An AI system inventory is the foundation of AI governance. It is the place where teams can see what exists, who owns it, what risk it creates, and what evidence supports its approval. A weak inventory becomes a stale list. A strong inventory becomes the control plane for governance work.
The template should capture enough detail to support risk decisions without turning intake into a research project.
Identity fields
Capture system name, short description, business owner, technical owner, department, repository or vendor, environment, status, launch date, and user population. Add whether the system is internal, customer-facing, employee-facing, partner-facing, or embedded in a regulated workflow.
Purpose and use
Record the intended purpose, business process, supported decision, user workflow, and prohibited uses. If the system is an agent, describe the goal it pursues and the actions it can take.
Model and vendor
Include model provider, model name where appropriate, vendor product, contract owner, hosting model, fine-tuning, retrieval sources, prompt owner, and evaluation approach. For vendor AI, capture data-processing and retention terms.
Data and autonomy
List data categories, personal data, confidential information, regulated records, retrieval sources, permissions, outputs, and storage. Classify autonomy: suggest, draft, recommend, act with approval, or act without review.
For agents, add the tool list and permission level for each tool.
Governance fields
Include risk tier, classification rationale, applicable obligations, required approvals, approval status, control requirements, monitoring owner, incident path, evidence links, review cadence, exceptions, and material change triggers.
A useful inventory should answer three questions quickly: what AI systems do we have, which ones need attention, and what proof shows they are governed?