Intellectual property risk is often invisible — until it becomes expensive.
Annex A 5.32 exists to ensure organisations respect and comply with intellectual property (IP) rights when using software, data, documentation, and other protected assets owned by third parties.
This control is preventative. It protects the organisation from legal, financial, and reputational harm caused by unintentional or unmanaged IP infringement.

Annex A 5.32 of ISO 27001:2022 focuses on compliance with intellectual property rights.
At a practical level, this means:
The control does not cover situations where the organisation owns the IP. It applies specifically to third-party intellectual property, including software, content, and licensed data.
Organisations routinely use assets that are protected by intellectual property rights, including:
If IP obligations are not understood or controlled:
Annex A 5.32 ensures organisations actively manage IP obligations, rather than relying on assumption or individual awareness.
This control also supports responsible behaviour by staff, reducing the risk of accidental infringement.
A pragmatic approach to Annex A 5.32 typically includes the following elements.
Organisations should identify where IP rights apply, including:
Identification helps ensure IP obligations are visible and manageable.
IP compliance depends on understanding what is permitted.
Organisations typically ensure they understand:
Visibility reduces the risk of inadvertent breach.
To reduce IP risk, organisations often:
Control at acquisition is easier than remediation later.
Records support both compliance and assurance.
These may include:
The level of record-keeping should be proportionate to risk and scale.
Unauthorised software introduces both IP and security risk.
Organisations often use:
Preventing unauthorised software reduces exposure on multiple fronts.
IP obligations do not end when assets are retired.
Organisations should consider:
Exit points are common sources of oversight.
7. Address Open-Source and Public Domain Use Carefully
Open-source and public domain assets still carry obligations.
Organisations should ensure:
Open-source does not mean unrestricted.
Annex A 5.32 does not require organisations to:
It does expect organisations to:
IP risk is best managed systematically, not reactively.
Most IP breaches are accidental — structure prevents them.
Annex A 5.32 is about using third-party assets responsibly and legally.
When intellectual property rights are managed effectively:
Intellectual property is easy to misuse unintentionally.
Annex A 5.32 ensures organisations do not learn that lesson the hard way.
We can help you understand your actual security needs and even if we cant help we can point you in the right direction
Talk to a security expert today