Control 1.1: Copilot Readiness Assessment and Data Hygiene
Control ID: 1.1 Pillar: Readiness & Assessment Regulatory Reference: GLBA §501(b), FFIEC IT Handbook (Information Security Booklet), SR 11-7 / OCC Bulletin 2011-12, OCC Bulletin 2023-17, Sarbanes-Oxley §§302/404 (where applicable to ICFR) Last Verified: 2026-07-26 Governance Levels: Baseline / Recommended / Regulated
Objective
Conduct a comprehensive pre-deployment assessment of the organization's data environment to identify and remediate data hygiene issues before enabling Microsoft 365 Copilot. This control supports compliance with regulatory expectations that financial institutions evaluate the risk posture of new technology deployments, including understanding where sensitive data resides, who has access to it, and whether existing classification and permission models are sufficient for AI-assisted data retrieval.
Why This Matters for FSI
- GLBA §501(b): Requires financial institutions to develop, implement, and maintain a comprehensive information security program. Pre-deployment assessment of data hygiene directly supports this obligation by identifying gaps in data protection before Copilot amplifies access patterns.
- FFIEC IT Handbook (Information Security Booklet): Expects risk assessments for new technology deployments, including evaluation of how the technology interacts with existing data stores and access models.
- SR 11-7 / OCC Bulletin 2011-12 (Model Risk Management): Interagency guidance on model risk management applies to AI-based tools. Institutions should assess AI-related risks — including data quality, data governance, and access control adequacy — as part of existing model risk management frameworks.
- Sarbanes-Oxley §§302/404 (where applicable to ICFR): To the extent AI tools surface or generate content used in financial reporting workflows, internal control assessments under Sarbanes-Oxley §§302 and 404 may need to evaluate those tools as part of disclosure controls and internal control over financial reporting (ICFR).
- OCC Bulletin 2023-17 (Third-Party Relationships): Supersedes OCC Bulletin 2013-29. Interagency guidance on third-party risk management requires assessment of how vendor AI services interact with institutional data throughout the relationship lifecycle.
Control Description
The Copilot Readiness Assessment evaluates four key dimensions of data hygiene before Copilot is enabled for any user group:
Assessment Dimensions
| Dimension | What It Evaluates | Key Risk if Unaddressed |
|---|---|---|
| Data Classification Maturity | Whether sensitivity labels are applied consistently across M365 content | Copilot may surface unclassified sensitive data (PII, NPI, trade secrets) to unauthorized users |
| Permission Sprawl Analysis | Breadth of user access across SharePoint, OneDrive, Exchange, Teams | Copilot inherits all user permissions -- overly broad access means overly broad AI retrieval |
| Stale Content Identification | Volume and risk profile of outdated, orphaned, or obsolete content | Copilot may generate responses based on outdated policies, superseded procedures, or archived data |
| Sensitive Data Inventory | Location and volume of sensitive data types (SSN, account numbers, PII) | Copilot could surface regulated data in responses without proper DLP controls in place |
Assessment Tools and Data Sources
| Tool | Purpose | Admin Portal |
|---|---|---|
| Microsoft 365 Copilot readiness report | Per-user Copilot eligibility: prerequisite licenses, users on an eligible Microsoft 365 Apps update channel, assigned and available Copilot licenses | Microsoft 365 admin center > Reports > Usage > Microsoft 365 Copilot > Readiness tab |
| Microsoft 365 network connectivity test tool | Measures average network latency to Microsoft 365 Copilot endpoints and verifies WebSocket (WSS) connectivity from user locations | Standalone tool at connectivity.m365.cloud.microsoft; adjunct network insights appear in the Microsoft 365 admin center under Health > Connectivity |
| Microsoft Purview Data Security Posture Management (DSPM) | Data risk assessments for oversharing, AI observability for Copilot and agents, sensitivity label and classification coverage reporting | Microsoft Purview portal > Solutions > DSPM |
| SharePoint Advanced Management (SAM) | Data Access Governance (DAG) snapshot and activity reports, site access reviews, sharing analytics | SharePoint admin center > Reports > Data access governance |
| Microsoft Purview on-demand classification | Scans historical and inactive files at rest in SharePoint, OneDrive, and onboarded endpoints against current classifiers | Microsoft Purview portal > Information Protection (or Data loss prevention) > Classifiers > On-demand classification |
| Microsoft Purview Content Explorer | Browse and audit actual content matched by sensitive information types, sensitivity labels, and retention labels | Microsoft Purview portal > Solutions > Data Lifecycle Management > Explorers > Content explorer |
| Microsoft Graph API | Programmatic access to permission models, sharing links, and group memberships | Microsoft Graph Explorer or custom scripts (no portal) |
Microsoft Purview Data Map is not an M365 content-scanning tool
Microsoft Purview Data Map and Unified Catalog do not support scanning SharePoint and OneDrive content. For sensitive-data discovery inside Microsoft 365 workloads, use on-demand classification, auto-labeling policies, and DSPM data risk assessments instead.
Readiness Scoring Model
Organizations should develop a readiness score based on quantifiable metrics:
| Metric | Target (Baseline) | Target (Recommended) | Target (Regulated) |
|---|---|---|---|
| Sensitivity label coverage | >50% of documents | >75% of documents | >90% of documents |
| Sites with oversharing findings | Reviewed top 20 | Remediated top 50 | Remediated all flagged |
| Stale content (>2 years, no access) | Identified | Archived or deleted | Archived with retention policy |
| Sensitive data types inventoried | Top 5 SIT types | All standard SITs | Custom SITs for institution |
| Permission audit coverage | SharePoint only | SharePoint + OneDrive + Teams | All M365 workloads + Graph API |
| Office update channel eligibility | >80% of in-scope users on a Copilot-eligible update channel | >95% on a Copilot-eligible update channel | 100% enforced via Intune or Group Policy |
Assessment Workflow
- Scope Definition: Identify which M365 workloads and user populations are in scope for initial Copilot deployment
- Infrastructure Readiness Assessment: Run the Microsoft 365 Copilot readiness report from Microsoft 365 admin center > Reports > Usage > Microsoft 365 Copilot > Readiness. This report shows prerequisite license eligibility and how many users are on an eligible Microsoft 365 Apps update channel. Pair it with the Microsoft 365 network connectivity test tool to measure latency to Copilot endpoints and confirm WebSocket (WSS) connectivity, and review the recommended Copilot tenant configuration settings in the Microsoft 365 admin center. Per FFIEC IT Examination Handbook (Information Security Booklet), risk assessments for new technology deployments must include infrastructure readiness evaluation.
- Update Channel Validation: Confirm that endpoints in the Copilot rollout scope are on an update channel that delivers Copilot features. Current Channel and Monthly Enterprise Channel are eligible. Beginning with the Version 2606 update release in July 2026, Microsoft unified Semi-Annual Enterprise Channel with Monthly Enterprise Channel: devices configured for Semi-Annual Enterprise Channel receive the same feature and security updates as Monthly Enterprise Channel and become eligible for Copilot once Version 2606 or later is installed, subject to the other Microsoft 365 Copilot requirements. Organizations should verify actual installed builds rather than relying on channel names, because some management tools and reports continue to display the Semi-Annual Enterprise Channel label after the update.
- Data Discovery: Run Microsoft Purview classification across in-scope workloads. Use auto-labeling and continuous classification for active content, and on-demand classification to scan historical or inactive files at rest in SharePoint and OneDrive
- Permission Analysis: Generate DAG reports from SharePoint Advanced Management and export sharing link inventory
- Stale Content Review: Identify content with no access activity in 24+ months using SharePoint site analytics (see Readiness Scoring Model thresholds per governance level)
- Sensitive Data Mapping: Use Content Explorer and sensitive information type (SIT) matches to map regulated data locations
- Gap Analysis: Compare current state against target readiness scores for the intended governance level
- Remediation Plan: Develop prioritized remediation plan addressing highest-risk findings first
- Stakeholder Report: Present readiness assessment findings to compliance, legal, and IT leadership
Copilot Surface Coverage
This control applies to readiness assessment for all Copilot surfaces, as data hygiene issues affect every surface where Copilot retrieves content:
| Copilot Surface | Relevance | Assessment Focus |
|---|---|---|
| Microsoft 365 Copilot Chat | Critical | Searches across all M365 data -- broadest exposure surface |
| Word / Excel / PowerPoint | High | Document-level content retrieval and generation |
| Outlook | High | Email content, attachment access, calendar data |
| Teams | High | Chat history, channel files, meeting transcripts |
| SharePoint | Critical | Document libraries, site content, metadata |
| OneDrive | High | Personal files that may contain sensitive data |
| Loop / Whiteboard | Medium | Collaborative content with potentially broad sharing |
| Viva (Insights, Engage) | Medium | Organizational analytics and communications data |
| Copilot Pages | High | AI-generated collaborative artifacts with sharing |
| Copilot Notebooks | High | AI-generated analytical notebooks with sharing |
| Extensibility (Plugins, Graph connectors) | High | External data brought into Copilot grounding scope |
Governance Levels
| Level | Requirement | Rationale |
|---|---|---|
| Baseline | Conduct readiness assessment using Microsoft Purview DSPM data risk assessments and SharePoint DAG reports. Run the Microsoft 365 Copilot readiness report and network connectivity test to validate infrastructure readiness. Confirm >80% of in-scope endpoints are on a Copilot-eligible update channel. Review top 20 sites for oversharing. Document findings and present to IT leadership. | Minimum due diligence before enabling Copilot for any user group. Addresses immediate, high-visibility risks including infrastructure gaps that block Copilot feature delivery. |
| Recommended | All Baseline requirements plus: comprehensive permission audit across SharePoint, OneDrive, and Teams. Remediate top 50 oversharing sites. Achieve >75% sensitivity label coverage for in-scope content. Achieve >95% update channel eligibility for in-scope endpoints. Develop remediation roadmap with timelines. | Addresses broader data hygiene risks and demonstrates proactive governance to regulators. Ensures Copilot feature parity across the in-scope user population. |
| Regulated | All Recommended requirements plus: full permission audit across all M365 workloads including Exchange and Graph API permissions. Remediate all flagged oversharing sites. Achieve >90% label coverage. Enforce 100% update channel eligibility via policy (Intune or Group Policy). Engage internal audit or compliance for independent validation of readiness assessment. Document assessment in regulatory examination file. | Comprehensive, examination-ready posture that supports compliance with GLBA, FFIEC, and interagency guidance expectations. Policy-enforced update channel management helps prevent endpoints from delivering degraded Copilot features due to stale Office versions. |
Setup & Configuration
Step 1: Run the Readiness and Network Assessments
Navigate to Microsoft 365 admin center > Reports > Usage > Microsoft 365 Copilot and open the Readiness tab. This report shows:
- Total prerequisite licenses: Users who hold, or can be assigned, a Copilot-eligible base license
- Users on an eligible update channel: Users enrolled in Current Channel or Monthly Enterprise Channel for Microsoft 365 Apps updates
- Assigned and available Copilot licenses, plus recommended actions such as moving users to a monthly update channel
Network readiness is assessed separately. Run the Microsoft 365 network connectivity test tool (connectivity.m365.cloud.microsoft) from the tested user location to measure average latency to Microsoft 365 Copilot endpoints (latency above 250 ms may degrade the Copilot experience) and to confirm that WebSocket (WSS) connections to *.cloud.microsoft and *.office.com are not blocked by proxies or TLS inspection. Aggregated network insights are also available in the Microsoft 365 admin center under Health > Connectivity.
Review the recommended Copilot tenant configuration settings in the Microsoft 365 admin center to identify configuration gaps before license assignment. Address infrastructure and configuration findings before proceeding with Copilot license assignment.
Step 2: Use Data Security Posture Management (DSPM)
Navigate to the Microsoft Purview portal > Solutions > DSPM to access posture dashboards and AI-specific reports. The earlier experiences are now labeled Data Security Posture Management (classic) and DSPM for AI (classic) in the portal; new capabilities are added to the current DSPM version only.
Key areas to review:
- Discover > Data risk assessments: A default assessment runs weekly against the top 100 SharePoint sites by usage, identifying potentially overshared and unlabeled content that Copilot could surface. Custom assessments can target specific users or sites, with optional item-level scanning for SharePoint
- Objectives: Guided remediation workflows, including Prevent data exposure in Microsoft 365 Copilot and Microsoft Copilot interactions and Prevent oversharing of sensitive data
- AI observability: Inventory of AI apps and agents with activity in the last 30 days, including which are high risk and which have sensitive interactions
- Reports and Discover > Activity explorer (AI activities tab): Sensitive data usage, labeling coverage, and Copilot interaction insights after initial deployment
Step 3: Run SharePoint Data Access Governance Reports
Navigate to SharePoint admin center > Reports > Data access governance and generate:
- Snapshot reports: Site permissions across your organization, site permissions for specific users, and sensitivity labels applied to files
- Activity reports: Sharing links created in the last 28 days, and content shared with 'Everyone except external users' (EEEU)
Organizations with Microsoft 365 E5 but without SharePoint Advanced Management can access activity reports only (limited to 10,000 sites, and requiring data collection to be enabled first) and do not get snapshot reports or in-report remedial actions.
Step 4: Content Explorer Analysis
Navigate to Microsoft Purview portal > Solutions > Data Lifecycle Management > Explorers > Content explorer and review:
- Volume of content matching sensitive information types (SSN, credit card, bank account)
- Distribution of sensitive content across SharePoint sites, OneDrive accounts, and Exchange mailboxes
- Content with no sensitivity labels applied
Step 5: Permission Audit via PowerShell
Use SharePoint Online Management Shell, Microsoft Graph PowerShell SDK, and Exchange Online PowerShell to export detailed permission reports:
# Key audit areas (refer to the PowerShell Setup playbook for full scripts):
# - SharePoint site collection permissions
# - Sharing link inventory (anonymous, company-wide, specific people)
# - Microsoft 365 Group memberships tied to Teams and SharePoint
# - OneDrive sharing configuration per user
# - Exchange mailbox delegation and folder permissions
Step 6: Document and Report
Compile findings into a Copilot Readiness Assessment Report. Document data hygiene findings, oversharing risks identified, remediation actions taken, and residual risk assessment.
Financial Sector Considerations
- Examination Readiness: Maintain the readiness assessment report in your regulatory examination file. FFIEC examiners and FINRA examiners increasingly ask about AI governance during examinations, and demonstrating pre-deployment due diligence is a strong indicator of mature risk management.
- Customer Data Sensitivity: Financial institutions hold particularly sensitive customer data (NPI under GLBA, account information, transaction histories). The readiness assessment should pay special attention to the location and accessibility of this data across M365 workloads.
- Multi-Entity Considerations: Broker-dealers, banks, and insurance subsidiaries within a holding company may each have distinct regulatory obligations. Readiness assessments should be scoped per legal entity where regulatory regimes differ.
- Board Reporting: For institutions where AI adoption is a board-level initiative, readiness assessment findings should be summarized for board risk committee reporting. Consider including readiness scores in existing technology risk dashboards.
- Merger and Acquisition Risk: Institutions that have recently completed M&A activity should pay particular attention to data hygiene in environments inherited from acquired entities, where permission models and classification practices may differ significantly.
- Regulatory Change Velocity: The regulatory landscape for AI in financial services is evolving rapidly. Build readiness assessment processes that can be repeated as new regulatory guidance emerges, not just at initial deployment.
Verification Criteria
- Microsoft 365 Copilot readiness report and Microsoft 365 network connectivity test have been run, and infrastructure findings (license eligibility, update channel eligibility, endpoint latency, WebSocket connectivity) have been reviewed and addressed
- Office update channel eligibility has been measured against installed builds and meets the target for the organization's governance level (>80% Baseline / >95% Recommended / 100% policy-enforced for Regulated)
- Microsoft Purview DSPM data risk assessments have been generated and reviewed by designated personnel within the past 30 days
- SharePoint Data Access Governance reports have been run for all in-scope site collections
- Content Explorer analysis has identified and documented the location and volume of sensitive information types across M365 workloads
- Permission audit has been completed for all workloads at the appropriate governance level (SharePoint minimum; all workloads for Regulated)
- Readiness scoring model has been applied and current scores documented
- Gap analysis comparing current state to target governance level has been completed
- Remediation plan with prioritized actions and timelines has been developed and approved by appropriate stakeholders
- Readiness assessment findings have been presented to IT leadership and compliance (Baseline) or documented in regulatory examination file (Regulated)
- Assessment artifacts (reports, exports, scoring worksheets) are retained per the organization's document retention policy
- Re-assessment cadence has been established (quarterly recommended; semi-annual minimum)
Additional Resources
- Microsoft Learn: Microsoft 365 Copilot readiness report
- Microsoft Learn: Microsoft 365 app and network requirements for Microsoft 365 Copilot
- Microsoft Learn: Microsoft 365 network connectivity test tool
- Microsoft Learn: Optimize Microsoft 365 Copilot configuration settings
- Microsoft Learn: Change update channel of Microsoft 365 Apps to enable Copilot
- Microsoft Learn: Upcoming channel unification - Semi-Annual Enterprise Channel to Monthly Enterprise Channel
- Microsoft Learn: Learn about Data Security Posture Management
- Microsoft Learn: Prevent oversharing with data risk assessments from Data Security Posture Management
- Microsoft Learn: Data Security Posture Management for AI
- Microsoft Learn: SharePoint Data Access Governance reports
- Microsoft Learn: Content Explorer
- Microsoft Learn: Create and analyze an on-demand classification scan
- FFIEC IT Examination Handbook - Information Security
- OCC Bulletin 2023-17: Third-Party Relationships
- Related Controls: 1.2 SharePoint Oversharing Detection, 1.5 Sensitivity Label Taxonomy Review, 1.6 Permission Model Audit, 3.1 Copilot Audit Logging, 4.1 Admin Settings & Feature Management
- Playbooks: Portal Walkthrough, PowerShell Setup, Verification & Testing, Troubleshooting
FSI Copilot Governance Framework v1.8.0 - July 2026