ISO 42001 for Claude and Microsoft Copilot.
Your people already use Claude or Copilot, so ISO 42001 already applies to them. What an auditor will ask, which platform records answer it, and the gaps no vendor closes for you.
The short answer
ISO/IEC 42001 applies to businesses that use AI, not only those that build it, so a Claude or Microsoft Copilot rollout is in scope. The platforms supply records an auditor will accept as part of the evidence: single sign-on and usage analytics on Claude Team, audit logs and the Compliance API on Claude Enterprise, and Copilot activity in Microsoft Purview audit. They do not supply the management system: the AI inventory, the risk and impact assessments dated before rollout, supplier oversight of Anthropic and Microsoft, and the approval trail for agents that act. Those are yours to build, and they are what Stage 2 inspects.
What the auditor asks, and what answers it
Six questions every Stage 2 auditor will put to a business running Claude or Copilot, the clause each comes from, and the platform record that answers it. The mapping is ours, from building these systems; the controls are the vendors' own.
| The question | Where it comes from | Claude | Microsoft Copilot |
|---|---|---|---|
| Which AI is in use, and who owns it? | Clause 6, Annex A inventory | Seat lists, connectors and skills from the admin console; usage per person shows what is actually used | Licence assignment in the Microsoft 365 admin centre; Copilot usage reports |
| Who used it, and when? | Clause 9.1, monitoring | Usage analytics on Team; audit logs and the Compliance API on Enterprise | Copilot activity in Microsoft Purview audit |
| What data may go in, and is that enforced? | Annex A, data for AI systems | Org instructions, connector admin controls; custom retention on Enterprise | Your tenant's existing permissions, sensitivity labels and retention |
| Who are your AI suppliers, and on what terms? | Annex A, third parties | Anthropic, on its commercial terms | Microsoft, and Anthropic as a Microsoft subprocessor where Claude models are on |
| Where does a human approve what AI does? | Annex A, human oversight | Not a platform record: your approval trail for agents and connectors that act | Not a platform record: your approval trail for agents built in Copilot Studio |
| Was the risk assessed before rollout? | Clause 6.1, 6.1.4 impact assessment | Not a platform record | Not a platform record |
The last two rows are the point. Logs show what happened; ISO 42001 asks whether it was meant to. Which Claude plan carries which control is set out in Claude Team vs Enterprise, and how the two platforms compare as products in Copilot vs Claude.
What no vendor closes for you
Buying Enterprise does not buy certification. Four gaps sit between the platform records and a management system that passes Stage 2.
The AI nobody bought centrally
Platform logs cover the seats you pay for. Personal ChatGPT and Claude accounts used for work are outside them, and an inventory that misses them collapses at Stage 2. That is the shadow AI problem, and the fix is an approved tool good enough that people prefer it.
Approval before an agent acts
Connectors and agents that write to your systems need a human approval point and a record that it was used. No vendor console keeps that trail for you.
Assessment before rollout
A risk and impact assessment dated before the tool went live. Most rollouts write it afterwards, and an auditor can tell from the dates.
Evidence across both platforms
Many businesses run Copilot Chat for everyone and Claude for the heaviest users. Two consoles, two record formats, one management system that has to read both.
How we collect it
Monitoring evidence without reading prompts
The Sentry AIOS records usage per person on Claude: who is active, which models and tools, how much and at what cost. That record is Clause 9.1 evidence from the day it switches on, and it is drawn in code, so what it never captures is not a policy promise but a field that is never stored.
- The text of any prompt
- Any answer the AI gives
- The contents of any file
- What a tool was asked to do, or what it returned
Today that evidence is Claude only: every organisation sending the Sentry AIOS live data runs Claude. For Copilot we work from Microsoft's own audit and usage records and build the register, assessments and approval trail around them. More on what usage data shows, and where it stops, is on shadow AI; how a rollout is run is on Claude for business.
Frequently asked questions
Does ISO 42001 apply if we only use Claude or Copilot?
Yes. The standard covers organisations that use AI as well as those that build it. If your people use Claude or Microsoft Copilot for work, those tools belong in your AI inventory, need a risk assessment and a named owner, and Anthropic or Microsoft is a supplier your system has to oversee.
Is using Claude Enterprise or Copilot enough to be ISO 42001 compliant?
No. The platforms supply controls and records, such as single sign-on, audit logs and usage reports, but ISO 42001 certifies your management system: the policy, the risk and impact assessments, the accountability and the evidence that you follow them. A vendor cannot hold that for you.
What evidence does Claude give an ISO 42001 auditor?
Claude Team includes single sign-on, usage analytics and organisation-wide skills. Claude Enterprise adds audit logs, the Compliance API, custom data retention and role-based access. Usage data per person, collected without prompt text, shows who uses Claude, for what kind of work and at what cost over time, which is the operating evidence Clause 9.1 asks for.
What evidence does Microsoft Copilot give an ISO 42001 auditor?
Microsoft records Copilot activity in Microsoft Purview audit and reports Copilot usage in the Microsoft 365 admin centre, under the permissions and retention your tenant already has. Those records answer who used it and when; your management system still has to answer whether that use was approved and assessed.
Does Claude inside Copilot change our ISO 42001 supplier oversight?
It can. Microsoft lists Anthropic as an AI subprocessor and Claude models run inside Copilot for most commercial tenants, so your supplier assessment for Copilot should say which models are on and under whose terms. If Claude is also bought directly, Anthropic is a supplier twice, on two different sets of terms.
Can Sentry AI monitor Copilot use?
Not yet. The Sentry AIOS is built to take any vendor's usage data, but every organisation sending it live data today runs Claude, so that is where our evidence is. For Copilot we work from Microsoft's own audit and usage records and build the register, assessments and approval trail around them.
Want to know how far you are from Stage 2?
Take the free readiness checker first. If the gaps are real, a short call will show you what building the management system involves for a business your size.
Ask an AI about this page
Opens the assistant with this page loaded: read it, summarise it, cite it.