Microsoft’s SSPA Program Update: What Suppliers Need to Know
Privacy Assessments | ISO Certifications | ISO 42001
Published: Feb 5, 2025
Microsoft’s Supplier Security and Privacy Assurance (SSPA) program received a major update with Version 10, which took effect on September 23rd, 2024. This update introduced new requirements, particularly around artificial intelligence (AI) and ISO 42001 compliance.
What is the SSPA Program?
The SSPA program applies to all Microsoft suppliers that process confidential or personal data. It serves as Microsoft's internal vendor risk management framework, ensuring suppliers meet security and privacy expectations. Companies must comply during procurement and annually thereafter through self-assessment and independent evaluations.
What’s Changing in SSPA Version 10?
The latest version brings Section K, which focuses on AI governance. This section applies to any Microsoft suppliers that use AI in their services provided to Microsoft. It is important to note here that Microsoft Copilot (their AI solution) is carved out. Key elements of Section K include:
- AI risk management and oversight
- Governance requirements for AI usage in services
- Compliance expectations for AI-driven decision-making
How ISO 42001 Ties In
With growing global interest in ISO 42001, the AI management system standard, Microsoft is integrating it into the SSPA program as a potential solution. Suppliers using AI have two pathways for compliance:
- Voluntary Compliance – Suppliers can pursue ISO 42001 certification to meet Section K requirements proactively.
- Mandatory Compliance – Suppliers handling sensitive AI use cases (e.g., legal or psychological impacts on individuals) will be required to obtain ISO 42001 certification.
Next Steps for Suppliers
If you’re a Microsoft supplier leveraging AI, now is the time to assess your AI governance and compliance readiness. Our team is mapping SSPA’s Section K requirements to ISO 42001, and we’ll be sharing further insights soon.
Stay tuned for our full breakdown of SSPA Version 10 and what it means for your compliance strategy!
About CHRIS LIPPERT
Chris Lippert is a Director and Privacy Technical Lead with Schellman and is based in Atlanta, GA. With more than 10 years of experience in information assurance across numerous industries, regulations, and frameworks, Chris developed a passion for and concentration in data privacy. He is an active member of the International Association of Privacy Professionals (IAPP), holds his Fellow of Information Privacy (FIP) designation, and advocates for privacy by design and the adequate protection of personal data in today’s business world.