Managing and monitoring your EU AI Act compliance with Compliance Manager

We have written before about what Microsoft Purview can, and cannot, solve for the EU AI Act. This time we get hands-on: how to set up an EU AI Act assessment in Microsoft Purview Compliance Manager, where it helps you, and where it falls short.
The business case for Compliance Manager
Securing funding for AI governance is its own challenge. Compliance Manager gives you one practical advantage: it produces evidence stakeholders can see and use.
Auditors ask for evidence, not intentions
“We have DLP policies” is not evidence. An export showing each control, who owns it, when it was tested and what the result was, is. Auditors do not doubt that you have policies. They want to see that someone checked them.
You may already be paying for it
Most tenants have the Microsoft data protection baseline available in Compliance Manager. If your organization also uses Microsoft 365 Copilot or Copilot Chat, check whether additional AI-related assessments or recommendations are already available in your tenant. Showing stakeholders that a starting point may already exist is a persuasive way to open the conversation.
One assessment covers several frameworks
The EU AI Act, ISO/IEC 42001 and the NIST AI framework overlap in several governance areas. Where the same improvement action is mapped across multiple assessments, completing it once can reduce duplicate work, which is a real efficiency argument for anyone who has to justify the effort.
That makes Compliance Manager more than an EU AI Act tool. It becomes a concrete way to justify budget, assign work, and show progress.
The foundation of Compliance Manager
This article cannot cover every Compliance Manager setting, so we focus on the foundation you need before creating an assessment: the building blocks, the roles, and the licensing.
Compliance Manager uses four terms throughout the interface:
- Assessment: one regulation applied to one or more services. You would create an EU AI Act assessment covering Microsoft 365.
- Control: a single requirement from that regulation, for example keeping records of AI activity.
- Improvement action: a task you complete to satisfy a control. Some are technical, some are things you do outside the system, such as writing a policy.
- Group: a folder holding related assessments. Assessments in the same group share completed work.
Two practical points before you start:
- Creating and managing assessments requires the appropriate Compliance Manager role: Compliance Manager Administration, Compliance Manager Assessor, or Global Administrator. Microsoft recommends using the role with the fewest permissions, so avoid Global Administrator for this.
- The EU AI Act assessment template sits under the Premium AI templates area, and availability depends on your organization’s Compliance Manager licensing agreement.
Check whether you already have an assessment
Most tenants have the Microsoft data protection baseline available in Compliance Manager. Be aware that this baseline covers data protection and general data governance, not the EU AI Act specifically. If your organization uses Microsoft 365 Copilot or Copilot Chat, also check whether AI-related assessments or recommendations are available in your tenant. It is still worth opening: several controls may overlap with what an EU AI Act assessment asks for, so you may already have progress to build on. A partly completed assessment is a better starting point than a blank project plan.
The four AI templates
On the regulations page, the AI templates sit under their own heading, Premium AI templates, separate from the other regulations: the EU Artificial Intelligence Act, ISO/IEC 23894:2023, ISO/IEC 42001:2023, and the NIST AI Risk Management Framework (RMF) 1.0.

At the time of writing, check your own tenant before assuming a dedicated template exists for any newly published European AI standard. ISO/IEC 42001 remains the closest management-system-oriented template to use alongside the EU AI Act template.
Managing your assessment
Four topics determine whether your EU AI Act assessment becomes useful, or turns into another compliance dashboard nobody opens: grouping, creating the assessment, improvement actions, and automated evidence from Azure AI Foundry.
Grouping
Spend five minutes on grouping before you create anything. Grouping affects how related assessments share completed work, and changing that structure later is limited. Plan the group as if you need to live with it beyond this single assessment.
Assessments in the same group share completed work, but not all of it in the same way. Technical improvement actions are picked up by assessments across all groups automatically. Non-technical actions, such as writing a policy, training staff or documenting a decision, are only recognized within the group where you complete them.
That distinction is the whole argument for grouping. The EU AI Act, ISO/IEC 42001 and NIST AI RMF overlap most heavily in exactly that non-technical space. Put related AI assessments in one group and you reduce duplicate policy, training and evidence work. Split them across groups and you may need to repeat more of that work than necessary.
Create one group, for example “AI Governance 2026”, and put related AI assessments in it deliberately. Changing the grouping later may not be available in your tenant.
Creating the assessment
From the Assessments page, select Add assessment. The wizard has four screens. Before you start, check the license counter near the top of the page so you know how much capacity remains.

Do this before you start the wizard. The counter tells you whether you still have free or purchased assessment capacity available, which prevents surprises halfway through setup.
The steps that matter:
- Base your assessment on a regulation: search for and select the EU Artificial Intelligence Act.
- Add name and group: give it a unique name, then assign it to the group you planned.
- Select services: choose what this covers, Microsoft 365, Azure, and others if relevant.
- Review and finish: check your choices, then create the assessment.
The first screen asks which regulation you are assessing against:

The regulation you choose determines the control set and improvement actions Compliance Manager will use. This is where you decide whether the assessment is about the EU AI Act specifically, or part of a broader AI governance framework.
Next, name the assessment and decide the group:

This is the most important setup decision. The group affects how related assessments reuse completed work, so create a structure you can reuse beyond this single assessment.
Finally, choose which services the assessment covers:

The services you select determine where Compliance Manager can look for automated signals and where it will rely on manual evidence.
Improvement actions
Once created, you land on the assessment details page. Four tabs matter: Progress, Controls, Your improvement actions, and Microsoft actions.
The Microsoft actions tab is worth showing to nervous stakeholders. It makes the shared responsibility model visible: Microsoft handles part of the work as the platform provider, and your organization owns the rest. That usually makes the remaining list feel manageable.
Think of the Controls tab as the compliance map. It shows where the assessment believes you stand, but the real work starts when you open the linked improvement actions.

Each control has its own detail page. Use that page to understand which actions drive the control status and which work belongs to Microsoft or to your organization.

The improvement actions tab turns the control view into a worklist. This is where you see the actions that need owners, test results and evidence.

Use the filters once the list grows. Filtering by service, test status, action type or control family turns the backlog into something owners can prioritize.

Open an improvement action and you move from assessment to execution. This is where you record implementation, testing, ownership and evidence.

This screen turns the assessment from a dashboard into an operating model. If owners, test results and evidence are missing here, the score may improve on paper but remain weak during an audit. Start with the five failing controls worth the most points. That is the fastest route to a stronger score and a more defensible position.
Automated evidence from Azure AI Foundry
This section only applies if your organization builds or hosts its own AI models in Azure AI Foundry.
Agents built in Copilot Studio run on Microsoft’s models by default, so Microsoft carries responsibility for how the model itself performs. The same applies to Microsoft 365 Copilot. If that describes you, skip ahead to the “Monitoring your AI compliance” section below.
If you are still reading, your organization likely builds or hosts AI workloads in Azure AI Foundry. In supported configurations, Microsoft Purview can use Foundry-related signals to help manage security and compliance for AI interactions, including Compliance Manager recommendations and regulatory control mappings.
To use these capabilities, make sure the required Purview and Foundry integration settings are enabled and that the relevant administrators have the required Foundry or Azure permissions. Role names are changing in this area, so verify the current names and permissions in Microsoft Learn and in your Azure tenant.
The Act expects high-risk AI systems to be accurate and perform consistently. A paragraph about taking accuracy seriously does not satisfy that. Automated measurements are stronger: they give you repeatable evidence against the relevant control.
Commercial terms in this area change quickly, so confirm the current licensing and any trial conditions in your own tenant before you budget for it.
Monitoring your AI compliance
Sharing with auditors
We advise giving auditors access to a single assessment, not to everything. Open the assessment, then in the upper-right corner select Manage user access. A flyout pane appears with three tabs:
- Readers: view the assessment without changing anything.
- Assessors: view and edit test data.
- Contributors: view and edit assessment data.
External auditors can be added the same way once they have a Microsoft Entra account.

Administrators whose permissions come from Entra roles, such as Global Administrator or Compliance Administrator, do not appear on this screen, so it is not a complete list of everyone who can see the assessment.
A user can only hold one assessment-based role at a time. If an auditor needs to move from Reader to Contributor, remove the first role before assigning the second.
Exporting your evidence
Select Export actions to generate an Excel file with the controls, owners, implementation status, testing dates and results. This is a practical evidence package people will ask for, but it is not a complete audit file by itself.

Use the export alongside policies, meeting decisions, screenshots, test notes and other evidence that explains why each status is defensible.
Date the export, store it in a retained location, and repeat it on a schedule; quarterly works well. By December 2027, those exports tell a stronger story, not a last-minute compliance claim, but a record of continuous control improvement.
Deleting an assessment is permanent, and any improvement actions that appear in no other assessment are deleted with it. Export a report before you delete anything. You also cannot delete all your assessments, because Compliance Manager needs at least one to function.
Template updates
Microsoft updates templates as regulations change, and you may see a Pending update notification when regulatory content or control mappings change. Before relying on the EU AI Act template for a formal compliance position, check whether it has been updated to reflect the July 2026 amendments. Accepting an update is permanent, so if you are mid-assessment it is reasonable to finish the current round first. Updates apply per group: the same template in two groups produces two notifications, and you accept each one separately.
Where the Compliance Manager score can mislead you
Everything above is useful. The danger is the score. Scores look objective, so it is worth being precise about what this one does not prove.
It records what people say they did
Some technical actions pick up signal from your Microsoft 365 configuration. Many are only someone’s own record that they did something. Nothing checks whether the agent published last Tuesday follows the control you marked complete six weeks ago.
A green assessment means the tasks were marked complete. It does not mean your AI estate is compliant.
It does not know your agents exist
This is the critical limitation. When you create an assessment, you scope it to services such as Microsoft 365 or Azure. Compliance Manager may surface AI app or agent assessments in eligible tenants, but it is not a substitute for your own AI system inventory. It will not automatically give you a complete register of every published agent, its owner, purpose, data access, and risk classification.
Your EU AI Act assessment therefore describes evidence for selected services and controls. It does not automatically describe every AI system your organization deploys. The Act’s obligations attach to systems and roles: provider, deployer, or another regulated actor. If your evidence is tenant-wide but your real AI estate is hundreds of separately configured agents with different data access and no review process, the assessment can be accurate and still miss the risk.
It looks more complete than it is
The four tabs and the score suggest full coverage. They do not provide it, and the gaps are not obvious from the interface.
Compliance Manager will not decide risk levels for you. Whether an agent is high-risk depends on what it is used for, not what data it reaches, and that judgment sits with people who understand the business.
It will not find what it was never told about: the agent nobody registered, the AI project running on someone’s Azure subscription, the tool a department signed up for on a credit card. None of it appears, and nothing indicates that something is missing.
And it will not confirm that your agents disclose themselves. No control by itself proves users are told they are interacting with AI. Article 50 transparency obligations apply from 2 August 2026, with specific transition rules for certain machine-readable marking duties.
This makes the assessment narrower than it looks, which is the more dangerous problem, because a narrow assessment still produces a confident score.
Ownership and adoption
The main challenge with Compliance Manager is ownership. It looks like an IT tool, but many improvement actions are legal, HR or business work: writing a policy, training staff, documenting a decision, approving a process.
Set up a meeting with the stakeholders, go over the improvement action list together, and assign owners immediately. This works far better than emailing a link and hoping the right people understand and pick up the ask.
Microsoft does provide training materials. The Explore compliance in Microsoft 365 module covers the dashboard, improvement actions and the compliance score, and Manage compliance with Microsoft Purview for Microsoft 365 Copilot covers the AI side. Point your administrators there.
What you will not find is material aimed at the people who own most of the work. Nothing explains to a legal or HR colleague what is expected of them when an improvement action lands in their name. That explanation is your responsibility, so plan for it.
A note from Rencore
Everything above points at the same hole: Compliance Manager tells you how well you are managing the AI systems you have told it about. It has no way to tell you which AI systems exist.
That is where Rencore fits, deliberately so. Microsoft Purview focuses on the data: classification, DLP, sensitivity labels, regulatory mappings. Rencore focuses on the services and systems that touch that data. It discovers every Copilot Studio agent, SharePoint-embedded agent, declarative agent, and Azure AI Foundry deployment across the tenant, whether or not anyone registered it. The two are built to work side by side, not to replace each other.
That discovery becomes the AI system inventory Article 6 to 11 of the EU AI Act assumes you already have. Every agent gets an owner, a risk score based on audience exposure and data sensitivity, and a policy check: unauthenticated agents touching SharePoint, agents shared with hundreds of users pulling from the open web, agents nobody has reviewed in three months. High-risk agents can be flagged for review or unpublished automatically, with the trail to prove it.
That inventory also fixes the ownership problem from the previous section. Instead of a meeting and a spreadsheet, each agent lands with a named owner, a lifecycle status, and an audit history, so “who owns this improvement action” stops being a question you re-ask every quarter.
One customer’s Copilot Studio rollout had surfaced over 50 unsanctioned agents before anyone had a full inventory. Twelve turned out to be high-risk. That is the scenario Compliance Manager’s score cannot see. It is the one Rencore is built to catch.
Conclusion
Compliance Manager turns scattered settings, improvement actions and evidence into something stakeholders and auditors can inspect. It structures the work, assigns ownership, monitors progress and exports evidence over time. Depending on your licensing and tenant configuration, it can also provide ready-made assessment templates, AI-related recommendations and, in some scenarios, signals from Azure AI Foundry.
But the score is not the governance model. A completed assessment does not automatically prove that every AI system is registered, risk classified, reviewed, tested and monitored. That still depends on your inventory, ownership model, policies, decision logs and operating processes.
Use Compliance Manager as the evidence engine, not the source of truth. It can show progress and make compliance work visible. Proving that your AI systems are governed is still your organization’s job.
Last updated 24 August 2026



.png)