AI System Inventory and Classification
Authored by Emmanuel Guilherme Jr. · Last reviewed 2026-05-01
Objective
Maintain a complete, current, and classified inventory of all AI systems in development, deployment, and decommissioning to enable risk-based governance.
Applicability
- AI types
- LLM, Agentic AI, Traditional ML, Computer Vision, Generative AI
- Deployment models
- SaaS, Self-hosted, Hybrid, Edge
- Lifecycle stages
- Strategy & Planning, Operation & Monitoring
- Risk domains
- Governance
- Regulatory regimes
- EU AI Act, ISO 42001, NIST AI RMF, Banking, Healthcare
- Company size
- SMB, MidMarket, Enterprise
Rationale
Without a comprehensive inventory, organizations cannot apply risk-based controls, comply with regulations such as the EU AI Act (which requires classification), or detect Shadow AI. The inventory is the foundation for every other AI control.
Control narrative
The organization maintains an authoritative inventory of all AI systems across the lifecycle. Each entry captures owner, business purpose, AI type, data sensitivity, autonomy level, third-party dependencies, deployment environment, regulatory classification (e.g., EU AI Act risk tier), and lifecycle stage. The inventory is reviewed quarterly and updated upon any material change. Intake of new AI systems requires registration prior to development or procurement. The inventory is governed by a designated owner (typically the AI Governance lead or CISO) and integrated with related registers (asset, application, vendor).
Test of Design
Procedures
- Obtain the AI System Inventory and confirm it is centrally managed and version-controlled.
- Confirm the inventory schema includes: owner, business purpose, AI type, data sensitivity, autonomy level, third-party dependencies, deployment, regulatory classification, lifecycle stage.
- Confirm a documented intake process exists requiring registration prior to development or procurement.
- Confirm review frequency is documented (minimum quarterly) with an assigned owner.
Inquiries
- Who owns the AI inventory?
- How are new AI systems discovered and registered?
- How are Shadow AI / unauthorized AI systems identified?
- What is the integration with the broader IT asset and application registers?
Inspections
- AI Inventory policy or standard.
- Inventory schema or data dictionary.
- Intake / registration workflow documentation.
- Sample of completed registration submissions.
Test of Operating Effectiveness
Procedures
- For the audit period, obtain the population of net-new AI systems registered.
- For a sample, confirm registration occurred prior to production deployment by inspecting workflow timestamps and change records.
- For each sampled system, confirm all required fields are populated and accurate by inspecting source artifacts (architecture diagrams, vendor contracts, DPIAs).
- Independently corroborate inventory completeness by sampling 5–10 known AI use cases (from interviews, network logs, SaaS spend, code repos) and confirming they appear in the inventory.
- For systems flagged as 'high-risk' under EU AI Act or equivalent, confirm classification rationale is documented.
Sample-size guidance
| Population | Net-new AI systems registered in audit period |
|---|---|
| Low risk | 5 systems |
| Moderate risk | 10 systems |
| High risk | 25 systems or 100% of high-risk classifications |
Reperformance
- For 3 sampled systems, independently re-derive the EU AI Act risk classification using the published criteria and compare to management's classification.
Evidence requirements
Required
- AI Inventory export (current state) CSV/Excel · At fieldwork
- AI Inventory policy PDF/Word · At fieldwork
- Registration workflow / ticket samples Screenshots or system export · Per sample
- EU AI Act classification rationale (for high-risk systems) Documented assessment · Per high-risk system
Supporting
- Inventory change logs System log export · Annual
- Quarterly review meeting minutes Meeting notes · Per quarter in scope
Retention: 7 years for regulated environments; 3 years otherwise
Framework mappings
| Framework | References |
|---|---|
| ISO 42001 | 6.1.2, 6.1.4, 8.2 |
| NIST AI RMF | GOVERN-1.6, MAP-1.1, MAP-3.1 |
| EU AI Act | Article 6, Article 9, Article 11 |
| OWASP DSGAI | DSGAI01, DSGAI02 |
| SOC 2 | CC1.2, CC1.3, CC3.1 |
| osfi_e21 | Principle 1 |
| nydfs_500 | 500.03 |
Related controls
Changelog
- v1.0.0 · 2026-05-01 · Initial publication.