If there is no design activity in the scope of certification, then 8.3 is not applicable, and we will not construct an argument that it is. Whichever body you use, establish where they stand on this before you finalise an exclusion rather than after.
Where scope goes wrong at audit
The scope wording you submit for certification should match what is documented in your management system. A discrepancy between the two is a common finding, and an avoidable one, because it usually means the scope was written twice by different people rather than written once and used.
The other pattern we see is the scope written to impress. Claim an activity and the audit will look for the processes, the records and the people behind it. Where they are not there, the scope gets narrowed before a certificate is issued, which is a worse outcome than having described the business accurately in the first place. A scope can always be widened later, once the system genuinely covers more ground.
What it means for what you claim
Any statement you make about being certified has to match the certificate behind it, scope included. Saying the organisation is certified to ISO 9001 when the system covers one part of it is an overstatement that is easy to make by accident and awkward to explain to a customer who reads the certificate properly. The rules on displaying certification marks are in is there an official ISO logo.
More on clause 4.3
Our knowledge base on isomanaged.com covers the requirement in full, including exclusions, the design clause and where to document the scope.
Determining the scope of the QMS › on isomanaged.com