GOV-015 Intellectual Property Rights Management
Description
Procedures are implemented to protect intellectual property rights, including software licensing compliance, tracking of licensed assets in use, and controls preventing unauthorised reproduction or distribution of copyright-protected material.
Rationale
Non-compliance with intellectual property obligations exposes the organisation to legal and financial liability. Documented procedures ensure licensing obligations are tracked and met.
Applicability (9 profiles)
Framework Mappings (10)
| EU-AI-Art.53.3 | GPAI Model Obligations — Copyright Compliance Policy | informative |
| COP-C-1 | Copyright policy | informative |
| COP-C-1.1 | Draw up, keep up-to-date and implement a copyright policy | informative |
| 5.32 | Intellectual property rights | full |
| CM-10 | Software Usage Restrictions | full |
| GV-6.1-001 | Third-Party AI Risk Policies | GV-6.1-001 | partial |
| MP-4.1-002 | AI Technology and Legal Risk Mapping | MP-4.1-002 | partial |
| MP-4.1-006 | AI Technology and Legal Risk Mapping | MP-4.1-006 | informative |
| MS-2.8-001 | AI Transparency and Accountability Risks | MS-2.8-001 | informative |
| GOVERN 6.1 | Third-Party AI Risk Policies | informative |
Evidence (2)
Software licence inventory listing all licensed software in use, with licence type, entitlement count, actual usage count, and renewal dates.
Example: Software Asset Management register (Zylo / Torii / spreadsheet), showing: software name, vendor, licence type, number of licences purchased, number of licences in use, and next renewal date.
Test: Request the software licence inventory. Verify: (1) all commercial software deployed in the organisation is listed, (2) entitlement and usage counts are present and usage does not exceed entitlement, (3) renewal dates are tracked and no licences are operating past expiry, (4) the inventory was reviewed within the last 12 months.
Intellectual property rights management procedure covering software licence compliance, prohibition on unauthorised copying, and obligations for AI-generated or third-party content.
Example: IP Rights Management Procedure or Acceptable Use Policy section (Confluence), including: software procurement process, prohibition on unlicensed software installation, process for flagging and resolving licence non-compliance, and acknowledgement requirement for personnel.
Test: Request the IP rights management procedure. Verify: (1) software licence compliance obligations are stated, (2) prohibited actions (unauthorised copying, piracy) are defined, (3) a process for identifying and remediating non-compliance is described, (4) the document has been approved and distributed within the last 12 months.
Questions (3)
Does your organisation maintain an inventory of the licensed software in use?
The inventory should show that usage does not exceed entitlement and that no licences are operating past expiry.
Which of the following does the software licence inventory record for each licensed product?
Options run from the most commonly recorded to the least. An inventory holding entitlements but no usage count cannot show that use stays within them, which is the condition the control tests.
Does a documented procedure define how licensing non-compliance is identified and remediated?
The procedure should name the prohibited actions, the route by which a violation is flagged and the remediation expected. An acknowledgement requirement on personnel belongs with it.