# ISO 42001 for Claude and Microsoft Copilot Rollouts

> What an ISO/IEC 42001 auditor asks a business that runs Claude or Microsoft Copilot, which platform records answer which clause, and the gaps no vendor closes for you.

- Canonical: https://sentrysolutions.ai/iso-42001/claude-and-copilot

# ISO 42001 for Claude and Microsoft Copilot.

Your people already use Claude or Copilot, so ISO 42001 already applies to them. What an auditor will ask, which platform records answer it, and the gaps no vendor closes for you.

[The evidence map](#evidence) [What vendors leave to you](#gaps)

The short answer

ISO/IEC 42001 applies to businesses that use AI, not only those that build it, so a Claude or Microsoft Copilot rollout is in scope. The platforms supply records an auditor will accept as part of the evidence: single sign-on and usage analytics on Claude Team, audit logs and the Compliance API on Claude Enterprise, and Copilot activity in Microsoft Purview audit. They do not supply the management system: the AI inventory, the risk and impact assessments dated before rollout, supplier oversight of Anthropic and Microsoft, and the approval trail for agents that act. Those are yours to build, and they are what Stage 2 inspects.

## What the auditor asks, and what answers it

Six questions every Stage 2 auditor will put to a business running Claude or Copilot, the clause each comes from, and the platform record that answers it. The mapping is ours, from building these systems; the controls are the vendors' own.

The question

Where it comes from

Claude

Microsoft Copilot

Which AI is in use, and who owns it?

Clause 6, Annex A inventory

Seat lists, connectors and skills from the admin console; usage per person shows what is actually used

Licence assignment in the Microsoft 365 admin centre; Copilot usage reports

Who used it, and when?

Clause 9.1, monitoring

Usage analytics on Team; audit logs and the Compliance API on Enterprise

Copilot activity in Microsoft Purview audit

What data may go in, and is that enforced?

Annex A, data for AI systems

Org instructions, connector admin controls; custom retention on Enterprise

Your tenant's existing permissions, sensitivity labels and retention

Who are your AI suppliers, and on what terms?

Annex A, third parties

Anthropic, on its commercial terms

Microsoft, and Anthropic as a Microsoft subprocessor where Claude models are on

Where does a human approve what AI does?

Annex A, human oversight

Not a platform record: your approval trail for agents and connectors that act

Not a platform record: your approval trail for agents built in Copilot Studio

Was the risk assessed before rollout?

Clause 6.1, 6.1.4 impact assessment

Not a platform record

Not a platform record

The last two rows are the point. Logs show what happened; ISO 42001 asks whether it was meant to. Which Claude plan carries which control is set out in [Claude Team vs Enterprise](https://sentrysolutions.ai/claude-for-business/team-vs-enterprise), and how the two platforms compare as products in [Copilot vs Claude](https://sentrysolutions.ai/compare/copilot-vs-claude).

## What no vendor closes for you

Buying Enterprise does not buy certification. Four gaps sit between the platform records and a management system that passes Stage 2.

### The AI nobody bought centrally

Platform logs cover the seats you pay for. Personal ChatGPT and Claude accounts used for work are outside them, and an inventory that misses them collapses at Stage 2. That is the shadow AI problem, and the fix is an approved tool good enough that people prefer it.

### Approval before an agent acts

Connectors and agents that write to your systems need a human approval point and a record that it was used. No vendor console keeps that trail for you.

### Assessment before rollout

A risk and impact assessment dated before the tool went live. Most rollouts write it afterwards, and an auditor can tell from the dates.

### Evidence across both platforms

Many businesses run Copilot Chat for everyone and Claude for the heaviest users. Two consoles, two record formats, one management system that has to read both.

How we collect it

## Monitoring evidence without reading prompts

The Sentry AIOS records usage per person on Claude: who is active, which models and tools, how much and at what cost. That record is Clause 9.1 evidence from the day it switches on, and it is drawn in code, so what it never captures is not a policy promise but a field that is never stored.

Never captured

-   The text of any prompt
-   Any answer the AI gives
-   The contents of any file
-   What a tool was asked to do, or what it returned

Today that evidence is Claude only: every organisation sending the [Sentry AIOS](https://sentrysolutions.ai/ai-operating-system) live data runs Claude. For Copilot we work from Microsoft's own audit and usage records and build the register, assessments and approval trail around them. More on what usage data shows, and where it stops, is on [shadow AI](https://sentrysolutions.ai/shadow-ai); how a rollout is run is on [Claude for business](https://sentrysolutions.ai/claude-for-business).

More on ISO 42001

-   [ISO/IEC 42001 explained, with the readiness checker](https://sentrysolutions.ai/iso-42001)
-   [ISO 42001 certification in Australia and NZ](https://sentrysolutions.ai/iso-42001/certification)
-   [ISO 42001 vs the NIST AI RMF](https://sentrysolutions.ai/iso-42001/vs-nist-ai-rmf)
-   [AI governance, the service](https://sentrysolutions.ai/ai-governance)

## Frequently asked questions

### Does ISO 42001 apply if we only use Claude or Copilot?

Yes. The standard covers organisations that use AI as well as those that build it. If your people use Claude or Microsoft Copilot for work, those tools belong in your AI inventory, need a risk assessment and a named owner, and Anthropic or Microsoft is a supplier your system has to oversee.

### Is using Claude Enterprise or Copilot enough to be ISO 42001 compliant?

No. The platforms supply controls and records, such as single sign-on, audit logs and usage reports, but ISO 42001 certifies your management system: the policy, the risk and impact assessments, the accountability and the evidence that you follow them. A vendor cannot hold that for you.

### What evidence does Claude give an ISO 42001 auditor?

Claude Team includes single sign-on, usage analytics and organisation-wide skills. Claude Enterprise adds audit logs, the Compliance API, custom data retention and role-based access. Usage data per person, collected without prompt text, shows who uses Claude, for what kind of work and at what cost over time, which is the operating evidence Clause 9.1 asks for.

### What evidence does Microsoft Copilot give an ISO 42001 auditor?

Microsoft records Copilot activity in Microsoft Purview audit and reports Copilot usage in the Microsoft 365 admin centre, under the permissions and retention your tenant already has. Those records answer who used it and when; your management system still has to answer whether that use was approved and assessed.

### Does Claude inside Copilot change our ISO 42001 supplier oversight?

It can. Microsoft lists Anthropic as an AI subprocessor and Claude models run inside Copilot for most commercial tenants, so your supplier assessment for Copilot should say which models are on and under whose terms. If Claude is also bought directly, Anthropic is a supplier twice, on two different sets of terms.

### Can Sentry AI monitor Copilot use?

Not yet. The Sentry AIOS is built to take any vendor's usage data, but every organisation sending it live data today runs Claude, so that is where our evidence is. For Copilot we work from Microsoft's own audit and usage records and build the register, assessments and approval trail around them.

## Want to know how far you are from Stage 2?

Take the free readiness checker first. If the gaps are real, a short call will show you what building the management system involves for a business your size.

[Take the readiness checker](https://sentrysolutions.ai/iso-42001#readiness-checker) [Book a call](https://calendly.com/james-sentry-ai)

Ask an AI about this page

[ChatGPT](https://chatgpt.com/?q=Read%20https%3A%2F%2Fsentrysolutions.ai%2Fiso-42001%2Fclaude-and-copilot%20and%20summarise%20what%20Sentry%20AI%20says%20about%20what%20ISO%2042001%20requires%20of%20a%20business%20using%20Claude%20or%20Microsoft%20Copilot.%20Cite%20the%20page.)[Claude](https://claude.ai/new?q=Read%20https%3A%2F%2Fsentrysolutions.ai%2Fiso-42001%2Fclaude-and-copilot%20and%20summarise%20what%20Sentry%20AI%20says%20about%20what%20ISO%2042001%20requires%20of%20a%20business%20using%20Claude%20or%20Microsoft%20Copilot.%20Cite%20the%20page.)[Perplexity](https://www.perplexity.ai/search/new?q=Read%20https%3A%2F%2Fsentrysolutions.ai%2Fiso-42001%2Fclaude-and-copilot%20and%20summarise%20what%20Sentry%20AI%20says%20about%20what%20ISO%2042001%20requires%20of%20a%20business%20using%20Claude%20or%20Microsoft%20Copilot.%20Cite%20the%20page.)[Google AI Mode](https://www.google.com/search?udm=50&q=Read%20https%3A%2F%2Fsentrysolutions.ai%2Fiso-42001%2Fclaude-and-copilot%20and%20summarise%20what%20Sentry%20AI%20says%20about%20what%20ISO%2042001%20requires%20of%20a%20business%20using%20Claude%20or%20Microsoft%20Copilot.%20Cite%20the%20page.)

Opens the assistant with this page loaded: read it, summarise it, cite it.
