EU AI Act GPAI obligations are now in force. Is your documentation ready? See GRC Toolkits →
Blog

Regulatory insight, plain-English guidance.

AI governance, compliance and finance, explained without the jargon — timed to the deadlines that actually matter.

An AI system inventory is the one document most compliance teams don’t have — and the first thing an auditor asks for. AI system inventory template - Excel register previewIf someone asked you right now for a complete list of every AI tool in use across your organisation — who owns each one, what data it touches, and how risky it is — could you produce it in an afternoon? Most compliance leads can’t. Not because the information doesn’t exist, but because it’s scattered across Slack threads, personal ChatGPT accounts, a half-finished spreadsheet from six months ago, and whatever the marketing team signed up for without telling IT.

That gap is now a governance problem, not just an untidy one. ISO 42001 requires a documented AI management system, the EU AI Act requires risk classification per system, and any board asking “are we exposed here?” expects a straight answer. An AI system inventory is the document that makes all three possible.

What is an AI system inventory?

An AI system inventory is a structured, maintained register of every AI tool, model, or system your organisation uses — whether that’s an enterprise-approved platform like Microsoft Copilot, a team’s ChatGPT subscription, or a vendor’s AI feature buried inside a SaaS product you already pay for. For each entry, a proper inventory captures:

It’s the single source of truth that every other AI governance document — policies, risk assessments, vendor reviews — ultimately points back to.

What auditors and regulators actually ask for

Almost every AI governance audit opens with a version of the same question: “give us a list of every AI tool in use, who owns it, and what data it touches.” Under ISO 42001, this maps directly to the requirement for a documented AI system inventory as part of the management system. Under the EU AI Act, you can’t classify risk per system if you don’t know which systems exist. Most organisations don’t have a clean answer to either, because AI adoption happens tool by tool, team by team, with no central record from day one.

Building one from scratch: the steps

1. Decide what counts as “AI”

Before you inventory anything, agree a working definition. Most teams end up including: dedicated AI platforms (ChatGPT, Claude, Copilot), AI features embedded in existing software (Salesforce Einstein, Grammarly’s AI suggestions), and any internally built model or automation. When in doubt, include it — a register that’s too broad is easier to narrow later than one that missed something an auditor finds first.

2. Run a discovery pass, not just a survey

A survey email asking “what AI tools does your team use?” will always undercount. Cross-check against: finance/procurement records for SaaS subscriptions, IT’s approved software list, browser extension inventories, and API key or SSO logs where available. Informally adopted tools — the ones a single team picked up without telling anyone — are exactly the ones auditors ask about first.

3. Capture ownership, not just existence

Every entry needs a named owner, not a department. “Marketing” is not accountable; the marketing ops lead who requested the tool is. This single change is what turns a list into a governance artefact.

4. Classify data sensitivity per tool

Map each tool against the data it touches: public, internal, confidential, or regulated (health, financial, biometric). A tool that only touches public marketing copy carries a different risk profile than one processing customer PII — your register needs to reflect that distinction, not just log that both exist.

5. Assign a risk tier using a recognised framework

Score each system against ISO 42001 and EU AI Act risk categories rather than inventing your own scale. Regulators and auditors recognise these frameworks; a homegrown “red/amber/green” system means re-explaining your logic every time someone asks.

6. Set a review cadence

Tools are adopted and retired constantly. Most organisations that keep their inventory current review it quarterly, alongside their broader governance cadence — not annually, and not “whenever someone remembers.”

Build it yourself vs. use a template

Both paths get you to a working inventory. The difference is mostly in the first afternoon and in how defensible the result looks under scrutiny.

Approach Time to first draft Aligned to ISO 42001 / EU AI Act Auditor-ready out of the box
Blank spreadsheet 2–4 hours minimum, plus iteration Only if you build it in yourself Rarely — columns usually miss what auditors ask for
Generic asset register 1–2 hours to adapt No — scoped to licence/cost tracking, not AI risk No — missing model provenance and risk tiering
Madalent AI System Inventory Template Under a day, ready to populate Yes — built to ISO 42001 and EU AI Act structure Yes — the first artefact most auditors ask to see

Common mistakes

The most frequent gap isn’t a missing tool — it’s a missing owner. A register full of “IT” or “Marketing” as the accountable party doesn’t survive an audit conversation. The second most common mistake is treating the inventory as a one-time project rather than a living document; a register that was accurate in January and hasn’t been touched since is functionally the same as not having one. The third is scoping too narrowly — logging only enterprise-approved tools while ignoring the ones individual teams adopted informally, which are usually the higher-risk entries.

Where this fits with your wider governance programme

An inventory rarely stands alone. Once you know what AI systems exist, the natural next steps are documenting how each one is governed — an AI governance framework to define roles and policy hierarchy, and an AI impact assessment for any system with real exposure to people’s rights, safety, or opportunities. The inventory tells you what exists; the framework tells you who’s accountable; the impact assessment tells you how risky each one actually is.

Frequently asked questions

How is an AI system inventory different from a regular software asset register?

A software asset register tracks licence cost and renewal dates. An AI system inventory tracks the specific fields an AI governance audit asks for — model provenance, data classification, and risk tier — which a standard IT asset tool typically doesn’t capture at all.

Do we need to log AI tools that individual teams adopted without approval?

Yes. Auditors typically expect a complete inventory, including tools adopted informally by individual teams, not just enterprise-approved systems. These are often the higher-risk entries precisely because they haven’t been reviewed.

How often should the inventory be updated?

Quarterly is the most common cadence, timed to align with your broader governance review cycle. Update it immediately whenever a new tool is adopted or an existing one is retired, rather than waiting for the scheduled review.

Can we build this in a plain spreadsheet instead of buying a template?

Yes — nothing stops you building your own. The trade-off is time and defensibility: a from-scratch spreadsheet usually takes several hours to structure properly and still needs the ISO 42001 and EU AI Act alignment built in manually, which is easy to get wrong on a first attempt.

Looking for a ready-built version of the register described above? The AI System Inventory Template ships pre-structured to ISO 42001 and EU AI Act requirements, with risk-tiering logic and an instructions tab already built in.

Leave a Reply

Your email address will not be published. Required fields are marked *