ISO 27001 Annex A 5.32 Intellectual property rights requires organisations to protect proprietary assets and comply with software licences. Documented rules prevent legal disputes, safeguard valuable business property, and stop unauthorised copying.
Table of contents
Key Takeaways
- Protect proprietary assets: Establish clear rules to safeguard source code, patents, trademarks, and copyright materials.
- Store rules centrally: Keep licensing policies, proof of purchase records, and asset registers in a central document repository.
- Maintain licence compliance: Track all purchased software licences to ensure company usage stays strictly within legal limits.
- Prevent unauthorised copying: Ban illegal software downloads, unlicensed media usage, and unapproved duplication of third-party tools.
- Define asset ownership: Ensure employment contracts state clearly that all work created by staff belongs to the business.
- Manage open source risks: Review open source software components to prevent licensing conflicts and protect company codebases.
- Conduct periodic software audits: Run automated scans and licence reviews to spot unapproved software installations early.
- Protect third-party materials: Respect copyright rules when using external images, documentation, code libraries, and customer data.
How to Implement ISO 27001 Annex A 5.32
- Draft an intellectual property policy: Write clear guidance on copyright, licensing, and code protection in your central repository.
- Maintain a software asset register: Build a central inventory listing all licensed software applications, seat counts, and renewal dates.
- Retain proof of purchase: Store software invoices, licence keys, and subscription agreements in a secure document library.
- Restrict admin install rights: Remove local administrator permissions from workstations to block unauthorised software downloads.
- Review open source licences: Create an approval process to evaluate open source components before engineers integrate them into company builds.
- Insert contract ownership terms: Ensure employment and contractor agreements explicitly assign all created intellectual property to the organisation.
- Deploy software inventory scanners: Use automated discovery tools to detect unapproved programmes across company hardware.
- Train staff on copyright rules: Teach workers how illegal copying, piracy, and unapproved web assets create legal risks.
- Set disposal terms for retired tools: Uninstall expired software and destroy unused licence certificates to prevent accidental misuse.
When you’re ready to bring compliance into one place

How to Audit ISO 27001 Annex A 5.32
- Review intellectual property policies: Inspect written guidelines to confirm clear instructions exist for software use, copyright, and code rights.
- Audit software licence records: Match active workstation software installations against purchased licences to verify full compliance.
- Inspect contract ownership clauses: Sample staff and contractor files to verify signed terms assign intellectual property to the business.
- Check proof of purchase archives: Confirm valid receipts, digital certificates, and supplier invoices exist for core business software.
- Audit open source code repositories: Inspect software projects to ensure external code packages follow approved open source licences.
- Verify install restriction controls: Test sample endpoints to ensure technical blocks stop users from installing unapproved tools.
- Check third-party content usage: Confirm external stock assets, fonts, and marketing media carry valid commercial licences.
- Review staff training completion: Confirm workers completed awareness training covering intellectual property protection and licence rules.
Audit Evidence Checklist
- Intellectual property policy: Maintain a documented intellectual property policy with version history in your central repository.
- Software licence register: Supply an active inventory mapping installed applications to valid licence keys and seat allocations.
- Proof of purchase records: Provide invoices, receipts, and subscription contracts for all commercial software tools.
- Signed employment agreements: Supply countersigned contracts containing intellectual property assignment clauses.
- Open source compliance logs: Maintain review records and approvals for open source software used in internal products.
- Software audit scan reports: Provide automated scan results verifying that no unapproved software runs on endpoints.
- Staff training logs: Show sign-off sheets proving workers completed security training on copyright and licensing rules.
What to Teach Employees
- Never install unapproved software: Warn workers against downloading personal tools, utilities, or browser add-ons onto work computers.
- Respect copyright laws: Teach staff not to copy text, images, or designs from external websites without proper commercial permission.
- Protect company creations: Remind workers that all documents, code, and inventions made during work belong exclusively to the business.
- Follow open source guidelines: Instruct developers to seek formal approval before adding third-party code libraries into products.
- Never share trade secrets: Remind staff that proprietary formulas, source code, and customer records must stay strictly confidential.
- Report suspected piracy: Ensure employees know how to report unlicensed software use or intellectual property leaks fast.
Common Implementation Challenges
- Shadow IT adoption: Teams install free or unapproved web tools to finish tasks fast. Provide approved software and restrict admin install rights.
- Exceeding seat limits: Fast-growing teams add users without purchasing additional licences. Reconcile software registers with staff counts monthly.
- Uncontrolled open source use: Developers pull unlicensed external code into production. Implement automated code dependency scanning tools.
- Missing contractor IP terms: Freelance agreements omit explicit ownership assignment clauses. Use standardized legal templates for all contractors.
- Scattered purchase receipts: Invoices stay buried in personal corporate cards and email threads. Centralise all licence purchasing and records.
- Unlicensed media usage: Marketing teams use online images without commercial licences. Supply access to approved commercial media libraries.
How to Measure Effectiveness (KPIs)
- Software licence compliance rate: Track the percentage of installed software applications fully backed by valid, active licences.
- Unapproved software incident count: Measure the number of unauthorised software installation attempts flagged or blocked each year.
- IP contract coverage rate: Track the percentage of active employees and contractors with signed IP assignment terms on file.
- Open source compliance rate: Measure the proportion of software projects passing code licence compliance checks.
- Licence audit finding count: Monitor the number of gaps or non-conformities raised against licence management in internal reviews.
- IP training completion rate: Track the percentage of workers who complete annual awareness training on intellectual property rights.
Related ISO 27001 Controls
ISO 27001 Control A 5.32 connects to several other ISO 27001 requirements:
- Annex A 5.10: Acceptable use of information and other associated assets.
- Annex A 5.31: Legal, statutory, regulatory, and contractual requirements.
- Annex A 8.3: Information labelling.

