ISO 42001 Clause 4.3: Determining the Scope of the AIMS
Clause 4.3 is the foundation of the entire ISO/IEC 42001:2023 AIMS. Scope too wide and you multiply work for no reason. Scope too narrow and you face Stage 2 findings. Here's how to get it right.
What Clause 4.3 requires
Clause 4.3 requires the organisation to determine the boundaries and applicability of the AI management system, taking into account:
- External and internal issues identified in Clause 4.1
- Requirements of interested parties identified in Clause 4.2
- The organisation's activities and their relationships with the activities of other organisations
The scope must be available as documented information, typically a Scope Statement. This is often the first document an auditor asks for.
Three dimensions of scope
1. Organisational scope
Which legal entities, business units, geographies, or functions are covered? A group-level AIMS with all subsidiaries is broader than a single-entity, single-division AIMS. Common patterns:
- Single entity, full organisation
- Single entity, specific division (e.g., "AI Research function", "AI-enabled product lines")
- Group-level with all controlled subsidiaries
- Multi-entity with specific subsidiary exclusions
2. AI system scope
Which AI systems are in scope? This is where most AIMS scope decisions happen. Options:
- All AI systems developed, provided, or used by the organisation
- Only production AI systems (excluding research experiments)
- Only customer-facing AI systems
- Only AI systems over a materiality threshold (e.g., "high-risk" per EU AI Act definition)
- Specific named AI systems or product lines
Narrow is usually better for first certification, expand at surveillance or re-certification.
3. Lifecycle scope
Which lifecycle phases does the AIMS govern?
- Development only (AI Provider scope)
- Deployment only (AI Deployer scope)
- Full lifecycle (development, deployment, operation, retirement)
- Integration only (AI System Integrator scope)
What belongs in a Scope Statement
- The organisation, legal name, address, registration number (if applicable)
- Organisational boundary, which entities and business units are covered
- AI system boundary, which AI systems are in scope, by name or by category
- AI system exclusions, which systems are out of scope, and why (this is critical, auditors check exclusions carefully)
- Lifecycle phases, which phases of the AI lifecycle are governed
- Geographic scope, where the AIMS operates
- Interfaces with other management systems, ISO 27001 ISMS, ISO 9001 QMS if present
- Reference to supporting documents, AI System Inventory, Risk Register, Statement of Applicability
- Approval and review, who signed, when, next review date
AIMS-02 in the Starter tier is a ready-to-customise Scope Statement covering all of these dimensions.
Common Clause 4.3 mistakes
- "All AI" as scope. Too broad. You'll be responsible for every Python script with a machine-learning library in it. Most orgs should narrow to production + customer-facing.
- No documented exclusion rationale. "Research AI is out of scope" is not enough. You need why, e.g., "Research AI is out of scope because it does not process production data, does not produce output that reaches end users, and is governed under the separate R&D Risk Policy (document R&D-POL-01)."
- Scope changes without document-control discipline. Scope must be versioned; changes are auditable.
- Scope inconsistent with AI System Inventory. AIMS-02 (Scope) and AIMS-18 (Inventory) must agree. If the Inventory lists a system the Scope excludes, that's an immediate finding.
- Scope inconsistent with EU AI Act or Colorado AI Act obligations. If you're a deployer of high-risk AI under the Colorado AI Act, your AIMS scope must include those systems, you can't exclude your way out of a regulatory obligation.
How auditors test Clause 4.3
- "Show me your Scope Statement. Who signed it? When?"
- "This AI system is in your Inventory. Is it in scope?" (cross-check)
- "This AI system isn't in your Inventory. Should it be?" (fishing for scope gaps)
- "What's excluded and why?" (pressure-testing exclusions)
- "If your organisation acquired a new AI system tomorrow, what triggers re-scoping?"
Practical recommendation
For first certification, scope narrowly to what you can operate well, document completely, and evidence cleanly. Typical first-cert scope is: one business unit, the 3–10 most material AI systems, full lifecycle. Grow the scope at surveillance and re-certification as the AIMS matures.