2.3 Determining the Scope of the BCMS

Key Takeaways

  • ISO 22301:2019 Clause 4.3 mandates establishing and documenting the BCMS scope, defining operational, geographical, organizational, and technological boundaries.
  • Scope determination must explicitly account for external/internal context (4.1), interested party requirements (4.2), and the mission-critical products and services of the organization.
  • Exclusions are strictly regulated: any exclusion that compromises the organization's ability to ensure the continuity of prioritized products and services or meet legal obligations violates ISO 22301 conformity.
  • The BCMS scope must be documented, maintained as documented information, and made available to interested parties where appropriate.
  • Clause 4.4 establishes the overarching mandate to establish, implement, maintain, and continually improve the BCMS, including the processes needed and their interactions, in accordance with ISO 22301 requirements.
Last updated: August 2026

2.3 Determining the Scope of the BCMS

Quick Answer: ISO 22301:2019 Clause 4.3 requires the organization to define the boundaries and applicability of the BCMS to establish its scope. The scope must consider external/internal context (Clause 4.1), interested party requirements (Clause 4.2), and the organization's mission-critical products and services. Any exclusions must be explicitly justified and must not undermine the delivery of prioritized activities. Clause 4.4 mandates establishing, implementing, maintaining, and continually improving the BCMS.

Defining the scope is one of the most critical responsibilities of a Lead Implementer. A scope that is too narrow creates blind spots that lead to catastrophic failures during real-world crises, while an overly broad scope squanders organizational resources on non-critical activities.


The Mandate of ISO 22301:2019 Clause 4.3

Clause 4.3 requires the organization to determine the boundaries and applicability of the BCMS. In doing so, the organization shall consider:

                 ┌──────────────────────────────────────────────┐
                 │       MANDATORY INPUTS TO BCMS SCOPE         │
                 └──────────────────────┬───────────────────────┘
                                        │
         ┌──────────────────────────────┼──────────────────────────────┐
         ▼                              ▼                              ▼
┌─────────────────┐            ┌─────────────────┐            ┌─────────────────┐
│ Clause 4.1      │            │ Clause 4.2      │            │ Core Mission &  │
│ External &      │            │ Needs & Reqs of │            │ Critical        │
│ Internal Issues │            │ Interested      │            │ Products and    │
│ & Context       │            │ Parties         │            │ Services        │
└────────┬────────┘            └────────┬────────┘            └────────┬────────┘
         │                              │                              │
         └──────────────────────────────┼──────────────────────────────┘
                                        │
                                        ▼
                 ┌──────────────────────────────────────────────┐
                 │         FOUR-DIMENSIONAL BCMS SCOPE          │
                 │  1. Organizational Boundaries (Legal entities)│
                 │  2. Physical Boundaries (Locations, plants)  │
                 │  3. Product & Service Boundaries             │
                 │  4. Technology & Supply Chain Dependencies   │
                 └──────────────────────┬───────────────────────┘
                                        │
                                        ▼
                 ┌──────────────────────────────────────────────┐
                 │        DOCUMENTED SCOPE STATEMENT            │
                 │  • Documented information (4.3)              │
                 │  • Available to interested parties           │
                 │  • Justified exclusions                      │
                 └──────────────────────────────────────────────┘

The Four Dimensional Boundaries of BCMS Scope

A rigorous BCMS scope cannot be articulated as a vague paragraph. It must define clear operational perimeter lines across four distinct dimensions:

┌────────────────────────────────────────────────────────────────────────┐
│                     THE FOUR SCOPING DIMENSIONS                        │
├─────────────────────────────┬──────────────────────────────────────────┤
│ 1. Organizational           │ • Legal entities, operating subsidiaries │
│    Boundaries               │ • Business units, departments, divisions │
├─────────────────────────────┼──────────────────────────────────────────┤
│ 2. Physical &               │ • Headquarters, branch offices, plants   │
│    Geographical Boundaries  │ • Primary/secondary data centers, depots │
├─────────────────────────────┼──────────────────────────────────────────┤
│ 3. Product & Service        │ • Revenue-generating commercial products │
│    Boundaries               │ • Critical customer & public services    │
├─────────────────────────────┼──────────────────────────────────────────┤
│ 4. Technology & Supply      │ • Core IT systems, networks, SaaS, cloud │
│    Chain Boundaries         │ • Tier-1 suppliers, 3PL logistics, CDNs  │
└─────────────────────────────┴──────────────────────────────────────────┘

1. Organizational Boundaries

  • Specifies exactly which corporate entities, legal subsidiaries, divisions, and business units fall within the management system.
  • Clarifies whether joint ventures, outsourced subsidiaries, or holding company entities are included or excluded.

2. Physical and Geographical Boundaries

  • Explicitly lists every physical facility, corporate campus, manufacturing plant, regional warehouse, research laboratory, and data center within the scope.
  • Defines geographic regions covered (e.g., All North American and European operations versus Global enterprise).
  • Explicitly incorporates remote, teleworking, and mobile workforces where operational tasks are distributed.

3. Product and Service Boundaries

  • Identifies the specific portfolio of products and services whose continuity is guaranteed by the BCMS.
  • Differentiates between prioritized products/services (e.g., emergency dispatch, real-time transaction processing) and non-critical peripheral offerings (e.g., internal employee merchandise store).

4. Technology, Infrastructure, and Supply Chain Boundaries

  • Identifies the critical digital platforms, applications, operational technology (OT/SCADA), network links, and cloud environments that underpin prioritized services.
  • Defines the interfaces and boundaries with third-party logistics (3PL) providers, SaaS vendors, and colocation data centers.
Scoping DimensionBoundary Definition QuestionsInclusion CriteriaAudit Evidence Required
OrganizationalWhich legal entities and business divisions are covered?All entities supporting prioritized servicesCorporate registry, org charts, governance charter
GeographicalWhich physical buildings, data centers, and regions are in-scope?All sites hosting critical staff, machinery, or dataFacility list, data center addresses, site blueprints
Product/ServiceWhich customer-facing deliverables must not fail?Products with severe downtime impact (financial, legal, life safety)Product catalog, revenue mapping, SLA inventory
TechnologyWhich IT systems, cloud tenants, and OT networks are included?Any technical asset upon which prioritized activities dependArchitecture diagrams, CMDB assets, data flow maps

Strict Rules and Justifications for Scope Exclusions

Organizations frequently seek to exclude certain departments, physical sites, or legacy systems to reduce implementation costs or audit complexity. However, ISO 22301:2019 imposes strict constraints on scope exclusions:

                    THE GOLDEN RULE OF ISO 22301 EXCLUSIONS
                                       │
                                       ▼
         ┌───────────────────────────────────────────────────────────┐
         │  Does excluding this entity, facility, or asset affect    │
         │  the organization's ability to ensure the continuity of   │
         │  its prioritized products and services or meet legal reqs?│
         └─────────────────────────────┬─────────────────────────────┘
                                       │
                      ┌────────────────┴────────────────┐
                      ▼                                 ▼
                   [ YES ]                           [ NO ]
                      │                                 │
                      ▼                                 ▼
         ┌───────────────────────────┐     ┌───────────────────────────┐
         │   EXCLUSION PROHIBITED!   │     │    EXCLUSION PERMISSIBLE  │
         │ (Major nonconformity if   │     │ (Must document rationale  │
         │  excluded from scope)     │     │  in formal Scope Doc)     │
         └───────────────────────────┘     └───────────────────────────┘

1. The "Negative Impact" Prohibition Rule

An organization cannot exclude any activity, process, function, or resource if that exclusion compromises the organization's ability and responsibility to deliver its prioritized products and services or satisfy statutory, regulatory, and contractual obligations.

Example of an Invalid Exclusion: An online bank attempts to exclude its internal IT Network Engineering department from the BCMS scope on the grounds that it is an "internal cost center." Because the customer-facing online banking service (in-scope) cannot operate without network connectivity, this exclusion is invalid and constitutes a major nonconformity during a certification audit.

2. Treatment of Outsourced and Third-Party Processes

An organization cannot exclude outsourced activities from its BCMS responsibility simply because they are performed by third parties. If an outsourced process (such as AWS cloud hosting or third-party logistics fulfillment) is essential for an in-scope product, the organization must include third-party supplier management and continuity oversight within its BCMS scope.

3. Valid Exclusions

Exclusions are legitimate only when the excluded activity or facility has zero operational, technological, or legal dependency on the in-scope deliverables. Example of a Valid Exclusion: A conglomerate operating both an aerospace defense manufacturing division and an independent retail clothing chain may legitimately certify the aerospace division under ISO 22301 while excluding the retail chain, provided they share no critical infrastructure, single-threaded staff, or interdependent supply chains.


Formulating and Documenting the Scope Statement

ISO 22301:2019 Clause 4.3 explicitly mandates that the scope shall be available as documented information. Furthermore, it states that the scope shall be made available to interested parties where appropriate.

┌────────────────────────────────────────────────────────────────────────────┐
│                ANATOMY OF AN ISO 22301 SCOPE STATEMENT                    │
├────────────────────────────────────────────────────────────────────────────┤
│ 1. Official Header & Organizational Entities Included                      │
│    "This Business Continuity Management System applies to Apex Corp LLC..."│
├────────────────────────────────────────────────────────────────────────────┤
│ 2. Physical & Geographic Scope                                             │
│    "Operating across Headquarters (London), Data Centers A & B (Frankfurt),│
│     and Customer Support Centers (Dublin & Manila)..."                     │
├────────────────────────────────────────────────────────────────────────────┤
│ 3. In-Scope Products & Services                                            │
│    "Covering the provision, operation, and maintenance of the Apex Cloud   │
│     Payments Gateway and Real-Time Settlement Engine..."                   │
├────────────────────────────────────────────────────────────────────────────┤
│ 4. Supporting Infrastructure & Critical Dependencies                       │
│    "Including core IT architecture, hybrid cloud environments, Tier-1 ISP  │
│     interfaces, and outsourced tier-1 database management operations..."   │
├────────────────────────────────────────────────────────────────────────────┤
│ 5. Explicit Exclusions & Documented Justifications                         │
│    "Excluding Apex Consumer Merchandise Ltd, which operates independently  │
│     with dedicated infrastructure and has no impact on payment services..."│
├────────────────────────────────────────────────────────────────────────────┤
│ 6. Governance, Approval & Availability                                     │
│    "Approved by the Board of Directors on 2026-08-31; available on public  │
│     trust portal for client and regulatory verification."                  │
└────────────────────────────────────────────────────────────────────────────┘

Making Scope Available to Interested Parties

The Lead Implementer must balance transparency with information security:

  • Public / Customer Scope Summary: Published on corporate trust portals or shared with enterprise clients and regulators, detailing covered products, certified sites, and high-level boundaries.
  • Internal Detailed Scope Document: Contains proprietary network architectures, exact IP address ranges, physical security blueprints, and specific vendor failover agreements.

Establishing and Maintaining the BCMS (Clause 4.4)

Clause 4.4 represents the overarching operational directive connecting all standard clauses:

The organization shall establish, implement, maintain and continually improve a business continuity management system, including the processes needed and their interactions, in accordance with the requirements of this document.

                     CLAUSE 4.4: THE CONTINUOUS BCMS LIFECYCLE
                                        │
         ┌──────────────────────────────┼──────────────────────────────┐
         ▼                              ▼                              ▼
┌─────────────────┐            ┌─────────────────┐            ┌─────────────────┐
│   ESTABLISH     │            │    IMPLEMENT    │            │    MAINTAIN     │
│ Define Context, │ ─────────► │ Deploy Plans,   │ ─────────► │ Test, Exercise, │
│ Scope, Policy & │            │ Capabilities &  │            │ Monitor & Audit │
│ Governance      │            │ Response Teams  │            │ Performance     │
└─────────────────┘            └─────────────────┘            └────────┬────────┘
                                                                       │
                                                                       ▼
                                                              ┌─────────────────┐
                                                              │CONTINUALLY IMPRO│
                                                              │ Execute CAPA,   │
                                                              │ Lessons Learned │
                                                              │ & Reviews (10)  │
                                                              └─────────────────┘

Clause 4.4 mandates that the BCMS is not a one-time project, binder on a shelf, or disjointed set of emergency procedures. It is an active, integrated management system with defined process inputs, transformations, outputs, and feedback loops across the entire Plan-Do-Check-Act (PDCA) cycle.


Worked Scenario: Global E-Commerce & Logistics Provider Determining Scope

Company Background: OmniStore International operates global e-commerce retail websites, physical automated distribution warehouses, and an in-house third-party cloud infrastructure platform (OmniCloud).

Step 1: Evaluating Scoping Inputs

  • Context (4.1): High cyber threat landscape; extreme peak revenue dependence during Q4 holiday shopping.
  • Interested Parties (4.2): 50M retail shoppers, 20,000 marketplace vendors, and financial payment processing clearinghouses requiring PCI-DSS compliance.
  • Critical Offerings: The Online Marketplace Checkout Engine and Automated Warehouse Robotic Dispatch.

Step 2: Formulating Boundary Dimensions

  • Organizational: OmniStore Retail Corp and OmniCloud Services Division are IN-SCOPE. OmniStore Entertainment (streaming media subsidiary) is EXCLUDED.
  • Physical: Corporate HQ (Seattle), 12 Primary Automated Fulfillment Hubs, and 3 Primary Cloud Data Centers (Virginia, Dublin, Frankfurt) are IN-SCOPE. 50 local temporary seasonal cross-docking depots are EXCLUDED.
  • Justification for Seasonal Depots Exclusion: If any temporary cross-docking depot fails, orders are automatically rerouted to adjacent permanent hubs within 2 hours without violating customer delivery SLAs.

Step 3: Audit Scrutiny

During the Stage 1 certification audit, the ISO 22301 Lead Auditor scrutinizes the exclusion of the 50 seasonal depots. The Lead Implementer presents documented traffic-routing simulation data proving that the permanent fulfillment hubs possess 150% surge capacity and that customer delivery SLAs remain intact during depot failures. The auditor accepts the exclusion as fully justified.


Lead Implementer Practical Implementation Checklist

┌────────────────────────────────────────────────────────────────────────────┐
│                   CLAUSE 4.3 & 4.4 IMPLEMENTATION CHECKLIST                │
├────────────────────────────────────────────────────────────────────────────┤
│ [ ] 1. Gather all primary scoping inputs: Context Profile (4.1),           │
│        Stakeholder Matrix (4.2), and Product/Service Catalog.              │
│ [ ] 2. Define the four scope dimensions: Organizational, Physical,         │
│        Product/Service, and Technology/Supply Chain boundaries.            │
│ [ ] 3. Identify and challenge all proposed scope exclusions using the      │
│        'Negative Impact Prohibition Rule'.                                 │
│ [ ] 4. Draft formal justification statements for every approved exclusion. │
│ [ ] 5. Author the formal 'BCMS Scope Statement' documented information.    │
│ [ ] 6. Obtain formal review, sign-off, and approval from Top Management.   │
│ [ ] 7. Publish an external-facing version for clients, auditors, and       │
│        regulators on corporate trust platforms.                            │
│ [ ] 8. Map process interactions to establish the ongoing lifecycle (4.4). │
└────────────────────────────────────────────────────────────────────────────┘

Common Exam Warning Traps

Exam Trap 1: Arbitrarily Excluding Shared Services as "Cost Centers" A classic implementation mistake is excluding internal supporting functions (e.g., Enterprise IT, Human Resources, Payroll, Corporate Legal, Facility Management) because they do not directly generate revenue. If an in-scope revenue-generating product depends on IT servers, facilities power, or payroll disbursement during a disaster, those supporting services must be included in scope.

Exam Trap 2: Excluding Outsourced Cloud or Supply Chain Functions Candidates often assume that because a function is outsourced to a tier-1 vendor (e.g., Microsoft Azure, AWS, FedEx), it is outside the BCMS scope. While the physical infrastructure of the vendor is managed by third parties, the management, contractual oversight, recovery targets, and fallback mechanisms for those outsourced services must remain inside the BCMS scope.

Exam Trap 3: Confusing BCMS Scope with Disaster Recovery (DR) Plan Scope Disaster Recovery (DR) scope typically covers specific IT systems, databases, and network failovers. BCMS Scope is significantly broader: it encompasses people, facilities, legal obligations, crisis communications, manual workarounds, supplier logistics, and operational governance across the whole business lifecycle.

Loading diagram...
BCMS 4-Dimensional Boundary Scoping Architecture & Exclusion Validation
Test Your Knowledge

An organization is preparing for an ISO 22301 certification audit and decides to exclude its primary IT data center from the BCMS scope because it is located in another country. The customer-facing online banking service is in-scope. How will an ISO 22301 Lead Auditor evaluate this exclusion?

A
B
C
D
Test Your Knowledge

Which of the following is an explicit requirement regarding the BCMS scope statement under ISO 22301:2019 Clause 4.3?

A
B
C
D
Test Your Knowledge

What is the primary mandate of ISO 22301:2019 Clause 4.4 within the management system structure?

A
B
C
D