Document {{ORG_PREFIX}}-001
IMS Scope Statement¶
1. Purpose¶
This document defines the scope of the {{ORG_NAME}} Integrated Management System (IMS): a single management system that meets the requirements of ISO 9001:2015 (quality) and ISO 45001:2018 (covering occupational health and safety) together, rather than as two parallel systems. It states the boundaries of the system, names the processes the system runs on and how they interact, records how resources for the system are determined and provided, assigns the responsibilities and authorities of the IMS roles, and justifies any requirement determined not applicable.
This document is the single controlled statement of the IMS scope, and
every other IMS document operates inside the boundary it draws.
{{ROLE_QUALITY_MANAGER}} maintains it through the document lifecycle in
document-record-control-procedure, on the review cadence in section 4.
2. Scope¶
In scope of this document: the boundary and applicability of the IMS, the core system processes and their interactions, IMS resourcing, IMS roles, responsibilities and authorities, and exclusions.
Out of scope: the policy commitments themselves (see
quality-ohs-policy), the analysis of context, interested parties and
compliance obligations that this scope draws on (see
context-interested-parties-compliance-obligations), and the working-level
methods of each process (see the individual procedures and plans).
Any ISO 9001 requirement determined not applicable is justified in section 3.4 of this document — never silently dropped from the clause maps.
3. Content¶
3.1 Scope of the IMS¶
The IMS covers {{ORG_NAME}} (legal entity {{ORG_LEGAL_NAME}}) as a whole. There are no organisational units outside the system.
Sites and locations. [ORG-DECISION: list every location where work under {{ORG_NAME}} control is performed — fixed premises with addresses withheld to the People/site register as appropriate, plus whether client sites, field work, vehicles and home-based work are included. {{ORG_NAME}} keeps every location where its work happens inside the boundary, so the list leaves none out.]
Activities, products and services covered. [ORG-DECISION: list the product and service types {{ORG_NAME}} provides, in the organisation's own commercial language. Keep the list aligned with the Product & Market Offers register; auditors and certification bodies read it as the definitive statement of what the system covers.]
How the scope was determined. Three inputs fix where the boundary above sits:
- the product and service list in this section, together with all the work that delivering it entails, which sets how far the OH&S dimension reaches;
- the interested parties identified in
context-interested-parties-compliance-obligationsand the requirements they place on {{ORG_NAME}}, including those adopted as compliance obligations; - the issues the same document's context review records, arising inside the organisation and outside it alike.
The scope is re-examined whenever any of those inputs materially changes, per the review trigger in section 4.
Applicability. {{ORG_NAME}} holds itself to the whole of both standards inside this boundary. Anything {{ORG_NAME}} sets aside is recorded and justified in section 3.4, and where section 3.4 carries no entry, the requirement applies in full. {{ORG_NAME}} keeps its safety obligations whole and records nothing against them.
OH&S coverage. The OH&S side of the scope follows the work wherever {{ORG_NAME}} performs or directs it: its own premises, client and third-party locations, vehicles, and remote or mobile settings. It covers the people the work brings into contact with the organisation, contractors and visitors included, and it covers the products and services the work delivers. Where {{ORG_NAME}} specifies the method a subcontractor works to, or sets the sequence others work in, that work is covered as well.
Availability. This document is controlled under
document-record-control-procedure, indexed in the Document Register
(Airtable), and available to all workers through the published IMS site. It
is provided to external interested parties on request. [ORG-DECISION:
whether the scope statement is additionally published externally, e.g. on
{{ORG_DOMAIN}}, for tender and certification purposes.]
3.2 System processes¶
{{ORG_NAME}}'s IMS is sixteen processes that feed each other: this document set gives them their shape, daily work runs them, and six of them (processes 11 to 16) exist to keep the whole system current and continually improving. The table below is the process map: each row hands one process to the role that answers for it, names the Airtable registers it reads and writes, and states what it consumes, what it produces, and how {{ORG_NAME}} judges it. Working-level detail lives in the procedure or plan that governs each process.
| # | Process | What it consumes | What it produces | How it is judged | Who answers for it | Registers it reads and writes |
|---|---|---|---|---|---|---|
| 1 | Context, risk and objective planning | Context issues; interested-party requirements; compliance obligations; performance data | Risk and opportunity actions; hazard controls; IMS objectives and plans | Registers current; actions closed by due date; objectives set and tracked | {{ROLE_TOP_MANAGEMENT}} | Risk & Opportunity Register; Hazard Register; Objectives & Targets |
| 2 | Compliance obligations management | Legal and other requirements; regulator and client communications | Decomposed obligations; evaluation results | Obligations current; evaluations run to schedule | {{ROLE_OHS_COORDINATOR}} | Instruments & Commitments; Compliance Obligations |
| 3 | Customer requirements and contract review | Enquiries, orders, tenders; statutory requirements | Reviewed, accepted commitments; resolved requirement changes | Every commitment reviewed before acceptance | {{ROLE_TOP_MANAGEMENT}} | Product & Market Offers; Customer Feedback & Complaints |
| 4 | Service delivery and operational control | Accepted commitments; delivery plans; competent people and equipment | Conforming products/services; release and delivery records | Acceptance criteria met before release; per-job evidence complete | {{ROLE_QUALITY_MANAGER}} | Equipment & Calibration Register (where applicable) |
| 5 | Design and development (applies only where the design_and_development capability is in scope; excluded and justified in section 3.4 otherwise) |
Design briefs; input requirements | Verified, validated design outputs | Reviews, verification and validation completed per plan | {{ROLE_QUALITY_MANAGER}} | Design & Development Procedure, where in scope |
| 6 | Procurement and contractor management | Purchasing needs; contractor scopes; OH&S criteria | Approved providers; controlled outsourced processes | Providers evaluated before use and re-evaluated on cadence | {{ROLE_QUALITY_MANAGER}} | Supplier & Contractor Register |
| 7 | Hazard identification and OH&S risk control | Worker reports; inspections; incident learnings; change proposals | Assessed hazards; controls per hierarchy | Hazards assessed and controls assigned; register current | {{ROLE_OHS_COORDINATOR}} | Hazard Register; Risk & Opportunity Register |
| 8 | Competence, training and awareness | Role competence needs; gaps from reviews and incidents | Competent, aware workers; training evidence | Curriculum coverage; training completed by due date | {{ROLE_QUALITY_MANAGER}} | Training Curriculum; Training Log; People |
| 9 | Communication, consultation and participation | Communication needs; worker input; external enquiries | Delivered communications; consultation outcomes | Matrix executed; consultation logged before affected decisions | {{ROLE_OHS_COORDINATOR}} | People; Policy Acknowledgements |
| 10 | Document and record control | Draft documents; approved changes; records of activities | Controlled documents; append-only records; current register | No drift between docs and register; lifecycle followed | {{ROLE_DOCUMENT_CONTROLLER}} | Document Register |
| 11 | Monitoring, measurement, analysis and evaluation | Monitoring plan; job data; customer perception data | Analysed performance results; calibration status | Monitoring executed to plan; equipment fit for purpose | {{ROLE_QUALITY_MANAGER}} | Equipment & Calibration Register; Customer Feedback & Complaints |
| 12 | Internal audit | Audit programme; prior results; process importance | Audit findings and reports | Programme delivered; findings reported and actioned | {{ROLE_QUALITY_MANAGER}} | Internal Audit Log; Schedule |
| 13 | Management review | Register digests; audit and monitoring outputs; consultation outcomes | Decisions on improvement, change and resources | Reviews held to schedule; actions tracked to closure | {{ROLE_TOP_MANAGEMENT}} | Management Review Log; Schedule |
| 14 | Incident reporting, investigation and emergency response | Incident and hazard reports; drill results | Investigations; corrective-action triggers; tested response capability | Incidents investigated; drills run and evaluated | {{ROLE_OHS_COORDINATOR}} | Incident Register; Schedule |
| 15 | Nonconformity, corrective action and improvement | Nonconforming outputs; audit findings; investigation outcomes | Corrections; verified corrective actions; improvement items | Actions proportionate, effective, closed on time | {{ROLE_QUALITY_MANAGER}} | Nonconformity & CAPA Register |
| 16 | Management of change | Change proposals; unintended changes | Assessed, controlled changes; updated documents and risks | Changes assessed before implementation | {{ROLE_TOP_MANAGEMENT}} | Risk & Opportunity Register |
How the processes connect. The processes run as one plan-do-check-act
loop. Processes 1 and 2 plan the system from context, obligations and risk;
processes 3 to 9 deliver work and build the capability to deliver it
safely; process 10 controls the documents and records every other process
relies on; processes 11 to 13 check performance; processes 14 to 16 respond
to what checking and operations reveal and feed changes and improvements
back into planning. Each process's outputs are the named inputs of its
downstream processes, and each is governed in detail by the procedure or
plan named in its slug-matched document (for example process 16 by
management-of-change-procedure).
When a process drifts. Processes 11 to 13 (monitoring, internal audit
and management review) check the full set of sixteen against the criteria
set for each in the process map. Where checking finds a shortfall, process
16 carries the change that fixes it, and improvements enter the pipeline in
ims-objectives-improvement-plan. Risks and opportunities affecting each
process are dealt with before they become shortfalls:
risk-opportunity-hazard-methodology sets how they are identified and
actioned, and the Risk & Opportunity Register tracks them to closure.
Documented information supporting the processes. The system's documented
information lives in three tiers. Controlled documents, the docs/ tree
indexed in the Document Register, tell each process how to run; the set
stays deliberately lean, sized by what {{ORG_NAME}} genuinely needs rather
than by what a larger or more complicated business would carry, and
process 10 governs its lifecycle. Records are the point-in-time proof of
what each process actually did. They land append-only in the
docs/records/ subfolders (management reviews, internal audits, incidents,
training, acknowledgements, consultation, emergency drills, compliance
evaluations, nonconformities, procurement evaluations, and, where the flags
are on, calibration and design reviews) and in per-job operational files
for delivery evidence; a record is never edited after commit, and a
correction is a new record. The Airtable registers are the third tier: live
indexes of status and schedule that point to evidence and never stand in
for it.
Resources¶
{{ROLE_TOP_MANAGEMENT}} works out what the IMS needs and supplies it. The resourcing question takes in the time and budget the system's activities consume, the instruments and tools that monitoring and measurement depend on, a work environment fit for the work being done, people and the competence development that keeps them capable, and the infrastructure, equipment and ICT they work with. {{ROLE_TOP_MANAGEMENT}} funds the system's set-up, its day-to-day running, the upkeep that keeps it current and the work that improves it through the same budget cycle, and tests at every management review whether what the system has is enough.
Resource needs are surfaced through defined channels rather than ad hoc:
- Objective planning — every objective plan in
ims-objectives-improvement-planstates the resources it requires before it is adopted. - Management review — resource adequacy is a standing input, and resource decisions are a required output, of every review; decisions are recorded in the Management Review Log.
- Corrective actions, incident investigations and change assessments — where these identify a resource shortfall, the resulting action carries the resource need to {{ROLE_TOP_MANAGEMENT}}.
- Worker consultation — resourcing barriers raised through consultation channels are treated as inputs to the same decisions.
Every resourcing decision {{ROLE_TOP_MANAGEMENT}} makes, whether for an
objective plan, a change or a day-to-day shortfall, is a buy-or-build call.
Before {{ORG_NAME}} buys capability in, {{ROLE_TOP_MANAGEMENT}} tests the
build side: whether the people and equipment already in house can carry
the work, limits included. Whatever fails that test is bought in, and
everything bought in is controlled under
procurement-contractor-management-procedure.
3.3 Roles, responsibilities and authorities¶
{{ROLE_TOP_MANAGEMENT}} decides what every IMS role carries: the duties it
performs, the calls it is empowered to make, and the outcomes it answers
for. The table below is the controlled record of those assignments. Who
currently holds each role is indexed in the People register (Airtable),
never in this document; no names or contact details appear in controlled
documents. Everyone in the organisation can see who carries what: the
assignments appear in this document and on the published IMS site and are
walked through at induction, and competence-training-awareness-procedure
builds and checks understanding of them.
| Role | Core responsibilities | Key authorities |
|---|---|---|
| {{ROLE_TOP_MANAGEMENT}} | Answers for whether the IMS delivers and for keeping work from injuring people or making them ill; owns processes 1, 3 and 16 in the map above and chairs management review (process 13); sets the policy commitments in quality-ohs-policy and the objectives in ims-objectives-improvement-plan; funds and staffs the system per the Resources section above; keeps IMS work embedded in the organisation's everyday business routines |
Final approval of controlled documents (approval = PR merge); resource allocation; acceptance of change assessments |
| {{ROLE_QUALITY_MANAGER}} | Coordinates the audit programme (process 12) and the monitoring plan (process 11); keeps {{ROLE_TOP_MANAGEMENT}} across QMS performance and the improvement opportunities it reveals; holds customer experience in view across every process, from contract review through delivery to complaint handling; the system's conformity to ISO 9001:2015 rests with this role | Hold release of outputs that have not passed planned verification; raise nonconformities on any process |
| {{ROLE_OHS_COORDINATOR}} | Answers for the system conforming to ISO 45001:2018; coordinates hazard identification (process 7), compliance evaluation (process 2), and incident investigation and emergency preparedness and response (process 14); briefs {{ROLE_TOP_MANAGEMENT}} on OH&S performance | Suspend work presenting a serious and imminent OH&S risk pending assessment; initiate incident investigations |
| {{ROLE_DOCUMENT_CONTROLLER}} | Operates the document and record lifecycle; keeps the Document Register mirroring document frontmatter; runs the drift and generation checks | Reject or return documents that do not meet control requirements before they enter review |
| {{ROLE_WORKER_REP}} | Channels worker consultation and participation per communication-consultation-participation-procedure; raises worker OH&S concerns and follows them to resolution |
Access to the OH&S information relevant to consultation; direct escalation to {{ROLE_TOP_MANAGEMENT}} |
| All workers | Take care of the parts of workplace health and safety that their own work and choices control; work to the procedures that apply to them; report hazards, incidents and nonconformities promptly; participate in consultation and training | Report through any channel without reprisal. [ORG-DECISION: whether all workers hold explicit authority to stop their own work when they judge it unsafe, recommended for adoption at instantiation] |
Two standing assignments sit alongside the table. {{ROLE_QUALITY_MANAGER}}
brings the system's quality performance to {{ROLE_TOP_MANAGEMENT}}, at
minimum whenever management review convenes, and keeps the system holding
to ISO 9001:2015, carrying the authority that job needs;
{{ROLE_OHS_COORDINATOR}} holds the same brief, and the same reporting
floor, for ISO 45001:2018 and OH&S performance. Changes are run so the
system keeps working while they happen: management-of-change-procedure
(process 16) assesses every change before implementation, and
{{ROLE_TOP_MANAGEMENT}} is accountable for the outcome.
In a small organisation one person may legitimately hold several of these roles. [ORG-DECISION: the role-to-person mapping is maintained in the People register at instantiation.] The invariant constraints are that on any controlled document the owner is never the approver and the reviewer is never the approver — this separation is enforced mechanically by the document checks and cannot be waived by role-sharing.
3.4 Exclusions¶
This section is the only place {{ORG_NAME}} records work it does not do, and the ISO 9001:2015 requirements determined not applicable because there is no such work for them to attach to; coverage is never trimmed anywhere else. {{ROLE_QUALITY_MANAGER}} proposes an entry with its reasoning, {{ROLE_TOP_MANAGEMENT}} approves it, the entry sits here naming the work and saying why {{ORG_NAME}} does not do it, and every scope review revisits it.
An entry narrows what {{ORG_NAME}} does. It never narrows what
{{ORG_NAME}} answers for. Customers judge {{ORG_NAME}} on the job they
receive and on whether they would come back, and neither judgement stops
at a boundary the organisation drew for itself, so
{{ROLE_TOP_MANAGEMENT}} turns down any entry that would leave a job
{{ORG_NAME}} has taken on short of what the client agreed to. Where a job needs work sitting outside the boundary, {{ORG_NAME}}
buys it in under procurement-contractor-management-procedure, holds the
provider to the specification, and stands behind the delivered result as
its own.
{{ORG_NAME}} applies every ISO 45001:2018 requirement and sets none aside.
No ISO 9001:2015 requirement is determined to be not applicable: every requirement of both standards is applied within the scope described in section 3.1.
4. Ownership and Review¶
- Owner: {{ROLE_QUALITY_MANAGER}} — drafts and maintains this document.
- Reviewer: {{ROLE_OHS_COORDINATOR}} — reviews every change, with particular attention to the OH&S boundary and role assignments.
- Approver: {{ROLE_TOP_MANAGEMENT}} — final approval is the approver's merge of the pull request; the approver is never the owner or reviewer.
- Review cadence: annual, or immediately upon any material change to IMS scope, organisational structure, sites, services, legal/regulatory requirements, or after a significant incident or nonconformity. Next review: 2026-08-15.
The Draft → Under Review → Approved lifecycle runs through GitHub pull
requests as defined in the Document & Record Control Procedure
(document-record-control-procedure); this document's register entry in the
Document Register mirrors the frontmatter above.
5. Revision History¶
| Version | Date | Author | Description of Changes | Reviewed By | Review Date | Approved By | Approval Date |
|---|---|---|---|---|---|---|---|
| 0.1 | 2026-07-16 | {{ROLE_QUALITY_MANAGER}} | Initial draft | — | — | — | — |
6. Document Control
| Document | {{ORG_PREFIX}}-001 |
|---|---|
| Type | IMS Core Document |
| Version | 0.1 |
| Status | Draft |
| Owner | {{ROLE_QUALITY_MANAGER}} |
| Reviewer | {{ROLE_OHS_COORDINATOR}} |
| Approver | {{ROLE_TOP_MANAGEMENT}} |
| Next Review | 2026-08-15 |
| Classification | Internal |
Held in the document frontmatter, mirrored to the Document Register.