A practical guide to building an AI inventory that records tools, use cases, owners, data, providers, risk and review status without creating unnecessary admin.

01

Why an AI inventory matters

An organisation cannot govern AI it cannot see. An AI inventory creates a reliable list of important systems and use cases so the business can assign ownership, assess risk, review suppliers and revisit decisions when a tool changes.

02

What to record

  • System or tool name and provider.
  • Business use case and intended purpose.
  • Business owner and teams using it.
  • Data categories entering the system.
  • People affected by outputs and the significance of decisions.
  • Human review arrangements.
  • Supplier review, risk rating and approval status.
  • Date last reviewed and the trigger for the next review.
03

Find shadow AI without creating fear

Ask teams what they use AI for, not only which AI products they have purchased. Browser tools, meeting assistants and AI features inside existing software can be missed by procurement-led searches. Make discovery an exercise in understanding work, not in catching employees out.

04

Keep the inventory alive

Connect updates to normal business events: procurement, tool approval, material feature changes, new use cases, incidents and periodic review. An accurate lightweight register is more valuable than a detailed spreadsheet that becomes obsolete after one quarter.

05

Blanche perspective

Start with systems and use cases that matter. Once the organisation has a repeatable intake process, broaden coverage. The inventory should become a decision tool, not a museum of software names.

S

Sources

Primary and authoritative sources used for this Insight.

  1. European Commission: AI Act and AI Pact