Live 17 practitioner certifications live · First lesson free on every course Back to main site →

The one-page scope document a founder will sign in a single meeting

The seven fields that make a scope document a decision, not a discussion. The three fields founders push back on and how to counter each pushback without losing the room. By the end of this lesson you have a template you can walk into Monday morning.

Free preview 11 min read Verified

If a scope document is longer than one page, two things will happen. The founder will not read it, and later, when the project is in trouble, the founder will say "I never agreed to that." I have signed engagements off a one-pager that fit in a WhatsApp screenshot and I have watched twelve-page scope decks collapse the moment a vendor contract became difficult. Length is a tell. Keep it short.

Here are the seven fields that belong on the page. Nothing else does.

The seven fields

Field 1 — In-scope entities. One line. Which legal entity. Which products or business units. If the client is a group, name only the entities you are covering. If the client has an India entity and a Singapore entity, say "India entity only" and get the founder to sign that. The number of engagements that have gone sideways because "we meant our Singapore entity too" is depressingly non-zero.

Field 2 — Out of scope. This is where you earn your fee. Name the three or four things you are explicitly not doing. For a 90-day Privacy Suite engagement these usually are: DPIA on legacy systems older than five years, M&A due diligence on data assets, cross-border transfer legal opinion to a specific country, and sector-specific regulator liaison beyond pointing at the overlay. Writing out-of-scope is more important than writing in-scope. In-scope is a wish list. Out-of-scope is a contract.

Field 3 — Three deliverables. Not twelve. Three. The ones a Data Protection Board officer will ask for first. These are the RoPA, the DSAR workflow, and the Rule 7 breach runbook [L2-C1]. Everything else in the programme produces input into one of these three. If you list twelve, the founder will argue about four of them. If you list three, the founder nods.

Field 4 — Three success criteria. Measurable, dated, and binary. Example criteria: "Board sign-off on RoPA and retention schedule by Day 30," "Audit dry run passes on Day 60," "DPO handover complete and DPO calendar operational by Day 90". Each criterion is either yes or no. No gradations.

Field 5 — Named stakeholders. Not roles. Names. The CEO, the GC or Legal Head, the CTO, the CMO, and the designated DPO. Six people maximum. If the founder cannot name all five, the programme is not ready to start, and that is a useful diagnosis.

Field 6 — Budget bracket and payment schedule. One line. "Fixed fee of ₹X plus GST, payable 40 percent on signing, 30 percent on Day 30 deliverable sign-off, 30 percent on Day 90 handover acceptance." Milestone-tied payment is non-negotiable. If a client wants to pay 100 percent upfront or 100 percent on completion, something is wrong with the project you have not yet discovered.

Field 7 — Timeline. Start date, Day 30, Day 60, Day 90. Four dates. Not a Gantt. The Gantt lives in Lesson 4. On this page, four dates is enough.

That is the whole page. One A4 sheet. Ten minutes of reading time. Sign-off should take one meeting.

The three fields founders push back on

Scoping meetings do not go in a straight line. Founders push back on three specific fields, and if you cannot handle each pushback cleanly, the meeting ends with "let me get back to you" and the engagement starts a week late.

Pushback on Field 2 (out of scope) — "but we need all of it." This is the single most common pushback. The founder reads your out-of-scope list and feels anxious. He wants comprehensive. The counter is not to argue scope. It is to re-frame. Say this: "You need all of it. We can do all of it. The question is whether you need all of it done in 90 days or whether you need the Board-reportable items done in 90 days and the rest on a 180-day follow-up. If I promise all of it in 90 days I am setting us both up to fail." The honest frame earns trust. Founders who hear it almost always sign on 90 days plus an optional phase 2.

Pushback on Field 6 (budget) — "₹X seems high." Do not defend the number. Reframe the cost of the alternative. Say this: "The cost of a Rule 7 breach misfiling, under Section 33 and the Schedule, is capped at ₹250 crore [L2-C2]. Star Health is the public pattern we all point to for late-reporting consequences. The 90-day programme costs you ₹X. One late-reported breach costs you orders of magnitude more. Which number is high depends on which number you compare it to." Founders are generally good at expected-value thinking once you frame it. The hard part is giving them the frame.

Pushback on Field 7 (timeline) — "can you do 30?" The honest answer, which you will give in Lesson 1 of Module 2, is that discovery alone takes two weeks because engineering sprint cycles are two weeks. You cannot discover faster than Engineering can answer. If the founder insists on 30 days, the real question is whether what he wants is a programme or whether he wants a one-page assessment he can show his investors. Those are different products. The one-page assessment is a 10-day engagement with a different scope document. Offer it. Do not try to run a 90-day programme on 30 days of calendar time.

Common mistakes in the scope document itself

Three traps I keep seeing in scope documents other consultants send me for review.

First, the "deliverables" section lists activities instead of artifacts. "Conduct discovery interviews" is an activity. "Draft data inventory" is an artifact. Only artifacts belong in Field 3. Activities are internal to your methodology. Clients do not pay for activities.

Second, the "named stakeholders" section lists roles with no names and no backups. If the Head of Engineering is named but the person acting as Head of Engineering changes in Week 4 because the previous one resigned, you need to have agreed in writing who the backup is. Add a parenthetical: "CTO (Priya Sharma), backup (Head of Platform, Rohan Mehta)". It feels pedantic until Week 4.

Third, the "success criteria" section is written in soft language. "A functioning DPDP programme" is not a criterion. "Board sign-off on the Day 30 RoPA deliverable" is a criterion. If you cannot tell on the day whether it was met, it is not a criterion.

What a bad scope document looks like

Last year I was asked to review a scope document another consultant had sent a client. It ran to twelve pages. It listed forty-seven "deliverables," including eighteen sub-deliverables of the RoPA alone (lawful basis mapping, retention mapping, system-of-record mapping, data-flow diagram, etcetera). It had no out-of-scope section. It had no named stakeholders. It had no payment schedule, only a bottom-line fee. The timeline said "six months, extendable".

The client had signed it. Three months in, the project was in trouble, which is why I was asked to look. The problem was not that the consultant was incompetent. The problem was that the scope document had no decisions in it. Every one of the forty-seven deliverables was negotiable, every stakeholder was unnamed, every timeline was elastic. When the project ran into friction in Month 2, there was nothing to point at. The scope document was a brochure, not a contract.

The contrast with a one-page document is not just that it is shorter. It is that every field on a one-page document is a decision. You cannot write "named stakeholders" and leave it blank. You cannot write "three deliverables" and list seven. You cannot write "timeline: start, Day 30, Day 60, Day 90" without the dates being real. The shortness forces the specificity, and the specificity is what makes it enforceable later.

Sample: ABC Tyres filled scope document

Here is what a filled scope document looks like for the capstone client we will use through the whole course. ABC Tyres Pvt Ltd is a 350-employee tyre manufacturer in Jaipur with a Head Office, one factory, a direct-to-consumer e-commerce site, a dealer portal and an active marketing stack. Study the specificity. Every field is a decision, not a wish.

1. In-scope entitiesABC Tyres Pvt Ltd (India entity, CIN U25111RJ2008PTC026541). Covered business units: Head Office (Jaipur), Factory operations (Bhiwadi plant), direct-to-consumer e-commerce (abctyres.in), Dealer Portal (dealers.abctyres.in), Marketing (owned-media, paid-media, lead-gen).
2. Out of scope(a) Re-litigation of the existing biometric attendance DPIA concluded in Q4 2025 — accepted as-is. (b) Factories Act 1948 opinion on worker-register data — a separate labour-law engagement. (c) Cross-border transfer legal opinion for any specific country of transfer beyond pointing at the Rule 15 register and the general posture. (d) Dealer Portal MySQL schema remediation — Engineering owns this on their 2027 roadmap; the programme flags the gap but does not fix it.
3. Three deliverables(1) RoPA covering all five in-scope business units, signed off by the GC. (2) DSAR intake form plus workflow in staging, with twelve response templates loaded. (3) Rule 7 breach runbook plus one tabletop exercise run and recorded [L2-C1].
4. Three success criteria(1) Board resolution recording RoPA and retention schedule sign-off at the Day-30 Board meeting. (2) Internal audit dry run on Day 60 passes with no critical findings. (3) DPO Nandini Pillai can walk the audit evidence file end-to-end in sixty minutes at Day-90 handover without consultant assistance.
5. Named stakeholdersMD and sponsor: Rakesh Agarwal. General Counsel: Vivek Khanna. Head of IT (acting CTO): Praveen Kumar. CMO: Priya Shah. Head of HR: Anita Rao. Designated DPO: Nandini Pillai (Legal Associate, promoted into the DPO seat for this engagement). CFO (informed sponsor): Deepak Mehta.
6. Budget and payment scheduleFixed fee ₹18,00,000 plus GST. Payable 40 percent on signing (₹7,20,000), 30 percent on Day-30 RoPA sign-off (₹5,40,000), 30 percent on Day-90 handover acceptance (₹5,40,000). Milestones tied to the three success criteria in Field 4. No upfront 100 percent. No success-fee back-end.
7. TimelineStart: 15 October 2026. Day 30: 13 November 2026. Day 60: 13 December 2026. Day 90: 12 January 2027. Four dates, binary, no shift without written amendment.

Signed by Rakesh Agarwal (MD, ABC Tyres Pvt Ltd) and the engagement partner on 10 October 2026. One page in a 10pt font. Twelve minutes in the room. One decision, not a discussion.

Your artifact from Lesson 2

Download the scope-document template from the resource panel. Fill it in for the hypothetical client introduced in the capstone (ABC Tyres, Jaipur) — or use the sample above as a starting point and change what would be different for your own real client. Share your fill-in with a peer and ask them to try to argue with it. If a peer cannot argue with your scope document in ten minutes, a founder cannot either. That is the test.

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview in progress 11 more modules waiting behind enrolment

Enjoying the preview? Here's what enrolment unlocks.

  • All 11 paid modules (58 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Lifetime access plus every future update
Inclusive of 18% GST. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
DPDP Rules 2025, Rule 7 (DPDP breach notification (parallel to CSCRF for personal data)) L2-C1
DPDP Rules 2025 Rule 7: on becoming aware of a personal data breach, the Data Fiduciary must intimate each affected Data Principal without delay and intimate the Data Protection Board without delay. Detailed report to the Board within 72 hours of awareness (extendable on written request). For a SEBI RE handling personal data, this runs in parallel with the CSCRF 6-hour clock.
DPDP Act 2023, Section 33 (Penalties for breach) L2-C2
The Board may impose penalty as specified in the Schedule. Factors to consider include nature/gravity/duration of breach, type of data affected, repetitive nature, gain avoided or loss suffered, mitigation, proportionality and impact. Penalty is credited to the Consolidated Fund of India.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: The Programme in One Diagram — Scoping, Buy-In and the 90-Day Calendar
Module 2: Discovery Sprint — Finding Where Personal Data Actually Lives
  • Discovery interview questions that get engineering to actually tell you where data lives
  • Reading a database schema the way an auditor reads it
  • The four hiding places engineering always forgets to mention
  • File-share and cloud-storage scanning without buying a six-figure DLP
  • Building the draft data inventory that will survive Day 15
  • Discovery sign-off and the Day-15 stop-or-go decision pack
Module 3: Building the Records of Processing (RoPA) That Will Survive an Audit
  • The eight columns of a DPDP RoPA, and why no ninth belongs
  • Filling the RoPA from the Module 2 inventory, column by column
  • The three red-flag cells an auditor spots in the first sixty seconds
  • The twenty-minute RoPA walkthrough a DPB officer will ask you to run
  • ABC Tyres worked example: four RoPA rows, filled column by column
  • RoPA sign-off, the Day-30 Board update, and setting up Module 4
Module 4: Lawful Basis Mapping and the Retention Schedule
  • The lawful basis decision tree, and why "legitimate interest" is not an answer
  • The retention matrix, layered by sector, that defends every cell
  • The Third Schedule three-year inactivity rule and the 48-hour pre-erasure notice
  • Erasure requests and the "unless required by law" response
  • Getting the retention schedule signed off by Day 30
Module 5: Notice, Consent, Cookies and the Consent Manager Wire-Up
  • Drafting the Rule 3 standalone notice without turning it into a wall of text
  • The Section 6 consent flow and the auditable consent record
  • Cookies and tracking under DPDP, when the Act does not mention cookies
  • Multilingual notice under the Eighth Schedule: 22 languages, Claude AI, not Bhashini
  • The Rule 4 Consent Manager integration plan: live-frontier work
  • Going live: the Day-45 checklist that keeps the notice from embarrassing you
Module 6: DSAR Intake, Workflow and the 90-Day Clock
  • The DSAR intake form that collects what you need and nothing more
  • Identity verification without over-collection — three tiers, one decision tree
  • The 90-day clock, and why you must beat it, not touch it
  • The four response templates — grant, carve-out, refuse, escalate
  • Section 13 grievance and the Section 15 duty that handles bad-faith requests
Module 7: Vendor Risk, DPAs and the Cross-Border Register
  • The vendor risk register — ten columns, one row per vendor, nothing more
  • The ten DPA clauses you do not negotiate away
  • The Rule 15 cross-border decision log — four columns and the empty negative list
  • Three vendor conversations that go sideways — and the exact scripts
  • Section 17 exemptions — when they genuinely apply and when founders only think they do
  • The Day-75 cutoff — accept the risk, or kill-switch the vendor
Module 8: Breach Response — Running Rule 7 and CERT-In in Parallel
  • Classifying an incident as a personal data breach under Section 2(u)
  • Rule 7 Stage 1 — the "without delay" intimation to Data Principals and the Board
  • Rule 7 Stage 2 — the 72-hour detailed report to the Data Protection Board
  • The CERT-In six-hour parallel clock — filing twice without duplicating effort
  • The two-hour tabletop that turns a paper runbook into a tested one
Module 9: DPIA for High-Risk Processing and the SDF Playbook
  • Scoping a DPIA before Legal is the one asking you to run one
  • A risk-rating methodology that survives a Board meeting
  • Algorithmic due diligence for AI systems, worked on a credit-scoring model
  • The Rule 13 independent audit on a 12-month clock
  • The DPO role that survives a change of CEO
Module 10: DPO Operations — Calendar, Metrics and Board Reporting
  • The 12-month DPO calendar that keeps a programme alive after Day 91
  • Five KPIs that indicate programme health — and the gaming behaviour that corrupts each
  • Board reporting cadence and the six-slide deck that gets fifteen minutes well-spent
  • The budget renewal ask — how to argue for a 10 percent increase, not accept a 10 percent cut
  • The DPO handover document — what a departing DPO owes a successor
Module 11: Running the Programme (Not Just the Checklist) — Leadership, Politics and Making Engineering Say Yes
  • Running a steering committee that decides, not one that updates
  • Converting an engineering "no, not this quarter" into a scheduled Yes
  • Handling the marketing pixel removal fight without losing the CMO
  • Briefing a Board on DPDP risk in ten minutes and six slides
  • The three recurring cross-functional disputes and how to mediate each
  • When to escalate to the CEO, when to absorb, and how to escalate once
Module 12: Capstone — Run the Full Programme on ABC Tyres (Fictional) + Final Exam
  • ABC Tyres — the client brief and your Day-0 engagement plan
  • Walking the full ABC Tyres programme file end to end
  • Submitting your capstone and preparing for the final exam