← Policies & standards

ISMS Scope Statement

Updated technical boundary for AI, prompts, agents and Microsoft services

Version: 0.3 Updated: 06 August 2026

1. Purpose

This statement defines the organisational, physical, technical and information boundaries of the TFG ISMS and the services subject to information-security governance, risk assessment, control operation, monitoring and review.

2. Organisational and service scope

The management scope covers TFG operating companies Republic of Media, Numodo and Intelligence22, and personnel and suppliers supporting media planning, buying, optimisation, analysis, reporting, data products, automation and approved AI-enabled services. Certification claims must follow the legal entity and service scope stated on the relevant certificate.

3. Physical scope

Edinburgh office: 4th Floor, 3 Ponton Street, Edinburgh, EH3 9QQ.

Manchester office: 4th and 5th Floor, 26 Cross Street, Manchester, M2 7AQ.

Authorised remote, hybrid, client, supplier and event locations subject to TFG controls.

4. Technical and logical scope

Microsoft 365, SharePoint, OneDrive, Teams, Exchange, Azure and Entra ID.

Managed endpoints, retained infrastructure, backup, monitoring and administrative services.

CM360, Meta Business Manager, The Trade Desk, DV360 and other approved campaign, analytics and reporting platforms.

Intelligence22 data foundations, Power BI environments, potent.ai, approved agents, connectors, APIs, retrieval stores and automation workflows.

Approved model providers and enterprise AI capabilities, including Microsoft Copilot and Copilot Studio where approved.

Prompt templates, system instructions, grounding sources, evaluation data, model outputs, feedback, audit logs and agent configuration.

5. Information in scope

Client and client-provided information; campaign, audience, targeting, reporting and analytics data.

Commercial, contractual, supplier, employee, finance and governance information.

Credentials, permissions, configuration, source code, secrets, audit records and security telemetry.

AI prompts, instructions, source documents, retrieval indexes, generated outputs, evaluations and feedback.

6. AI interfaces and dependencies

Dependencies include cloud and model providers, Microsoft tenant services, APIs, connectors, advertising platforms, client portals, third-party data sources and external specialists. Each dependency is subject to risk assessment, due diligence, contract review, access control, incident requirements, continuity planning and periodic review proportionate to risk.

7. Exclusions

An exclusion is permitted only where the service or asset does not process, store, transmit, access, support, secure or materially affect in-scope information or services. Exclusions must be documented, justified, risk assessed and approved.

8. Review triggers

New model, agent, connector, data source or high-impact use case.

Material permission, hosting, retention, provider or architecture change.

New legal entity, office, supplier or client requirement.

Significant incident, audit finding or certification change.