Australian Compliance for Microsoft 365 Copilot and AI
TL;DR: Microsoft 365 Copilot inherits your existing Microsoft 365 controls, so Australian compliance starts with the tenant you already run. Skills in this library read that tenant and produce evidence for Essential Eight, ISM, PSPF, IRAP and APRA CPS 234 work. They do not certify anything.
Does Microsoft 365 Copilot inherit our Australian compliance posture?
Microsoft 365 Copilot operates within your existing Microsoft 365 apps, so Microsoft Learn states it inherits your existing Essential Eight controls and posture. The same guidance says Microsoft Purview configuration is not a prerequisite for Copilot, but strengthens your security posture. Your tenant configuration is therefore the compliance surface.
Microsoft’s Copilot guidance for sensitive and regulated customers describes an IRAP assessment of Microsoft 365 with Microsoft Copilot, assessed to store information at the Protected level. It also says introducing Copilot requires specific configuration. Under the AI Shared Responsibility Model, Microsoft splits responsibility into customer, Microsoft and shared items, so you own the configuration decisions and the evidence for them.
This guide covers what the skills here can evidence. It does not restate the frameworks themselves.
What do these skills produce, and what do they not?
Skills in this library are read-only unless a page names exactly what it changes. They produce evidence: ranked findings, control mappings and remediation lists. They do not certify compliance, replace an IRAP assessor, or give legal advice. Microsoft’s own compliance pages say your organisation is wholly responsible for compliance with applicable laws and regulations.
- Evidence, not certification: an assessor, regulator or your accountable officer makes the decision.
- Point in time: Microsoft notes Essential Eight assessment using its guides is a point-in-time activity, so re-run skills to show drift.
- Read-only by default: review each skill page for the roles and permissions it needs.
See What is an AI skill? for how the library works.
Which Australian frameworks apply to Copilot, and to whom?
The frameworks apply to different organisations. Match your obligations first, then choose skills. The table below records only what the opened sources state.
| Framework | Who it applies to, per opened sources | Source |
|---|---|---|
| Essential Eight | Recommended baseline for all Australian organisations. Maturity Level 2 is mandatory for non-corporate Commonwealth entities subject to the PGPA Act. | Microsoft Learn |
| ISM | Australian Government Information Security Manual. IRAP assessments check its controls, and the Purview guide aligns with it. | Microsoft Learn |
| PSPF | Protective Security Policy Framework. Microsoft’s Purview guide aligns with it for government organisations. | Microsoft Learn |
| IRAP | Applies to Australian federal, state and local government agencies that use cloud services. | Microsoft Learn |
| APRA CPS 234 | Requires regulated institutions to define roles, maintain security capability, protect and test controls, and promptly notify APRA of material incidents. | Microsoft Learn |
| SOCI Act | Not summarised here. Not covered by the sources cited on this page. See the skill page. | Not cited |
| Privacy Act | Not summarised here. Not covered by the sources cited on this page. See the skill page. | Not cited |
What should we have in place before running the skills?
The skills need reviewer access and licences, and each skill page lists its own. A common baseline:
- A Microsoft 365 tenant with Microsoft 365 Copilot licences assigned or planned.
- Read-only reviewer roles, as listed on each skill page such as ISM Control Pack.
- Microsoft Purview auditing switched on, so Copilot activity can be evidenced.
- A named owner for each framework, so findings have someone accountable.
- An agreed evidence folder and naming convention for outputs.
How do Essential Eight controls apply to Microsoft 365 Copilot?
The Essential Eight has eight mitigation strategies: application control, patch applications, Microsoft Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multifactor authentication and regular backups. Microsoft Learn states Copilot inherits the posture you already have, and does not operate on macro-enabled Office documents.
Microsoft also says Purview Compliance Manager has Essential Eight premium templates at all three maturity levels to monitor drift. Skills here that produce Essential Eight evidence include the Essential Eight Maturity Self-Assessment, Essential Eight ML3 Uplift and Essential Eight Evidence Packager.
How do ISM, PSPF and IRAP evidence differ?
The ISM is the Information Security Manual, PSPF is the Protective Security Policy Framework, and IRAP is the independent assessment process. Microsoft Learn describes IRAP as an independent assessment of a system’s security against Australian government policies, administered by the Australian Cyber Security Centre. Learn also says you engage an assessor for your own implementation and processes.
That means Microsoft’s assessment covers Microsoft’s platform, while your tenant configuration is yours to evidence. Use ISM Control Pack, PSPF Control Mapping, IRAP Control Evidence and IRAP Evidence Trail.
What does APRA CPS 234 mean for a regulated entity using Copilot?
CPS 234 requires regulated institutions to protect information assets, test controls and promptly notify APRA of material information security incidents. Microsoft Learn says CPS 234 mirrors a protect, detect and respond model. The APRA CPS 234 Readiness skill maps tenant controls against those obligations and scores readiness. Learn also lists an APRA CPS premium template in Compliance Manager.
What about SOCI and the Privacy Act?
For critical infrastructure incident notification, SOCI Incident Responder drafts the structured notification brief. For automated decisions affecting individuals, Privacy Act ADM Logger produces a decision log. Both are drafting and logging aids. Confirm obligations with the Act, the regulator and your legal advisers. This guide does not state their requirements.
Which skills produce evidence for which framework?
| Framework | Skills that produce evidence |
|---|---|
| Essential Eight | Essential Eight Maturity Self-Assessment, Essential Eight ML3 Uplift, Essential Eight Evidence Packager, Defender ASR Config Assessment, MFA Strong Auth Coverage Audit, Intune Device Compliance Baseline Gap |
| ISM | ISM Control Pack, Audit Log Retention Validator, DSPM for AI Remediation |
| PSPF | PSPF Control Mapping, Purview Label Coverage, Tenant DLP Coverage Audit |
| IRAP | IRAP Control Evidence, IRAP Evidence Trail |
| APRA CPS 234 | APRA CPS 234 Readiness |
| SOCI | SOCI Incident Responder |
| Privacy Act | Privacy Act ADM Logger |
| Cross-framework | Compliance Manager Control Mapper |
What should we run first, and why?
Run in this order. Each step feeds the next, and Copilot-specific steps come after the tenant foundation.
- Copilot Readiness Assessment to score whether the tenant is ready and what to fix first.
- Essential Eight Maturity Self-Assessment to establish the baseline Copilot inherits.
- MFA Strong Auth Coverage Audit, Defender ASR Config Assessment and Intune Device Compliance Baseline Gap to evidence the identity and device controls.
- SharePoint Oversharing Audit and Restricted SharePoint Search Readiness because Copilot inherits the Microsoft 365 permission model, so existing oversharing carries into Copilot.
- DSPM for AI Remediation, Purview Label Coverage, Tenant DLP Coverage Audit and Copilot DLP Impact Simulation to protect sensitive data before enforcement.
- Audit Log Retention Validator and Retention and Records Audit to confirm Copilot activity is captured and kept.
- Copilot Interaction Compliance Audit and Purview AI Activity Explorer to find where prompts and responses touched sensitive data.
- Shadow AI App Discovery to find unsanctioned AI applications.
- ISM Control Pack and PSPF Control Mapping to map configuration to controls.
- APRA CPS 234 Readiness, if you are an APRA-regulated entity.
- IRAP Control Evidence, then IRAP Evidence Trail and Essential Eight Evidence Packager to organise artefacts for an assessor.
- Compliance Manager Control Mapper to rank remaining gaps across frameworks.
- Privacy Act ADM Logger and SOCI Incident Responder where they apply to you.
Where should you read next?
- Copilot readiness guide covers fixing oversharing before rollout.
- Copilot governance guide covers Microsoft Purview guardrails and monitoring.
- Agent governance guide covers governing agents once Copilot is live.
- What is an AI skill? explains how this library works.
Sources
- ACSC Essential Eight (Microsoft Learn)
- Microsoft Purview Information Protection Guide for the Australian Government (Microsoft Learn)
- Microsoft Copilot guidance for Sensitive and Regulated customers (Microsoft Learn)
- Australian Government Information Security Registered Assessor Program (IRAP) (Microsoft Learn)
- Australian Prudential Regulation Authority (APRA) (Microsoft Learn)
Licensed under CC BY 4.0 by EDUC4TE .
Last reviewed 2026-09-30