Someone in your business bought ChatGPT seats. A handful at first, on a card, because a team wanted them. Then it spread, and the plan was moved onto ChatGPT Business, because that is the one with "Business" in the name and a shared workspace and an admin console. The reasonable conclusion at that point is that governance is handled.
It holds until one of three things happens. Your insurer or your ISO auditor asks for the certification scope. A client sends a procurement questionnaire asking how you export AI conversation logs into your SIEM. Or someone starts a DPIA and asks where the data is stored.
ChatGPT Business and ChatGPT Enterprise are not the same product at a different volume discount. They are two governance postures, and one of the differences cannot be fixed by upgrading later.
The difference that cannot be retrofitted is data residency
Start here, because it is the only item on the list where the cost of getting it wrong is not just money.
Data residency, meaning where your content is stored at rest, covers the UK, the EU and eight other regions. It is included on ChatGPT Enterprise and Edu, and on eligible API accounts. It is not available on ChatGPT Business at all.
The trap is in the mechanics rather than the availability. OpenAI provisions residency at creation time. On the API, the region is set when a Project is created and cannot be added to an existing Project. On ChatGPT, it applies to new Enterprise and Edu workspaces, provisioned with content stored in the chosen region from the moment they exist.
So a business that runs on ChatGPT Business for eighteen months, accumulates conversation history, uploaded files and custom GPTs, then wins a client who requires UK storage, is not looking at a settings change. It is looking at standing up a new workspace and moving people onto it. Whether an in-place Business to Enterprise upgrade counts as a new workspace for residency purposes is not something OpenAI states publicly. Put that question to their sales team in writing before you commit if UK residency is anywhere on your roadmap.
Residency and inference residency are also two separate controls. Residency governs where content is stored. Inference residency governs where the model actually runs, and it requires residency in that region to be enabled first.
Business has SOC 2. It does not have ISO 27001, and that is the line UK procurement tests
Here is the comparison, taken from OpenAI's own Business and Enterprise comparison table, checked 08 Aug 2026.
| Control | ChatGPT Business | ChatGPT Enterprise |
|---|---|---|
| SAML single sign-on | Yes | Yes |
| Domain verification | Yes | Yes |
| Admin console, admin roles, bulk member management | Yes | Yes |
| SOC 2 Type 2 | Yes | Yes |
| No training on workspace data by default | Yes | Yes |
| SCIM provisioning | No | Yes |
| Role-based access control | No | Yes |
| Compliance API (audit logs) | No | Yes |
| Enterprise Key Management | No | Yes |
| IP allowlisting | No | Yes |
| Data residency (UK, EU and eight other regions) | No | Yes |
| ISO 27001, 27017, 27018, 27701 | No | Yes |
| Analytics dashboard | No | Yes |
| Connector registry | No | Yes |
Four of those stop deals rather than merely annoying an IT manager.
ISO 27001. OpenAI's ISO/IEC 27001:2022 certificate covers the API, ChatGPT Enterprise and ChatGPT Edu. ChatGPT Business is outside that scope. If your own certification body, your insurer or a client's supplier questionnaire asks for ISO 27001 evidence for the AI tooling in scope, a SOC 2 Type 2 report is a different answer to the one being asked for. UK procurement packs ask for ISO 27001 by name far more often than they ask for SOC 2.
Audit log export. The Compliance Platform pushes ChatGPT workspace log events into eDiscovery, DLP or SIEM tooling, with named integrations including Microsoft Purview, Netskope, CrowdStrike and Varonis. It is Enterprise and Edu only, and Business has no equivalent export. If your security policy commits you to monitoring, or a regulator expects you to reconstruct who did what, that gap is structural. One caveat before you build a retention process on it: the platform retains data for 30 days, and OpenAI's own guidance is that anyone wanting longer should continuously download the logs and retain them under their own policy. So treat it as a pipe, not an archive.
SCIM. Without directory sync, joiners and leavers are handled by hand. SAML SSO on Business controls how people authenticate. It does not deprovision them. In an organisation with real staff turnover, manual deprovisioning is the control that quietly fails, and it is the one an auditor tests by sampling leavers.
Role-based access control and IP allowlisting. Both absent on Business. If your policy assumes you can restrict a sensitive workspace by role or by network, that assumption does not survive contact with the Business tier.
One more, for finance rather than IT: Business is a self-serve plan and does not support invoice billing, purchase orders, bank transfer or net terms. If your finance function does not accept card payments for recurring software, that alone decides the tier.
The training default is the opposite of the way most people state it
This gets inverted in conversation constantly, in both directions, and the inversion sends attention to the wrong risk.
OpenAI does not train on inputs or outputs from ChatGPT Business, ChatGPT Enterprise or the API by default. Business customers are opted out unless they explicitly opt in. That commitment extends to data reached through connectors and to workspace-built GPTs, and a fine-tuned model is served only to the customer that created it.
Consumer ChatGPT is the other way round. Content from the individual plans may be used to train models unless the user opts out through the privacy portal. One carve-out is worth knowing: if a user submits feedback with a thumbs up or down, the whole associated conversation may be used for training even where training is otherwise switched off.
So in most businesses the real exposure is not the corporate tier. It is the staff who never moved off a personal account and are pasting contract text, customer data or pricing into a plan that is opted in by default. Buying Business seats does nothing about that population until you find them and move them.
Zero Data Retention is a negotiated contract, not a toggle you find in settings
"We have ZDR" comes up often enough in supplier conversations to be worth stating plainly.
Zero Data Retention excludes customer content from OpenAI's abuse-monitoring logs, which otherwise run for up to 30 days. It is an API-side control, it requires prior approval by OpenAI and acceptance of additional terms, and it is configured per organisation or per project once granted. There is no self-serve switch, and ChatGPT Business does not offer it.
It also does not mean nothing is ever retained. OpenAI reserves the right to apply Eyes Off, where content is excluded from human review but still logged, or Safety Retention, where content is retained and reviewed, for specific models and customers, with advance written notice. Eligibility also varies by endpoint: chat completions, responses, embeddings, moderations and audio are eligible, while conversations, threads, vector stores and video are not.
If a supplier tells you your data is never stored anywhere, ask which endpoints their system calls and whether their OpenAI organisation has written ZDR approval. Those are answerable questions and the answer is a document.
Check your own paperwork before you buy the seats, not after
Three checks, in this order, and all three can be done in an afternoon.
- Open your DPIA template and your last three client security questionnaires. Search them for
"ISO 27001", "audit log", "SIEM", "data residency" and "provisioning". If those words appear, ChatGPT Business will not satisfy the answer and you should price Enterprise now.
- Decide whether UK storage is a requirement or a preference, and get that decision in writing
from whoever owns it. This is the one you cannot defer, because of the creation-time constraint.
- Find the personal accounts. Expenses claims, SSO logs and a straight question in a team
meeting will get you most of the way. The governance risk sitting on consumer plans is usually larger than anything the tier choice fixes.
Two facts that will come up in the DPIA and are easy to get wrong. A UK customer's counterparty under OpenAI's Data Processing Addendum is OpenAI OpCo, LLC, the US entity, not OpenAI UK Ltd. And the transfer mechanism named in that DPA is the EU Standard Contractual Clauses as amended by the ICO's UK Addendum, which is a different instrument from the standalone IDTA. Write "UK Addendum" in your paperwork.
ChatGPT Business is genuinely the right answer for a lot of companies
None of this is an argument for buying Enterprise reflexively. Enterprise is sales-led and negotiated, which means a procurement cycle, a security review and a commitment. That is real cost, and plenty of businesses do not need what it buys.
Business is a sound choice if you have low staff turnover, no client contract or regulatory obligation naming ISO 27001 or log export, no requirement for data to stay in the UK, and the work being done in ChatGPT is drafting, summarising and research rather than anything touching regulated or client-confidential material. It still gives you SAML SSO, a shared workspace, an admin console, SOC 2 Type 2, spend controls and the training opt-out by default. For a two-seat minimum on self-serve billing, that is a lot of governance for the money.
The failure is not choosing Business. It is choosing Business without knowing what it excludes, then discovering the list during someone else's procurement process, on their timetable.
The decision in front of you
It is not really a tier comparison. It is one question: in the next two years, will anything oblige you to prove where this data lives?
If no, buy Business and spend the time you saved finding the personal accounts instead. If yes, or you cannot rule it out, settle the residency question before a workspace exists, because that is the door that closes behind you.
If you have not yet decided which route you are on, how the OpenAI options compare for a UK business covers the ground.
If you do not know, that is a scoping exercise rather than a purchase. We cover it as part of OpenAI implementation work, and the same governance questions apply whichever model you end up running, which is why they sit under AI implementation rather than under any one vendor. We resell nothing and take no margin on your usage, so we have no reason to talk you up a tier you do not need. To have the decision documented before you commit, request a quote.
Stay Updated with Our Latest Insights
Get expert HubSpot tips and integration strategies delivered to your inbox.




