Verification Brief on ISO 45001:2018 Clause 4.3

Confirming the declared boundary matches the operation it describes

Mission 45001 is our deep dive into ISO 45001:2018, a network of clauses working together to help organisations run safe, resilient operations. Our mission is to show how that network works from the inside. This is our verification brief on 'The Cartographer' of the safety syndicate.

This verification brief examines ISO 45001:2018 Clause 4.3 and how auditors confirm that the declared boundary of the OH&S management system matches the operation it claims to describe.

Within the LDP framework, Clause 4.3 sits closest to the proving layer. A scope is a statement until documents, interviews, and site-level practice show the same boundary, which is why this clause carries an explicit documented information requirement that 4.1 and 4.2 do not.

Clause 4.3 Requirements

Determining the scope of the OH&S management system

  • Clause 4.3: The organization shall determine the boundaries and applicability of the OH&S management system to establish its scope
  • Consideration (a): Consider the external and internal issues referred to in 4.1
  • Consideration (b): Take into account the requirements referred to in 4.2
  • Consideration (c): Take into account the planned or performed work-related activities
  • Inclusion rule: The system shall include the activities, products and services within the organisation's control or influence that can impact its OH&S performance
  • Documentation: The scope shall be available as documented information. Unlike 4.1 and 4.2, this clause carries an explicit documentation requirement

What Verifying OH&S Scope Means

Confirming Definition and Application of OH&S Scope

  • Verification focus: Confirm that the organisation has clearly defined the scope of its OH&S management system, considering its activities, functions, physical boundaries, and interested parties
  • Scope boundaries: Ensure the scope accurately includes all relevant sites, activities, workers, and external parties where OH&S risks are controlled or influenced
  • Application of scope: Verify that the system's boundaries are consistently applied in policies, planning, operations, monitoring, and improvements
  • Audit boundary: Focus on whether the defined scope is documented, up-to-date, justified, and traceable across the OH&S management system

Why Verifying OH&S Scope Matters

Setting the Boundaries for Risk Control, Planning, and Compliance

  • Defines system applicability: A clear scope sets the boundary for what the OH&S system covers and where it applies
  • Ensures appropriate risk management: Activities, processes, and sites inside the scope must be actively controlled for OH&S risks
  • Prevents false assurance: An incomplete or outdated scope may leave critical risks unmanaged or misreported
  • Supports compliance and certification: Certification bodies and regulators assess whether the scope matches real operations and legal requirements
ISO 45001 Clause 4.3 scope of the OH&S management system: confirming boundaries, inclusions, and justified exclusions

Evidence Sources for OH&S Scope

Documents That Prove the Scope Is Defined, Applied, and Updated

  • Scope statements: OH&S manual, policy documents, or standalone scope definitions
  • Legal and operational registers: Evidence that all sites and activities under legal control are considered
  • Risk registers: Confirm risks are assessed only within scoped areas
  • Planning and objective-setting records: Verify that plans reflect scoped activities and locations
  • Management review minutes: Proof that scope is reviewed and updated as necessary

Verification Criteria for Scope Management

What Good Scope Management Looks Like

  • Scope is documented and current: Confirm that the scope clearly defines sites, activities, and responsibilities
  • Scope reflects real operations: Ensure all relevant activities where OH&S risks exist are included
  • Exclusions are justified: Any exclusions must be clearly stated and reasonably explained
  • Scope aligns with system documents: Policies, planning, and controls must match the defined scope
  • Scope is reviewed periodically: Check that scope is revalidated after major organisational or operational changes

Risk & Compliance Impact of Poor Scope Definition

How Poor Scope Management Creates Hidden Risks and Legal Gaps

  • Hidden risks outside the system: Incomplete scope may leave unmanaged hazards in operations
  • Compliance failure: Gaps between actual operations and declared scope may breach legal and certification standards
  • Audit nonconformities: Poor scope management leads to findings during external or internal audits
  • Reputational damage: Certification claims may be challenged if the scope is inaccurate or misleading
  • System inefficiency: Resources may be misallocated when the scope is unclear or outdated

System Linkages for Scope Definition

Where Scope Definition Must Influence the Wider OH&S System

  • Clause 4.1: Context understanding defines the boundaries influencing the scope
  • Clause 4.2: Stakeholder needs may affect inclusions or exclusions in scope determination
  • Clause 5.2: OH&S policy must be applicable to the defined scope
  • Clause 6.1: Risk and opportunity planning must address scoped activities and conditions
  • Clause 9.3: Management review must verify the continued suitability of the scope

Interview Prompts on OH&S Scope

Testing Leadership and Team Understanding of OH&S Scope

  • How was the OH&S system scope determined?: Ask who was involved and what factors were considered
  • What activities and sites are included in the scope?: Confirm understanding across leadership and operational teams
  • Have there been any changes to the scope recently?: Explore how organisational changes are reflected
  • How are exclusions justified?: Ask for examples where activities or locations were left out and why
  • How often is the scope reviewed?: Confirm regular validation during management review or after major changes

Compliance Check Questions on OH&S Scope

Core Auditor Queries to Verify Scope Definition

  • Has the organisation documented the boundaries and applicability of its OH&S management system?
  • Does the scope reflect all sites, activities, and workers under its control or influence?
  • Are exclusions clearly stated and reasonably justified?
  • Do policies, risk assessments, and controls apply consistently across the declared scope?
  • Is the scope revalidated after organisational, geographic, or operational change?

Red Flags in Scope Definition

Signs That Scope Definition Is Incomplete, Outdated, or Misleading

  • No formal statement: No scope document exists, or its boundaries are left unclear
  • Missing operations: Key sites or activities are absent from the declared scope
  • Mismatch with control: The scope diverges from actual activities, or from where legal control sits
  • Static after change: The scope is unchanged despite restructures, acquisitions, or closures
  • Boundaries ignored downstream: Policies, risk assessments, and controls take no account of the declared scope

Positive Indicators of Scope Definition

Proof That the Declared Boundary Matches the Operation

  • Exclusions justified: Any exclusion carries a recorded justification that withstands challenge
  • Documented as required: The scope is available as documented information in the form Clause 4.3 requires
  • Coverage lived at the edge: Workers at peripheral and recently acquired sites describe the same coverage the statement claims
  • Partial control explicit: Interfaces with parties controlling shared premises are defined
  • External claims match: Certification and commercial claims about coverage match the declared boundary

In Summary

Clause 4.3 only matters if it can be proven. Auditors don't check intentions, they check evidence. Scope must be visible through documents, interviews, and site-level practice.

Well-designed systems demonstrate scope through risk assessments, control plans, and audit trails. Verification confirms that scope statements are defensible; without demonstrable evidence, Clause 4.3 remains unverified assumption rather than verified fact.

Inside the Extended Edition

Ten Further Sections Available to Subscribers

  • Policy implications: What the Policy Must Cover Once the Boundary Is Fixed
  • Leadership implications: What the Boundary Commits Top Management To
  • Planning implications: How the Boundary Shapes What Gets Planned
  • Support implications: Where Resources Follow the Boundary
  • Operational control implications: How the Boundary Reaches Daily Work
  • Performance evaluation implications: What the Boundary Means for Measurement
  • Improvement implications: How the Boundary Directs Corrective Action
  • Cultural implications: What the Boundary Signals Inside and Outside
  • System integration implications: How the Boundary Holds Across Management Systems
  • Next steps: Where the Scope Trail Usually Runs

Subscribers gain access to the complete presentation, while higher-tier members can download the full .pptx version for use in their own training programmes.

Background Data on 'The Cartographer', Clause 4.3

Focus: Determining the Scope of the OH&S Management System

  • Codename: The Cartographer
  • Function: Defines the boundaries and applicability of the OH&S system within the organization's context
  • System Role: Clarifies what parts of the organization the OH&S system covers, and ensures alignment with organizational risks, operations, and obligations
  • Syndicate Caucus: Works with The Scout (4.1), The Connector (4.2), The Architect (4.4), and The Strategist (6.1)
  • Modus Operandi: Precision-oriented, boundary-setting, contextualizing system reach without over- or under-extension
  • Activation Threshold: Any organizational change in structure, geography, services, activities, or legal exposure
  • Known For: Preventing false assumptions, ensuring inclusion of critical areas, and clarifying system applicability
  • Field Signals: New site operations, acquisitions, outsourcing, or shifts in operational control
  • Boardroom Signals: Governance inquiries about compliance coverage, audit scope, or systemic exclusions
  • Audit Signals: Incomplete or overly broad scope statements, misalignment between scope and operational reality, unclear exclusions
  • PDCA Coordinates: Lives in Plan. Establishing system limits is foundational to meaningful planning, leadership clarity, and risk targeting

Frequently Asked Questions

What does ISO 45001 Clause 4.3 require?

The organization shall determine the boundaries and applicability of the OH&S management system to establish its scope, considering the external and internal issues from 4.1, the requirements from 4.2, and the planned or performed work-related activities. The scope shall be available as documented information.

Does Clause 4.3 require documented information?

Yes. Unlike Clauses 4.1 and 4.2, which carry no documentation requirement, Clause 4.3 states that the scope shall be available as documented information.

Can activities be excluded from the OH&S scope?

Exclusions are possible but must be clearly stated and reasonably explained. The system must include activities, products and services within the organisation's control or influence that can impact its OH&S performance.

How do auditors verify Clause 4.3?

By confirming the scope is documented and current, reflects real operations, justifies any exclusions, aligns with policies and controls, and is revalidated after major organisational or operational change.

What are the red flags in scope verification?

No formal scope document or unclear boundaries, key operations or sites missing, scope that does not match operational activities or legal control, scope unchanged despite organisational change, and policies or risk assessments that ignore scoped boundaries.

← Back to Insights