Deciding the Scope and Boundaries of Your AI Management System

Deciding the Scope and Boundaries of Your AI Management System

Scope definition is the foundation of any ISO 42001 implementation. The standard requires you to establish the boundaries of your AI management system, meaning you must decide which AI activities, business processes, departments and locations your system will cover. This decision affects everything downstream: which controls apply, what evidence you must collect, how auditors will assess conformity, and ultimately whether your system is credible during the certification audit.

Why Scope Matters

The scope statement becomes your contract with auditors and stakeholders. If you define scope too narrowly, you create audit risk by excluding AI activities that actually exist in your organisation. If you define it too broadly without adequate resources, you set yourself up for nonconformities because you cannot manage what you have declared. Many organisations that fail their Stage 2 audit did so because they excluded critical AI systems from scope or defined control requirements they could not meet.

Lesson concept diagram

Scope Decisions in Practice

A common approach is to start with business units. A financial services firm might say, “Our AI management system covers mortgage origination AI, fraud detection systems and customer service chatbots operated by our retail and risk divisions.” That is specific and manageable. A manufacturing company might scope to, “All AI systems used in quality control, predictive maintenance and supply chain forecasting across our three plants and our central data science team.”

Excluded activities are equally important. Many organisations explicitly exclude third-party SaaS systems where the vendor holds the responsibility for compliance. This is allowed under ISO 42001, provided you document your rationale and have appropriate supplier controls in place. If you use a cloud vendor’s machine learning service but cannot modify or assess the model directly, you should document whether that system is in or out of scope and why.

Clause 4 Context

ISO 42001 Clause 4 requires you to determine the context of your organisation and the needs and expectations of interested parties. This means you must identify who cares about your AI systems and why: regulatory authorities, customers, employees, business partners, auditors, and end-users. Once you understand these stakeholders and their expectations, you can define a scope that addresses the risks that matter most to them.

If you operate in regulated sectors like financial services or healthcare, scope will likely include systems that could affect customer safety or data privacy. If you are a software provider, scope might include AI systems embedded in your products. The scope you choose must connect logically to the stakeholder expectations you have identified.

Document Your Scope

Write a scope statement that is specific and testable. Avoid vague language like, “All AI systems across the company”. Instead write, “All AI systems owned by the data science team and the machine learning engineering team that make decisions affecting customer accounts, product recommendations or operational risk management.” Then list the systems by name or project identifier. This gives auditors a clear definition of what you intend to manage.

You may also need to clarify what “AI system” means for your purpose. ISO 42001 assumes you have already defined what constitutes an AI system in your organisation, but the standard does not dictate this. Some organisations include all machine learning models. Others include only systems that operate without human review. You decide, provided your definition is written down and applied consistently.

Scope Review Triggers

Plan to review and update your scope statement annually or whenever significant new AI systems are introduced. If you acquire a business unit with existing AI systems, you need to decide whether those systems fall within your existing scope or require scope expansion. If your company stops using a major AI system, update your scope accordingly. Auditors will check that your documented scope matches the actual AI activities you are running.

A realistic scope enables you to implement controls effectively. The goal is not to scope every possible AI system, but to scope the systems that matter most to your organisation’s risk profile and your stakeholders’ expectations. This is the foundation on which everything else builds.