Building an AI inventory that stays current
What fields an AI system inventory needs, how to keep it fresh without a dedicated team, and the tools that suit each organisation size.
The minimum viable field set
| Field | Why an assessor asks for it |
|---|---|
| System name and vendor | Identifies the thing being governed |
| Purpose and business process | Determines the risk tier and who is affected |
| Business owner | Someone accountable, by name |
| Provider or deployer role | Drives obligations under the EU AI Act and similar regimes |
| Data categories in and out | Links to your data protection records |
| Personal or special category data | Triggers a data protection impact assessment |
| Human in the loop | Evidence for the oversight control |
| Trains on your data | Contract and confidentiality exposure |
| Hosting region | Transfer and residency questions |
| Risk rating and date | Shows the assessment actually happened |
| Last reviewed and next review | Proves the register is live |
Anything beyond this is optional until the basics are reliable.
Keeping it current
Three routines do most of the work.
Entry point control. New AI tools arrive through one route: a short request form that creates the register row. If procurement, IT and line managers all know the route, the register updates itself.
Owner attestation. Once a quarter, email each named owner their own rows and ask for a yes or a correction. This produces both freshness and evidence in one action.
Change triggers. A vendor announcing a new AI feature in an existing product is a register event. Subscribe to release notes for your top five vendors.
Tools by size
- Under 50 people: a spreadsheet or an Airtable base. Do not over engineer. Add a change log tab.
- 50 to 500: a SaaS management or GRC tool you already pay for, or a Notion or Airtable base with a request form feeding it.
- Larger or regulated: your configuration management database, with AI system as a class and the fields above as attributes, so the register inherits existing ownership and review workflows.
Where inventories fail
The usual failure is not the format. It is that the register was built as a one off project for an audit, so no business process writes to it. Fix the entry point first, then the format.