Microsoft's Supplier Security & Privacy Assurance (SSPA) Data Protection Requirements v12 accepts ISO/IEC 42001 in lieu of an independent Section K assessment for general AI services, and requires ISO 42001 certification for suppliers delivering "Sensitive Use" AI. For Microsoft suppliers in scope, this is the most consequential AI governance development of 2026.
Microsoft released SSPA DPR v12 on 30 March 2026. The changes most relevant to AI suppliers are:
For AI Systems in scope of Section K, Microsoft suppliers have two options:
Microsoft defines Sensitive Use AI as systems whose reasonably foreseeable use or misuse could affect an individual through consequential impact on legal position or life opportunities, physical or psychological harm, or significant impact on human rights. Examples include AI in hiring, credit, insurance, healthcare diagnosis, law enforcement, education access, public benefits, and biometric identification.
For suppliers delivering Sensitive Use AI services, Microsoft removes the choice, ISO 42001 certification is required. Option A is not available. This is the strongest signal yet that Microsoft has operationalised ISO 42001 as the de facto AI governance standard in its supply chain.
An Independent Assessment of Section K by a Microsoft Preferred Assessor typically runs $15,000–$30,000 per annual cycle. An ISO 42001 certification covers the same Section K obligation, plus enterprise customer questionnaire responses, plus EU AI Act readiness alignment, for a comparable or lower total cost over a 3-year cycle. For Sensitive Use AI suppliers, ISO 42001 is not a cost saving, it's the only path.
The Professional tier includes PRO-SSPA_Section_K_Mapping.docx, a dedicated artefact that maps every Section K requirement in DPR v12 to the corresponding ISO 42001 clauses, Annex A controls, and toolkit evidence locations. The mapping document is structured in three columns:
If your organisation is a Microsoft supplier, meaning Microsoft is a direct customer, or you provide services that process Microsoft-furnished data or deliver AI capabilities into Microsoft-managed workflows, SSPA is a contractual obligation. Attestation cycles happen annually; failures can put contracts at risk.
Typical SSPA-relevant suppliers include: SaaS providers integrated with Microsoft 365, Copilot, or Power Platform; ISVs in the Microsoft Cloud Partner Program; outsourcing / BPO providers processing Microsoft customer data; consultancies providing AI-implementation services where Microsoft data is in scope.
For SSPA-bound suppliers:
SSPA DPR revisions are Microsoft's to issue. The v12 details above reflect Microsoft's public documentation as of the toolkit's April 2026 edition. Always verify against the current DPR text at the Microsoft SSPA portal. The toolkit's 24-month update window covers material DPR revisions.