Drata provides flexible tools to help you define and manage the scope of your compliance program. When certain controls or individuals do not apply to your organization or a specific audit period, you can mark them as Out of Scope to ensure your compliance posture accurately reflects your operating environment.
This guide explains how to exclude controls and personnel from scope in Drata and outlines best practices for maintaining consistency and audit readiness.
Marking Controls as Out of Scope
You can exclude one or more controls directly from the Controls page.
To mark controls as Out of Scope:
Navigate to Controls page in the Drata.
Use the checkbox next to each control you want to exclude.
You can select multiple controls or use Select All to include all controls visible on the page.
Select Out of Scope.
Important:
If the excluded controls are linked to specific requirements, ensure the corresponding requirements are also marked as Out of Scope. This helps maintain consistency across your compliance framework.
Excluding Personnel from Scope
You can bulk-mark personnel as Out of Scope from the Personnel section.
To exclude personnel from scope:
Navigate to Personnel.
Select the users you would like to exclude.
To include more users at once, increase the page size (for example, from 20 to 50).
Select Actions > Change employment status.
Then select Out of Scope, and choose either Ignore or Service Account Out of Scope, depending on how the account should be treated.
This approach allows you to efficiently exclude multiple individuals without editing each record individually.
