Library
Building an AI System Inventory
Start with a list. Most governance programmes stall because nobody has an honest register of what is already in use, including the vendor copilots people forget to mention. The sheet below is the one we use in an audit. Copy it.
Last reviewed
MikeFounder & developer
- AI governance
- Workflow
- Compliance
On this page
Who this is for
- Operators about to start an AI governance or workflow audit
- Teams who have a slide titled “AI inventory” and a blank spreadsheet behind it
- Anyone classifying systems against Annex III or the UK ADM regime
Why this is the first artefact
You cannot classify, oversee, or contract what you have not named. Shadow copilots in email, the IDE, the CRM and the support suite count. If a tool can change a decision, a message, a price or a record, it belongs on the sheet, even when a vendor “handles compliance”.
This is practice, not a statutory form. EU high-risk duties for Annex III systems apply from 2 December 2027; UK ADM rules already apply. The inventory is how you stop guessing.
The template
Copy the columns. One row per system, including pilots and tools used by a single team.
| Field | What to capture | Pass looks like |
|---|---|---|
| System name | What people call it day to day, plus the vendor product name if different | “Support draft helper (Vendor X)” not “AI” |
| Purpose | The job in one sentence | “Drafts a first reply to a complaint for an agent to send” |
| Data used | Categories, not a dump: personal / special-category / confidential / public | “Customer tickets, names, order history. No health.” |
| Risk tier | Your working tag: prohibited / high-risk (name the Annex III point or UK ADM) / transparency / limited / out of scope, plus “unknown” | “Unknown” with an owner is allowed. A confident fiction is not. |
| Owner | Named human, not a department | A person who can be interrupted |
| Vendor | Who supplies the model or the SaaS, legal entity if you have it | “Vendor X Ltd; model Y via API” |
Add these once the six fields above exist. They are how the sheet becomes usable rather than decorative:
| Field | What to capture |
|---|---|
| Role | Provider, deployer, or both, in the EU AI Act sense |
| Where it runs | Internal / customer-facing / vendor SaaS; region of hosting |
| Human oversight | Who can stop, edit or refuse an output. Link the pattern on Human Oversight by Design |
| Legal hooks | GDPR basis; transfer mechanism; UK 22A–22D; Article 50; none |
| Status | Live / pilot / retired |
| Last reviewed | Date. Empty means it is not a living register |
Keep it in the tool the operation already uses. A wiki table beats a slide.
How to fill it honestly
- Walk one real week of work. Skip the architecture diagram.
- Ask each team what they paste into chat tools when the official path is slow.
- Include copilots bundled inside email, IDE, CRM and support suites.
- Mark unknowns as unknowns. Assign an owner to close them.
- Rank live rows by how much they touch people or money. Close those gaps first.
If you cannot name the owner, you do not have an inventory. You have a list of software.
What to do with a completed sheet
- Pair each high-stakes row with the regime that likely applies: EU timeline, UK who-enforces-what, US tracker, China rules.
- Put vendors through the vendor checklist.
- Put dates on the global calendar.
Questions
Do we include Excel macros and old RPA?
If they change a decision, a message, a price or a record, yes. The word “AI” is not the test.
How often do we update it?
When a tool is bought, a prompt is wired into a live path, or a vendor changes the model. A quarterly pass at minimum. Faster if you are in a high-risk category.
Can we publish this internally with real system names?
Yes. Keep the real names. Redact personal data in examples, not the existence of the tool.
What changed
- 13 August 2026: First publication of the full audit sheet (expanded from the earlier starter). Cadence: stable / evergreen (180–365 days). Next review due 13 May 2027.
Note: This is compliance consulting and training, not legal advice. We work alongside your legal counsel, translating regulation into operational reality rather than replacing them. For a structured pass, see AI compliance or workflow auditing.
Was this helpful?
Also in the library
- The AI Vendor Risk ChecklistA procurement list you can actually use. Data handling, training-on-your-data, sub-processors, audit rights, and model-change notifications: the clauses that decide whether a vendor is safe to put on a live path.
- What Counts as High-Risk Under Annex IIIAnnex III is a use-case list, not a model list. Most Lathestone clients who over-classify do it because the tool is 'AI'; most who under-classify miss internal HR and customer-decision systems. Article 6(3) exemptions exist. They are narrow, and profiling is not one of them.
- Automation vs AI: A Decision FrameworkA rule, a model, and a person are three different tools. Use a rule when the path is stable and the answer is known. Use a model when the input varies and a person will still confirm. Leave it with a person when the volume is low, the judgement is high, or the failure is expensive.