If a scope document is longer than one page, two things will happen. The founder will not read it, and later, when the project is in trouble, the founder will say "I never agreed to that." I have signed engagements off a one-pager that fit in a WhatsApp screenshot and I have watched twelve-page scope decks collapse the moment a vendor contract became difficult. Length is a tell. Keep it short.
Here are the seven fields that belong on the page. Nothing else does.
The seven fields
Field 1 — In-scope entities. One line. Which legal entity. Which products or business units. If the client is a group, name only the entities you are covering. If the client has an India entity and a Singapore entity, say "India entity only" and get the founder to sign that. The number of engagements that have gone sideways because "we meant our Singapore entity too" is depressingly non-zero.
Field 2 — Out of scope. This is where you earn your fee. Name the three or four things you are explicitly not doing. For a 90-day Privacy Suite engagement these usually are: DPIA on legacy systems older than five years, M&A due diligence on data assets, cross-border transfer legal opinion to a specific country, and sector-specific regulator liaison beyond pointing at the overlay. Writing out-of-scope is more important than writing in-scope. In-scope is a wish list. Out-of-scope is a contract.
Field 3 — Three deliverables. Not twelve. Three. The ones a Data Protection Board officer will ask for first. These are the RoPA, the DSAR workflow, and the Rule 7 breach runbook [L2-C1]. Everything else in the programme produces input into one of these three. If you list twelve, the founder will argue about four of them. If you list three, the founder nods.
Field 4 — Three success criteria. Measurable, dated, and binary. Example criteria: "Board sign-off on RoPA and retention schedule by Day 30," "Audit dry run passes on Day 60," "DPO handover complete and DPO calendar operational by Day 90". Each criterion is either yes or no. No gradations.
Field 5 — Named stakeholders. Not roles. Names. The CEO, the GC or Legal Head, the CTO, the CMO, and the designated DPO. Six people maximum. If the founder cannot name all five, the programme is not ready to start, and that is a useful diagnosis.
Field 6 — Budget bracket and payment schedule. One line. "Fixed fee of ₹X plus GST, payable 40 percent on signing, 30 percent on Day 30 deliverable sign-off, 30 percent on Day 90 handover acceptance." Milestone-tied payment is non-negotiable. If a client wants to pay 100 percent upfront or 100 percent on completion, something is wrong with the project you have not yet discovered.
Field 7 — Timeline. Start date, Day 30, Day 60, Day 90. Four dates. Not a Gantt. The Gantt lives in Lesson 4. On this page, four dates is enough.
That is the whole page. One A4 sheet. Ten minutes of reading time. Sign-off should take one meeting.
The three fields founders push back on
Scoping meetings do not go in a straight line. Founders push back on three specific fields, and if you cannot handle each pushback cleanly, the meeting ends with "let me get back to you" and the engagement starts a week late.
Pushback on Field 2 (out of scope) — "but we need all of it." This is the single most common pushback. The founder reads your out-of-scope list and feels anxious. He wants comprehensive. The counter is not to argue scope. It is to re-frame. Say this: "You need all of it. We can do all of it. The question is whether you need all of it done in 90 days or whether you need the Board-reportable items done in 90 days and the rest on a 180-day follow-up. If I promise all of it in 90 days I am setting us both up to fail." The honest frame earns trust. Founders who hear it almost always sign on 90 days plus an optional phase 2.
Pushback on Field 6 (budget) — "₹X seems high." Do not defend the number. Reframe the cost of the alternative. Say this: "The cost of a Rule 7 breach misfiling, under Section 33 and the Schedule, is capped at ₹250 crore [L2-C2]. Star Health is the public pattern we all point to for late-reporting consequences. The 90-day programme costs you ₹X. One late-reported breach costs you orders of magnitude more. Which number is high depends on which number you compare it to." Founders are generally good at expected-value thinking once you frame it. The hard part is giving them the frame.
Pushback on Field 7 (timeline) — "can you do 30?" The honest answer, which you will give in Lesson 1 of Module 2, is that discovery alone takes two weeks because engineering sprint cycles are two weeks. You cannot discover faster than Engineering can answer. If the founder insists on 30 days, the real question is whether what he wants is a programme or whether he wants a one-page assessment he can show his investors. Those are different products. The one-page assessment is a 10-day engagement with a different scope document. Offer it. Do not try to run a 90-day programme on 30 days of calendar time.
Common mistakes in the scope document itself
Three traps I keep seeing in scope documents other consultants send me for review.
First, the "deliverables" section lists activities instead of artifacts. "Conduct discovery interviews" is an activity. "Draft data inventory" is an artifact. Only artifacts belong in Field 3. Activities are internal to your methodology. Clients do not pay for activities.
Second, the "named stakeholders" section lists roles with no names and no backups. If the Head of Engineering is named but the person acting as Head of Engineering changes in Week 4 because the previous one resigned, you need to have agreed in writing who the backup is. Add a parenthetical: "CTO (Priya Sharma), backup (Head of Platform, Rohan Mehta)". It feels pedantic until Week 4.
Third, the "success criteria" section is written in soft language. "A functioning DPDP programme" is not a criterion. "Board sign-off on the Day 30 RoPA deliverable" is a criterion. If you cannot tell on the day whether it was met, it is not a criterion.
What a bad scope document looks like
Last year I was asked to review a scope document another consultant had sent a client. It ran to twelve pages. It listed forty-seven "deliverables," including eighteen sub-deliverables of the RoPA alone (lawful basis mapping, retention mapping, system-of-record mapping, data-flow diagram, etcetera). It had no out-of-scope section. It had no named stakeholders. It had no payment schedule, only a bottom-line fee. The timeline said "six months, extendable".
The client had signed it. Three months in, the project was in trouble, which is why I was asked to look. The problem was not that the consultant was incompetent. The problem was that the scope document had no decisions in it. Every one of the forty-seven deliverables was negotiable, every stakeholder was unnamed, every timeline was elastic. When the project ran into friction in Month 2, there was nothing to point at. The scope document was a brochure, not a contract.
The contrast with a one-page document is not just that it is shorter. It is that every field on a one-page document is a decision. You cannot write "named stakeholders" and leave it blank. You cannot write "three deliverables" and list seven. You cannot write "timeline: start, Day 30, Day 60, Day 90" without the dates being real. The shortness forces the specificity, and the specificity is what makes it enforceable later.
Sample: ABC Tyres filled scope document
Here is what a filled scope document looks like for the capstone client we will use through the whole course. ABC Tyres Pvt Ltd is a 350-employee tyre manufacturer in Jaipur with a Head Office, one factory, a direct-to-consumer e-commerce site, a dealer portal and an active marketing stack. Study the specificity. Every field is a decision, not a wish.
| 1. In-scope entities | ABC Tyres Pvt Ltd (India entity, CIN U25111RJ2008PTC026541). Covered business units: Head Office (Jaipur), Factory operations (Bhiwadi plant), direct-to-consumer e-commerce (abctyres.in), Dealer Portal (dealers.abctyres.in), Marketing (owned-media, paid-media, lead-gen). |
| 2. Out of scope | (a) Re-litigation of the existing biometric attendance DPIA concluded in Q4 2025 — accepted as-is. (b) Factories Act 1948 opinion on worker-register data — a separate labour-law engagement. (c) Cross-border transfer legal opinion for any specific country of transfer beyond pointing at the Rule 15 register and the general posture. (d) Dealer Portal MySQL schema remediation — Engineering owns this on their 2027 roadmap; the programme flags the gap but does not fix it. |
| 3. Three deliverables | (1) RoPA covering all five in-scope business units, signed off by the GC. (2) DSAR intake form plus workflow in staging, with twelve response templates loaded. (3) Rule 7 breach runbook plus one tabletop exercise run and recorded [L2-C1]. |
| 4. Three success criteria | (1) Board resolution recording RoPA and retention schedule sign-off at the Day-30 Board meeting. (2) Internal audit dry run on Day 60 passes with no critical findings. (3) DPO Nandini Pillai can walk the audit evidence file end-to-end in sixty minutes at Day-90 handover without consultant assistance. |
| 5. Named stakeholders | MD and sponsor: Rakesh Agarwal. General Counsel: Vivek Khanna. Head of IT (acting CTO): Praveen Kumar. CMO: Priya Shah. Head of HR: Anita Rao. Designated DPO: Nandini Pillai (Legal Associate, promoted into the DPO seat for this engagement). CFO (informed sponsor): Deepak Mehta. |
| 6. Budget and payment schedule | Fixed fee ₹18,00,000 plus GST. Payable 40 percent on signing (₹7,20,000), 30 percent on Day-30 RoPA sign-off (₹5,40,000), 30 percent on Day-90 handover acceptance (₹5,40,000). Milestones tied to the three success criteria in Field 4. No upfront 100 percent. No success-fee back-end. |
| 7. Timeline | Start: 15 October 2026. Day 30: 13 November 2026. Day 60: 13 December 2026. Day 90: 12 January 2027. Four dates, binary, no shift without written amendment. |
Signed by Rakesh Agarwal (MD, ABC Tyres Pvt Ltd) and the engagement partner on 10 October 2026. One page in a 10pt font. Twelve minutes in the room. One decision, not a discussion.
Your artifact from Lesson 2
Download the scope-document template from the resource panel. Fill it in for the hypothetical client introduced in the capstone (ABC Tyres, Jaipur) — or use the sample above as a starting point and change what would be different for your own real client. Share your fill-in with a peer and ask them to try to argue with it. If a peer cannot argue with your scope document in ten minutes, a founder cannot either. That is the test.