AI systems inventory: how to build one step by step (with minimum fields)
Almost everything in AI governance starts with a simple question: which AI systems do we have? Without that list you cannot classify risk, train the team or answer a client or an inspector. Here is how to build it in a few weeks.
What it is for (the warehouse analogy)
A warehouse without an inventory does not know what it holds, what expires or what is missing. AI is the same: tools appear in departments, new features arrive in familiar software and pilots stay in production. The inventory is the single source of truth on which AI exists, what it is used for and who answers for it.
What goes into the inventory
- Systems you build or train yourself.
- Third-party systems you buy or use (models, APIs, platforms).
- Built-in AI features in tools you already used (CRM, office suite, HR).
- Pilots and tests, including informal ones.
- AI agents able to act; they merit a more detailed record, as covered in the agents guide.
Minimum fields for each record
- Identification: name, version, provider, start date.
- Purpose and business process it supports.
- Owner (person or team) and who oversees it.
- Data: types used, whether personal or special-category data is involved, source and where it is hosted.
- People affected: customers, employees, candidates, the public.
- Provisional risk level under the AI Act and its rationale (see AI Act).
- Human oversight: who reviews and when.
- Contract and provider: terms on data and training, incidents.
- Evidence: assessments done (DPIA, FRIA), training, logs.
- Status and review: active, in pilot or retired; last review date.
How to find the AI you already have
- Ask the teams with a short form (“which AI tools do you use and for what?”).
- Review purchases and contracts with Finance and IT: subscriptions, licences, new features.
- Look at traffic and sign-ins for known tools, respecting employment and privacy rules.
- Cross-check with the GDPR records of processing: many AI systems process personal data.
For unauthorised tools, read the shadow AI guide.
Who maintains it and how it connects to everything else
The inventory needs one overall owner (usually the AI governance or compliance role) and an owner per system who updates its record. It underpins risk classification, the internal audit, incident handling and the usage policy.
Start small
Do not wait for an expensive tool: a well-designed spreadsheet with an owner and a review date works to begin. As you grow, consider a catalogue; see the guide on choosing a tool.
Frequently asked questions
Does the AI Act require an inventory?
It does not mention one as such generally, but other duties are hard to meet without it.
Does it include third-party AI?
Yes, and AI features embedded in software you already used.
How often is it updated?
With each relevant change and a full review at least yearly.
Informational and indicative content; it is not legal advice. Review your case with a qualified professional.
What's your Data Governance maturity?
Free assessment with your priority gaps, plus the self-assessment quiz and savings calculator on the Data Governance path.