Microsoft Purview Compliance Manager: From Regulatory Requirements to Reviewable Evidence

Learn how controls, assessments, improvement actions, testing, evidence, ownership, and compliance scoring fit together—and why a higher score is not the same as legal compliance.

Translate an Obligation Into Work Someone Can Own

A regulation can require an organization to protect information, restrict access, retain records, report incidents, or demonstrate oversight. None of those sentences tells a system administrator exactly which setting to change or tells an auditor which artifact will prove the requirement is met. Compliance work therefore needs a translation layer between an obligation and the evidence produced by everyday operations.

Microsoft Compliance Manager documentation describes a system built around regulations, assessments, controls, and improvement actions. A regulation or standard provides the source requirements. An assessment groups the controls relevant to a chosen scope. A control describes a requirement to manage. Improvement actions turn that requirement into work that can be assigned, implemented, tested, documented, and monitored.

Read that hierarchy from both directions. Starting from the regulation preserves purpose. Starting from the improvement action preserves operational detail. If the two no longer connect, a team can complete tasks that look productive without supporting the original obligation.

Keep Microsoft, Customer, and Shared Responsibilities Visible

Cloud compliance does not transfer every responsibility to the service provider. Compliance Manager distinguishes Microsoft-managed controls, customer-managed controls, and shared controls. Microsoft-managed controls concern implementation within Microsoft cloud services. Customer-managed controls remain with your organization. Shared controls contain obligations on both sides.

This distinction changes the evidence you should expect. A Microsoft control may include service implementation details or testing results supplied by Microsoft. A customer control might require your policy, configuration, training record, access review, incident procedure, or test result. For a shared control, the assessment must show how the parts meet rather than attaching one party’s evidence and assuming the whole control is satisfied.

Make the service and organizational boundary explicit. If your control depends on knowing where regulated data exists, the Purview Data Map can support discovery and ownership, but the map itself does not prove that access, retention, or response requirements are operating effectively.

Scope the Assessment Before You Interpret Its Score

An assessment groups controls from a regulation, standard, or policy for a defined set of services. Scope determines which business units, systems, data, locations, and time periods your conclusion covers. A beautifully documented assessment can still mislead if readers assume it applies to environments that were never included.

Start with the obligation and legal interpretation established by accountable counsel or compliance specialists. Identify in-scope services and organizational boundaries, then select the appropriate template. Microsoft provides hundreds of regulatory templates, but availability depends on licensing. The Compliance Manager regulations documentation also distinguishes universal templates, which provide broad control mapping and generally require manual implementation and testing, from service-specific templates.

Record exclusions and dependencies. A Microsoft 365 assessment does not silently cover an unmanaged archive, a third-party SaaS system, or an on-premises process. If evidence comes from another system, preserve its scope and ownership rather than presenting it as universal.

Treat an Improvement Action as a Small Assurance Case

An improvement action gives guidance intended to help align with a control. It can have an owner, implementation status, notes, test status, and supporting evidence. The action becomes useful when those elements explain a coherent claim.

Imagine an action requiring periodic review of privileged access. The implementation record should define the identity population, review frequency, reviewers, decision criteria, revocation process, and systems included. Evidence might include an approved procedure, review export, sampled decisions, remediation records, and dates. Testing should ask whether the review occurred as designed and whether exceptions were handled, not merely whether a document exists.

Assign ownership to someone who can change the control, and separate implementation from independent review where the risk calls for it. When an action is reused across assessments, confirm that the evidence and scope genuinely satisfy each mapped requirement. Reuse reduces duplication; it should not erase differences between regulations.

Read the Compliance Score as Prioritization, Not Certification

Compliance Manager awards points for completing improvement actions and combines them into a risk-based compliance score. Actions have different point values based on their potential risk impact. The score can help prioritize unfinished work and show movement over time.

It cannot make a legal conclusion for you. A high score does not prove that every applicable obligation has been identified, that implementation is effective across the entire business, that uploaded evidence is accurate, or that a regulator will accept the organization’s interpretation. It also reflects the actions and scoring model available within the chosen assessments.

Use the score as a navigation aid. Examine which actions changed it, whether high-impact gaps remain, whether automated signals are healthy, and whether improvements occurred in the intended population. Data Security Posture Management can surface related data-security risks, but neither posture score should become a substitute for the underlying evidence.

Test Whether the Control Operates, Not Whether the Screen Is Green

Control testing asks whether the implemented control is suitably designed and whether it operated during the period under review. Those are different questions. A policy might be well designed but not followed. A configuration might exist now but have been absent for most of the assessment period.

Choose evidence that matches the assertion. A configuration export can support the current state. Audit history can support operation over time. A sample of access reviews can support execution and decision quality. Incident records can reveal failures that a dashboard summary hides. Preserve source, collection date, reviewer, population, and limitations.

Where a control change can disrupt users or data, use the same simulation-first reasoning applied elsewhere in Purview. Preproduction evidence helps reduce implementation risk, but production monitoring is still needed to establish ongoing operation.

Make Evidence Reviewable and Time-Bounded

Compliance evidence often contains security configuration, employee information, incident details, contracts, and audit findings. Store it with least privilege, a defined retention period, change history, and an owner. A screenshot without source, date, scope, or explanation is easy to collect and difficult to defend.

Use status language consistently. Implemented should describe the action taken. Tested should identify the procedure and result. Alternative implementation should explain how the requirement is satisfied differently. Not applicable should include the scope reasoning and approval. None of these states should be inferred from a score alone.

Schedule reassessment when regulations, services, organizational scope, or control designs change. Evidence expires conceptually even when the file remains available. A prior review cannot prove a current configuration after a migration, acquisition, policy change, or new data source.

Build a Program That Can Explain Its Remaining Uncertainty

A mature Compliance Manager program does not claim perfection. It can identify which obligations were interpreted, which services and business units were assessed, which controls belong to Microsoft or the customer, which actions were implemented, how operation was tested, and which gaps remain.

Report facts, assessments, and uncertainty separately. Facts include configuration exports, completed reviews, dates, and test samples. The assessment explains whether that evidence supports the control conclusion. Uncertainty includes incomplete populations, stale evidence, inherited provider claims, untested periods, or disputed interpretations.

That separation makes the program useful to more than auditors. Security leaders can prioritize remediation, service owners can see what they must operate, and executives can understand where exposure remains without mistaking a rising score for a guarantee.

Frequently asked questions

Does a 100 percent compliance score prove that an organization complies with a law?

No. The score measures progress on scored improvement actions in Compliance Manager. It does not replace legal interpretation, define the complete scope of an obligation, prove that every control operates effectively, or guarantee an auditor or regulator will reach the same conclusion.

Are Microsoft-managed controls the customer's responsibility?

Microsoft-managed controls are implemented for Microsoft cloud services by Microsoft. Customer-managed controls remain the organization's responsibility, while shared controls divide responsibility. The assessment must preserve these distinctions instead of treating all control evidence as interchangeable.

Does every tenant receive every regulatory template?

No. Template availability depends on licensing, and many templates are premium. The Microsoft Data Protection Baseline is broadly available. Organizations can also create custom regulations for requirements not represented by an available template.

What makes compliance evidence useful?

Useful evidence is tied to a specific action and scope, identifies its source and period, supports a stated implementation or test conclusion, is protected against inappropriate change, and can be understood by a reviewer who did not perform the work.