How compliance shapes Microsoft 365 decisions in 2026

34% delay or avoid migrations over compliance risk, up from 20% just one year ago.

Chapter 5 in brief
56%

name access control policies as a top compliance challenge

49%

of on-premises teams need proof Microsoft 365 meets their regulatory requirements before they'd move

80%

say digital sovereignty is influencing their AI governance decisions


What changed this year The total held. The composition didn't.

The share of teams who let compliance shape a migration decision barely moved, from 82% to 87%. Underneath it the share who delay or avoid outright went from 20% to 34%, and the validate-first middle gave up the difference. Confidence in the platform stayed flat across the same period, so this isn't teams losing faith in Microsoft 365. It's teams finding it harder to prove their own use of it.

The distinction to carry A requirement that won't move, or the time to assemble an answer.

Some of what gets called a compliance blocker is a requirement that will never move. Some of it is the weeks it takes to put an answer together by hand. They look the same on a roadmap and they don't respond to the same fixes. Most of this chapter is about the second group, because that's the one you can do something about.

Where sovereignty comes in It stopped being a hosting question.

Compliance in Microsoft 365 has meant knowing where data lives for most of the last decade. Digital sovereignty turns that into a question about what can reach into the data, which is why it now shows up in AI governance decisions rather than hosting ones. A Copilot business case increasingly has to answer where the processing happens as well as what it costs CH2The AI reckoning.

Every stat is tagged with the study it came from: the AI governance survey (n=851) or the IT operations survey (n=943). Full methodology →

This is Chapter 5 of The State of Microsoft 365, a report on how organizations run, secure, and migrate in 2026. Learn more →

See where you stand

The Microsoft 365 Governance Index scores your visibility and content control against 1,700+ IT pros and ranks your widest gaps.

Get your score

Compliance is the chapter everyone expects to be about restriction. It isn't. It's about evidence.

Teams are focused on whether they can show, on demand, that they're meeting their obligations. And on what happens to a project if they can't.

This chapter is about what that looks like in practice: the specific things IT pros name when asked what's holding up a decision right now, where data has to sit, who signs off before anything moves, and what teams still running on-premises say they'd need before they'd move.

Compliance became a stop sign for Microsoft 365 migrations

Before a migration, someone has to establish that the destination satisfies the requirements, that the move itself won't create exposure, and that both can be evidenced afterwards. We asked IT pros how heavily that weighs on their migration decisions, and the change from last year was toward more caution.

Compliance stops or defers migrations for a third of teams

WE ASKED

How do compliance concerns impact your migration decisions?

everyone
Data
  • Significantly delay/avoid
  • Require strict validation
  • Minor consideration
  • Not at all

A third stop or defer work outright. Another 53% validate first, which is what the 87% is made of.

IT operations survey

From validate-and-move to don't-move

Against last year the combined figure moved modestly, from 82% to 87%. The composition underneath it shifted much harder.

A gate that became a stop sign

WE ASKED

How do compliance concerns impact your migration decisions?

The overall figure moved five points. The group that stops work outright moved fourteen.

IT operations survey · 2026 n=943 · 2025 n=650
Japan and Australia are new this year and both sit above average, so some of the rise is the sample changing. Not much: across the five countries asked in both years the top answer still went from 20% to 32%, and it rose in four of them. Compare by region to see each one.

Four countries moving the same way points to something shared rather than local, and the composition is where it shows: the band that stops work outright took everything the validate-first middle gave up.

Compliance teams are under real pressure from the board now. It may not be perfect, but they're trying to make visible progress against risk, and that pressure is new.”

Newness is the operative part, because the platform assessment underneath it didn't move.

Nobody is doubting Microsoft

Asked directly, teams don't hedge.

Almost nobody actually doubts M365

WE ASKED

How confident are you in Microsoft 365's ability to meet your organization's compliance needs?

selection everyone
Very confident57%
Somewhat confident39%
Not confident3%
Neutral1%

96% are confident, only 3% are not. Yet 87% say compliance still shapes their migration decisions: caution without doubt.

IT operations survey
Last year → this year
60%57%
20252026
−3 pts

‘Very confident’ M365 meets compliance needs

A verdict on Microsoft's platform rather than on their own tenant, and it barely moved.

A year ago it was 60% very confident. So across the same period that produced a 14-point rise in teams blocking migrations, the platform assessment underneath it barely moved.

Those two facts are the chapter. Near-total confidence in what the platform can do, sitting beside compliance as one of the largest brakes on actually using it. Teams aren't losing faith in Microsoft 365. They're finding it harder to prove their own use of it, and confidence in Microsoft's capability is not the same thing as confidence in your own ability to demonstrate it Confidence ≠ control. The platform being compliant, and you being able to show that your configuration of it is compliant, are two different problems, and only one of them is Microsoft's to solve.

The moderate band is the one to notice. Requiring strict validation before migrating isn't resistance, it's a process requirement, and at 53% it's still the majority position. Validation is real and it's widespread. What varies is whether it's scheduled or discovered.

Same question, different jurisdictions

Compliance stops or defers migrations for half of IT teams in Japan and a fifth in Canada. The 34% average sits between two quite different pictures.

Compliance stops migrations for half of Japanese teams

WE ASKED

How do compliance concerns impact your migration decisions?

Japan49% vs 34%
United States40% vs 34%
France37% vs 34%
Australia36% vs 34%
Germany31% vs 34%
United Kingdom24% vs 34%
Canada20% vs 34%

Japan 49%, Canada 20%. The widest gap between two industries is barely more than half that.

IT operations survey
Between 90 and 270 people answered in each country, so all seven rows can be compared directly. The survey doesn't ask what drives the gap, and the likely causes are hard to separate: local law, how strictly it's enforced, how much data a country still keeps on its own servers, or just how readily IT pros there call their own position blocking.

What the spread does establish is that the national picture matters. Two teams with comparable estates and comparable tooling can be working under materially different constraints. Japan is also the market least confident in the Microsoft platform itself, at 44% very confident against 57% for the study average, and it's the one place where the two measures move together.

In some jurisdictions an unauthorised disclosure of a single document containing a passport number is enough to trigger a reportable breach. That's why organizations have started asking where their data actually sits.”

Industry varies too, but less.

Industry spreads compliance gating less than geography does

WE ASKED

How do compliance concerns impact your migration decisions?

Energy / Utilities (n=48)48% vs 34%
Retail / E-commerce41% vs 34%
Public Sector (n=41)39% vs 34%
Financial Services38% vs 34%
Education (n=70)36% vs 34%
Healthcare35% vs 34%
Technology / Software32% vs 34%
Professional Services (n=57)28% vs 34%
Manufacturing23% vs 34%

Retail 41% down to Manufacturing 23%. Where a team operates matters more than what business it's in.

IT operations survey
Four sectors had too few answers to rank and carry their count in the label. The 41-to-23 comparison uses only the five sectors with more than 100.

Seven constraints, unevenly carried

What Microsoft 365 compliance actually consists of

The obligations behind the word "compliance" aren't interchangeable. Some describe a state the tenant has to be in. Others describe a process the team has to go through. They don't respond to the same fixes, and they don't cost the same amount of time.

56% name access control, the top compliance challenge

WE ASKED

What are the biggest compliance challenges impacting your IT decisions right now? (choose up to three)

selection everyone
Strict access control56%
Data residency / sovereignty44%
Regulatory approval delays41%
Advanced auditing needs37%
Industry certifications36%
Sensitivity labeling25%
Multi-tenant M&A compliance14%

Three of the top four aren't about where data can live. They're about whether you can show what happened to it.

IT operations survey

IT pros selected 2.5 challenges on average, so these stack rather than substitute. The three the chart groups are access control, auditing and reporting, and approval processes. That's an evidence problem, and evidence problems respond to tooling rather than to intent.

Access control leading is consistent with what the same survey found elsewhere. Chapter 3 reported stale access as the most common governance incident of the year at 38%, with oversharing at 26% Governance. The access surface producing those incidents is the same one compliance policy gets written against. The likeliest reading is that the compliance requirement and the governance backlog are the same work arriving under two different names.

Seven constraints, unevenly carried

The M365 Governance Index scores ten dimensions of your estate and your AI governance, then names the three where you sit furthest behind the field.

Ranked by distance rather than by lowest score, so the weakness everyone shares doesn't crowd out the one that's actually yours.

Get your score

The industry breakdown holds one result worth pausing on.

Top compliance challenges, by industry
Industry n Data residency Access control Regulatory delay Auditing needs
Technology / Software 190 56% 53% 43% 33%
Healthcare & Life Sciences 101 50% 50% 38% 36%
Retail / E-commerce 109 46% 60% 38% 34%
Manufacturing 164 38% 57% 43% 36%
Financial Services / Insurance 138 36% 57% 46% 41%
Sample average 943 44% 56% 41% 37%
IT operations survey

Technology and software organizations report the highest data residency concern in the study, at 56%, twenty points above Financial Services. That's the opposite of the intuitive ranking, and the likely explanation is the sovereignty pressure covered later in this chapter: technology companies are disproportionately multinational, disproportionately European in this sample, and disproportionately the ones being asked where their customers' data physically sits.

Of the five sectors with bases above 100, Financial Services leads on the two evidentiary measures, auditing needs and regulatory delay, which is closer to what you'd expect. Across all ten sectors those two are led by Energy and by Education, both on bases too small to rank.

The requirement is fixed. The approval cycle isn't.

Regulatory approval processes are named by 41% of IT pros, and they're the clearest dividing line in the study between teams who delay migrations and teams who don't.

Approval is what separates stalling teams

WE ASKED

What are the biggest compliance challenges impacting your IT decisions right now? (choose up to three)

Regulatory approval processes47% vs 38%
Industry certifications41% vs 34%
Advanced auditing tools39% vs 35%
Data residency46% vs 43%
Sensitivity labelling25% vs 25%
Access control policies53% vs 57%
Multi-tenant M&A9% vs 17%

Access control is the most-named challenge in the study, and it barely tells these two groups apart: 53% against 57%.

IT operations survey
Each row compares the 320 teams that delay or avoid migrations with the 623 that don't. People could pick more than one challenge, so the two figures on a row are separate shares rather than halves of a split.

Approval processes split the two groups by nine points, the widest gap in the list. Certifications come next at seven. The M&A row is the same size and points the other way, which is the one worth stopping on.

Labelling is identical at 25% either way. Access control barely moves, and what movement there is runs backwards: 53% of the teams that stall name it, against 57% of the teams that don't. The most-named compliance challenge in the study is not what separates them. The queue is.

Teams whose compliance challenge is managing multiple tenants during a merger are less likely to delay, at 9% against 17%. The survey doesn't test why, but it could be that deal-driven migrations arrive with a contractual deadline, and a deadline someone else set doesn't leave room to wait.

The approval cost doesn't show up where you'd look for it. Teams naming approval processes don't report longer projects. If anything they report slightly shorter ones: 19% finished inside three months against 13% of everyone else, and the share running past a year is identical at about 10%. That looks backwards until you notice who the question reaches. It only asks teams who ran a project. A migration still sitting in an approval queue has no timeline to report, so the teams that got through the queue are the only ones the question can see.

The auditing gap is a tooling gap

Two numbers, from opposite ends of the same problem.

37% need audit-grade reporting. 1% own a tool built for it.

Name advanced auditing and reporting as a compliance challenge37%
Govern Microsoft 365 with a purpose-built tool1%

Teams that took an audit finding last year name reporting 43% of the time, against 33% of teams that didn't.

IT operations survey
Two ends of one problem, from two different questions: the biggest compliance challenges here, and how teams are handling governance and security in Microsoft 365 in Governance.

Those two numbers describe the same problem from opposite ends. A meaningful share of teams are being asked to produce audit-grade evidence about permissions, retention, and access history, using tooling that was designed to administer a tenant rather than to report on it Governance.

The usual result is a manual export, a spreadsheet, and a week nobody planned for. When an auditor asks who had access to this site in March, the honest answer for most environments is that it would take some work to find out.

Having been caught moves the number. Chapter 3 reported that 35% of organizations had an audit or compliance gap in the past 12 months. Among those teams, 43% name auditing and reporting tools as a compliance challenge, against 33% of teams with no finding. The teams who have been through a finding are the likeliest to name the reporting gap.

Given a single choice about what would most improve their governance and security, 25% of teams who delay or avoid migrations choose executive buy-in to prioritize governance, against 17% of everyone else. Only 1% of them ask for more budget, so this isn't a money problem. It's about getting leadership to prioritize governance work at all, even though it isn't glamorous and doesn't have a concrete deadline like other projects. Chapter 4 found the mirror image on migrations: prioritization came last among the reasons a legacy migration hadn't finished The estate. Governance work stalls for want of a mandate. Migration work has the mandate and stalls anyway.

Two constraints that connect to other chapters

Sensitivity labelling and data classification (25%) looks like a middling concern until you read it alongside chapter 1 Confidence ≠ control. Labels are one of the primary levers for controlling what AI can surface, because they're how the platform knows which content deserves the strictest defaults. A quarter of teams naming labelling as a compliance challenge is, in practice, a quarter of teams telling you their AI exposure controls rest on an incomplete foundation.

Managing compliance across multiple tenants during M&A is the smallest entry on the list at 14% across the sample, and one of the hardest problems on it. Chapter 6 finds that 23% of organizations say their most significant migration was an M&A move Migration. During those integrations, two tenants run in parallel with different policies, different labels, and different retention rules, while the compliance obligation applies to both as one organization. The teams who named it are not overreacting.


Proof, and the keys

What on-prem teams need before migrating to Microsoft 365

Not every organization keeps its data where Microsoft 365 can reach it. File shares, on-premises SharePoint and local servers still hold a meaningful share of the corporate record, and the teams running them carry the same obligations as everyone else.

Chapter 4 covers how large that footprint is and how much of it is deliberate The estate. The question here is narrower: for teams still holding data on-premises, what would have to be true before they'd be confident moving it. Their answers are the most direct statement in the study of what compliance assurance actually has to look like.

What moves on-prem data to the cloud? Proof.

WE ASKED

If your organization stores data on-prem, what would need to be true for you to feel confident moving it to the cloud? (choose up to two)

selection everyone
Proof M365 meets our regs49%
Control our encryption keys45%
Successful validated pilot37%
Data residency guarantees34%
Auditor endorsement12%
Third-party assessment8%

The two ways of having somebody else vouch for it come last, at 12% and 8%. Nobody's waiting to be told it's fine.

IT operations survey · the 675 who still store some data on-premises

⚠ SMALL SAMPLE (n=) — READ AS DIRECTIONAL

Every leading answer is an artefact. Proof. Key control. A validated pilot. Residency guarantees. Nobody is asking to be reassured, and the two options that amount to someone else vouching for it, an auditor endorsement and a third-party assessment, come last by a wide margin.

Two of those conditions are less about where data sits than about who can read it. 45% want to hold their own encryption keys. Residency guarantees sit fourth overall at 34%, but that average hides two different worlds: Japan at 49%, Australia at 42%, Germany at 41% and France at 39%, against the US and Canada at 28% and the UK at 23%. The markets that want a residency guarantee are the ones about to ask the same question of their AI, which is where this chapter goes next. Japan's cut stands on 71 respondents and France's on 59, so read both as directional.

The alternative to delaying your migration is moving without the artefacts. And finding out afterwards that you missed something.

I would far rather carry the delay than finish a migration and discover I lost the crown jewels. I have seen that happen.”

Every condition on this list is a way of making sure that doesn't happen. Which is unusually good news, because artefacts can be produced on a schedule. A validated pilot migration is a project with a start date. A control-mapping document against your specific regulatory obligations is a deliverable. Customer-managed keys are an architectural, licensing, and operating decision. None of this requires the regulator to change position or the platform to add a feature.

A validated pilot with the compliance team in the room from day one does more to unblock a roadmap than another year of vendor assurances, because at the end of it you own an artefact instead of an opinion. And you can reuse that artefact on the next twelve workloads.”

Fully cloud, still gated

As we mentioned in chapter 4, we were surprised to find that 72% of organizations still have data on-premises The estate. We thought compliance might be the explanation. The data doesn't support that, and the way it fails is more interesting than the assumption.

Finishing your migration doesn't end the compliance delays

WE ASKED

How do compliance concerns impact your migration decisions?

43% 32% 27% 29% 38% sample avg 34% Fully cloud Mostly cloud Roughly50/50 Mostlyon-prem All on-prem Cloud footprint →

43% of the teams that already finished still delay or avoid a move over compliance. That's the highest of any group.

IT operations survey
If compliance were what kept data on-premises, this would climb to the right. The two groups on the right are the smallest, 68 people and 32, so the upturn there is too small to rank.

So compliance isn't the main reason organizations are keeping data on-premises. Chapter 4 asked the 180 organizations still carrying SharePoint 2016 or 2019 why they hadn't finished, and compliance came fourth at 13%, behind migration complexity at 37% and a lack of internal resources at 26% The estate.

Read the other way round, the same crosstab is starker still.

Cloud completeness, by how much compliance shapes migration decisions
Compliance impact on migration n Fully in the cloud
Significantly delays or prevents moves 320 36%
Moderately — we validate before moving 503 24%
Slightly — a consideration, not a barrier 91 24%
Not at all 29 38%
Sample average 943 28%
IT operations survey

Gating and cloud completeness move together at the top of that table. The 29 teams who say compliance doesn't affect them at all are too few to read, which is why that row is marked.

The likeliest explanation is volume. Fully-migrated organizations are the most migration-active group in the study, reporting 2.6 migration types completed, underway or planned in the past 24 months against a sample average of 2.4, and only 2% report none at all. Among organizations with all their data on-premises, a third ran no migrations in the period. More migration work means more occasions for compliance to stop one.

Volume doesn't account for all of it. Teams with a small on-premises remainder report almost as much activity, at 2.5 types, and gate 11 points lower. But it reframes what the top row means.

Reaching the cloud doesn't end the migration programme. Chapter 6 makes the case that migration is a standing capability rather than a project Migration, and the compliance validation travels with it. Compliance doesn't stop movement. It adds a stage to it, and that stage is producing the evidence, for an auditor, a regulator, or a board.


From where it sits to what can reach it

Sovereignty is now an AI governance question

Residency asks where data is stored. Sovereignty asks the broader question: whose jurisdiction does it sit under, and who ultimately controls the systems it passes through? What's changed this year is how far sovereignty reaches, because it's now shaping decisions about AI, not just storage.

80% say digital sovereignty is shaping AI decisions

WE ASKED

To what degree is digital sovereignty influencing your AI governance decisions?

everyone
everyone
  • Major influence
  • Moderate influence
  • Minor influence
  • No influence
  • Not sure

For a third it's a major influence, not just a consideration. Only 4% say it has none.

AI governance survey

Sovereignty requirements are written by national governments and regional blocs. If the pressure followed the policy, it would concentrate where the policy is written. It doesn't.

Everyone feels the pressure. Nobody agrees it's covered.

Sovereignty influences our AI governance 12-pt spread Very confident M365 will keep meeting it 34-pt spread
0% 25% 50% 75% 100% 25 84 Netherlands n=56 58 84 US n=219 37 81 Ireland n=54 59 81 UK n=204 28 79 France n=108 35 77 Canada n=106 31 72 Germany n=104

On the pressure, every market lands between 72% and 84%. On whether Microsoft has it covered, they run from 25% to 59%.

AI governance survey
Two questions from the same study, on one scale. Ask the same pair by company size instead and the difference closes, 15 against 18: this is about where you operate, not how big you are.
In highly regulated organizations I see people digging in hard on where their data sits. The political climate is part of it. But it varies enormously from one company to the next, far more than you would expect.”

So the useful question isn't which jurisdiction you're in. It's how hard your own compliance function is pushing.

National averages make poor substitutes

The M365 Governance Index scores your estate and your AI governance against the 1,700+ IT pros in these studies, filtered to your industry and your country.

You get a percentile instead of an impression, and your gaps ranked by how far behind the field they actually are.

Get your score

Most teams say they'd prioritize EU platforms

Asked how much they prioritize EU-based or French-developed platforms over US platforms such as Microsoft 365, a majority of IT leaders said they lean European.

A majority now lean to EU platforms

WE ASKED

How much do you prioritize EU-based or French-developed platforms over US platforms such as Microsoft 365?

selection everyone
Strongly prefer EU23%
Somewhat prefer EU36%
Somewhat prefer US19%
Strongly prefer US12%
Neutral10%

A majority lean toward EU-based platforms.

AI governance survey

France's EU-platform push lands unevenly

WE ASKED

To what extent has your organization been affected by French government directives encouraging EU-based technology platforms?

selection everyone
Significantly affected14%
Moderately affected32%
Slightly affected24%
Not affected27%
Not sure3%

46% are moderately or significantly affected; 27% not at all. The regional cut is the story here, not the total.

AI governance survey · the whole sample, across seven countries

59% lean toward EU-based or French-developed platforms, 31% toward US platforms, and 10% are neutral. Read that as a stated preference rather than a procurement plan: chapter 1 found Copilot deployed or being deployed in 93% of these organizations Confidence ≠ control. Preference and installed base are pointing in different directions.

Unlike the sovereignty requirement, the platform preference does follow the map. European countries prefer EU-based platforms most, followed by the UK, the US, and Canada, with a 42-point spread between France at 82% and Canada at 40%. Ireland and the Netherlands sit inside that European cluster on 54 and 56 respondents, so treat both as directional.

Half of US-based IT leaders leaning toward EU platforms is the part worth pausing on, and the policy question underneath it points the same way. 46% report being significantly or moderately affected by French government directives encouraging EU-based technology platforms, and that includes plenty of respondents nowhere near France. Only 27% report no effect.

Part of that is the sample: this study is weighted toward European markets and technology-sector organizations, so read these figures as that audience rather than as a global average. But the question also asks about the organization rather than the individual, and the likeliest reading is that multinationals with European subsidiaries or European customers are answering for the whole entity. The rest of their answers support it. US respondents reporting significant impact favour EU platforms at 83%, against 44% of other US respondents, and 95% say sovereignty is influencing their AI governance, against 81%. Whatever they're describing, they describe it consistently. That group is 41 respondents, so it's directional, but it's internally coherent.

And then the pattern that has run through this entire report

Ask whether Microsoft has it covered, and the doubt disappears again.

Still trusting M365 on sovereignty

WE ASKED

How confident are you that Microsoft 365 will continue to meet your data sovereignty and regulatory requirements over the next two years?

selection everyone
Very confident45%
Somewhat confident45%
Somewhat uncertain7%
Not confident at all1%
Neutral2%

90% are confident and only 8% have any doubt, while four in five say sovereignty is reshaping their AI decisions.

AI governance survey

Eighty percent say sovereignty is shaping their AI decisions. Fifty-nine percent lean European. Ninety percent still trust Microsoft 365 to meet their sovereignty needs. Those three numbers are not contradictory, but they describe an unstable position: teams are hedging toward EU platforms while expecting the incumbent to remain adequate. Something eventually resolves that tension, and it will probably be resolved by procurement rather than by IT.

The country split is the figure above. 34 points separate the UK at 59% very confident from the Netherlands at 25%, and the Netherlands anchors that low end on 56 respondents, so the width of the spread is directional even though its shape isn't.

Doubt is the sharper measure, because it doesn't depend on anyone reaching for a top box. 17% of French respondents say they're uncertain or not confident, along with 16% in the Netherlands and 11% in both Germany and Ireland. In the UK and the US it's 4% each. Canada belongs to neither group: just 5% express doubt, but only 35% are very confident, with a clear majority sitting in the middle.

It would be tidy if platform preference and platform doubt were the same thing, if leaning European meant expecting Microsoft to fall short. The data doesn't support it.

Wanting a European platform isn't the same as doubting Microsoft 365

Strongly prefer EU (n=197)8%
Somewhat prefer EU (n=308)8%
Neutral (n=89)8%
Somewhat prefer US (n=159)9%
Strongly prefer US (n=98)6%

Doubt sits near 8% whichever way a team leans. No two groups here are more than three points apart.

AI governance survey
Each row is the share of that group who are uncertain or not confident, against 8% for everyone. Read doubt rather than "very confident": people who picked a strong answer on platform preference also picked the strongest answer on unrelated questions in this study, in all seven countries, which is a habit of answering rather than a view about sovereignty.

Respondents who prioritize EU platforms most strongly are no less likely to doubt Microsoft 365 than anyone else. Preference and doubt are running on separate tracks.

A sovereignty requirement used to shape an infrastructure decision. On this evidence it now shapes an AI one, which means a Copilot business case has to answer where the processing happens as well as what it costs The AI reckoning. The teams that already know where their AI processing happens will spend the next two years answering the question rather than researching it.

Your move

What to do about it

1 Quick win · This week

Turn your constraints into a requirements register

Not a list of the top three in this report. Access control, residency and approval timelines are the three most-named constraints in the data, and this chapter's own industry table shows they're the top three for almost nobody in particular: Technology leads on residency and sits below sample on access control, Financial Services leads on approval delay and sits eight points below on residency, Retail leads on access control and sits below on approval. The delay-vs-everyone cut goes further: the most-named challenge in the study is the one that least distinguishes teams that stall from teams that don't.

So build the register instead. For each requirement record the obligation and its source, the applicable data and workload, the control objective, the required evidence, the decision owner, the current status or exception, and a review date. Chapter 4's estate inventory is where these surface The estate; this is where they get specified.

Then identify the three unresolved requirements most likely to delay work in flight. Precision matters, because vague constraints block more than specific ones. "We can't put regulated data in the cloud" stops a project. "Category 3 data requires customer-managed keys and EU residency, with a six-week approval cycle" is a scope item, and it's the version you can hand to a vendor.

IT operations survey
2 Medium lift · This quarter

Run a validated pilot migration, and keep the evidence pack

37% of on-prem holdouts say a successful pilot with compliance validation is what they need, and 49% want proof of regulatory fit. A pilot produces both at once.

Choose a workload that's genuinely representative rather than conveniently easy, involve the compliance team in defining the validation criteria before you start, and document the controls, the testing, and the outcome as you go. The artefact is as much the point as the migration. Done once properly, it becomes the template that unblocks everything behind it.

The pilot is also the thing to take upstairs. Executive buy-in to prioritize governance is the ask that rises most among teams who delay or avoid migrations: 25% pick it against 17% of everyone else, which moves it past automated remediation into second place behind AI agent controls. Budget comes last in both groups, at 1% among the teams that stall. A completed validation with a compliance sign-off attached is a considerably better ask than a request for money nobody is asking for.

IT operations survey
3 Strategic investment · This year

Negotiate key control and residency up front, and build a reusable evidence set

45% of on-premises holdouts say control of their own encryption keys is a precondition. That's a contractual and architectural decision best made at the start of a program rather than discovered in the middle of one.

Alongside it, build the evidence set as a maintained asset rather than a per-project scramble: control mappings to your specific obligations, audit and reporting coverage, residency documentation, and the pilot validation record. Across the whole sample, 41% say regulatory approval processes are delaying deployments and 37% say they lack adequate auditing and reporting tools.

The requirement is fixed. The approval cycle usually isn't, and it runs long because the evidence gets rebuilt rather than maintained. A standing evidence pack, produced by tooling rather than by hand, is what turns each approval from a research exercise into a review.

And expect sovereignty to keep escalating from an infrastructure question into an AI question. The teams that already know where their AI processing happens will spend the next two years answering the question rather than researching it.

IT operations survey
ShareGate Protect

Protect gives you a tenant-wide view of what users and Copilot agents can access, ranked by severity, then lets you close what shouldn't be open and keep it closed with automated policies.

Know what your AI can reach →