How to Build an AI System Inventory (2026 Guide)
AI Governance

How to build an AI system inventory that survives an audit

6 min read · Certifyi research team · Updated July 2026

Short answer

An AI inventory is a live register of every AI system your organisation builds, buys or embeds, with an owner, purpose, data sources, risk classification and lifecycle status for each. Every AI governance framework depends on it, and incompleteness is the most common reason an AI governance programme fails its first review.

What each entry must record

A list of model names is not an inventory. Each entry needs enough detail to support a risk decision.

  • System name and business purpose
  • Named accountable owner
  • Whether built in-house, procured, or embedded in a vendor product
  • Data sources used for training, fine-tuning and inference
  • Whether personal or special-category data is involved
  • Risk classification under your chosen framework
  • Human oversight arrangement
  • Lifecycle status: experimental, production, deprecated

Where the hidden AI lives

The systems you know about are rarely the problem. Run a deliberate discovery pass across these sources.

  1. Product code: search for API calls to model providers
  2. SaaS admin consoles: AI features enabled by default after vendor updates
  3. Expense and procurement records: AI tools bought on cards
  4. Data pipelines: scoring, ranking or classification steps
  5. Internal tooling: scripts and automations built by individual teams

Keeping it current

An inventory built once and never updated is worse than none, because it creates false assurance. Tie updates to events that already happen.

  • Add an AI question to your existing change-approval process
  • Review at each vendor security review or renewal
  • Reconcile quarterly against actual API spend
  • Require registration before any model reaches production

Common audit findings

What assessors flag

  • Third-party and embedded AI missing entirely
  • Entries with no named owner
  • Risk classification recorded with no supporting reasoning
  • No deprecation path, so retired models stay listed as live
  • Inventory maintained in a spreadsheet nobody has opened in six months

Key takeaways

  • Inventory is the foundation of every AI governance framework.
  • Record owner, purpose, data, classification and lifecycle status.
  • Most gaps are embedded vendor AI and shadow experiments.
  • Tie updates to existing processes or it will go stale.

Frequently asked questions

Do we include AI features inside SaaS tools we buy?

Yes. If it processes your data or affects your decisions, it belongs in the inventory even though you did not build it.

How granular should entries be?

One entry per system with a distinct purpose and risk profile. Do not create an entry per model version; track versions within the entry.

Who should own the inventory?

A named individual, usually in security, engineering leadership or GRC. Shared ownership consistently means no ownership.

Is a spreadsheet enough to start?

To start, yes. It stops scaling once you need approval workflows, evidence and change history tied to each entry.

Get audit-ready in 8 to 12 weeks

Certifyi pairs the platform with a named compliance lead, at published pricing from $8,000/year.

Book a 20-min deal readiness call

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top