Why the inventory comes first
Policies, risk assessments and board reporting all depend on knowing which AI systems exist. Without an inventory, governance becomes guesswork: controls get applied unevenly, high-risk uses go unnoticed, and leaders can't answer basic questions from regulators, customers or auditors. When a regulator or a major customer asks 'where do you use AI?', an organization without an inventory is left reconstructing the answer from memory and email threads—an exercise that is slow, incomplete and hard to defend.
Frameworks such as the NIST AI Risk Management Framework and ISO/IEC 42001 both assume an organization can identify its AI systems and their context. The inventory is the practical expression of that assumption. It is also the connective tissue of the whole program: every risk assessment, control, piece of evidence and board metric ultimately hangs off a record in the inventory. Get this foundation right and everything else has somewhere to attach.
There is a second, less obvious benefit. The act of building the inventory surfaces decisions that were never made deliberately—teams using tools no one approved, data flowing to models no one reviewed. Finding these gaps early, on your own terms, is far better than discovering them during an incident or an audit.
What counts as an AI system
Define scope broadly enough to capture reality. A common failure mode is scoping the inventory to 'models we built,' which misses the majority of actual exposure. Most organizations find AI in four places:
The embedded category deserves special attention. Established enterprise tools—CRMs, HR platforms, office suites—have added AI features rapidly, often enabled by default. A system that was benign at procurement time may now summarize meetings, score leads or draft communications using models you never evaluated. Your inventory needs a way to capture these feature-level uses, not just whole products.
- Internally built models and applications
- AI features embedded in existing vendor tools
- General-purpose assistants and chat tools used by employees
- AI used by suppliers and service providers on your behalf
- 01DiscoverSurveys, procurement, SSO and expense data
- 02RecordOwner, purpose, data, vendor, model
- 03ClassifyAssign a risk tier
- 04ReviewRecertify on a set cadence
The minimum fields that matter
A useful record answers who, what, why and with which data. At minimum capture: business owner, technical owner, purpose, users affected, data categories processed, vendor and model, deployment status, and the decisions the system influences. Anything beyond that should earn its place by supporting a real decision—fields that exist 'because we might need them' tend to go stale and erode trust in the whole register.
Ownership is the field that matters most and is most often missing. Every system needs a named business owner who can answer for its purpose and accept its risk, and a technical owner who can answer for its operation. When either role is vacant, the system is effectively ungoverned, and that fact should be visible on a dashboard rather than discovered during an incident.
Data categories deserve equal care. Knowing that a system processes personal data, health information, financial records or confidential business information drives the risk tier, the controls required and the regulatory obligations that apply. Record categories, not raw data inventories—enough detail to make decisions, not so much that maintenance becomes a burden.
Finding the AI you don't know about
Self-reporting surveys are a starting point, but shadow AI rarely announces itself. Combine surveys with procurement records, expense reports, single sign-on logs, browser extension reviews and network usage data. Each channel sees a different slice: procurement catches purchased tools, SSO catches authenticated ones, expense data catches team-level subscriptions, and network data catches everything else.
Make disclosure easy and non-punitive—people report more when registering a tool is faster than hiding it. If the registration process takes weeks and ends in 'no,' teams learn to stop asking. A lightweight intake that gives a fast initial answer, with deeper review reserved for higher-risk uses, turns the inventory from a police function into a service.
Expect the first pass to be uncomfortable. Most organizations discover meaningfully more AI in use than leadership expected. That is not a failure of the exercise—it is the exercise working. The goal is not a small, tidy list; it is an accurate one.
Keeping it alive
Inventories decay quickly. New tools appear monthly, owners change roles, and systems are retired without anyone updating the register. Tie registration to procurement and change management so new systems enter automatically—no purchase order or production deployment without a corresponding record. This single integration does more for completeness than any annual sweep.
Schedule owner recertification on a cadence matched to risk: quarterly for high-risk systems, annually for low-risk ones. Recertification should be lightweight—the owner confirms the record is still accurate or updates what changed—but it should be tracked, with overdue recertifications escalated visibly.
Finally, report inventory freshness as a metric in its own right. 'We have 140 registered systems, 96% recertified on time' is a statement a board can rely on. 'We have a spreadsheet somewhere' is not. The inventory is never finished; it is operated, and its health is itself a governance indicator.
Ready to build an inventory that stays current?
GovernIQX Operations gives every AI system a record, an owner and a recertification cadence—so the answer to “what AI do we use?” is always at hand.





