Start free trial
AI Governance

Managing and monitoring your EU AI Act compliance with Compliance Manager

Managing and monitoring your EU AI Act compliance with Compliance Manager

We have written before about what Microsoft Purview can, and cannot, solve for the EU AI Act. This time we get hands-on: how to set up an EU AI Act assessment in Microsoft Purview Compliance Manager, where it helps you, and where it falls short.

The business case for Compliance Manager

Securing funding for AI governance is its own challenge. Compliance Manager gives you one practical advantage: it produces evidence stakeholders can see and use.

Auditors ask for evidence, not intentions

“We have DLP policies” is not evidence. An export showing each control, who owns it, when it was tested and what the result was, is. Auditors do not doubt that you have policies. They want to see that someone checked them.

You may already be paying for it

Most tenants have the Microsoft data protection baseline available in Compliance Manager. If your organization also uses Microsoft 365 Copilot or Copilot Chat, check whether additional AI-related assessments or recommendations are already available in your tenant. Showing stakeholders that a starting point may already exist is a persuasive way to open the conversation.

One assessment covers several frameworks

The EU AI Act, ISO/IEC 42001 and the NIST AI framework overlap in several governance areas. Where the same improvement action is mapped across multiple assessments, completing it once can reduce duplicate work, which is a real efficiency argument for anyone who has to justify the effort.

That makes Compliance Manager more than an EU AI Act tool. It becomes a concrete way to justify budget, assign work, and show progress.

The foundation of Compliance Manager

This article cannot cover every Compliance Manager setting, so we focus on the foundation you need before creating an assessment: the building blocks, the roles, and the licensing.

Compliance Manager uses four terms throughout the interface:

  • Assessment: one regulation applied to one or more services. You would create an EU AI Act assessment covering Microsoft 365.
  • Control: a single requirement from that regulation, for example keeping records of AI activity.
  • Improvement action: a task you complete to satisfy a control. Some are technical, some are things you do outside the system, such as writing a policy.
  • Group: a folder holding related assessments. Assessments in the same group share completed work.

Two practical points before you start:

  • Creating and managing assessments requires the appropriate Compliance Manager role: Compliance Manager Administration, Compliance Manager Assessor, or Global Administrator. Microsoft recommends using the role with the fewest permissions, so avoid Global Administrator for this.
  • The EU AI Act assessment template sits under the Premium AI templates area, and availability depends on your organization’s Compliance Manager licensing agreement.

Check whether you already have an assessment

Most tenants have the Microsoft data protection baseline available in Compliance Manager. Be aware that this baseline covers data protection and general data governance, not the EU AI Act specifically. If your organization uses Microsoft 365 Copilot or Copilot Chat, also check whether AI-related assessments or recommendations are available in your tenant. It is still worth opening: several controls may overlap with what an EU AI Act assessment asks for, so you may already have progress to build on. A partly completed assessment is a better starting point than a blank project plan.

The four AI templates

On the regulations page, the AI templates sit under their own heading, Premium AI templates, separate from the other regulations: the EU Artificial Intelligence Act, ISO/IEC 23894:2023, ISO/IEC 42001:2023, and the NIST AI Risk Management Framework (RMF) 1.0.

Compliance Manager's Regulations page, with the Premium AI templates group expanded to show the EU Artificial Intelligence Act, ISO/IEC 23894:2023, ISO/IEC 42001:2023, and NIST AI RMF 1.0, all marked Ready to use.

At the time of writing, check your own tenant before assuming a dedicated template exists for any newly published European AI standard. ISO/IEC 42001 remains the closest management-system-oriented template to use alongside the EU AI Act template.

Managing your assessment

Four topics determine whether your EU AI Act assessment becomes useful, or turns into another compliance dashboard nobody opens: grouping, creating the assessment, improvement actions, and automated evidence from Azure AI Foundry.

Grouping

Spend five minutes on grouping before you create anything. Grouping affects how related assessments share completed work, and changing that structure later is limited. Plan the group as if you need to live with it beyond this single assessment.

Assessments in the same group share completed work, but not all of it in the same way. Technical improvement actions are picked up by assessments across all groups automatically. Non-technical actions, such as writing a policy, training staff or documenting a decision, are only recognized within the group where you complete them.

That distinction is the whole argument for grouping. The EU AI Act, ISO/IEC 42001 and NIST AI RMF overlap most heavily in exactly that non-technical space. Put related AI assessments in one group and you reduce duplicate policy, training and evidence work. Split them across groups and you may need to repeat more of that work than necessary.

Create one group, for example “AI Governance 2026”, and put related AI assessments in it deliberately. Changing the grouping later may not be available in your tenant.

Creating the assessment

From the Assessments page, select Add assessment. The wizard has four screens. Before you start, check the license counter near the top of the page so you know how much capacity remains.

Compliance Manager's Assessments page, showing the free and purchased regulation licence counters above the assessment list.

Do this before you start the wizard. The counter tells you whether you still have free or purchased assessment capacity available, which prevents surprises halfway through setup.

The steps that matter:

  • Base your assessment on a regulation: search for and select the EU Artificial Intelligence Act.
  • Add name and group: give it a unique name, then assign it to the group you planned.
  • Select services: choose what this covers, Microsoft 365, Azure, and others if relevant.
  • Review and finish: check your choices, then create the assessment.

The first screen asks which regulation you are assessing against:

Step one of Compliance Manager's Create assessment wizard, with the EU Artificial Intelligence Act selected from the regulation search results.

The regulation you choose determines the control set and improvement actions Compliance Manager will use. This is where you decide whether the assessment is about the EU AI Act specifically, or part of a broader AI governance framework.

Next, name the assessment and decide the group:

Step two of the wizard, naming the assessment and choosing between an existing or a new assessment group.

This is the most important setup decision. The group affects how related assessments reuse completed work, so create a structure you can reuse beyond this single assessment.

Finally, choose which services the assessment covers:

Step three of the wizard, selecting Microsoft 365 as the service in scope for the assessment.

The services you select determine where Compliance Manager can look for automated signals and where it will rely on manual evidence.

Improvement actions

Once created, you land on the assessment details page. Four tabs matter: Progress, Controls, Your improvement actions, and Microsoft actions.

The Microsoft actions tab is worth showing to nervous stakeholders. It makes the shared responsibility model visible: Microsoft handles part of the work as the platform provider, and your organization owns the rest. That usually makes the remaining list feel manageable.

Think of the Controls tab as the compliance map. It shows where the assessment believes you stand, but the real work starts when you open the linked improvement actions.

The Controls tab for an EU AI Act assessment, with a bar chart breaking down control status by chapter.

Each control has its own detail page. Use that page to understand which actions drive the control status and which work belongs to Microsoft or to your organization.

A control's detail page listing its improvement actions, test status, and the points each contributes toward the score.

The improvement actions tab turns the control view into a worklist. This is where you see the actions that need owners, test results and evidence.

The improvement actions tab for an assessment, showing 0% of actions completed and the full worklist below it.

Use the filters once the list grows. Filtering by service, test status, action type or control family turns the backlog into something owners can prioritize.

The improvement actions worklist filtered by service, status, type and control family, listing individual actions with their points and solution area.

Open an improvement action and you move from assessment to execution. This is where you record implementation, testing, ownership and evidence.

An individual improvement action's detail page, showing its owner, implementation status, test status, service and testing source.

This screen turns the assessment from a dashboard into an operating model. If owners, test results and evidence are missing here, the score may improve on paper but remain weak during an audit. Start with the five failing controls worth the most points. That is the fastest route to a stronger score and a more defensible position.

Automated evidence from Azure AI Foundry

This section only applies if your organization builds or hosts its own AI models in Azure AI Foundry.

Agents built in Copilot Studio run on Microsoft’s models by default, so Microsoft carries responsibility for how the model itself performs. The same applies to Microsoft 365 Copilot. If that describes you, skip ahead to the “Monitoring your AI compliance” section below.

If you are still reading, your organization likely builds or hosts AI workloads in Azure AI Foundry. In supported configurations, Microsoft Purview can use Foundry-related signals to help manage security and compliance for AI interactions, including Compliance Manager recommendations and regulatory control mappings.

To use these capabilities, make sure the required Purview and Foundry integration settings are enabled and that the relevant administrators have the required Foundry or Azure permissions. Role names are changing in this area, so verify the current names and permissions in Microsoft Learn and in your Azure tenant.

The Act expects high-risk AI systems to be accurate and perform consistently. A paragraph about taking accuracy seriously does not satisfy that. Automated measurements are stronger: they give you repeatable evidence against the relevant control.

Commercial terms in this area change quickly, so confirm the current licensing and any trial conditions in your own tenant before you budget for it.

Monitoring your AI compliance

Sharing with auditors

We advise giving auditors access to a single assessment, not to everything. Open the assessment, then in the upper-right corner select Manage user access. A flyout pane appears with three tabs:

  • Readers: view the assessment without changing anything.
  • Assessors: view and edit test data.
  • Contributors: view and edit assessment data.

External auditors can be added the same way once they have a Microsoft Entra account.

The Manage user access pane for an assessment, with the Readers, Assessors and Contributors tabs and an Add readers action.

Administrators whose permissions come from Entra roles, such as Global Administrator or Compliance Administrator, do not appear on this screen, so it is not a complete list of everyone who can see the assessment.

A user can only hold one assessment-based role at a time. If an auditor needs to move from Reader to Contributor, remove the first role before assigning the second.

Exporting your evidence

Select Export actions to generate an Excel file with the controls, owners, implementation status, testing dates and results. This is a practical evidence package people will ask for, but it is not a complete audit file by itself.

The assessment's action menu, showing Download as report, Export actions, Download evidence, Update actions and other assessment-level options.

Use the export alongside policies, meeting decisions, screenshots, test notes and other evidence that explains why each status is defensible.

Date the export, store it in a retained location, and repeat it on a schedule; quarterly works well. By December 2027, those exports tell a stronger story, not a last-minute compliance claim, but a record of continuous control improvement.

Deleting an assessment is permanent, and any improvement actions that appear in no other assessment are deleted with it. Export a report before you delete anything. You also cannot delete all your assessments, because Compliance Manager needs at least one to function.

Template updates

Microsoft updates templates as regulations change, and you may see a Pending update notification when regulatory content or control mappings change. Before relying on the EU AI Act template for a formal compliance position, check whether it has been updated to reflect the July 2026 amendments. Accepting an update is permanent, so if you are mid-assessment it is reasonable to finish the current round first. Updates apply per group: the same template in two groups produces two notifications, and you accept each one separately.

Where the Compliance Manager score can mislead you

Everything above is useful. The danger is the score. Scores look objective, so it is worth being precise about what this one does not prove.

It records what people say they did

Some technical actions pick up signal from your Microsoft 365 configuration. Many are only someone’s own record that they did something. Nothing checks whether the agent published last Tuesday follows the control you marked complete six weeks ago.

A green assessment means the tasks were marked complete. It does not mean your AI estate is compliant.

It does not know your agents exist

This is the critical limitation. When you create an assessment, you scope it to services such as Microsoft 365 or Azure. Compliance Manager may surface AI app or agent assessments in eligible tenants, but it is not a substitute for your own AI system inventory. It will not automatically give you a complete register of every published agent, its owner, purpose, data access, and risk classification.

Your EU AI Act assessment therefore describes evidence for selected services and controls. It does not automatically describe every AI system your organization deploys. The Act’s obligations attach to systems and roles: provider, deployer, or another regulated actor. If your evidence is tenant-wide but your real AI estate is hundreds of separately configured agents with different data access and no review process, the assessment can be accurate and still miss the risk.

It looks more complete than it is

The four tabs and the score suggest full coverage. They do not provide it, and the gaps are not obvious from the interface.

Compliance Manager will not decide risk levels for you. Whether an agent is high-risk depends on what it is used for, not what data it reaches, and that judgment sits with people who understand the business.

It will not find what it was never told about: the agent nobody registered, the AI project running on someone’s Azure subscription, the tool a department signed up for on a credit card. None of it appears, and nothing indicates that something is missing.

And it will not confirm that your agents disclose themselves. No control by itself proves users are told they are interacting with AI. Article 50 transparency obligations apply from 2 August 2026, with specific transition rules for certain machine-readable marking duties.

This makes the assessment narrower than it looks, which is the more dangerous problem, because a narrow assessment still produces a confident score.

Ownership and adoption

The main challenge with Compliance Manager is ownership. It looks like an IT tool, but many improvement actions are legal, HR or business work: writing a policy, training staff, documenting a decision, approving a process.

Set up a meeting with the stakeholders, go over the improvement action list together, and assign owners immediately. This works far better than emailing a link and hoping the right people understand and pick up the ask.

Microsoft does provide training materials. The Explore compliance in Microsoft 365 module covers the dashboard, improvement actions and the compliance score, and Manage compliance with Microsoft Purview for Microsoft 365 Copilot covers the AI side. Point your administrators there.

What you will not find is material aimed at the people who own most of the work. Nothing explains to a legal or HR colleague what is expected of them when an improvement action lands in their name. That explanation is your responsibility, so plan for it.

A note from Rencore

Everything above points at the same hole: Compliance Manager tells you how well you are managing the AI systems you have told it about. It has no way to tell you which AI systems exist.

That is where Rencore fits, deliberately so. Microsoft Purview focuses on the data: classification, DLP, sensitivity labels, regulatory mappings. Rencore focuses on the services and systems that touch that data. It discovers every Copilot Studio agent, SharePoint-embedded agent, declarative agent, and Azure AI Foundry deployment across the tenant, whether or not anyone registered it. The two are built to work side by side, not to replace each other.

That discovery becomes the AI system inventory Article 6 to 11 of the EU AI Act assumes you already have. Every agent gets an owner, a risk score based on audience exposure and data sensitivity, and a policy check: unauthenticated agents touching SharePoint, agents shared with hundreds of users pulling from the open web, agents nobody has reviewed in three months. High-risk agents can be flagged for review or unpublished automatically, with the trail to prove it.

That inventory also fixes the ownership problem from the previous section. Instead of a meeting and a spreadsheet, each agent lands with a named owner, a lifecycle status, and an audit history, so “who owns this improvement action” stops being a question you re-ask every quarter.

One customer’s Copilot Studio rollout had surfaced over 50 unsanctioned agents before anyone had a full inventory. Twelve turned out to be high-risk. That is the scenario Compliance Manager’s score cannot see. It is the one Rencore is built to catch.

Conclusion

Compliance Manager turns scattered settings, improvement actions and evidence into something stakeholders and auditors can inspect. It structures the work, assigns ownership, monitors progress and exports evidence over time. Depending on your licensing and tenant configuration, it can also provide ready-made assessment templates, AI-related recommendations and, in some scenarios, signals from Azure AI Foundry.

But the score is not the governance model. A completed assessment does not automatically prove that every AI system is registered, risk classified, reviewed, tested and monitored. That still depends on your inventory, ownership model, policies, decision logs and operating processes.

Use Compliance Manager as the evidence engine, not the source of truth. It can show progress and make compliance work visible. Proving that your AI systems are governed is still your organization’s job.

Common questions on this

Is the EU AI Act assessment template included in our Microsoft 365 licence?
Not automatically. The EU AI Act template sits under the Premium AI templates heading on the Regulations page, next to ISO/IEC 23894:2023, ISO/IEC 42001:2023 and the NIST AI Risk Management Framework 1.0, and whether you can use it depends on your organization's Compliance Manager licensing agreement. Most tenants do have the Microsoft data protection baseline available, but that baseline covers data protection and general data governance rather than the EU AI Act specifically. Check the free and purchased regulation counters at the top of the Assessments page before you open the wizard, so you know what capacity is left.
Who is allowed to create an EU AI Act assessment, and who ends up owning the work?
Creating and managing assessments needs one of the Compliance Manager roles: Compliance Manager Administration, Compliance Manager Assessor or Global Administrator. Microsoft's own advice is to use the role with the fewest permissions, which makes Global Administrator the wrong choice for this. Ownership of the work is a second question and it is the one that catches people out. Many improvement actions are legal, HR or business tasks such as writing a policy, training staff or documenting a decision, so the list does not belong to IT alone. Walk through it in a meeting and assign named owners on the spot rather than emailing a link.
Does a completed EU AI Act assessment prove we are compliant?
No. A green assessment means the tasks were marked complete. Some technical improvement actions pick up signal from your Microsoft 365 configuration, but many are simply one person's own record that they did something, and nothing rechecks them afterwards. An agent published last Tuesday is never measured against a control someone marked complete six weeks ago. Compliance Manager also will not classify risk for you, because whether an AI system is high risk depends on what it is used for rather than what data it can reach, and that judgment belongs to people who understand the business.
Does Compliance Manager know which AI agents exist in our tenant?
No, and this is the gap that matters most. You scope an assessment to services such as Microsoft 365 or Azure. Eligible tenants may see AI app or agent assessments appear, but that is not a register of every published agent with its owner, purpose, data access and risk classification, and nothing in the interface indicates that something is missing. Rencore discovers every Copilot Studio agent, SharePoint-embedded agent, declarative agent and Azure AI Foundry deployment across the tenant whether or not anyone registered it, and gives each one a named owner and a lifecycle status, which is the AI system inventory Articles 6 to 11 of the EU AI Act assume you already keep.
Do we have to tell people they are interacting with AI, and does Compliance Manager prove that we do?
Article 50 transparency obligations under the EU AI Act apply from 2 August 2026, with specific transition rules for certain machine-readable marking duties, so disclosure is a question for this year rather than a future one. Compliance Manager does not answer it. No control by itself confirms that every agent your organization has published tells its users they are talking to AI, because the assessment records evidence for the services you scoped, not the behaviour of each individual agent. That proof only comes from checking the agents themselves, which means starting from a list of all of them.
We already use Microsoft Purview for data governance. What does that not cover for the EU AI Act?
Purview works on the data: classification, data loss prevention, sensitivity labels and regulatory mappings. Compliance Manager turns that into assessments, controls, improvement actions and an evidence export auditors can read. What neither one tracks is the services and systems that touch the data, so questions like who owns this agent, whether it is still in use and who reviewed it last stay open. Rencore covers that second half, extending Purview rather than standing in for it, and the two are built to run side by side.

Last updated 24 August 2026

Related articles

Rencore newsletter

Subscribe to our newsletter

Get the latest Microsoft 365 governance insights delivered to your inbox.

Loading form