GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

GOV-015 Intellectual Property Rights Management

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Procedures are implemented to protect intellectual property rights, including software licensing compliance, tracking of licensed assets in use, and controls preventing unauthorised reproduction or distribution of copyright-protected material.

Rationale

Non-compliance with intellectual property obligations exposes the organisation to legal and financial liability. Documented procedures ensure licensing obligations are tracked and met.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (10)

EU-AI-Art.53.3GPAI Model Obligations — Copyright Compliance Policyinformative
COP-C-1Copyright policyinformative
COP-C-1.1Draw up, keep up-to-date and implement a copyright policyinformative
5.32Intellectual property rightsfull
CM-10Software Usage Restrictionsfull
GV-6.1-001Third-Party AI Risk Policies | GV-6.1-001partial
MP-4.1-002AI Technology and Legal Risk Mapping | MP-4.1-002partial
MP-4.1-006AI Technology and Legal Risk Mapping | MP-4.1-006informative
MS-2.8-001AI Transparency and Accountability Risks | MS-2.8-001informative
GOVERN 6.1Third-Party AI Risk Policiesinformative

Evidence (2)

recorddocumentmanual

Software licence inventory listing all licensed software in use, with licence type, entitlement count, actual usage count, and renewal dates.

Example: Software Asset Management register (Zylo / Torii / spreadsheet), showing: software name, vendor, licence type, number of licences purchased, number of licences in use, and next renewal date.

Test: Request the software licence inventory. Verify: (1) all commercial software deployed in the organisation is listed, (2) entitlement and usage counts are present and usage does not exceed entitlement, (3) renewal dates are tracked and no licences are operating past expiry, (4) the inventory was reviewed within the last 12 months.

policydocumentmanual

Intellectual property rights management procedure covering software licence compliance, prohibition on unauthorised copying, and obligations for AI-generated or third-party content.

Example: IP Rights Management Procedure or Acceptable Use Policy section (Confluence), including: software procurement process, prohibition on unlicensed software installation, process for flagging and resolving licence non-compliance, and acknowledgement requirement for personnel.

Test: Request the IP rights management procedure. Verify: (1) software licence compliance obligations are stated, (2) prohibited actions (unauthorised copying, piracy) are defined, (3) a process for identifying and remediating non-compliance is described, (4) the document has been approved and distributed within the last 12 months.

Questions (3)

boolean

Does your organisation maintain an inventory of the licensed software in use?

The inventory should show that usage does not exceed entitlement and that no licences are operating past expiry.

multi

Which of the following does the software licence inventory record for each licensed product?

The entitlement count heldThe number of installations or users in active useThe renewal or expiry dateThe owner accountable for the licenceThe evidence of entitlement, such as the purchase or subscription recordNone of the above

Options run from the most commonly recorded to the least. An inventory holding entitlements but no usage count cannot show that use stays within them, which is the condition the control tests.

boolean

Does a documented procedure define how licensing non-compliance is identified and remediated?

The procedure should name the prohibited actions, the route by which a violation is flagged and the remediation expected. An acknowledgement requirement on personnel belongs with it.