Defining the OH&S Management System Scope for ISO 45001
ISO 45001 Clause 4.3
Define what is in and what is out - the boundaries of the OH&S management system.
ISO 45001 Clause 4.3 - Determining the Scope of the OH&S Management System
ISO 45001:2018 Clause 4.3 requires the organisation to determine the boundaries and applicability of the OH&S management system to establish its scope. The scope is one of the few outputs of the standard that must be available as documented information.
In determining the scope, the organisation considers the external and internal issues identified at Clause 4.1, the requirements of interested parties from Clause 4.2, and the planned or performed work-related activities. The OH&S management system must include activities, products and services within the organisation's control or influence that can impact OH&S performance.
The scope is usually a short statement - one or two sentences. Most certified organisations include a scope statement in their management system manual, on certificates and in commercial communications. A typical scope might read: The provision of construction and refurbishment services from our head office and four regional sites.
Why Scope Definition Matters
The scope sets the boundary for everything else in the system. Activities, locations and operations included in the scope are subject to the full set of OH&S management system controls. Anything outside is not. For an external auditor, the scope determines what they will and will not look at during a certification audit.
Excluding activities or locations from the scope is permitted, but ISO 45001 requires that activities under the organisation's control or influence that can impact OH&S performance are included. An organisation cannot exclude high-risk activities simply because they are awkward to manage. Auditors are alert to scope statements that appear to carve out problem areas.
Keep the scope short and clear. Two sentences is usually enough. The activities you do, the places you do them, and any obvious limits.
The most common mistake is making the scope too vague. If your scope just says management services it tells nobody what you actually do, and the auditor will have to work it out from other sources. Be specific.
The scope is something I look at right at the start of an audit. It tells me what is in and what is out. If a scope looks like it has been written to exclude awkward parts of the business I will probe further. The activities under your control or influence that affect health and safety performance need to be included, even if they are tricky to manage.
Document the scope in one place only. If it appears in two or three places that drift apart over time, an external auditor will pick up the inconsistency. The IMS Manual is the natural home for it.
Practical Compliance Guidance
The IMS1 Manual is the primary location for the scope statement. Section 1.3 Context, Company Profile and Scope of Operations holds the scope alongside the company profile and context information.
The following alphaZ documents support compliance with ISO 45001:2018 Clause 4.3.
| alphaZ document | How to use it |
|---|---|
| ISO 45001 Toolkit | The full set of documents needed to build an OH&S management system, including the IMS1 Manual where the scope is recorded. |
| ISO 9001/14001/45001 IMS Toolkit | The integrated management system version of the toolkit, suitable for organisations seeking joint or triple certification. |
Note - all the above files can be downloaded with an alphaZ subscription.
Frequently Asked Questions
UK Legislation
While Clause 4.3 itself does not map directly to specific legislation, the following UK legislation establishes the broad scope of OH&S obligations that organisations operating in the UK address through their management system.
