AI System Inventories: The Foundation Most Governance Programmes Skip

Ask most organisations how many AI systems are in production and the honest answer is a guess, hedged with “at least.” You cannot govern what you cannot list, and an AI inventory that starts as a guess stays a guess, because nothing about “defensible governance” survives contact with a register nobody trusts.

Every serious AI governance framework — the AI Act’s provider and deployer obligations, NIST’s Map function, any genuine model risk extension — assumes an inventory exists as its foundation. None of them work without one, and most organisations discover, the first time they’re actually asked to produce theirs, that it’s incomplete in specific and predictable ways. The gap is rarely deliberate concealment. It’s simply that nobody was ever assigned to own the completeness of the list.

Where the inventory actually breaks

Embedded AI nobody classified as AI. A CRM’s built-in lead-scoring feature, a support platform’s auto-categorisation, a spreadsheet add-in’s forecasting function — AI capability is increasingly bundled invisibly inside SaaS platforms that were never procured as “AI systems” and never flagged for inclusion in an AI inventory, because nobody thought to ask whether an existing, familiar tool had quietly gained an AI-powered feature in a recent update.

Free · 4 minutes

Do you actually know what you are running — and what it is about to cost you?

Fourteen questions on the systems you depend on, the ones nobody owns, and the support dates that turn a routine upgrade into a forced re-platform. Banded finding on screen, full sheet by email.

Shadow AI adopted outside any procurement process. Individual employees and teams adopting AI tools directly — a consumer chatbot subscription expensed as a minor cost, a browser extension nobody registered anywhere — sit entirely outside any inventory built from procurement records, because they never went through procurement at all.

Vendor-side AI the organisation doesn’t directly control. A payment processor’s fraud model, a cloud provider’s anomaly detection — AI systems operating on the organisation’s data, materially affecting its outcomes, that live entirely inside a vendor’s infrastructure. These rarely appear in an internal inventory because the organisation never built them, but they still need to appear somewhere, because the organisation is still accountable for the outcomes they produce.

What a genuinely defensible inventory actually records

A defensible inventory isn’t a spreadsheet of tool names. For each AI system, it needs: what decision or output it influences, and how directly; who owns it, with a real name attached, not a department; what data it touches, connecting to the same data-classification discipline that has to precede any serious AI deployment; how it was validated before deployment, and how it’s monitored since; and its regulatory status — whether it’s high-risk under the AI Act, whether it falls under an existing model risk tier, whether it’s in scope for any sector-specific obligation. A list missing any one of those fields answers what AI is present without answering the more useful question of what it would actually take to govern each entry properly.

Building this isn’t a one-time survey. Shadow AI and embedded AI both accumulate continuously, which means the inventory needs an ongoing discovery mechanism — a recurring review, a procurement gate that specifically asks about AI capability, a technical scan of what’s actually running — not a single point-in-time audit that goes stale within months of being completed. A discovery scan run once and never repeated is only marginally better than no inventory at all, since the same accumulation that created the original gap starts again immediately.

The organisations that get caught out aren’t usually the ones with no AI governance at all — a genuine absence at least prompts urgency once noticed. It’s the ones with a plausible-looking governance framework sitting on top of an inventory nobody has stress-tested, discovered to be incomplete only when a regulator, an auditor, or a due-diligence process actually asks for the complete list and the gaps become visible in real time.

What a real discovery exercise actually finds

A mid-sized insurer, confident in its AI governance after eighteen months of building a formal programme, ran a genuine technical discovery exercise ahead of a regulatory examination — scanning actual network and procurement data rather than relying on the self-reported inventory departments had submitted. The official inventory listed six AI systems. The discovery exercise found nineteen: a claims-processing platform’s recently-added auto-triage feature nobody had flagged, four separate teams individually subscribed to the same consumer AI writing tool on expensed personal accounts, and a marketing analytics platform’s predictive-scoring module that had been running, unreviewed, for over a year. None of the additional thirteen were malicious or even particularly risky individually. All of them were invisible to a governance programme that had, in practice, only been governing what people remembered to report. The insurer’s regulator, notably, asked for the discovery methodology before asking for the inventory itself — a sign of how seriously a self-reported list is now treated versus one backed by genuine technical verification.

Once the inventory exists, the next question is how each system’s risk actually gets managed — see extending operational risk management to cover AI.

Building an AI inventory that’s actually complete — including the embedded, shadow, and vendor-side systems a procurement-based list misses — is exactly the kind of discovery work a technology control assessment is built to run.

Free interactive tool

Interactive deadline calculator

Check which regulations apply to you and when

Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.

Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.

Governance is what happens when nobody is watching.

Policies are easy. Consistent decision-making is harder. Understand where governance exists and where it has quietly become assumed.

Full Governance by Sixteen Pillars

Govern your business. Prove your compliance.

A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.

See what's coming