Defining the right scope is the single biggest determinant of ISO 31000 success. Too narrow and the certificate is meaningless; too broad and the programme stalls under its own weight.
ISO/IEC 27001 Certified
ISO/IEC 27701 Certified
ISO 9001 Certified
Delivered by an ISO/IEC 27001, 27701 & 9001 certified organisation
Who the standard applies to
Any organisation seeking an internationally recognised certification
Vendors required to provide assurance to enterprise customers
Regulated entities mapping local obligations to a global baseline
Groups consolidating multiple frameworks into one management system
Typical in-scope boundaries
Legal entities and business units in scope
Geographies and data residency boundaries
Cloud accounts, data centres and end-user computing estates
Third parties processing in-scope data on your behalf
Products, services or customer segments included
Scope dimensions
Icon grid titled "Scope dimensions" with 5 categories: Legal entities and business units in scope, Geographies and data residency boundaries, Cloud accounts, data centres and end-user computing estates, Third parties processing in-scope data on your behalf, Products, services or customer segments included.
01Legal entities and business units in scope
02Geographies and data residency boundaries
03Cloud accounts, data centres and end-user computing estates
04Third parties processing in-scope data on your behalf
05Products, services or customer segments included
Common scoping mistakes
Excluding shared services (HR, payroll, identity) that handle in-scope data.
Treating SaaS platforms as out-of-scope when they process production data.
Omitting DR, backup and recovery sites from the boundary.
Forgetting to include the security operations function itself.
Scoping pitfalls to avoid
Checklist titled "Scoping pitfalls to avoid" with 4 items, every item marked complete: Excluding shared services (HR, payroll, identity) that handle in-scope data.; Treating SaaS platforms as out-of-scope when they process production data.; Omitting DR, backup and recovery sites from the boundary.; Forgetting to include the security operations function itself..
✓Excluding shared services (HR, payroll, identity) that handle in-scope data.
✓Treating SaaS platforms as out-of-scope when they process production data.
✓Omitting DR, backup and recovery sites from the boundary.
✓Forgetting to include the security operations function itself.
How we run the scoping exercise
A two-week scoping sprint with your sponsor, IT, security, legal and audit produces a written scope statement, an asset and data-flow map, and a signed-off boundary diagram. This becomes the anchor for the entire ISO 31000 programme.