Part 2 of the Corporate Assist Data and AI Governance Series
Creating an accurate AI inventory is an essential starting point for effective AI governance.
Before an organisation can assess its legal, data protection, compliance or risk responsibilities, it needs to understand where AI is being used, why it is being used and how it affects its activities.
Some AI systems are introduced formally for a specific purpose. Others arrive through routine software updates or are embedded within services supplied by third parties. Employees may also use publicly available AI tools informally to help with their work.
AI use may be more widespread than senior management or the Board realises. An organisation cannot govern what it has not identified.
Why an AI inventory matters
AI can create useful opportunities, but it can also introduce risks related to confidentiality, personal information, accuracy, discrimination, intellectual property, and transparency.
These risks cannot be assessed properly if the organisation does not know which AI systems are being used, what information they process or how their output influences decisions.
An AI policy may state that employees must use only approved tools or must not enter confidential information into a public system. However, the policy provides limited assurance if the organisation has not identified the systems and activities it applies to.
An AI inventory creates a central record that operational owners and relevant specialists can use to assess the organisation's position.
An AI inventory is more than a list of software products. It records how the organisation uses AI. The same system may support several activities, each with different owners, information and consequences. Those uses may need separate entries or linked records so that important differences are not lost.
Information held across different functions
Information about AI is often spread across the organisation.
IT may know which systems are available, while procurement holds contracts and supplier information. Information Security may have completed technical assessments, Data Protection may hold impact assessments, and operational teams understand how systems and outputs are used in practice.
Each team may hold part of the answer without anybody having a complete organisational view.
Teams may also interpret what should be included differently. One person may identify only a well-known generative AI tool, while another includes AI-enabled functions embedded within recruitment, finance or customer systems.
A useful AI discovery exercise requires a clear scope and consistent information requirements.
Identifying embedded and informal AI use
AI use doesn't always involve a separate product with an obvious AI label.
AI functionality may be embedded within software and services the organisation already uses, including recruitment systems, customer service platforms, meeting transcription tools, marketing software, data analysis platforms and finance systems.
An organisation may use AI without making a specific decision to introduce an AI system.
An approved system may also be used for a purpose that was not originally considered, or employees may rely on its output more heavily than expected.
The review needs to establish what happens in practice rather than rely only on approved software lists.
What an AI inventory should include
An AI inventory does not need to resolve every legal or technical question at the outset. It needs to record enough information to identify those questions, prioritise them, and refer them to the appropriate specialists.
For each system and its use, the inventory could record:
The system and supplier
The function using it
Its intended purpose and how it is actually used
The responsible business owner
The teams or roles that are using the system
The individuals affected, both internal and external
The information entered, accessed or generated, including personal or confidential information
The outputs produced
How the outputs are used
Who reviews the output, when the review takes place and whether the reviewer can change or reject it
Where the system is used, where affected individuals are located and any known processing or hosting locations
Approval status, any conditions or restrictions, and who approved the use
The date, outcome and owner of the last review, together with the next review date
Links to existing supplier information, assessments and supporting documentation
Outstanding questions, actions and the person responsible for resolving them
Not every answer will be available at the outset. Missing information should be recorded as an outstanding question, with a named person responsible for obtaining or confirming it. An incomplete but transparent record is more useful than one that appears complete because assumptions have filled the gaps.
The AI inventory should distinguish between live use, pilots, proposed use and retired systems. It should also record whether the use is approved, unapproved or awaiting review, including where AI functionality is embedded within an existing product or supplier service.
Recording an unapproved use does not legitimise it. It enables the organisation to decide whether to approve, change, restrict, or stop the use.
Ownership and responsibility
The overall AI inventory needs a named owner responsible for maintaining the central record and coordinating updates. Individual business areas remain accountable for their respective uses.
Ownership should not automatically sit with IT simply because a system uses technology. The business area using the system should be accountable for its purpose, day-to-day use and implementation of agreed controls, drawing on specialist advice where required.
Other functions may provide specialist advice or oversight. Data Protection may consider personal information, Information Security may assess technical risks and Procurement may obtain supplier assurance.
Several functions may contribute, but this should not obscure accountability for each use.
Prioritising higher-impact uses
Not every AI use requires the same level of attention.
Prioritisation should reflect the potential consequences of each use, the sensitivity of the information involved, the number of people affected and the degree of reliance on the output. Uses that influence recruitment or other decisions about individuals, involve confidential information, or support regulated activities may warrant earlier specialist review.
The relevant specialists can then decide whether legal review, a data protection impact assessment, information security testing or further supplier due diligence is required.
The connection with data protection
When an AI system processes personal information, the organisation must consider the applicable UK data protection requirements. The inventory should help the relevant specialists understand what information is processed, how outputs influence decisions about individuals and what human involvement takes place.
The Data (Use and Access) Act 2025 has amended the framework governing solely automated decisions. Part 1 of this series considered the changes introduced by the Act and the practical steps organisations should now take.
Data protection law and legislation specifically governing AI are different, but both may apply to the same system.
The AI inventory should provide enough information for the relevant functions to assess which requirements apply and what further information is needed.
Keeping the AI inventory current
An AI inventory is a working record, not a one-off exercise. Its value reduces if new systems, changed uses or additional AI features are not reflected in it.
Updates should form part of relevant procurement, approval and change processes. Business owners should also confirm their entries periodically and report changes to how systems are used, what information they process or how their outputs influence decisions.
The inventory can link to assessments, approvals and evidence held elsewhere. It does not need to duplicate those records, but it should make them easy to locate and identify where information or follow-up remains outstanding.
Supporting an AI inventory project
Your organisation may already hold much of the information it needs. The challenge is often gathering it from different teams, resolving inconsistencies and producing a reliable record.
Corporate Assist can support an AI inventory project by coordinating contributions, consolidating responses, identifying missing information and tracking questions and actions requiring specialist input.
Your Legal, Compliance, Data Protection, Risk and technical teams retain responsibility for their assessments. Corporate Assist provides additional project capacity to keep the discovery exercise organised, with clear ownership of outstanding information and follow-up.
If you need support with a defined AI inventory or governance project, please get in touch to discuss your requirements.
Share this post: