Scoping is the single biggest decision in an ISO 42001 programme: the right boundary keeps a programme focused on the systems that matter and holds up at certification. Here is the working checklist we use with clients.
Inventory every AI system
Bespoke ML and deep-learning models built in-house.
Third-party AI APIs (OpenAI, Anthropic, Azure OpenAI, Bedrock, Vertex).
AI features embedded in SaaS (Salesforce Einstein, HubSpot Breeze, ServiceNow Now Assist, Microsoft Copilot, Google Workspace Gemini).
Robotic process automation with ML components.
Predictive analytics and recommendation engines.
Classify each system
| Dimension | Options |
|---|---|
| Role | Provider, Developer, User, Customer |
| Use case | Decision support, automation, content generation, prediction, classification |
| Risk level | Minimal, limited, high, unacceptable |
| Data sensitivity | Public, internal, confidential, regulated (PII, PHI, financial) |
| Audience | Internal staff, customers, regulators, public |
Define the boundary
Organizational, which legal entities and business units are included?
Functional, which AI roles (provider, developer, user)?
Technical: which systems, lifecycle stages, and supporting infrastructure?
Identify interfaces and exclusions
Any AI system excluded from scope must have a documented justification and a clean interface definition (what data crosses the boundary, what controls apply at the boundary).
Run the applicability assessment
Walk every Annex A control of ISO 42001 and decide: applicable, applicable with modification, or not applicable. Justify exclusions in the Statement of Applicability (SoA).
Validate with stakeholders
Workshop the scope and SoA with: legal, privacy, security, business owners, and internal audit. Surface disagreements before the certification body does.
07
Common scoping mistakes
Excluding embedded SaaS AI on the basis that "we did not build it." Wrong, the User role still applies.
Picking only one pilot system for scope. Auditors expect the boundary to reflect actual organizational AI activity.
Excluding training data lifecycle. Data preparation is in scope.
Ignoring shadow AI. Address it through policy and controls, not through scope exclusion.
Need Expert Guidance?
Our team of specialists can help you navigate these challenges and build a tailored strategy for your organization.
Schedule a ConsultationAllo Technologies provides advisory and managed services across cybersecurity, cloud, and AI.
Frequently asked questions
Find answers to common questions about our services
Share this article
Stay up to date
Get notified when new compliance guides and cybersecurity articles are published.
Related Reading
More insights from the Allo Technologies practice
AI Governance ROI: Business Case for Executives
AI governance investments yield measurable returns through risk reduction, market access, and competitive advantage. Build your business case here.
Read moreAI Risk Assessment: Gulf-Specific Use Cases
AI risks vary by industry and region. Healthcare, finance, and smart cities in the Gulf face unique challenges requiring tailored assessment approaches.
Read moreBuilding Your AI Governance Team: Roles & Skills
Effective AI governance requires dedicated roles including AI Ethics Officer and governance committees. Here is how to structure your team for success.
Read moreTalk to an Expert
Get personalized guidance from our senior security and compliance practitioners