Skip to content

Scope Creep

Definition

The unintended expansion of a penetration test beyond the agreed boundaries, either because testers follow a vulnerability chain into an out-of-scope system or because the client adds targets mid-engagement without a formal scope change. Scope creep creates legal exposure and invalidates the original test design.

Related terms

Attestation Letter
A formal document issued by a qualified assessor, such as a PCI Qualified Security Assessor (QSA) or an ISO 27001 certification body,...
Attorney-Client Privilege
A legal protection shielding confidential communications between an attorney and their client from compelled disclosure in litigation. A forensic accountant retained by...
Audit Criteria
The standards, policies, or requirements against which audit evidence is compared. Common criteria include ISO/IEC 27001, NIST SP 800-53, PCI-DSS, and the...
Audit Objectives
The questions the audit is designed to answer, stated in terms of control criteria. For example: do access management controls satisfy the...
Audit Plan
The document that translates scope and objectives into a structured programme of fieldwork: what will be tested, how, by whom, on what...
Audit Scope
The documented boundaries of an audit: which systems, processes, organizational units, locations, and time periods are included. Scope is agreed between auditor...
Auditee
The organization or organizational unit being audited. In planning, the auditee provides key inputs: system inventory, risk register, previous audit findings, control...
Common Vulnerability Scoring System (CVSS)
A standardised scoring framework that rates vulnerability severity on a 0-10 scale using base metrics (attack vector, complexity, privileges required, user interaction,...
Concession
An acknowledgment by the expert witness that a particular proposition put by counsel is correct. A partial concession accepts part of a...
Cross-Examination
Questioning of a witness by the opposing party. For an expert, cross-examination probes qualifications, methodology, the basis of opinions, limitations, inconsistencies with...
Daubert Gatekeeping
The judicial function under Daubert v. Merrell Dow Pharmaceuticals (1993) and Federal Rules of Evidence Rule 702, requiring the trial judge to...
Engagement Letter
A written contract between the forensic accountant and the retaining party that defines the scope, deliverables, fee arrangement, confidentiality terms, and the...

Explained in these topics

  • Audit Planning and Scope DefinitionThe uncontrolled expansion of audit boundaries beyond what was agreed in the audit plan. Scope creep extends timelines, consumes unbudgeted resources, and weak...
  • Penetration Testing Scope and Audit InterfaceThe unintended expansion of a penetration test beyond the agreed boundaries, either because testers follow a vulnerability chain into an out-of-scope system or...
  • Predication and Engagement Planning in Fraud ExaminationsThe gradual, unjustified expansion of an examination beyond its defined scope without new predication. Scope creep creates legal risk, increases cost, and may...
  • Surviving Cross-ExaminationThe error of allowing cross-examination to push the expert into territory outside their expertise or outside the scope of their report. Scope creep typically b...
  • The Forensic Accounting EngagementThe gradual expansion of an engagement beyond its original boundaries, often without a corresponding adjustment to the fee, timeline, or privilege structure. I...

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.