ISO/IEC 42001:2023 is the first international standard for managing artificial intelligence responsibly. It is not a checklist for one AI tool. It is a management system, built the way ISO 27001 was built for information security: risk based, run on a continual-improvement cycle, backed by a set of Annex A controls you can point to when someone asks how you govern AI.
If you already run an ISMS under ISO 27001, you will recognise this immediately: same logic, same audit rhythm, now aimed at the AI systems touching your data as well as the data itself.
Strip it back and ISO 42001 asks four things of any organisation that builds, buys, or uses AI. Know what AI you are running. Understand the risk each use case carries. Put controls around that risk. Keep evidence that you did. That is the standard. Everything after it is detail about how those four requirements apply to your organisation, and for a Microsoft 365 team the detail arrives the day Copilot is switched on.
Microsoft 365 Copilot does not arrive as a separate, contained tool you evaluate at arm's length. It plugs directly into the tenant your team already lives in, and it inherits whatever access each user has: their mailbox, their Teams chats, their SharePoint libraries, everything Microsoft's permission model grants them. Microsoft's own documentation states this plainly: Copilot only surfaces organisational data to which individual users have at least view permissions. That is a real safeguard, and it is also exactly the problem. Copilot's risk profile is your existing access governance, magnified. Give someone excess access to a file they should not see, and Copilot will surface it for them faster than they would ever have found it themselves.
The EU AI Act puts dates around that risk, and some of those dates moved this summer. Obligations for general-purpose AI models and the Act's governance structure have applied since 2 August 2025. Article 50's transparency duties, disclosing when someone is interacting with an AI system and labelling AI-generated content that could pass as human-made, took effect on schedule on 2 August 2026. The general obligations for high-risk AI systems now arrive later. The Digital Omnibus on AI, in force since 27 July 2026, moved them to 2 December 2027, and to 2 August 2028 for AI built into regulated products.
Employment is one of the sensitive areas the Commission names under that 2027 deadline. Most everyday Copilot use, drafting an email, summarising a meeting, will not trip the high-risk category on its own, but a team wiring Copilot agents into HR screening sits closer to the profile those rules are aimed at. Whether a specific deployment qualifies, and whether you count as its provider or its deployer, is a question for your compliance reviewer.
Sixteen extra months on the high-risk paperwork does not change what Copilot can reach in your tenant this morning. Tightening permissions is worth doing, and it is only the access half of the job. The other half is a record: what AI is running, who turned it on, and why someone judged the use acceptable. That record is what ISO 42001 is built to produce.
An ISO 27001 ISMS already gives you most of the machinery: a risk register, named owners, an internal audit cycle, and a management review that has to look at something. ISO 42001 changes what you feed into it.
The obvious objection at this point is that Microsoft has already done this for you. Microsoft 365 Copilot and Copilot Studio both sit inside the scope of Microsoft's own ISO/IEC 42001 certification, and Microsoft is precise about what that buys you: you may use the applicable certification in your own compliance assessment, and you remain responsible for engaging an assessor to evaluate the controls and processes within your own organisation and your own implementation. The scope stops at Microsoft's systems. Which agents run in your tenant, who authorised them, and what they were pointed at all sit on your side of that line.
So the register grows. Alongside your information assets it starts carrying the systems reading them, including the Copilot Studio agent somebody built on a Thursday afternoon. Classification changes shape too, because the useful question is how risky this specific use of Copilot is. Summarising a standup and ranking job applicants share a licence and very little else.
Agents are where this gets concrete. Each one declares the permissions and the data access it needs, and an admin can review exactly that in the Microsoft 365 admin center before allowing it into the tenant. Around that, access control widens to cover what an AI system can reach, supplier management has to start asking what a vendor's certificate actually covers, and incident response needs a path for an AI system doing something nobody predicted. The evidence trail, the ownership model, and the audit rhythm you already built carry straight over.
The certificate is a separate decision from the governance. Whether you pursue an ISO 42001 certificate of your own is a scoping conversation to have with your auditor, and the governance starts the same way regardless, with knowing what is running.
Getting from exposed to governed takes three moves, and the order matters.
Start by counting: list every AI system touching your tenant, Copilot itself, any Copilot Studio agents, and the AI features quietly embedded in the other SaaS tools your team runs. Give the list an owner and a date. You cannot govern what you have not counted.
Once you have that list, the real work is judging it honestly: score each entry for how risky that specific use is, and feed the result into the risk register you already run for ISO 27001 instead of standing up a parallel one. A separate AI register is one more thing to forget about.
The last move is where governance lands. Put Copilot and its agents inside the same access governance you already apply to sensitive files and systems: named ownership, documented scope, and a decision someone signed and dated. That last one is the evidence the standard asks for.
ISOPlanner™ brings ISO 42001 into the same Microsoft 365 environment your team already works in, mapped alongside ISO 27001, with the risk register, ownership, and evidence living in SharePoint and Teams where the actual work happens.
An AI rollout treated as "IT switched something on" is a gap waiting to be found. An AI rollout treated as a management-system decision is not.
Log in to your ISOPlanner™ workspace, or start a free trial.
Log in Start your free trial