Skip to content
Singahi

Compliance · guide

ISO 27001 A.5.32: Intellectual Property Rights

47 min read

Share
On this page

Quick Reference: A.5.32 in 60 Seconds

AttributeDetail
Control IDA.5.32
Control TitleIntellectual property rights
ObjectiveEnsure the organization respects and protects intellectual property (IP) rights-both its own and third-party-through documented procedures, asset tracking, licensing compliance, and enforcement.
DomainOrganizational controls
What You Must DoImplement appropriate procedures to protect IP rights: maintain an IP register, manage software licenses, acquire from reputable sources, respect copyright/trademarks/patents, enforce employment IP clauses, monitor use, and dispose safely.
Typical OwnerCISO / Information Security Manager (co-owned with Legal Counsel and Procurement)
Maturity Level 1Ad-hoc awareness; no IP register; unlicensed software present; no formal policy.
Maturity Level 2Basic IP policy drafted; license tracking via spreadsheet; software purchases ad-hoc.
Maturity Level 3Documented IPR policy and procedures; asset register includes IP assets; quarterly license reconciliation; employment contracts include IP clauses.
Maturity Level 4Automated SAM/SCA tools; real-time dashboards; integration with procurement and HR; DLP controls for source code and designs.
Maturity Level 5Predictive IP risk analytics; continuous compliance monitoring; board-level IP risk reporting; automated open-source license governance.
Audit Red FlagNo IP policy; unlicensed software installed; missing software license records; employees using personal cracked tools; no IP assignment clauses in contracts.
Quick WinRun a 48-hour software inventory and delete/unlicense any unauthorized installations; publish a one-page IP policy.
Time to Implement4–8 weeks for initial framework; ongoing monitoring forever.
Related ControlsA.5.1, A.5.9, A.5.12, A.5.13, A.5.30, A.5.31, A.5.33, A.5.35, A.5.36, A.5.37, A.6.1, A.6.6, A.8.1, A.8.5, A.8.12, A.8.25

What the Standard Actually Requires

Figure · Process

What A.5.32 asks you to do

The 7 requirements of ISO 27001 A.5.32, intellectual property rights, in order: topic-specific policy; procedures for software and ict; reputable sources; asset register; proof of ownership; license usage limits; periodic reviews.
The 7 things the control expects. Each is expanded in the section below.

ISO 27001:2022 A.5.32 Text

ISO 27001:2022 Annex A 5.32 asks organizations to put procedures in place to protect intellectual property rights.

ISO 27002:2022 Implementation Guidance (Section 5.32)

ISO 27002 expands the single "shall" statement into twelve practical guidance points:

  1. Topic-specific policy, Implement a policy on the protection of IP rights, tailored to the organization's operations and risk profile.
  2. Procedures for software and ICT products, Publish and communicate clear procedures defining how software and ICT products should be acquired, used, and maintained to remain compliant with IP standards.
  3. Reputable sources, Acquire software and digital content only from respected, reputable sources to avoid counterfeit or infringing copies.
  4. Asset register, Identify ICT assets that carry IP requirements in the organizational asset register.
  5. Proof of ownership, Be able to produce proof of ownership or license at any time, including physical and electronic licensing documents, communications, and files.
  6. License usage limits, Comply with agreed software usage limits, including concurrent users, virtual resources, processor/core counts, and geographic restrictions.
  7. Periodic reviews, Plan and implement periodic reviews to ensure the ICT estate does not contain unauthorized or unlicensed software.
  8. License renewal, Create operational and financial procedures that ensure licenses are kept up to date.
  9. Safe transfer and disposal, Establish procedures for the safe, responsible, and legally compliant transfer or disposal of software assets.
  10. Public-domain compliance, Ensure compliance with terms, conditions, and fair-use guidelines for any software acquired from the public domain (including open-source and freeware).
  11. Commercial recordings, Do not extract, copy, convert, or manipulate commercial recordings in ways not permitted by licensing or copyright law.
  12. Textual copyright, Respect and adhere to copyright laws and licensing terms for textual data such as standards, books, articles, and reports.

Shall / Should Analysis

TermMeaning for Your ISMS
ShallMandatory. The organization must have documented, implemented, and operating procedures that protect IP rights.
Should (ISO 27002)Strongly recommended implementation guidance. Auditors treat these as the expected baseline unless you can justify an alternative.
AppropriateProportional to size, complexity, industry, and risk. A 20-person startup needs less bureaucracy than a 2,000-person bank, but both must have procedures.

What Auditors Actually Check

Auditor ActionWhat They Want to See
Review IPR policyDocumented, approved, communicated, and current
Inspect IP / software asset registerAll software and IP assets listed with license type, owner, expiry, and proof
Sample software installationsMatch installed products to license entitlements
Check procurement processPurchase from authorized vendors; contracts include IP clauses
Review employment contractsIP assignment and confidentiality clauses for employees and contractors
Check open-source governanceSCA reports, license whitelist, approval workflow
Review DLP / access controlsRestrictions on source code, design files, and other critical IP
Verify disposal recordsSecure deletion and license transfer records
Test awarenessEmployees can explain how to report unlicensed software
Review management review / audit recordsIP risks discussed, findings closed

Why This Control Matters

Figure · Matrix

Comparison: License true-up to Incident response

Typical RangeNotes
License true-up– sDepends on vendor
Legal fees–Higher for cross-border
Engineering remediation– sOSS rewrite, code cleanup
Lost deal value– s+Enterprise deals lost due
Valuation haircut5–30%Particularly damaging
Incident response–IP exfiltration
Condensed from the table below, which carries the full detail for each cell.

The Business Risk Narrative

Intellectual property is often the single most valuable asset class in a modern B2B technology company. For a SaaS startup it is the source code, product roadmap, and customer-facing algorithms. For a manufacturer it is the CAD drawings, process recipes, and tooling designs. For a media or e-commerce company it is the brand identity, product images, marketing content, and customer databases. Losing control of IP does not just mean a lawsuit-it means loss of competitive advantage, erosion of investor confidence, customer churn, and sometimes business failure.

A.5.32 sits at the intersection of information security, legal compliance, and enterprise risk management. While other Annex A controls focus on confidentiality, integrity, and availability of information, A.5.32 focuses on the legal ownership and permitted use of that information. You can have perfect encryption and still fail an audit because 30% of your laptops run unlicensed software, or because a contractor walked away with your source code.

Indian Regulatory Context

Indian organizations operate under a layered compliance environment where IP protection is reinforced by several statutes and regulators:

  • The Copyright Act, 1957 (as amended) protects original literary, artistic, musical, and software works. Running unlicensed software, copying proprietary documents, or using pirated images can trigger civil and criminal penalties, including imprisonment up to three years and fines up to per offence.
  • The Trade Marks Act, 1999 protects brand names, logos, and service marks. Unauthorized use of third-party trademarks in marketing or product interfaces can lead to infringement suits and takedown orders.
  • The Patents Act, 1970 protects inventions and processes. Using patented algorithms or manufacturing techniques without a license can result in injunctions and damages.
  • The Designs Act, 2000 protects industrial designs. Copying UI/UX layouts or product packaging can infringe registered designs.
  • The Information Technology Act, 2000 (Section 43, 66, 66C, 66D) penalizes unauthorized access, theft, and fraud involving computer resources. Exfiltration of source code or confidential IP can be prosecuted as a cybercrime.
  • The Digital Personal Data Protection Act, 2023 does not directly govern IP, but it governs personal data that may be embedded in proprietary datasets, model training data, and customer analytics. Mishandling such data can compound IP and privacy liabilities.
  • CERT-In Directions, 2022 require organizations to report specified cyber incidents within six hours. Large-scale IP exfiltration or ransomware that destroys IP may trigger reporting obligations.
  • RBI Cyber Security Framework in Banks and the Master Direction on IT Framework for NBFCs require board-approved policies, vendor risk management, and incident reporting. Banks and NBFCs must ensure that licensed software is used in regulated environments and that vendor contracts protect RBI-classified data and IP.
  • SEBI cybersecurity circulars for market infrastructure institutions (MIIs) and intermediaries mandate complete policies, data protection, and periodic reporting. IP theft in capital markets can amount to market manipulation or insider trading.
  • IRDAI Guidelines on Information and Cyber Security for insurers require protection of policyholder data and business-critical systems, with implicit requirements to use licensed and supported software.

Industry-Specific Consequences

IndustryIP at RiskConsequence of Failure
SaaS / TechnologySource code, algorithms, API designs, customer data modelsGPL contamination, investor due-diligence failure, product shutdown
Banking / FintechTrading algorithms, customer PII, fraud models, payment interfacesRBI/SEBI penalties, loss of license, reputational damage
ManufacturingCAD files, process IP, supplier drawings, tooling designsProduction stoppage, patent infringement, loss of OEM contracts
Pharma / HealthcareFormulations, clinical data, regulatory submissions, patient datasetsIP theft, regulatory rejection, litigation
Media / EdTechVideo content, courseware, images, music, e-booksCopyright strikes, platform bans, royalty disputes
E-commerce / RetailProduct photos, brand assets, licensing algorithms, seller dataTrademark suits, marketplace delisting, margin erosion

impact of Non-Compliance: Statistics and Realities

  • The Business Software Alliance (BSA) has consistently ranked India among the top countries for commercial value of unlicensed software, with historical unlicensed installation rates above 50%. Even a single license shortfall across hundreds of endpoints can result in seven-figure rupee settlements.
  • Software audits by vendors such as Microsoft, Adobe, Oracle, and SAP can impose true-up overhead, back-maintenance fees, and penalties ranging from to several crores depending on deployment size.
  • Open-source license violations can force an organization to release proprietary source code under copyleft terms, destroying product valuation. GPL enforcement actions have led to injunctions and product recalls.
  • IP exfiltration by insiders overhead Indian companies an estimated –50 lakhs per incident in investigation, legal fees, and remediation for growing companies, and can run into crores for product companies.
  • Regulatory fines under the IT Act for data theft can reach per violation. DPDP Act penalties can reach for data breaches involving personal data.

These numbers do not capture the hidden overhead: delayed funding rounds, lost enterprise deals, and the months of management distraction spent defending audits or litigation.

The Hidden impact of an IP Failure

Beyond fines and true-up payments, an IP failure creates a cascade of indirect overhead that rarely appear in the initial incident report. Smart organizations account for these overhead when building the business case for an IPR program.

Direct overhead

  • Vendor audit settlements and license true-ups.
  • Legal fees for defense, contract disputes, and enforcement actions.
  • Remediation engineering for open-source license contamination or unauthorized asset removal.
  • Forensic investigation and incident response for IP theft or suspected exfiltration.
  • Regulatory fines and penalties under the Copyright Act, IT Act, and sectoral regulations.

Indirect overhead

  • Customer and investor trust: A publicized IP dispute signals poor governance. Enterprise customers may terminate contracts, exclude the vendor from RFPs, or demand damaging audits.
  • Management distraction: Leadership can spend 20–40% of their time for several quarters managing audits, litigation, and remediation instead of growing the business.
  • Valuation impact: For startups and scale-ups, unaddressed IPR gaps can reduce valuation by 10–30% during funding or acquisition due to legal risk and uncertainty.
  • Opportunity overhead: Engineering teams pulled off roadmap work to rewrite contaminated code or respond to audits delay product launches and revenue recognition.
  • Employee morale: Developers may become frustrated by sudden restrictions if governance is introduced without training and communication.
  • Insurance and financing: Cyber insurers may increase premiums or exclude IP-related claims. Lenders may impose covenants or reduce credit exposure.

Sample overhead Categories

overhead CategoryTypical Range (Indian Growing companies)Notes
License true-up and penalties– sDepends on vendor, deployment scale, and negotiation
Legal fees–Higher for cross-border contractor disputes or patent cases
Engineering remediation– sOSS rewrite, code cleanup, tooling changes
Lost deal value– s+Enterprise deals lost due to audit findings or trust erosion
Valuation haircut5–30%Particularly damaging for SaaS and technology startups
Incident response and forensics–IP exfiltration investigations and e-discovery

The real lesson is that IPR is not a compliance checkbox-it is a financial and strategic risk that belongs in the boardroom. Organizations that treat A.5.32 as a proactive investment rather than a reactive audit requirement consistently outperform their peers in customer trust, funding outcomes, and operational resilience. Building a strong IPR posture today prevents the emergency spending, legal exposure, and reputational damage that can derail growth tomorrow.


Scope and Applicability

What the Control Covers

A.5.32 applies to all intellectual property that the organization owns, licenses, uses, or distributes. This includes:

  • Proprietary software and source code developed in-house or by contractors.
  • Commercial software licenses, perpetual, subscription, SaaS, enterprise agreements, and OEM bundles.
  • Open-source and free software including libraries, frameworks, fonts, icons, and tools.
  • Copyrighted documents, standards, whitepapers, reports, training material, proposals, and marketing content.
  • Trademarks and brand assets, logos, taglines, product names, domain names.
  • Patents and patent-pending inventions including algorithms, business methods, and industrial processes.
  • Industrial designs and CAD files, product designs, molds, tooling, packaging.
  • Trade secrets and know-how, customer lists, licensing models, formulas, roadmaps.
  • Digital media, images, videos, music, sound effects, fonts, templates.
  • Datasets and model weights, training data, embeddings, ML models, analytics outputs.

Who It Applies To

The control applies to:

  • All employees, interns, and trainees.
  • Contractors, freelancers, and consultants.
  • Outsourced development partners and Managed Service Providers (MSPs).
  • Suppliers and vendors who handle the organization's IP.
  • Customers and partners who receive IP under license or data-sharing agreements.
  • Board members and senior leadership who approve IP strategy.

Role Categories

Role CategoryExamplesPrimary IP Obligations
CreatorsDevelopers, designers, researchers, architects, writersFollow IP policy, use only approved assets, assign IP to organization, document OSS usage
UsersSales, marketing, HR, finance, operationsUse only licensed software and media, no unauthorized copying, report suspected infringement
CustodiansIT admins, asset managers, procurementMaintain registers, ensure license compliance, control access, manage disposal
OwnersCISO, Legal Counsel, CTO, Product HeadApprove policy, accept risks, enforce contracts, report to board
Third PartiesVendors, contractors, cloud providersProtect IP under contract, return/destroy IP on exit, comply with license terms

Size-Based Applicability

Organization SizeFocus Areas
Small (1–50 employees)Basic software license tracking; employment IP clauses; no cracked software; approved image/font library.
Medium (50–500 employees)Formal IPR policy; SAM tool; open-source license tracking; vendor IP clauses; periodic audits.
Large (500–5000 employees)Enterprise SAM; DLP for source code; patent/trademark register; brand protection program; geo-license compliance.
Enterprise (5000+ employees)Global IP governance; regional license optimization; AI/model IP; M&A IP due diligence; board reporting.

Key Definitions and Terminology

TermDefinition
Intellectual Property (IP)Creations of the mind-such as inventions, literary and artistic works, designs, symbols, names, and images-used in commerce and protected by law.
Intellectual Property Rights (IPR)Legal rights granted to creators and owners of IP, including copyright, trademarks, patents, and trade secrets.
CopyrightLegal protection for original works of authorship fixed in a tangible medium, including software code, documents, images, music, and videos.
TrademarkA recognizable sign, design, or expression that identifies products or services of a particular source and distinguishes them from others.
PatentAn exclusive right granted for an invention, which may be a product or a process, providing a new way of doing something or a technical solution to a problem.
Trade SecretInformation that derives independent economic value from not being generally known and is subject to reasonable efforts to maintain its secrecy.
LicenseA legal permission to use IP owned by another party under specified terms, scope, duration, and restrictions.
End-User License Agreement (EULA)A contract between a software vendor and the user that defines permitted use, restrictions, and liabilities.
Open-Source Software (OSS)Software distributed with a license that grants users the right to use, study, modify, and distribute the software and its source code.
CopyleftA type of OSS license (e.g., GPL) requiring derivative works to be distributed under the same license terms, potentially affecting proprietary code.
Permissive LicenseAn OSS license (e.g., MIT, Apache 2.0, BSD) with minimal restrictions, typically allowing proprietary use.
Software Asset Management (SAM)The practice of managing and optimizing the purchase, deployment, maintenance, use, and disposal of software applications.
Software Composition Analysis (SCA)Automated inspection of source code and binaries to identify third-party and open-source components and their licenses.
Digital Rights Management (DRM)Technologies used to control the use, modification, and distribution of copyrighted works.
Data Loss Prevention (DLP)Tools and processes that detect and prevent unauthorized exfiltration of sensitive information, including IP.
Work for HireA legal doctrine under which works created by employees within the scope of employment are owned by the employer.
IP Assignment AgreementA contract in which a contractor or employee assigns ownership of created IP to the organization.
Fair Use / Fair DealingLimited exceptions to copyright infringement allowing use for purposes such as research, criticism, review, or news reporting, subject to local law.

Relationship to Other Controls

Upstream Controls (Provide Input to A.5.32)

ControlRelationship
A.5.1 Policies for information securityThe IPR policy is a topic-specific policy under the master policy and must be approved, communicated, and reviewed.
A.5.9 Inventory of information and other associated assetsThe asset register must identify IP-bearing assets such as software, source code, design files, and datasets.
A.5.12 Classification of informationClassification determines handling rules for IP assets (e.g., Restricted source code vs. Public marketing images).
A.5.31 Identification of legal, statutory, regulatory and contractual requirementsProvides the external compliance obligations that the IPR procedures must address.
A.5.37 Documented operating proceduresIPR procedures must be documented and available to personnel who need them.

Parallel Controls (Operate Alongside A.5.32)

ControlRelationship
A.5.13 Information backupBackups of IP assets must respect license terms and protect against loss of source code or designs.
A.5.30 ICT readiness for business continuityIP recovery (e.g., source code escrow, design repositories) is part of continuity planning.
A.6.1 ScreeningBackground checks reduce risk of IP theft by insiders.
A.6.6 Confidentiality or non-disclosure agreementsNDAs reinforce IPR protection for employees, contractors, and visitors.
A.8.1 User endpoint devicesEndpoint devices store IP; must be secured, inventoried, and wiped on disposal.
A.8.5 Secure authenticationStrong authentication protects repositories and systems containing IP.
A.8.12 Information transferTransfer of IP to third parties must be authorized, logged, and encrypted.
A.8.25 Secure development life cycleSDLC must include open-source license checks and IP protection gates.

Downstream Controls (Receive Input from A.5.32)

ControlRelationship
A.5.33 Protection of recordsLicense records, contracts, and IP registers must be protected from loss and falsification.
A.5.35 Independent review of information securityInternal audits sample IPR compliance as part of the independent review.
A.5.36 Compliance with policies, rules and standardsManagers verify that teams comply with the IPR policy.
A.8.32 Change managementChanges to software assets and repositories must be controlled to prevent IP contamination.

Detailed Implementation Guidance

The IPR Implementation Model

We recommend a seven-phase model that moves from governance to continuous monitoring:

┌─────────────────────────────────────────────────────────────┐
│  PHASE 1: GOVERNANCE                                        │
│  • Approve IPR policy and assign owner                       │
│  • Identify legal and contractual obligations                │
│  • Define IP asset categories and classification             │
└─────────────────────────────────────────────────────────────┘
                              │
                              ▼
┌─────────────────────────────────────────────────────────────┐
│  PHASE 2: DISCOVERY                                         │
│  • Inventory software, source code, designs, media           │
│  • Map ownership and licenses                                │
│  • Identify unauthorized or unlicensed items                 │
└─────────────────────────────────────────────────────────────┘
                              │
                              ▼
┌─────────────────────────────────────────────────────────────┐
│  PHASE 3: CONTROL DESIGN                                    │
│  • Design procurement, access, labeling, and disposal rules  │
│  • Implement SAM/SCA/DLP tooling                             │
│  • Draft employment and vendor IP clauses                    │
└─────────────────────────────────────────────────────────────┘
                              │
                              ▼
┌─────────────────────────────────────────────────────────────┐
│  PHASE 4: REMEDIATION                                       │
│  • Remove unlicensed software                                │
│  • True-up license shortfalls                                │
│  • Resolve OSS license conflicts                             │
│  • Secure high-value IP repositories                         │
└─────────────────────────────────────────────────────────────┘
                              │
                              ▼
┌─────────────────────────────────────────────────────────────┐
│  PHASE 5: OPERATIONALIZATION                                │
│  • Run approval workflows for new software/media             │
│  • Train employees and contractors                           │
│  • Acknowledge IPR policy                                    │
└─────────────────────────────────────────────────────────────┘
                              │
                              ▼
┌─────────────────────────────────────────────────────────────┐
│  PHASE 6: MONITORING & REVIEW                               │
│  • Quarterly license reconciliation                          │
│  • Periodic unauthorized software scans                      │
│  • Annual IPR policy review                                  │
└─────────────────────────────────────────────────────────────┘
                              │
                              ▼
┌─────────────────────────────────────────────────────────────┐
│  PHASE 7: CONTINUOUS IMPROVEMENT                            │
│  • Incident-driven policy updates                            │
│  • Maturity benchmarking                                     │
│  • Board reporting and optimization                          │
└─────────────────────────────────────────────────────────────┘

Step-by-Step Implementation

Step 1: Establish the IPR Governance Board

Create a cross-functional IPR working group with representatives from Legal, IT/Security, Procurement, HR, R&D/Product, and Finance. The board meets quarterly to review IP risks, license spend, audit findings, and policy changes. Define RACI: Legal owns contracts and legal interpretation, CISO owns technical controls, Procurement owns vendor licensing, HR owns employment clauses, and CTO/Product owns source code and R&D IP.

Step 2: Conduct a Legal and Contractual Review

List all laws, regulations, and contractual obligations that affect IP. For Indian companies this includes the Copyright Act, Trade Marks Act, Patents Act, Designs Act, IT Act, DPDP Act, sectoral RBI/SEBI/IRDAI guidelines, and customer contracts. Document these in the legal register (A.5.31). Identify license types in use: perpetual, subscription, SaaS, enterprise, OEM, academic, open-source, freeware, trial.

Step 3: Build the IP Asset Register

Extend the information asset register (A.5.9) with an IP lens. For each asset record:

  • Asset name and description
  • Asset owner and custodian
  • Asset classification (Public, Internal, Confidential, Restricted)
  • IP category (software, source code, design, document, media, patent, trademark, dataset, trade secret)
  • License type and license key / entitlement ID
  • Licensor/vendor name
  • Number of entitled users/devices/installations
  • Actual usage count
  • Purchase/order reference
  • Expiry/renewal date
  • Location (on-prem, cloud, endpoint)
  • Restrictions (geo, concurrent, virtualization, sub-licensing)
  • Open-source license (if applicable)
  • Link to proof of ownership or license agreement

For software, use automated discovery tools where possible and validate with manual spot checks.

Step 4: Implement Software Asset Management (SAM)

SAM is the operational backbone of A.5.32. Key processes:

  • Procurement gate: No software may be purchased or deployed without procurement and security approval. Cloud app procurement must pass through the sanctioned SaaS list.
  • License entitlement management: Centralize purchase orders, EULAs, and SaaS admin consoles. Reconcile entitlements against installations monthly.
  • Usage optimization: Identify shelfware and unused subscriptions; reharvest licenses before buying new ones.
  • Renewal workflow: Finance receives 90/60/30-day renewal alerts; no auto-renewal without owner confirmation.
  • True-up process: When audits reveal overuse, document the decision to buy more licenses or remove installations.

Step 5: Govern Open-Source Software

Open-source is not free of obligations. Implement an OSS governance program:

  • Maintain an approved open-source license whitelist (e.g., MIT, Apache 2.0, BSD, PostgreSQL, LGPL with conditions) and blacklist (e.g., GPL-3.0 in proprietary products, AGPL, proprietary-style licenses with onerous terms).
  • Integrate SCA into CI/CD to scan every commit and pull request.
  • Require developers to declare new OSS components in a request form.
  • Review copyleft and license compatibility before release.
  • Maintain a Software Bill of Materials (SBOM) for every product release.
  • Train engineering on license obligations and contribution policies.

Step 6: Protect Employment-Related IP

Ensure the organization owns what its people create:

  • Include "work for hire" and IP assignment clauses in all employment agreements.
  • For contractors and agencies, use standalone IP Assignment Agreements and NDAs before sharing confidential information.
  • Define "scope of employment" clearly for creators working on side projects or open-source contributions.
  • Document pre-existing IP brought by employees to avoid disputes.
  • Include post-employment confidentiality and non-solicitation clauses where enforceable under Indian law.

Step 7: Control Access to High-Value IP

Apply defense-in-depth to IP repositories and endpoints:

  • Enforce role-based access control (RBAC) and least privilege for source code, design, and document repositories.
  • Require MFA for all access to IP-bearing systems.
  • Use DLP rules to block bulk downloads of source code, CAD files, and customer lists to personal cloud storage or USB.
  • Apply digital watermarks or metadata labels to confidential documents and designs.
  • Log and review access to critical IP assets; flag anomalous access outside business hours or from unusual locations.

Step 8: Secure Procurement and Vendor IP Clauses

Every vendor agreement that involves IP should include:

  • Clear ownership of deliverables and background IP.
  • License grant scope (use, modify, sublicense, territory, duration).
  • Confidentiality and data protection obligations.
  • Right to audit for license compliance.
  • Return or secure destruction of IP on termination.
  • Indemnification for IP infringement caused by vendor deliverables.
  • Sub-processor and open-source disclosure obligations.

For cloud/SaaS vendors, verify that the organization retains ownership of its data and that the vendor does not train AI models on customer data without consent.

Step 9: Manage Media and Content Use

Marketing, HR, and L&D teams frequently use images, videos, music, and fonts. Establish:

  • A central, pre-approved media library with clear license terms (e.g., Shutterstock, Adobe Stock, Envato, Unsplash for limited use).
  • Prohibition on downloading "free" assets from random websites.
  • License tracking for stock media, including model releases and usage limits.
  • Clear rules on using third-party trademarks, logos, and celebrity images.
  • Accessibility and DPDP Act consent checks for images containing personal data.

Step 10: Implement Safe Transfer and Disposal

When software or IP assets are no longer needed:

  • Uninstall software and revoke licenses in the SAM tool.
  • Return physical media and license certificates to the vendor if required.
  • For source code and design repositories, follow retention and archival policies.
  • For disposal of endpoints, use secure wipe (NIST 800-88 Clear/Purge/Destroy) and record destruction.
  • For trade-secret documents, use cross-cut shredding or certified e-waste destruction.
  • Maintain disposal records for audit evidence.

IPR Controls by Asset Type

Different IP assets carry different risks and require tailored controls. The following matrix maps asset types to recommended controls.

Asset TypeKey RisksRequired ControlsEvidence
Commercial softwareUnlicensed use, over-deployment, expired subscriptionsSAM, procurement gate, periodic scans, renewal workflowLicense register, reconciliation reports
Source code (proprietary)Exfiltration, unauthorized copying, OSS contaminationRBAC, MFA, SCA, DLP, code review, SBOMAccess reviews, SCA reports, SBOMs
Open-source librariesCopyleft infection, patent risk, unsupported componentsLicense whitelist, SCA in CI/CD, Legal reviewApproval records, SBOM, CI/CD logs
Design files / CADTheft by competitors or contractors, version misusePDM/PLM access control, watermarking, NDARepository logs, watermarked files, NDAs
Digital media (images, video, music)Copyright infringement, unapproved useApproved DAM, license tracking, pre-publish checkDAM records, licenses, review checklist
Documents and standardsUnauthorized distribution, copyright breachClassification, DLP, controlled distributionClassification labels, access logs
Trademarks and brand assetsUnauthorized use, brand dilution, infringementBrand guidelines, trademark register, legal monitoringTrademark certificates, usage guidelines
Patents and inventionsInfringement by others, accidental disclosurePatent filings, invention disclosure process, NDAsPatent register, NDAs, disclosure forms
Datasets and ML modelsData theft, model extraction, privacy overlapClassification, encryption, access control, DLP, model watermarkingData classification, access logs, DLP alerts
Trade secretsInsider leakage, competitive useStrict need-to-know, NDAs, DLP, exit interviewsAccess lists, DLP records, exit statements

Software and SaaS Software is the most frequently audited IP category. Treat SaaS subscriptions as licenses with renewal dates, user counts, and feature tiers. Map each SaaS application to a business owner and require re-certification before renewal. When employees leave, reclaim SaaS seats immediately-unused SaaS licenses are a common source of both waste and compliance ambiguity. Document any Bring-Your-Own-License (BYOL) arrangements with cloud providers and ensure that virtualization and container use does not exceed core-based entitlements.

Source Code Source code is the crown jewel for technology companies. Use repository branch protection, require pull-request reviews with at least one security-aware reviewer, scan for secrets and unauthorized OSS, and restrict fork/export permissions. Maintain an SBOM for every release so customers and auditors can verify license hygiene. For on-premise deployments, ensure that source code escrow agreements are in place for critical third-party components.

Digital Media Marketing teams often unintentionally infringe copyright because they assume online content is free. Provide a curated library and a simple approval path for exceptions. Include "no internet downloads" in the acceptable use policy. For user-generated content, obtain model releases and consent documentation to comply with both copyright and DPDP Act requirements.

Datasets and AI Models With the rise of generative AI and machine learning, datasets and model weights have become portable, high-value IP. Classify them as Restricted, apply encryption at rest and in transit, and include clauses in cloud vendor contracts that prohibit training on your data. If you license training data from third parties, ensure the license permits your intended use, including fine-tuning and commercial deployment.

Trade Secrets Trade secrets rely on secrecy rather than registration. Limit access to the smallest group necessary, use NDAs, conduct exit interviews reminding leavers of confidentiality obligations, and monitor for unusual access patterns. Document the "reasonable efforts" you take to maintain secrecy-this is essential if you ever need to enforce trade-secret rights in court. In India, courts look for documented confidentiality agreements, access controls, and training records when deciding whether information qualifies as a trade secret. Therefore, a strong trade-secret program is both an information security control and a legal prerequisite for enforcement.

Implementation by Organization Size

Small Organizations (1–50 employees)

  • Use a simple spreadsheet for software inventory and a shared folder for license documents.
  • Purchase software only through a single authorized channel.
  • Include IP assignment clauses in offer letters.
  • Use only approved stock-image subscriptions.
  • Review quarterly.

Medium Organizations (50–500 employees)

  • Adopt a lightweight SAM tool (e.g., ManageEngine AssetExplorer, Snipe-IT, or Lansweeper).
  • Implement procurement workflow in the ITSM tool.
  • Add SCA scanning for development teams.
  • Deploy DLP for source code and design repositories.
  • Conduct bi-annual IPR internal audits.

Large/Enterprise Organizations (500+ employees)

  • Deploy enterprise SAM (Flexera, Snow, ServiceNow SAM) integrated with procurement and HR.
  • Implement global license optimization and chargeback.
  • Use dedicated brand protection and trademark monitoring services.
  • Run continuous SCA, DLP, and access analytics.
  • Establish an IP risk dashboard for the board.

Tools, Technologies, and Solutions

Tool Categories

CategoryPurposeExample Tools
Software Asset Management (SAM)Discover, normalize, and reconcile software installations against entitlementsFlexera, Snow Software, ServiceNow SAM, ManageEngine AssetExplorer, Lansweeper
Software Composition Analysis (SCA)Identify OSS components and licenses in source codeSnyk, Black Duck, Mend (formerly WhiteSource), FOSSology, GitLab SCA, GitHub Advanced Security
Data Loss Prevention (DLP)Prevent exfiltration of source code, designs, and documentsMicrosoft Purview DLP, Symantec DLP, Forcepoint DLP, Digital Guardian, Trellix
Digital Asset Management (DAM)Manage licensed images, videos, and brand assetsBynder, Brandfolder, Widen, Adobe Experience Manager
Contract / CLMManage license agreements, NDAs, and vendor contractsIcertis, Agiloft, SpotDraft, Zoho Contracts, DocuSign CLM
Digital WatermarkingProve ownership and deter leakage of documents and mediaDigimarc, Imatag, Vitrium, Custos
Source Code ProtectionSecure repositories and detect secrets or unauthorized accessGitHub Advanced Security, GitLab Ultimate, Bitbucket, SonarQube, Checkmarx
Endpoint ProtectionDetect unauthorized software and enforce USB/cloud restrictionsMicrosoft Intune, CrowdStrike, SentinelOne, Sophos

Vendor Comparison Matrix

Vendor / ToolBest ForIndian Availabilitylicensing IndicationProsCons
FOSSologyFree OSS license complianceOpen sourceFreeefficient, SPDX outputRequires self-hosting expertise
Microsoft Purview DLPMicrosoft 365 ecosystemsDirectBundled with E5Native integrationLess effective on non-MS platforms

Build vs. Buy Guidance

ScenarioRecommended Approach
<100 endpoints, no dedicated security teamSpreadsheet + approved vendor list + manual quarterly review
100–1000 endpoints, small IT teamCloud SAM (e.g., ManageEngine) + Snyk SCA + Microsoft Purview DLP
1000+ endpoints, multi-locationEnterprise SAM + enterprise SCA + enterprise DLP + CLM
Regulated BFSI/PharmaBest-of-breed with audit-grade reporting and local support

Policy and Procedure Templates

Intellectual Property Rights (IPR) Policy Template

INTELLECTUAL PROPERTY RIGHTS POLICY
[Organization Name]
Version: 1.0
Approved by: [CISO / Legal Counsel / CEO]
Date: [Date]
Review Date: [Date + 12 months]
Classification: Internal

1. PURPOSE
This policy defines [Organization Name]'s approach to identifying, protecting,
and managing intellectual property rights in compliance with ISO 27001:2022
Annex A 5.32 and applicable Indian and international laws.

2. SCOPE
This policy applies to all employees, contractors, consultants, vendors, and
third parties who create, use, manage, or have access to [Organization Name]
intellectual property or third-party licensed materials.

3. POLICY STATEMENTS

3.1 Ownership of Work Product
All work product created by employees within the scope of employment is the
property of [Organization Name] under the "work for hire" doctrine. Contractors
must sign an IP Assignment Agreement before accessing confidential information
or creating deliverables.

3.2 Software Licensing
Only properly licensed software from approved vendors may be installed or used
on [Organization Name] assets. Unlicensed, cracked, pirated, or unauthorized
software is prohibited. All software purchases must be approved by Procurement
and IT Security.

3.3 Open-Source Software
Developers may only use open-source components that have been approved through
the OSS governance process. Copyleft licenses require Legal review before use.
All OSS components must be recorded in the SBOM.

3.4 Third-Party Content
Employees may only use images, videos, music, fonts, documents, and templates
from approved sources with valid licenses. Trademarks and logos of third
parties may not be used without written permission.

3.5 Confidentiality and Protection
High-value IP (source code, designs, customer lists, trade secrets) must be
stored in approved repositories with access limited by role. Bulk downloads,
screenshots, and transfers to personal devices or cloud storage are prohibited
unless authorized.

3.6 Procurement and Contracts
All vendor agreements must specify IP ownership, license scope,
confidentiality, return/destruction, and infringement indemnification.

3.7 Monitoring and Compliance
[Organization Name] reserves the right to scan devices and repositories for
unauthorized software and IP. Non-compliance may result in disciplinary action,
contract termination, or legal proceedings.

3.8 Reporting
Employees must immediately report suspected IP infringement, unauthorized
software, or IP exfiltration to the CISO or Legal Counsel.

4. ROLES AND RESPONSIBILITIES
- CISO / IPR Policy Owner: Maintain policy, coordinate audits, report to board.
- Legal Counsel: Interpret laws, review contracts and OSS licenses.
- Procurement: Ensure license compliance in purchases.
- IT / Security: Maintain SAM tool, enforce technical controls.
- HR: Include IP clauses in employment contracts and exit process.
- All Employees: Comply with policy, use only approved assets, report issues.

5. ENFORCEMENT
Violations of this policy may result in corrective action, disciplinary action
up to and including termination, and civil or criminal liability under
applicable law.

6. REVIEW
This policy is reviewed annually and upon significant changes in operations,
technology, or regulation.

7. ACKNOWLEDGMENT
All personnel must acknowledge this policy at onboarding and after any
material change.

IPR Procedure: Software License Compliance

PROCEDURE: SOFTWARE LICENSE COMPLIANCE
Version: 1.0
Owner: IT Asset Manager

OBJECTIVE
Ensure all software used by [Organization Name] is properly licensed and used
within entitlement limits.

PROCEDURE STEPS

1. REQUEST
   a. Employee or manager submits software request via ITSM ticket.
   b. Request includes business justification, number of users, and preferred
      vendor.

2. APPROVE
   a. Manager approves business need.
   b. IT Security confirms compatibility and security posture.
   c. Procurement confirms vendor is approved and negotiates license terms.

3. PURCHASE
   a. Procurement issues purchase order.
   b. License certificate, EULA, and proof of purchase stored in contract
      repository and linked in SAM tool.

4. DEPLOY
   a. IT installs software via approved package or self-service portal.
   b. License key assigned to user/device in SAM tool.

5. MONITOR
   a. SAM tool reconciles installations against entitlements monthly.
   b. Overuse is flagged for true-up or removal.
   c. Unused licenses are identified for reharvesting.

6. RENEW
   a. Finance receives 90/60/30-day renewal alerts.
   b. Owner confirms continued need and user count.
   c. Renewal executed and records updated.

7. DISPOSE
   a. On termination or replacement, software is uninstalled.
   b. License is reclaimed or returned per vendor terms.
   c. Disposal recorded in SAM tool and asset register.

8. AUDIT
   a. Quarterly internal spot-check of 10% of endpoints.
   b. Annual comprehensive license reconciliation.
   c. Findings logged in corrective action register.

RECORDS
- ITSM tickets
- Purchase orders and invoices
- License certificates and EULAs
- SAM reconciliation reports
- Disposal records

IPR Procedure: Open-Source Approval

PROCEDURE: OPEN-SOURCE SOFTWARE APPROVAL

1. Developer identifies a required OSS component.
2. Developer completes OSS Request Form with component name, version, source,
   license, and intended use.
3. SCA tool scans component for license, vulnerabilities, and dependencies.
4. Legal reviews license for copyleft, patent, and commercial restrictions.
5. Security reviews component for known vulnerabilities.
6. Component is added to approved SBOM or rejected with justification.
7. Developer is notified and usage is tracked.

Risk Assessment and Treatment

IP Risk Register (Sample)

Risk IDRisk DescriptionLikelihoodImpactRisk LevelTreatmentOwner
R-IP-01Unlicensed software discovered during vendor auditMediumHighHighImplement SAM, quarterly reconciliation, procurement gateCISO / Procurement
R-IP-02Open-source copyleft license contaminates proprietary productMediumHighHighDeploy SCA in CI/CD, maintain license whitelist, Legal reviewCTO / Legal
R-IP-03Contractor walks away with source code / designsMediumHighHighIP assignment clauses, DLP, MFA, access revocationCISO / HR
R-IP-04Employee uses pirated images in marketing campaignLowHighMediumApproved media library, training, pre-publish reviewMarketing Head
R-IP-05License renewal lapses causing operational outageLowMediumMediumRenewal alerts, Finance workflow, SAM calendarIT Asset Manager
R-IP-06Trade secret leaked via personal email / cloud storageMediumHighHighDLP, labeling, awareness, access reviewsCISO
R-IP-07Vendor uses organization's data to train AI modelLowHighMediumContract clause prohibiting AI training, vendor auditLegal / Procurement
R-IP-08Patent infringement from use of third-party componentLowHighMediumPatent indemnification in vendor contracts, SCALegal
R-IP-09Disposal of equipment without secure wipe leaks IPLowMediumMediumSecure wipe procedure, certified e-waste vendorIT / Facilities
R-IP-10Failure to document IP ownership delays M&A or fundingLowHighMediumMaintain IP register and assignment agreementsLegal / CFO

Risk Treatment Options

TreatmentWhen to UseExample
MitigateMost IP risksDeploy SAM, SCA, DLP, access controls
TransferHigh-value vendor riskRequire vendor indemnification and cyber insurance
AvoidUnacceptable legal exposureProhibit copyleft OSS in commercial products
AcceptLow residual risk with documented justificationAccept risk of minor image reuse after legal clearance

Residual Risk Acceptance

Any residual high-risk items must be accepted by the CISO or CEO with documented justification. Accepted risks are reviewed quarterly.

Audit and Compliance Checklist

Auditor Questions and Evidence

#Audit QuestionExpected EvidenceRed Flag
1Is there an approved IPR policy?Signed policy, version history, approval recordNo policy or policy not approved
2Is the IPR policy communicated to relevant personnel?Communication records, acknowledgment logsPolicy not distributed or acknowledged
3Are software and IP assets inventoried?Asset register, SAM tool reportsNo register or incomplete inventory
4Can you prove ownership or license for all software?Purchase orders, EULAs, license certificates, SaaS admin recordsMissing proof for critical software
5Are all software installations within license entitlements?Reconciliation report showing entitlement vs. usageOver-deployment or negative compliance
6Are software purchases made only from approved vendors?Approved vendor list, procurement recordsEvidence of gray-market or pirated software
7Are open-source components tracked and approved?SBOM, SCA reports, OSS approval recordsUnapproved GPL/AGPL components in products
8Do employment contracts include IP assignment clauses?Sample contracts, HR recordsNo IP assignment or NDA clauses
9Do contractor agreements include IP assignment and NDA?Contractor contracts, IP Assignment AgreementsContractors working without agreements
10Are high-value IP repositories protected by access controls?RBAC configuration, access review recordsOpen access to source code or designs
11Is MFA enforced for IP-bearing systems?IAM policy, conditional access settingsSingle-factor access to source code
12Is DLP configured to prevent IP exfiltration?DLP policy, incident recordsNo DLP or unmonitored egress
13Are devices scanned for unauthorized software?Scan reports, remediation recordsNo scanning or repeated unlicensed installs
14Is there a process for license renewal?Renewal calendar, Finance workflowExpired licenses causing operational risk
15Is software disposed/returned safely?Disposal records, license return confirmationsNo disposal records
16Are media and marketing assets used from approved sources?DAM records, media licensesRandom images from internet in campaigns
17Do vendor contracts include IP protection clauses?Contract templates, executed agreementsVendors free to use customer data/IP
18Is there a process to report suspected IP violations?Incident report form, training recordsEmployees don't know how to report
19Are IP risks reviewed at management review?Management review minutesIP not discussed in governance forums
20Are internal audits conducted for A.5.32?Internal audit plan, findings, closureNo IPR-specific audit
21Are exceptions to IPR policy documented and approved?Exception register, approval recordsUnauthorized exceptions
22Is there evidence of employee awareness training?Training records, quiz resultsNo training on IPR
23Are source code and designs labeled or watermarked?Labeling standard, sample assetsConfidential IP unlabeled
24Is trade-secret information subject to access reviews?Quarterly access review recordsStale access to sensitive IP
25Are AI/model weights and datasets classified as IP?Classification records, protection controlsAI assets unprotected

Pre-Audit Self-Assessment

Before the certification or surveillance audit, complete this self-assessment:

  • IPR policy is current, approved, and acknowledged by >95% of staff.
  • Software asset register covers 100% of endpoints and servers.
  • License entitlement vs. usage reconciliation completed in the last quarter.
  • All unlicensed software removed or true-up completed.
  • SBOM generated for the last product release.
  • All employment and contractor contracts include IP clauses.
  • Access reviews completed for source code and design repositories.
  • DLP policies active for IP exfiltration vectors.
  • Vendor contract template includes IP protection clauses.
  • Disposal records available for the last 12 months.
  • Management review minutes include IP risk discussion.
  • Internal audit findings for A.5.32 are closed.

Metrics and KPIs

Figure · Measures

The measures that show A.5.32 is working

  • Software license compliance rate100%Monthly
  • License reconciliation coverage100%Monthly
  • Open-source approval rate100%Per release
  • IPR policy acknowledgment rate>98%Quarterly
  • IPR training completion rate>95%Annually
Targets and reporting cadence as defined in the table below, where the formula for each is given.

IPR Governance Scorecard

MetricFormulaTargetFrequency
Software license compliance rate(Compliant installations / Total installations) × 100100%Monthly
License reconciliation coverage(Assets reconciled / Total software assets) × 100100%Monthly
Open-source approval rate(Approved OSS components / Total OSS components) × 100100%Per release
IPR policy acknowledgment rate(Acknowledged personnel / Total personnel) × 100>98%Quarterly
IPR training completion rate(Trained personnel / Target personnel) × 100>95%Annually
Unauthorized software incidentsCount of unlicensed installations detected0Monthly
IPR audit findingsNumber of findings per audit0 majorPer audit
High-value IP access review completion(Reviews completed / Scheduled reviews) × 100100%Quarterly
Vendor contract IP clause coverage(Contracts with IP clauses / Total contracts) × 100100%Per contract
License renewal on-time rate(Renewals completed before expiry / Total renewals) × 100100%Monthly
IP exfiltration events detected/blockedCount of DLP blocks/quarantine actionsTrend downMonthly
IPR maturity scoreWeighted score across policy, register, controls, monitoringLevel 3+Annually

Sample IPR Dashboard

┌──────────────────────────────────────────────────────────────┐
│  IPR DASHBOARD — June 2026                                  │
├──────────────────────────────────────────────────────────────┤
│  Software License Compliance      99.2% ████████████████████░ │
│  OSS Approval Coverage            100%  █████████████████████ │
│  IPR Policy Acknowledged          97%   ███████████████████░░ │
│  High-Value IP Access Reviewed    100%  █████████████████████ │
│  Renewals Due ≤30 Days            3     → Action required     │
│  Unauthorized Software Detected   0     → Good                │
│  Open IPR Audit Findings          1     → Due 2026-07-15      │
└──────────────────────────────────────────────────────────────┘

Target Setting by Maturity

Maturity LevelLicense CompliancePolicy AcknowledgmentAudit Findings
Level 1–2≥90%≥80%≤3 minor
Level 3≥98%≥95%0 major, ≤2 minor
Level 4–5100%≥98%0 major, ≤1 minor

Common Pitfalls / Audit Failures & How to Avoid Them

#Pitfall / Audit FailureWhy It HappensHow to Avoid
1No IPR policy or generic copy-paste policySecurity team treats IP as legal-only issue; policy not tailoredAssign CISO+Legal co-ownership; write organization-specific policy
2Software inventory based on purchase records onlySAM tool not deployed; employees install freelyUse automated discovery; reconcile against entitlements
3Unlicensed software on endpointsShadow IT, personal software, cracked toolsScan quarterly; block unauthorized installs; enforce procurement gate
4Missing IP assignment clauses in contractsHR uses outdated templates; contractors not screenedUpdate templates; no work starts before signed NDA/IP assignment
5Open-source license contaminationDevelopers copy code without legal reviewSCA in CI/CD; whitelist/blacklist; Legal review for copyleft
6No proof of license for SaaSSaaS bought with corporate cards; no central recordMandate procurement approval; centralize admin consoles and POs
7Marketing uses unlicensed imagesTeams download from GoogleProvide approved DAM; pre-publish IP check
8DLP not covering source codeDLP tuned only for PIIAdd IP classification and DLP rules for code/design exfiltration
9Vendor contracts silent on AI/data useNew AI clauses not added to templatesUpdate templates to prohibit training on customer data/IP
10Disposal without license return/wipe recordsIT focuses on hardware disposal, not data/IPAdd license reclaim and secure wipe steps to disposal SOP

Illustrative Scenarios

Illustrative scenario, a composite example for guidance, not a specific Singahi engagement or a verified outcome.

Illustrative Scenario 1: Mumbai Manufacturing Firm, The Unlicensed Software Audit

Background A 250-employee precision engineering company in Mumbai supplied components to automotive OEMs. The company had grown rapidly through acquisitions and had no centralized IT procurement. Each plant manager bought software independently, and the design team relied on AutoCAD, SolidWorks, and Adobe tools.

The Incident In early 2025, a major OEM customer requested evidence of license compliance as part of its supplier sustainability audit. The company could produce purchase records for only 60% of its installed design and productivity software. A follow-up scan revealed:

  • 47 unlicensed installations of CAD software across three plants.
  • 120 installations of Microsoft Office without sufficient Office 365 licenses.
  • Multiple copies of cracked PDF and image editing tools on shop-floor PCs.
  • No centralized asset register or license certificates.

The OEM placed the supplier on probation and threatened to remove them from the approved vendor list. Software vendor audit letters followed, demanding true-up payments estimated at plus penalties.

Root Cause Analysis

  1. Decentralized purchasing, No procurement gate or approved vendor list.
  2. No SAM process, License tracking was non-existent; IT did not know what was installed.
  3. Cultural tolerance, Shop-floor supervisors believed "everyone uses cracked tools."
  4. No awareness, Employees did not understand that unlicensed software was a business risk.
  5. Weak management oversight, IP and software compliance were never discussed at board level.

Remediation The company engaged Singahi to implement an IPR framework:

Phase 1 (Weeks 1–2): Stabilize

  • Declared an immediate moratorium on new software purchases.
  • Deployed an agentless discovery tool (Lansweeper) to map all installations.
  • Deleted cracked tools and unauthorized software from all endpoints.
  • Purchased emergency true-up licenses to close the most critical gaps.

Phase 2 (Weeks 3–6): Govern

  • Approved an IPR policy co-owned by the CFO and CISO.
  • Implemented a procurement gate via the ITSM system.
  • Centralized license certificates and purchase orders in a contract repository.
  • Trained all plant managers and designers on approved software and reporting.

Phase 3 (Weeks 7–12): Optimize

  • Adopted ManageEngine AssetExplorer for ongoing SAM.
  • Set up quarterly reconciliation and 90-day renewal alerts.
  • Negotiated an enterprise agreement with the CAD vendor, reducing per-seat overhead by 18%.
  • Added IP clauses to all supplier and contractor agreements.

Results

  • License compliance improved from 60% to 99.5% within four months.
  • True-up and penalty overhead reduced from to through negotiation and remediation.
  • OEM supplier status restored; company won a multi-year contract that had been at risk.
  • Passed a follow-up ISO 27001 surveillance audit with zero IPR findings.
  • Recovered annually by identifying and reharvesting unused licenses.

Key Lessons

  1. Decentralized purchasing is the enemy of license compliance.
  2. A single discovery exercise can reveal hidden liabilities worth crores.
  3. Management tone matters: when the CFO treated IPR as a board-level risk, behavior changed.
  4. License optimization pays for itself-unused licenses are cash left on the table.
  5. Customer audits are becoming standard; IPR readiness is a competitive advantage.

Illustrative Scenario 2: Bengaluru Fintech Startup, Source Code Exfiltration and OSS License Contamination

Background A 90-employee Bengaluru fintech startup built a lending platform used by NBFCs. The engineering team included 25 full-time developers and 15 contractors in India and Ukraine. The company was preparing for a Series B funding round and an ISO 27001 certification.

The Incident During investor due diligence, two critical issues surfaced:

  1. OSS license contamination: An SCA scan commissioned by the investor found that the platform contained 18 GPL-2.0-licensed libraries linked directly into the proprietary backend. The startup's distribution model (on-premise deployment at customer data centers) triggered copyleft obligations that could force disclosure of the entire backend source code.
  2. Source code exfiltration: A recently terminated Ukrainian contractor had downloaded the entire Git repository to a personal cloud storage account two days before leaving. The contractor's agreement did not contain a clear IP assignment clause enforceable under Indian or Ukrainian law.

The investor made the funding contingent on resolving both issues. The estimated impact of rewriting the GPL-infected modules was and three months of engineering time. The exfiltration triggered a legal response and delayed the certification by six months.

Root Cause Analysis

  1. No OSS governance: Developers chose libraries based on functionality, not license. No SCA tool was in use.
  2. Weak contractor IP clauses: The contractor agreement was a generic service agreement with no explicit IP assignment or return/destruction obligations.
  3. No DLP on repositories: Bulk downloads to personal cloud were not blocked or alerted.
  4. No access review: The contractor retained access until the last day; offboarding was delayed by HR.
  5. No board-level IP risk view: The CTO believed "we own the code because we paid for it," misunderstanding contractor IP law.

Remediation The startup engaged Singahi for a full A.5.32 implementation:

Phase 1 (Weeks 1–3): Contain and Assess

  • Revoked the contractor's access immediately and sent a legal notice demanding deletion and confirmation.
  • Conducted a full SCA scan across all repositories.
  • Quarantined GPL-infected modules and identified replacement libraries with permissive licenses.
  • Reviewed all active contractor agreements and required signed IP Assignment Addendums.

Phase 2 (Weeks 4–8): Remediate

  • Rewrote or replaced 14 of the 18 GPL libraries; obtained commercial licenses for the remaining 4.
  • Integrated Snyk SCA into the CI/CD pipeline with a license policy.
  • Created an approved OSS license whitelist and a developer approval workflow.
  • Deployed Microsoft Purview DLP rules to block bulk downloads from GitHub and cloud storage.

Phase 3 (Weeks 9–16): Institutionalize

  • Approved an IPR policy and trained all engineering and product staff.
  • Updated employment and contractor templates with enforceable IP assignment clauses.
  • Implemented quarterly access reviews and automated leaver access revocation.
  • Generated an SBOM for every release and added it to customer security documentation.

Results

  • Series B closed six months late but at the original valuation; the investor's security concerns were fully addressed.
  • ISO 27001 certification achieved with no major findings on A.5.32.
  • Customer security questionnaires now completed in two days instead of two weeks.
  • Engineering velocity initially dropped 15% during remediation but recovered as the approval workflow became routine.
  • The company added an "IP Risk" slide to every board deck.

Key Lessons

  1. Contractor agreements are not optional paperwork-they determine who owns your product.
  2. GPL in proprietary products is a funding and exit killer; SCA is non-negotiable.
  3. DLP must cover code repositories, not just endpoints.
  4. Funding due diligence will increasingly include IPR audits; prepare early.
  5. IPR is a board-level risk in technology companies.

Multi-Framework Mapping

Control Mapping Table

ISO 27001:2022 A.5.32SOC 2 Type IIPCI DSS 4.0NIST 800-53 Rev 5CIS Controls v8COBIT 2019GDPR / DPDP Act 2023
Intellectual property rightsCC1.2, CC1.3, CC6.1, CC6.612.3.1, 12.3.2, 12.4.1, 12.5.1PM-1, PM-2, CM-10, CM-11, MP-7, PS-6, PS-7, SA-4, SA-9Control 3 (Data Protection), Control 7 (Continuous Vulnerability Management), Control 10 (Malware Defenses), Control 13 (Network Monitoring and Defense)APO01.01, APO01.02, APO01.03, APO04.03, APO12.01, APO12.02, APO12.03, DSS01.04, DSS05.02GDPR Art. 32 (Security of processing), Art. 28 (Processor obligations); DPDP Act 2023 Section 8 (Reasonable security safeguards), Section 12 (Breach notification)

Mapping Notes

  • SOC 2 Type II: CC1.2 (communication of information objectives) and CC1.3 (establishment of responsibility) support the IPR policy and governance. CC6.1 (logical access) and CC6.6 (encryption) map to access controls for IP repositories.
  • PCI DSS 4.0: Requirements 12.3 (security impact analysis), 12.4 (acceptance of risk), 12.5 (maintenance of information security policy) align with IPR governance and policy maintenance.
  • NIST 800-53 Rev 5: CM-10 (software usage restrictions) and CM-11 (user-installed software) are directly relevant. PS-6 (access agreements) and PS-7 (external personnel security) map to employment and contractor IP clauses. SA-4 (acquisition) and SA-9 (external system services) map to vendor IP clauses.
  • CIS Controls v8: Data protection, vulnerability management, malware defenses, and network monitoring all contribute to preventing unauthorized software and IP exfiltration.
  • COBIT 2019: APO01 (managed I&T management framework) and APO12 (managed risk) establish governance; DSS01 (managed operations) and DSS05 (managed security services) operationalize controls.
  • GDPR / DPDP Act 2023: While focused on personal data, security of processing and breach notification obligations overlap when IP assets contain personal data or when IP theft involves data breaches.

Industry-Specific Mapping

IndustryAdditional FrameworkRelevant Requirement
BFSIRBI Cyber Security FrameworkBoard-approved cyber security policy, vendor risk management, incident reporting
Capital MarketsSEBI Cybersecurity CircularsComplete policies, quarterly reporting, data protection
InsuranceIRDAI Cyber Security GuidelinesProtection of policyholder data, business continuity, licensed software
HealthcareNABH / DPDP Act 2023Patient data confidentiality, consent, secure records
GovernmentMeitY / CERT-InData localization, incident reporting, procurement security

Implementation Roadmap

Figure · Timeline

Rollout in order

  1. Phase 1: Foun…1–30
  2. Phase 2: Build31–60
  3. Phase 3: Embed61–90
Milestones in delivery order. Owners and the evidence each produces are in the table below.

Standard 8-Week Roadmap

WeekFocusKey ActivitiesDeliverables
Week 1Governance & Legal ReviewForm IPR working group; review legal and contractual obligations; approve policy ownerIPR charter, legal register update
Week 2Discovery & InventoryDeploy discovery tools; inventory software, code, media, designs; identify unlicensed itemsIP asset register v1, gap report
Week 3Remediation, SoftwareRemove/delete unauthorized software; true-up critical licenses; centralize license recordsClean baseline, license records
Week 4Remediation, Contracts & OSSUpdate employment/contractor templates; scan repositories; resolve OSS conflictsNew contract clauses, SCA baseline
Week 5Control Design & ToolingImplement procurement gate; deploy SAM/SCA/DLP; configure access controlsWorkflow live, tools configured
Week 6OperationalizationTrain employees and contractors; launch acknowledgment campaign; run approval workflows>95% acknowledgment, trained teams
Week 7Monitoring & ReviewFirst monthly reconciliation; access reviews; exception registerReconciliation report, review records
Week 8Audit ReadinessInternal audit of A.5.32; close findings; management reviewAudit report, closed findings

90-Day Sprint for New ISMS

PhaseDaysActivities
Phase 1: Foundation1–30Approve IPR policy, legal register, asset inventory, remove unlicensed software
Phase 2: Build31–60SAM/SCA/DLP deployment, contract updates, OSS governance, training
Phase 3: Embed61–90First reconciliation, access reviews, internal audit, management review, continuous improvement plan

Ongoing Cadence

ActivityFrequencyOwner
License reconciliationMonthlyIT Asset Manager
Open-source SBOM reviewPer releaseEngineering Lead
Access review for high-value IPQuarterlyData/Repository Owners
IPR policy reviewAnnuallyCISO / Legal
Internal audit of A.5.32AnnuallyInternal Audit
Vendor contract IP clause reviewPer contract / AnnuallyLegal / Procurement
Management review of IP risksQuarterlyIPR Working Group

FAQ

Does A.5.32 apply only to software?

No. While software licensing is the most common audit focus, A.5.32 covers all intellectual property: source code, patents, trademarks, designs, copyrighted documents, digital media, datasets, and trade secrets. Your procedures must address each relevant category.

Can a small company satisfy A.5.32 with just a policy?

No. ISO 27001 requires procedures that are implemented and operating. A policy alone is insufficient. You also need evidence of an asset register, license tracking, employment clauses, and periodic review.

Do we need a separate IPR policy, or can it be part of another policy?

For small organizations, IPR rules can be embedded in the Acceptable Use Policy or IT Security Policy. For medium and large organizations, a dedicated topic-specific IPR Policy is strongly recommended and expected by auditors.

How often should we review software licenses?

Reconcile license entitlements against actual usage at least monthly. Review the IPR policy annually and after any significant change such as a new product launch, merger, or regulatory update.

What is the biggest open-source license risk?

Copyleft licenses such as GPL, AGPL, and LGPL can require you to release your proprietary source code if you distribute derivative works. Always run SCA and obtain Legal review before using copyleft components in commercial products.

Can employees use free images from the internet?

Only if the image has a clear license permitting commercial use and you retain proof. The safest approach is to use an approved stock-media subscription or a vetted creative-commons library. Random search-engine images are high risk.

What should we do if we find unlicensed software?

Remove or uninstall it immediately, document the finding, determine the root cause, and decide whether to purchase licenses or discontinue use. Repeat offenders should face disciplinary action.

How do we protect IP when using contractors?

Require signed NDAs and IP Assignment Agreements before sharing any confidential information. Use least-privilege access, monitor activity, revoke access on termination, and include return/destruction clauses.

Is source code escrow relevant to A.5.32?

Yes. Source code escrow protects your continuity rights if a vendor goes out of business. It also demonstrates that you have procedures to safeguard access to critical IP. Escrow agreements should be reviewed as part of vendor IP clauses.

How does A.5.32 relate to the DPDP Act 2023?

While A.5.32 focuses on IP rights, many IP assets contain personal data. The DPDP Act requires reasonable security safeguards and breach notification. An IPR program that protects datasets, ML models, and customer analytics also supports DPDP compliance.

What evidence do auditors expect for A.5.32?

Auditors expect: an approved IPR policy, an IP/software asset register, proof of licenses, reconciliation reports, employment/contractor IP clauses, SCA reports (if applicable), DLP/access controls, disposal records, training records, and management review minutes.

How long does it take to implement A.5.32?

A focused organization can reach baseline compliance in 4–8 weeks. Achieving maturity levels 4–5 with automated SAM, SCA, and DLP typically takes 3–6 months.


References and Further Reading

Standards and Frameworks

  • ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection, Information security management systems, Requirements
  • ISO/IEC 27002:2022, Information security, cybersecurity and privacy protection, Information security controls
  • ISO/IEC 27036, Information security for supplier relationships
  • ISO/IEC 19770, Information technology, IT asset management
  • NIST Special Publication 800-53 Rev 5, Security and Privacy Controls for Information Systems and Organizations
  • NIST SP 800-88 Rev 1, Guidelines for Media Sanitization
  • CIS Controls v8, Center for Internet Security
  • COBIT 2019, ISACA
  • SOC 2 Trust Services Criteria, AICPA
  • PCI DSS 4.0, PCI Security Standards Council

Indian Laws and Regulations

  • The Copyright Act, 1957 (as amended)
  • The Trade Marks Act, 1999
  • The Patents Act, 1970
  • The Designs Act, 2000
  • The Information Technology Act, 2000
  • The Digital Personal Data Protection Act, 2023
  • RBI Cyber Security Framework in Banks, 2016
  • RBI Master Direction on IT Framework for NBFCs, 2017
  • SEBI Circulars on Cyber Security and Cyber Resilience
  • IRDAI Guidelines on Information and Cyber Security for Insurers
  • CERT-In Directions, 2022

Useful Resources

  • BSA | The Software Alliance, Global Software Survey
  • Open Source Initiative (OSI), License list
  • SPDX (Software Package Data Exchange), sbom.dev
  • OWASP Dependency-Check
  • Linux Foundation OpenChain Project
  • MeitY, National Cyber Security Policy and Data Protection Guidance

How we can help

Working toward this?

If a certification or a customer's security questionnaire is what brought you here, tell us where you are. We'll give you an honest read on the work and the timeline, with no obligation.

What happens next

  1. Tell us the trigger

    A questionnaire, an audit date or an investor ask. The short form or a call both work.

  2. A practitioner replies

    A senior practitioner, not a bot, within four business hours.

  3. You get a scoped next step

    An honest view of what the work involves. No pressure, no theatre.