Microsoft

microsoft.com

Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.

TrustyCyber Score
57 / 100C
Procurement decision
Security review required
4 conditions outstanding
  • Dragon Copilot (healthcare, ex-Nuance) trains on customer data, with human review
  • No clear commitment that your data will not train their models
  • Data retention window not stated

+1 more

See Before you sign, with what to ask for ↓

Evidence Medium HighFreshness CurrentVerification Partial

Scanned Aug 28, 2026 · Public evidence · Point-in-time

Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.

Before you sign

Dragon Copilot (healthcare, ex-Nuance) trains on customer data, with human reviewBlocking

Why it matters: The Product Terms for Dragon Copilot - the healthcare clinical-documentation product, formerly Nuance DAX, and a DIFFERENT product from Microsoft Copilot or Microsoft 365 Copilot - instruct Microsoft and its subprocessors to process Customer Data, including via human review, to train and develop the AI/ML models.

What to ask for: Confirm the product family in your agreement; for Dragon Copilot deployments, confirm the training and human-review terms and any opt-outs.

Evidence
Vendor publishedMicrosoft Product Termsretrieved Aug 24, 2026
Customer instructs Microsoft (and its Subprocessors) to: Process (including via human review) Customer Data for the purpose of training and developing the AI/ML models
No clear commitment that your data will not train their modelsCondition

Why it matters: The public sources scanned do not clearly state that customer prompts, files, and outputs are excluded from training or fine-tuning of first- or third-party models.

What to ask for: Get a no-training clause covering first- and third-party models into the DPA/order form.

Evidence
Vendor publishedMicrosoft Product Termsretrieved Aug 24, 2026
Customer instructs Microsoft (and its Subprocessors) to: Process (including via human review) Customer Data for the purpose of training and developing the AI/ML models
Prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation LLMs, including those used by Microsoft Copilot.
Data retention window not statedCondition

Why it matters: The public sources scanned do not give a retention period for customer data or prompts/outputs.

What to ask for: Get retention windows, in days, in writing.

Evidence
Vendor publishedMicrosoft Product Termsretrieved Aug 24, 2026
For the purposes of data retention and deletion, a Services configuration or custom model that has been inactive may at Microsoft's discretion be treated as an Online Service for which the Customer's subscription has expired.
Underlying model providers not namedCondition

Why it matters: AI is used but the public sources scanned do not name which foundation models or providers sit in the request path.

What to ask for: Require named providers and model versions, plus notice before any model change.

Buyer questionsanswered only from the public evidence scanned — click a row for the answer

!Will they train on your data?Ask the vendor

The Product Terms state that by using Customer Data to provide Dragon Copilot, the customer instructs Microsoft and its Subprocessors to process Customer Data - including via human review - to train and develop the AI/ML models.

Requires written confirmation — see Before you sign ↓

Evidence
Vendor publishedMicrosoft Product Termsretrieved Aug 24, 2026
Customer instructs Microsoft (and its Subprocessors) to: Process (including via human review) Customer Data for the purpose of training and developing the AI/ML models
Prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation LLMs, including those used by Microsoft Copilot.
!How long do they keep your data?Ask the vendor

The Product Terms disclose that inactive service configurations or custom models (90 days without calls, modification or key) may be treated as expired for retention and deletion.

Requires written confirmation — see Before you sign ↓

Evidence
Vendor publishedMicrosoft Product Termsretrieved Aug 24, 2026
For the purposes of data retention and deletion, a Services configuration or custom model that has been inactive may at Microsoft's discretion be treated as an Online Service for which the Customer's subscription has expired.
Who else can access your data?Clear

The Product Terms point to published Subprocessor lists (e.g. for Dragon Copilot) covering entities used in conjunction with the product.

Evidence
Vendor publishedMicrosoft Product Termsretrieved Aug 24, 2026
Information about Subprocessors used by Microsoft in conjunction with Dragon Copilot can be accessed at https://aka.ms/hls-subprocessor-list
!Where is your data processed?Ask the vendor

The Product Terms commit to storing Customer Data at rest within a configured Geo, disclosing that some services cannot be Geo-configured and may store backups in other locations.

Confirm in writing: Ask the vendor to state this in writing before signing.

Evidence
Vendor publishedMicrosoft Product Termsretrieved Aug 24, 2026
If Customer configures a particular service to be deployed within a Geo then, for that service, Microsoft will store Customer Data at rest within the specified Geo. Certain services may not enable Customer to configure deployment in a particular Geo or outside the United States and may store backups in other locations.
calls to the LLM are routed to the closest data centers in the region, but also can call into other regions where capacity is available during high utilization
!What happens in a security incident?Ask the vendor

Microsoft publishes security.txt routing to the MSRC researcher portal, bug bounty policy, coordinated vulnerability disclosure policy, and CSAF advisory feed.

Requires written confirmation — see Before you sign ↓

Evidence
Vendor publishedmicrosoft.comretrieved Aug 24, 2026
# Our Researcher Portal Contact: https://msrc.microsoft.com/report/vulnerability/new # Our PGP Key Encryption: https://msrc.microsoft.com/.well-known/csaf/openpgp/998D7EC1A516E3D17FF90480EF148D3CDE714E0D.asc Expires: 2026-09-23T16:00:00.000Z # Our Bounty policy Policy: https://www.microsoft.com/en-us/msrc/bounty/ # Our Coordinated Vulnerability Disclosure Policy Policy: https://www.microsoft.com/en-us/msrc/cvd

Key findingsclick a row for the evidence

The vulnerability-handling surface is exemplaryStrong

MSRC researcher portal, bounty with legal safe harbor, coordinated disclosure policy, and machine-readable CSAF advisories, all discoverable from security.txt.

This is the reference implementation of public vulnerability handling.

Evidence
Vendor publishedmicrosoft.comretrieved Aug 24, 2026
# Our Researcher Portal Contact: https://msrc.microsoft.com/report/vulnerability/new # Our PGP Key Encryption: https://msrc.microsoft.com/.well-known/csaf/openpgp/998D7EC1A516E3D17FF90480EF148D3CDE714E0D.asc Expires: 2026-09-23T16:00:00.000Z # Our Bounty policy Policy: https://www.microsoft.com/en-us/msrc/bounty/ # Our Coordinated Vulnerability Disclosure Policy Policy: https://www.microsoft.com/en-us/msrc/cvd
!Geo commitments carry explicit caveatsGap

Geo-configured storage is committed, but some services cannot be Geo-configured and backups may be stored elsewhere.

Which of the AI services in use honour the Geo boundary needs confirming per service.

Question for vendor: Which AI services in your deployment support Geo configuration, and where do their backups reside?

Evidence
Vendor publishedMicrosoft Product Termsretrieved Aug 24, 2026
If Customer configures a particular service to be deployed within a Geo then, for that service, Microsoft will store Customer Data at rest within the specified Geo. Certain services may not enable Customer to configure deployment in a particular Geo or outside the United States and may store backups in other locations.
Dragon Copilot (healthcare, ex-Nuance) trains on customer data, with human reviewGap

The Product Terms for Dragon Copilot - the healthcare clinical-documentation product, formerly Nuance DAX, and a DIFFERENT product from Microsoft Copilot or Microsoft 365 Copilot - instruct Microsoft and its subprocessors to process Customer Data, including via human review, to train and develop the AI/ML models.

Materially adverse terms on one AI product in the portfolio; by contrast, M365 Copilot documentation commits that prompts, responses and Graph data are not used to train foundation models. Buyers should map which product family their terms fall under.

Question for vendor: Confirm the product family in your agreement; for Dragon Copilot deployments, confirm the training and human-review terms and any opt-outs.

Evidence
Vendor publishedMicrosoft Product Termsretrieved Aug 24, 2026
Customer instructs Microsoft (and its Subprocessors) to: Process (including via human review) Customer Data for the purpose of training and developing the AI/ML models
!Model suppliers behind Copilot are not named in the collected sourcesGap

None of the collected pages names the foundation-model suppliers behind Copilot experiences.

The provider relationship determines whose terms sit underneath the product.

Question for vendor: Which model providers or in-house models power the Copilot features in scope?

Evidence
Microsoft Copilot remembers details that matter to your daily life while keeping your personal data secure and protecting your  privacy . You can always manage your privacy preferences in your Copilot Privacy settings.
?Technical dependency observed: AtlassianObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Atlassian as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedMicrosoft Product Termsretrieved Aug 24, 2026
Information about Subprocessors used by Microsoft in conjunction with Dragon Copilot can be accessed at https://aka.ms/hls-subprocessor-list
?Technical dependency observed: GoogleObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Google as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Google appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedMicrosoft Product Termsretrieved Aug 24, 2026
Information about Subprocessors used by Microsoft in conjunction with Dragon Copilot can be accessed at https://aka.ms/hls-subprocessor-list
?Technical dependency observed: MicrosoftObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedMicrosoft Product Termsretrieved Aug 24, 2026
Information about Subprocessors used by Microsoft in conjunction with Dragon Copilot can be accessed at https://aka.ms/hls-subprocessor-list

Assurance dimensionsweighted components of one score — not eight separate ratings

Organisation & AI governance15% of the score60
Governance & accountability

Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.

Assessed against ISO 42001 · NIST AI RMF · AIUC-1

Partial
Evidence — Governance & accountability
Microsoft Responsible AI Dashboard to monitor and manage AI systems. Engage stakeholders across the organization and provide training on responsible AI principles and practices. The Microsoft Responsible AI Standard
Vendor publishedResponsible AI Principles and Approach | Microsoft AIretrieved Aug 24, 2026
committed to developing AI systems in a way that is transparent,

Governance & accountability: vendor-evidenced, not yet independently corroborated.

AI system15% of the score27
AI system description

What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.

Assessed against ISO 42001 · NIST AI RMF

Partial
Evidence — AI system description
Microsoft Copilot remembers details that matter to your daily life while keeping your personal data secure and protecting your  privacy . You can always manage your privacy preferences in your Copilot Privacy settings.
Testing & evaluation

How AI features are evaluated before and after release — evals, red-teaming, monitoring.

Assessed against NIST GenAI · NIST AI RMF · ISO 42001

Partial
Evidence — Testing & evaluation
Vendor publishedResponsible AI Principles and Approach | Microsoft AIretrieved Aug 24, 2026
Red teams think like hackers to help keep AI safe Read more
Change management

How changes to models and AI features are controlled and communicated — versioning, notice, rollback.

Assessed against ISO 27001 · ISO 42001

Not Evidenced

Change management: not publicly evidenced.

Model10% of the score0
Model & provider transparency

Which model providers and versions process customer data, and how changes to them are disclosed.

Assessed against NIST GenAI · ISO 42001

Not Evidenced

Model provider transparency: not publicly evidenced.

Customer data15% of the score72
Customer data treatment

Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.

Assessed against ISO 27018 · OAIC APPs · EU AI Act

Partial
Evidence — Customer data treatment
Vendor publishedMicrosoft Product Termsretrieved Aug 24, 2026
If Customer configures a particular service to be deployed within a Geo then, for that service, Microsoft will store Customer Data at rest within the specified Geo. Certain services may not enable Customer to configure deployment in a particular Geo or outside the United States and may store backups in other locations.
Vendor publishedMicrosoft Product Termsretrieved Aug 24, 2026
For the purposes of data retention and deletion, a Services configuration or custom model that has been inactive may at Microsoft's discretion be treated as an Online Service for which the Customer's subscription has expired.
Vendor publishedMicrosoft Product Termsretrieved Aug 24, 2026
Customer instructs Microsoft (and its Subprocessors) to: Process (including via human review) Customer Data for the purpose of training and developing the AI/ML models
Prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation LLMs, including those used by Microsoft Copilot.
calls to the LLM are routed to the closest data centers in the region, but also can call into other regions where capacity is available during high utilization

Customer data treatment: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.

AI supply chain10% of the score60
Subprocessors & supply chain

The named chain of AI and infrastructure providers behind the product, and how it is disclosed.

Assessed against ISO 27001 · ISO 27017

Partial
Evidence — Subprocessors & supply chain
Vendor publishedMicrosoft Product Termsretrieved Aug 24, 2026
Information about Subprocessors used by Microsoft in conjunction with Dragon Copilot can be accessed at https://aka.ms/hls-subprocessor-list

Subprocessors & supply chain: vendor-evidenced, not yet independently corroborated.

Security foundation15% of the score85
Vulnerability & incident handling

How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.

Assessed against ISO 27001 · NIST AI RMF

Partial
Evidence — Vulnerability & incident handling
Vendor publishedmicrosoft.comretrieved Aug 24, 2026
# Our Researcher Portal Contact: https://msrc.microsoft.com/report/vulnerability/new # Our PGP Key Encryption: https://msrc.microsoft.com/.well-known/csaf/openpgp/998D7EC1A516E3D17FF90480EF148D3CDE714E0D.asc Expires: 2026-09-23T16:00:00.000Z # Our Bounty policy Policy: https://www.microsoft.com/en-us/msrc/bounty/ # Our Coordinated Vulnerability Disclosure Policy Policy: https://www.microsoft.com/en-us/msrc/cvd

Vulnerability & incident handling: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.

Independent assurance evidence10% of the score85
Independent assurance

Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.

Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008

Partial
Evidence — Independent assurance
comprehensive set of more than 90 offerings.

Read from the registry record above — cited, not reproduced.

Registry verifiedCSA STAR Registry record — CSA STAR Level 2retrieved Aug 24, 2026

Read from the registry record above — cited, not reproduced.

Document held and reviewed by TrustyCyber — cited, not reproduced.

Document held and reviewed by TrustyCyber — cited, not reproduced.

Document held and reviewed by TrustyCyber — cited, not reproduced.

Read from the registry record above — cited, not reproduced.

Capped at 85: none of the corroborated certifications is AI-specific — this is security attestation, not AI-management-system assurance.

None of the corroborated certifications is AI-specific (ISO/IEC 42001 or AIUC-class) — this assurance is security and data-transfer attestation, not AI-management-system assurance.

Legal & contractual10% of the score60
Legal & contractual transparency

The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.

Assessed against EU AI Act · OAIC APPs

Partial
Evidence — Legal & contractual transparency
Vendor publishedMicrosoft Product Termsretrieved Aug 24, 2026
If Customer configures a particular service to be deployed within a Geo then, for that service, Microsoft will store Customer Data at rest within the specified Geo. Certain services may not enable Customer to configure deployment in a particular Geo or outside the United States and may store backups in other locations.
Law enforcement data requests View the number of requests for customer data we receive from law enforcement agencies.
commercial customers, including the General Data Protection Regulation (GDPR) and European Union (EU) Data Boundary.

Legal & contractual transparency: vendor-evidenced, not yet independently corroborated.

Not graded: Agent — not applicable to this scan.

What would strengthen assuranceeach figure is from today's score — resolving one changes the others

+6Publish Model provider transparency evidenceModel 060
+3Publish Change management evidenceAI System 2747
+3Publish independently corroborated ISO/IEC 42001 (AI management system) certificationIndependent Assurance 85100
+2Have Customer data treatment disclosures independently corroboratedData 7287
+2Have Governance & accountability disclosures independently corroboratedOrganisation 6075

Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 57 → up to 82 with every identified gap resolved.

AI supply chainclick a node to focus it · drag to pan · zoom with the controls

ORGANISATIONPRODUCT & AI FEATURESMicrosoftMicrosoftMicrosoft 365 CopilotMicrosoft 365 Copilot

What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0

This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.

Map your inherited responsibilities
Assurance evidence: certifications 7 — registry checks and verification ladders, click to view
ISO/IEC 42001Not claimed

Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.

SOC 2 Type IIClaimed & corroborated

Org-level report; Product Terms mark SSAE 18 SOC 2 Type II as Yes for Office 365 Services, defined to include Microsoft 365 Copilot. The Service Trust Portal catalogue lists a current Azure + Dynamics 365 + Online Services SOC 2 Type II report (period 1 Apr 2025 to 31 Mar 2026) and Microsoft 365 SOC 2 Type 2 reports, with bridge letters covering the period since.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against Microsoft Service Trust Portal (SOC report catalogue), Aug 27, 2026: Verified on the registry

SOC 1 Type IIClaimed & corroborated

Org-level report; the claim is SOC 1 Type II marked Yes for Office 365 Services in the Product Terms. The Service Trust Portal catalogue lists a current Azure + Dynamics 365 + Online Services SOC 1 Type II report (period 1 Apr 2025 to 31 Mar 2026) and Microsoft 365 SOC 1 Type 2 reports with a July 2026 bridge letter.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against Microsoft Service Trust Portal (SOC report catalogue), Aug 27, 2026: Verified on the registry

ISO/IEC 27001Claimed & corroborated

Certificate face states the scope: the ISMS supporting Microsoft Azure, Dynamics 365, and other Online Services deployed in Azure Public and Government Cloud, per statement of applicability version 2026.01. Resolves the scope_unclear on this org-level report; the vault also holds the separate Microsoft 365 ISO/IEC 27001:2022 certificate (valid 2024-2027) covering the M365 scope.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Currentuntil Jun 16, 2029

Checked against Schellman certificate of registration held in the TrustyCyber vault (Microsoft Service Trust Portal), Aug 27, 2026: Verified on the registry

EU-U.S. Data Privacy FrameworkClaimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against Data Privacy Framework (dataprivacyframework.gov), Aug 28, 2026: Verified on the registry

CSA STAR Level 2Claimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against CSA STAR Registry, Aug 28, 2026: Verified on the registry

FedRAMP AuthorizationClaimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against FedRAMP Marketplace (fedramp.gov), Aug 28, 2026: Verified on the registry

Sources 19 — click to view
Responsible AI: Ethical policies and practices | Microsoft AI
AI Documentation · Vendor · retrieved Aug 24, 2026
Responsible AI Principles and Approach | Microsoft AI
AI Documentation · Vendor · retrieved Aug 24, 2026
Microsoft AI - Business Solutions and Tools
AI Documentation · Vendor · retrieved Aug 24, 2026
AI Tools, Features & Assistance in Windows 11 | Microsoft Windows
AI Documentation · Vendor · retrieved Aug 24, 2026
Microsoft Trust Center | Data Security, Privacy, and Compliance
Trust Or Security Page · Vendor · retrieved Aug 24, 2026
Cloud Data Integrity at its Finest | Microsoft Trust Center
Trust Or Security Page · Vendor · retrieved Aug 24, 2026
Cloud Security Solutions | Microsoft Security
Trust Or Security Page · Vendor · retrieved Aug 24, 2026
https://www.microsoft.com/.well-known/security.txt
Trust Or Security Page · Vendor · retrieved Aug 24, 2026
Microsoft Product Terms
DPA · Vendor · retrieved Aug 24, 2026
Microsoft Privacy Principles | Microsoft Trust Center
Privacy Notice · Vendor · retrieved Aug 24, 2026
Microsoft Privacy Statement – Microsoft privacy
Privacy Notice · Vendor · retrieved Aug 24, 2026
Privacy
Privacy Notice · Vendor · retrieved Aug 24, 2026
Data, Privacy, and Security for Microsoft Copilot | Microsoft Learn
AI Documentation · Vendor · retrieved Aug 28, 2026
Data Privacy Framework (dataprivacyframework.gov) record — EU-U.S. Data Privacy Framework
External Registry Or Certification Evidence · Registry · retrieved Aug 24, 2026
CSA STAR Registry record — CSA STAR Level 2
External Registry Or Certification Evidence · Registry · retrieved Aug 24, 2026
Schellman certificate of registration held in the TrustyCyber vault (Microsoft Service Trust Portal) record — ISO/IEC 27001
External Registry Or Certification Evidence · External Corroborating · retrieved Aug 27, 2026
Microsoft Service Trust Portal (SOC report catalogue) record — SOC 1 Type II
External Registry Or Certification Evidence · External Corroborating · retrieved Aug 27, 2026
Microsoft Service Trust Portal (SOC report catalogue) record — SOC 2 Type II
External Registry Or Certification Evidence · External Corroborating · retrieved Aug 27, 2026
FedRAMP Marketplace (fedramp.gov) record — FedRAMP Authorization
External Registry Or Certification Evidence · Registry · retrieved Aug 28, 2026
Appendix: standards landscape 8 — click to view

Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.

NIST AI RMF 1.0 (AI 100-1)Published (2023; GenAI profile 2024)
AI risk management (+ Generative AI Profile) · Voluntary AI RMF (Govern/Map/Measure/Manage); the US counterpart to ISO/IEC 42001 for AI governance.
AI management system · Anchor for responsible AI governance — internal audit, management review and continual improvement. World's first AI management system standard.
Interpretation of the 13 APPs · Authoritative APP interpretation under the Privacy Act 1988; watch for privacy-reform updates.
EU AI Act (Reg 2024/1689)In force, phased to 2028 (amended by Reg (EU) 2026/1744)
AI regulation — risk tiers, GPAI, high-risk obligations · Extraterritorial AI law; GPAI obligations and the Code of Practice are live. The Digital Omnibus on AI, Regulation (EU) 2026/1744 (OJ 24 Jul 2026, in force 27 Jul 2026), defers Annex III standalone high-risk obligations to 2 Dec 2027 and Annex I embedded high-risk to 2 Aug 2028; Article 50 transparency duties applied from 2 Aug 2026.
ISMS requirements · Core assurance anchor. Amendment 1 (2024) adds climate-action considerations to clauses 4.1/4.2; base edition remains 2022.
PII protection in public clouds · 3rd edition (Aug 2025), aligned to 27002:2022 with a new Annex B; useful for SaaS privacy, processor obligations and customer assurance packs.
130-control AI usage framework · Control-level AI usage framework with mandatory/supplemental classifications and evidence guidance.
Requirements for management-system certification bodies · The base certification-body standard that ISO/IEC 27006-1 and 42006 extend; foundational for audit/cert integrity (also in the reference vault).

Want to go further?

This scan assesses Microsoft at an organisational level. Assurance can vary significantly between products, models and agents — enter the product you’re evaluating to run a deeper AI System Assurance Scan.

Scan a specific product →

This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.