<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Scope | Haksung</title><link>https://haksungjang.github.io/en/tags/scope/</link><description>Haksung Jang — Open Source Program Manager at SK telecom</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Sun, 09 Aug 2026 17:03:59 +0900</lastBuildDate><atom:link href="https://haksungjang.github.io/en/tags/scope/index.xml" rel="self" type="application/rss+xml"/><item><title>3.4 Program Scope</title><link>https://haksungjang.github.io/en/docs/ai-sbom_guide/1-program-foundation/4-scope/</link><pubDate>Sun, 09 Aug 2026 17:03:59 +0900</pubDate><guid>https://haksungjang.github.io/en/docs/ai-sbom_guide/1-program-foundation/4-scope/</guid><description>Explains how to clearly declare the scope and limits to which the AI SBOM compliance program applies.</description><content:encoded>&lt;![CDATA[<div class="alert alert-info" role="alert"><div class="h4 alert-heading" role="heading">Implementation Stage</div><p>This clause is established during<strong>Phase 1 — Program Foundation</strong>.<a href="/en/docs/ai-sbom_guide/#phased-implementation-roadmap">View the full implementation roadmap</a></p></div><h2 id="1-clause-overview">1. Clause Overview</h2><p>Program scope determines how far compliance extends. If the scope is ambiguous, it becomes unclear
which AI systems need an SBOM and which models&rsquo; licenses need review. Scope must be declared first
so that every subsequent clause knows what it applies to.</p><p>3.4 requires declaring the scope of application for each program. Scope can differ by organization.
Some organizations cover a single product line; others cover an entire department or the whole
organization. In AI, scope determination covers not only self-developed models but also externally
sourced models and datasets, and the external release of in-house models.</p><h2 id="2-required-activities">2. Required Activities</h2><ul><li>Define what the program applies to (externally deployed AI systems, externally sourced models and
datasets, external release of in-house models, and so on).</li><li>Record what is excluded from application and the rationale for the exclusion.</li><li>Keep the scope statement consistent with the scope of application in the policy document.</li><li>Review and update the scope periodically as the business environment changes.</li></ul><h2 id="3-requirements-and-verification-material">3. Requirements and Verification Material</h2><table><thead><tr><th>Clause</th><th>Requirement (EN)</th><th>Verification Material</th></tr></thead><tbody><tr><td>3.4</td><td>Different programs may be governed by different levels of scope. For example, a program could govern a single product line, an entire department, or an entire organisation. The scope designation needs to be declared for each program.</td><td><strong>3.4.1</strong> A written statement that clearly defines the scope and limits of the program</td></tr></tbody></table><details><summary>View original English text</summary><blockquote><p><strong>3.4 Program scope</strong>
Different programs may be governed by different levels of scope. For example, a program could govern
a single product line, an entire department, or an entire organisation. The scope designation needs
to be declared for each program.</p><p><strong>Verification material(s):</strong></p><ul><li>A written statement that clearly defines the scope and limits of the program.</li></ul></blockquote></details><h2 id="4-compliance-methods-and-samples-by-verification-material">4. Compliance Methods and Samples by Verification Material</h2><h3 id="341-program-scope-statement">3.4.1 Program scope statement</h3><p><strong>Compliance Method</strong></p><p>State the program&rsquo;s scope and limits in writing. Clearly note what is included, what is excluded,
and if excluded, on what grounds. An AI SBOM program becomes clearer when it declares what it
applies to by breaking it down into material types and activities. The table below is an example of
organizing scope.</p><p><strong>Table 1.</strong> Example of an AI SBOM program scope declaration</p><table><thead><tr><th>Category</th><th>Applies</th><th>Notes</th></tr></thead><tbody><tr><td>AI systems, models, and services deployed externally</td><td>Yes</td><td>AI SBOM generation and license review obligations</td></tr><tr><td>Pretrained models sourced externally</td><td>Yes</td><td>Reflected in the AI SBOM as inbound material</td></tr><tr><td>Datasets sourced externally</td><td>Yes</td><td>License and provenance review</td></tr><tr><td>External release of in-house models</td><td>Yes</td><td>Review of public-release license and transparency obligations</td></tr><tr><td>Internal experimental models (not deployed externally)</td><td>Conditionally excluded</td><td>Applicability determined by separate review</td></tr></tbody></table><p><strong>Considerations</strong></p><ul><li><strong>Consistency with policy</strong>: The scope statement should not conflict with the scope of
application in<a href="/en/docs/ai-sbom_guide/1-program-foundation/1-policy/">3.1 Policy</a>.</li><li><strong>Grounds for exclusion</strong>: Record the rationale for excluded items. Even an internal
experimental model falls into scope once it moves to external deployment, so put a review
procedure in place for that transition point.<em>([Recommendation of this guide])</em></li><li><strong>Periodic review</strong>: Update the scope whenever a new product line or new AI service is
introduced.</li></ul><p><strong>Sample (Scope Statement)</strong></p><pre tabindex="0"><code>## AI SBOM Compliance Program Scope
### Applies To
This program applies to all AI systems, models, and services that the company deploys
externally, and to pretrained models and datasets sourced externally. It also covers
activities that release in-house models externally.
### Excluded
Models used solely for internal experimentation or research and not deployed externally
are excluded. However, if such a model transitions to external deployment, it is brought
into scope through the intake review procedure.
### Review Cycle
Scope is reviewed and updated at least once a year, or as the business environment
changes.</code></pre><h2 id="5-see-also">5. See Also</h2><ul><li>Scope of application in the policy:<a href="/en/docs/ai-sbom_guide/1-program-foundation/1-policy/">3.1 Policy</a></li><li>AI SBOM for material within scope:<a href="/en/docs/ai-sbom_guide/2-ai-extension/3-ai-sbom/">3.9 AI SBOM</a></li><li>ISO/IEC 5230 scope example:<a href="https://openchain-project.github.io/OpenChain-KWG/guide/iso5230_guide/1-program-foundation/4-scope/">ISO/IEC 5230 Compliance Guide — 3.1.4 Program Scope</a></li></ul>
]]></content:encoded></item></channel></rss>