Skip to content

Scope & Applicability

Where to find it: Regulatory Compliance, then Scope & Applicability (/scope-applicability).

An Applicability Determination records whether a specific obligation applies within a specific declared scope, why, who decided, and who approved.

Its business reference is APP-YYYY-NNNN.


Two states, deliberately separate

Every applicability record carries two independent states. Confusing them is the source of most compliance reporting errors in this area.

Applicability state — what we concluded

StateMeaning
ApplicableThe obligation applies within this scope
Not ApplicableThe obligation does not apply, for a documented reason
Under ReviewThe determination has not been reached

Governance state — how far the conclusion has got

StateMeaning
draftRecorded but not submitted
pending_reviewSubmitted, awaiting an independent reviewer
approvedApproved by someone other than the person who made it
rejectedReturned by the reviewer

Only an approved decision is authoritative

A Not Applicable decision sitting in draft has no effect on your compliance position whatsoever. It does not shrink your denominator, it does not remove the obligation from assurance, and it does not appear as excluded in reporting.

This is the control that stops the fastest route to 100% compliance being "mark everything out of scope."


What each combination means downstream

ApplicabilityGovernanceEffect on assurance
ApplicableapprovedEvaluated normally through the full pipeline
Not ApplicableapprovedExcluded from the denominator; never marked satisfied or compliant; retained with justification
Anythingdraft, pending_review, rejectedTreated as an unresolved obligation; never silently excluded
Under ReviewanyUnresolved

The middle row is worth reading twice. An approved Not Applicable obligation is excluded from the denominator, but it is not counted as a success. It appears in the Statement of Applicability as an exclusion with its justification and approver visible, because an assessor is entitled to challenge your exclusions and needs to see them.


Mandatory justification

Marking an obligation Not Applicable requires a meaningful written justification. OrviQ rejects an empty or trivially short rationale.

Where a requirement is marked as statutorily mandatory, the justification is expected to cite the lawful waiver or exemption relied on — a business preference is not a basis for disapplying a statutory duty.

What a good justification looks like

QualityExample
Good"The institution does not store, process or transmit cardholder data. No card acquiring or issuing business line exists within this scope. Confirmed with the Head of Payments, March 2026."
Good"This clause applies to institutions operating their own data centres. All in-scope workloads run on contracted cloud infrastructure; the equivalent obligation is discharged through the provider assurance requirements at clause 8.4."
Poor"Not relevant"
Poor"Handled elsewhere"
Poor"N/A"

The test: will this sentence still answer an assessor's challenge in eighteen months, when the person who wrote it has left?


The approval flow

Approval uses the organisational workflow layer with a four-eye maker-checker default. Six-eye and eight-eye chains are available where your governance model requires an executive or committee stage.

Segregation of duties is enforced: the person who created or last edited an applicability decision cannot approve it.

See Multi-Eye Approvals.


How to determine applicability

For a single obligation

  1. Open the adoption in Scope & Applicability.
  2. Find the requirement.
  3. Set the applicability state.
  4. If Not Applicable, write the justification.
  5. Submit for review.
  6. An independent reviewer approves or rejects it.

In bulk

Where a whole section is clearly out of scope, decisions can be recorded across a batch of requirements. Each still becomes an individual APP-YYYY-NNNN record with its own justification and its own approval — bulk entry is a convenience for the maker, not a bypass of the checker.

Bulk entry still needs specific reasons

If a batch justification reads "section 9 does not apply", write why: "Section 9 governs proprietary trading activity. The entity holds no trading licence and operates no trading book." One sentence more, and the exclusion survives challenge.


AI assistance

OrviQ can draft an applicability rationale for you. The AI reads the requirement and the scope context and proposes wording.

AI doesAI does not
Draft rationale wordingSet the applicability state
Suggest a likely determinationApprove anything
Note relevant scope characteristicsMake the decision authoritative

The suggestion is a starting draft. You own what it says. See AI Applicability Rationale.


Effective applicability

Downstream engines ask a single question: what is the authoritative applicability of this obligation, in this scope, at this instant?

The answer resolves to one of:

  • Applicable — approved, evaluated normally
  • Not Applicable — approved, excluded from the denominator, never satisfied
  • Under Review — everything else, treated as unresolved

Historical queries resolve against the decisions approved as of the requested date, so a determination made in June does not retroactively change what your March position was.


Permissions

ActionPermission
View applicability recordscompliance.read
Record or edit a decisioncompliance.manage or obligations.update
Submit for reviewcompliance.manage or obligations.update
Approve or rejectcompliance.validate or workflow.approve
Export the Statement of Applicabilitycompliance.read or export.data

Example

The example below uses an ISO 27001-style structure for illustration. It shows how OrviQ handles applicability decisions; it is not a statement about any particular certification requirement.

A bank adopts an information security standard for its payments platform: FAD-2026-0004, 93 requirements.

Decisions the lead assessor records:

RequirementDecisionJustification
A.5.1 Policies for information securityApplicable
A.7.4 Physical security monitoringApplicable
A.8.1 User endpoint devicesApplicable
A.5.7 Threat intelligenceApplicable
Teleworking provisionsNot Applicable"The payments platform is operated exclusively from two secured facilities. No remote operational access is permitted to in-scope systems; remote administrative access is technically blocked at the network boundary and evidenced under A.8.20. Confirmed with the Head of Platform Operations."
Development environment separationNot Applicable"No development activity occurs within this scope. All change is delivered by the group engineering function under separate scope SCP-2026-0009, where this clause is Applicable."

What happens next:

The Compliance Manager reviews each decision. She approves the first four immediately. She rejects a third proposed exclusion — a clause the assessor proposed excluding on the grounds it was "covered by the cloud provider" — with the comment: "Provider responsibility does not remove our obligation. This is Applicable, discharged through provider assurance evidence."

The assessor revises it to Applicable and it is approved.

Final position: 81 Applicable, 12 Not Applicable. The Statement of Applicability shows all 93, with the 12 exclusions and their justifications visible to the certification assessor.

The rejected exclusion is the system working. A maker-checker chain that never rejects anything is not a control.


Troubleshooting

"My Not Applicable decision has not taken effect." It is in draft or pending_review. Only approved decisions are authoritative.

"I cannot approve my own decision." Correct. Segregation of duties requires an independent approver.

"OrviQ rejected my justification." A meaningful rationale is required for Not Applicable. Say what is out of scope and why.

"Compliance percentages did not change after I approved exclusions." Check whether the assurance view you are reading is scoped to the adoption. Also remember that exclusions leave the denominator; they do not add to the numerator.

"A requirement shows as unresolved but I decided it months ago." The decision was likely never submitted or never approved. Filter the register by governance state to find records stuck in draft.


OrviQ Enterprise Governance, Risk & Compliance Platform