Set boundaries for the engagement
Scope is where a discovery record turns into commitments. A useful scope statement says what will be delivered, what will not, what each side assumes and who decides when something changes. It protects the firm and the consultant alike, because both can point to the same written boundary when a question arises months later.
Treat scope as a set of decisions
A scope statement, often called a statement of work, is easy to fill with tool names and enthusiasm. It is more useful as a list of decisions already taken: which processes from the discovery record are included, which systems may be connected, which exceptions the automation will handle and which it will hand back to a person. Each decision should trace back to something in the discovery record, so nobody has to reconstruct why it was made.
For many SMEs the first engagement is deliberately narrow, covering one process end to end rather than several partially. A narrow scope gives the firm a complete example of acceptance and handover before committing further.
Word deliverables so they can be checked
Vague deliverables invite disagreement at sign-off. The illustrative pairs below show the difference between an intention and something both sides can verify.
| Vague wording | Checkable wording |
|---|---|
| Automate invoice processing | Invoices received in the shared finance mailbox are read, matched to an open purchase order and posted as drafts in the accounts package |
| Handle errors gracefully | Unmatched invoices are moved to a named review queue and the process owner receives a daily summary |
| Provide documentation | A run book, a current BPMN diagram and a list of credentials held, stored in the firm's own file storage |
| Train staff | Two recorded walkthroughs for the process owner and deputy, covering daily checks and pausing the automation |
Name exclusions and assumptions
Exclusions are as important as inclusions. Typical ones include changes to the accounts package itself, data migration from older systems, ongoing support after a set handover date, and licences for third-party platforms such as Microsoft Power Automate, Zapier, Make or UiPath, which the firm usually buys and holds in its own name. Holding licences and accounts directly avoids a common handover problem: an automation that runs on a consultant's subscription.
Assumptions record what each side relies on, for example that test accounts will be available, that a named person can answer questions within an agreed period, or that a supplier's interface will not change during the build.

A responsibility matrix for the engagement
RACI assigns each activity a person who is Responsible for doing it, one who is Accountable for the outcome, those who are Consulted and those kept Informed. The convention of exactly one accountable person per row is what makes it useful. Variants such as RASCI add a Supporting role. The example is illustrative, not a recommended allocation.
| Activity | Owner-manager | Process owner | Consultant | IT support |
|---|---|---|---|---|
| Approve scope statement | A | C | R | I |
| Provide system access | A | I | C | R |
| Build and configure | I | C | A/R | C |
| Write acceptance criteria | C | A | R | I |
| Sign off acceptance | I | A/R | C | I |
| Data protection review | A | C | C | R |
Put data protection inside the boundary
Under UK GDPR and the Data Protection Act 2018, the firm is normally the controller of the personal data its processes use, and a consultant or platform handling that data on its behalf acts as a processor. Article 28 requires a written contract with processors, and the Information Commissioner's Office publishes guidance on controllers, processors and data protection impact assessments. Scope should say whether this review is included, who carries it out and who signs it. For basic security hygiene, many UK firms refer to Cyber Essentials, the government-backed scheme run with the National Cyber Security Centre. This is general information, not legal advice.
Handle change requests in writing
- Record the requested change and who raised it.
- Check it against the scope statement and discovery record.
- Estimate the effect on effort, timing and acceptance criteria.
- Obtain approval from the accountable person in the RACI.
- Update the scope statement and file the decision.