The use of AI assistants such as Microsoft 365 Copilot introduces new types of information security and privacy risks. Organizations that already operate an Information Security Management System (ISMS) will typically address these risks through established security controls. But are the controls defined in ISO 27001 sufficient to govern the use of AI assistants like Copilot? The short answer is no. To address this properly, we must look to a different ISO standard.
ISO/IEC 42001:2023 specifies requirements for an Artificial Intelligence Management System (AIMS). The standard defines requirements for the management system itself and includes a set of recommended controls related to the use of AI. Organizations using Microsoft 365 have strong capabilities for governing and managing 365 Copilot, and as expected, this is largely achieved through Microsoft Purview. Let’s explore how Purview supports an AIMS.
ISO 42001 Requirements
The requirements in ISO 42001 follow the same high-level structure as other management system standards. They include, among other things, establishing an AI policy, defining roles and responsibilities, performing AI risk assessments, and conducting impact assessments of AI systems.
One of the requirements in ISO 42001 is clause 9.1 – Monitoring, measurement, analysis, and evaluation. Under this requirement, the organization must determine what should be monitored and measured in order to analyze and evaluate the performance and effectiveness of the AI management system.
| ISO 42001:2023 requirement | Relevant Purview solution |
| 9.1 Monitoring, measurement, analysis and evaluation | Data Security Posture Management for AI (DSPM for AI) – Analyze reports, including activity, data and user insights Copilot dashboard – Analyze the value of Copilot-assisted hours |
Security controls in ISO 42001 Annex A
ISO 42001 Annex A specifies 39 recommended controls. As part of an AIMS, organizations must assess whether each control is relevant and, if so, implement it. This assessment is documented in the Statement of Applicability (SoA), which is a core part of the AIMS. In practice, this is very similar to how Annex A controls are handled in an ISMS.
Below are examples of how Microsoft Purview can be used to support selected controls from ISO 42001 Annex A.
| ISO 42001:2023 control | Relevant Purview solution |
| A.6.2.6 Operation and monitoring of the AI system | DSPM for AI – Review reports |
| A.6.2.8 Recording of AI System event logs | Audit – Enable auditing and search activity logs (tip: specify Copilot as the workload) Data Lifecycle Management – Create retention policies to ensure AI-related logs are not deleted |
| A.7.3 Data acquisition | Data Loss Prevention (DLP) – Create DLP policies to prevent Copilot from processing private and/or confidential content, based on sensitivity labels and/ord sensitive information types |
| A.7.4 Data quality | Information Protection – Create sensitive information types that match the organization’s business-critical or confidential data, such as health or financial information – Use Content Explorer to gain insight to the data processed eDiscovery – Search for stale data – Delete stale data, as outdated or incorrect data kan negatively impact the quality of responses |
| A.9.4 Intended use of the AI system | Data Security Posture Management for AI (DSPM for AI) – Use Activity Explorer to analyze Copilot interactions and assess whether they allign with the defined intended purpose – Use Data Risk Assessments to identify potential oversharing risks Insider Risk Management – Create IRM policies to detect potential data leakage – Enable Adaptive Protection |
The ISO 42001 Template in Compliance Manager
ISO/IEC 42001:2023 is available as a regulatory template in Microsoft Purview Compliance Manager. This means Microsoft has analyzed the standard and broken its requirements and Annex A controls down into concrete improvement actions.
By enabling this template, organizations gain a structured set of improvement actions mapped directly to ISO 42001 requirements and controls. This provides a practical overview of what can be configured and governed in Microsoft 365 to support compliance with the standard and establish a robust Artificial Intelligence Management System.
