Microsoft SSPA Section K: the AI requirements
If you supply Microsoft and your service involves AI, this is a real deadline with a hard consequence: for new suppliers, work cannot start until the compliance cycle is complete. It is also the clearest evidence available that ISO/IEC 42001 has commercial value entirely independent of the EU AI Act.
Verify the current version before relying on this
Microsoft revises the SSPA Program Guide and the Data Protection Requirements annually. Requirement counts, section contents and assurance rules change between versions. Everything below is as at our last review and should be checked against the current DPR and Program Guide published on Microsoft’s procurement site before you act on it.
What SSPA is
The Supplier Security and Privacy Assurance programme delivers Microsoft’s data processing instructions to its supply base through the Supplier Data Protection Requirements (DPR). Its scope covers suppliers globally that process Personal Data, Microsoft Confidential Data, and/or use AI Systems in connection with their performance under contract.
| Who it binds | Suppliers globally, where the contracted service involves Personal Data, Microsoft Confidential Data or AI Systems |
| The AI section | Section K — AI Systems, applicable to suppliers providing services involving AI |
| Cycle | Annual self-attestation of DPR compliance; some suppliers additionally selected for independent assurance |
| The hard consequence | For new suppliers, work cannot start until the compliance cycle is complete |
| DPR version | Version 12, live 30 March 2026: 63 requirements, down from 67 in v11. Section K carries 18 of them, of which 15 were updated. Two net-new requirements were added across Sections J and K, covering network security and prohibited AI system uses |
| Consequence of failure | Suppliers who cannot evidence compliance are placed in Red Status: a hard block on new Microsoft purchase orders until resolved |
| Supplier types for AI | The Program Guide distinguishes Publishers (develop or own the AI system) from Deployers (use a third-party AI system to deliver their services). Independent assurance applies to both |
Where this usually goes next
Three situations account for most people reading this page. Each has a different answer.
A deal is blocked on an AI questionnaire
Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.
You need ISO/IEC 42001 documentation
23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.
You are not sure what reaches you
Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.
This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →
The part that matters commercially
ISO/IEC 42001 is named as the assurance route
Microsoft accepts ISO/IEC 42001 in lieu of an independent assessment for AI-specific requirements in Section K. For “Sensitive Use” AI, hiring, credit, healthcare, biometrics and similar, ISO/IEC 42001 is required outright, with no alternative. Suppliers providing AI Systems are required to provide independent assurance options, and where an independent assessment against Section K is performed it must be carried out by an assessor from Microsoft’s preferred assessor list.
ISO 27701 for privacy and ISO 27001 for security are relied on the same way in their respective areas.
This is worth stating plainly because it cuts against the framing of most AI governance content, including some of ours in earlier drafts: ISO/IEC 42001 does not satisfy the EU AI Act (and we say so at length), but a major enterprise buyer has named it as the assurance mechanism for AI supplier requirements, with a hard commercial consequence attached.
The EU AI Act deadline for Annex III high-risk moved to December 2027. The SSPA cycle did not. That asymmetry is the entire argument for treating procurement rather than regulation as the driver of AI governance investment.
The Publisher / Deployer split
The Program Guide’s distinction between AI Publishers and AI Deployers parallels the EU AI Act’s provider and deployer roles closely enough to be useful, and not closely enough to be interchangeable.
| SSPA | EU AI Act | |
|---|---|---|
| Builds it | Publisher, develops or owns the AI system | Provider (Art. 3(3)) |
| Uses it | Deployer, uses a third-party AI system to deliver services | Deployer (Art. 3(4)) |
| Assurance | Independent assurance applies to both | Obligations differ substantially by role |
| Trigger | Contractual: you supply Microsoft | Statutory: Art. 2 scope |
Do not map one onto the other in a compliance document. Two regimes, two definitions, two sets of consequences. AI Act roles →
What overlaps with EU AI Act work
Expert analysis. The DPR is a contractual instrument and the AI Act is law; nothing here is a mapping either party has published. But the evidence base overlaps substantially, and organisations building for one should not build twice.
| What both want | Where it comes from |
|---|---|
| An AI system inventory with intended purpose and role | Gates everything in both regimes. Template → |
| Human oversight: the DPR references human-in-command, the ability to supervise the overall activity of the AI system and decide when and how to use it | Closely parallels AI Act Art. 14. Art. 14 → |
| Impact on people, organisations and society | ISO/IEC 42001 impact assessment; AI Act Art. 27 FRIA. FRIA → |
| Prohibited uses: v12 added a requirement on prohibited AI system uses | AI Act Art. 5 analysis. Art. 5 → |
| Supplier and subcontractor governance | ISO/IEC 42001 Annex A third-party controls; AI Act Arts. 23–25 |
What to do if you supply Microsoft
- Establish whether Section K applies. Does your contracted service involve an AI System as SSPA defines it? Check the DPR Definitions section rather than assuming.
- Determine whether you are a Publisher or a Deployer under the Program Guide. Both carry independent assurance requirements.
- Read the current DPR version. Requirement counts and section contents change annually.
- Decide your assurance route. If ISO/IEC 42001 is your path, understand the certification lead time, typically several months of preparation before a two-stage audit, and that an independent assessment against Section K must use a preferred assessor.
- Do not wait for the request. For new suppliers, work cannot start until the cycle completes. That is a revenue timing problem, not a compliance one.
Status labels on this page
Verified fact: That SSPA covers AI Systems in DPR Section K; that DPR v12 refreshed in March 2026 with 63 requirements; that ISO/IEC 42001 is named as an assurance route for Section K and required for AI-sensitive cases; and the Publisher/Deployer distinction in the Program Guide.
Expert analysis: The overlap table with EU AI Act obligations, and the argument that procurement rather than regulation is the durable driver.
Unsettled: Current version specifics. Microsoft revises the DPR and Program Guide annually; verify before acting.
The certification lead time is the constraint
ISO/IEC 42001 preparation typically runs several months before a two-stage certification audit. If a Microsoft engagement depends on it, the timeline works backwards from the contract date, not from the audit date.
Not sure where you sit?
The classifier maps your system against Articles 5, 6, 50 and Annex III. Twelve questions, no email.
Frequently asked
What is Microsoft SSPA Section K?
Section K of the Microsoft Supplier Data Protection Requirements covers AI Systems. It applies to suppliers providing services to Microsoft that involve AI. The SSPA programme, Supplier Security and Privacy Assurance, delivers Microsoft's data processing instructions through the DPR to suppliers working with Personal Data, Microsoft Confidential Data and AI Systems, and drives compliance through an annual cycle. For new suppliers, work cannot start until that cycle is complete.
Does Microsoft require ISO 42001 from suppliers?
Microsoft's SSPA materials state that ISO/IEC 42001 can be offered to validate compliance against Section K of the Data Protection Requirements, and that it is required for AI-sensitive cases. Suppliers providing AI Systems are required to provide independent assurance options, and where an independent assessment against Section K is performed it must be carried out by an assessor from Microsoft's preferred list. ISO 27701 for privacy and ISO 27001 for security are relied on in the same way for their respective areas.
What is the difference between an AI Publisher and an AI Deployer under SSPA?
The SSPA Program Guide distinguishes Publishers, who develop or own the AI system, from Deployers, who use a third-party AI system to deliver their services. Independent assurance requirements apply to both. The distinction closely parallels the provider and deployer roles in the EU AI Act, though the two regimes are separate and the definitions are not identical.
How many requirements are in the Microsoft DPR?
Version 12 of the Data Protection Requirements, which refreshed in March 2026, contains 63 requirements, reduced from 67 in version 11. The changes primarily consolidated and refined the AI system requirements in Section K and added two new requirements covering network security and prohibited AI system uses. Verify the current version before relying on any figure.