How to build an AI system inventory that survives an audit
6 min read · Certifyi research team · Updated July 2026
An AI inventory is a live register of every AI system your organisation builds, buys or embeds, with an owner, purpose, data sources, risk classification and lifecycle status for each. Every AI governance framework depends on it, and incompleteness is the most common reason an AI governance programme fails its first review.
What each entry must record
A list of model names is not an inventory. Each entry needs enough detail to support a risk decision.
- System name and business purpose
- Named accountable owner
- Whether built in-house, procured, or embedded in a vendor product
- Data sources used for training, fine-tuning and inference
- Whether personal or special-category data is involved
- Risk classification under your chosen framework
- Human oversight arrangement
- Lifecycle status: experimental, production, deprecated
Where the hidden AI lives
The systems you know about are rarely the problem. Run a deliberate discovery pass across these sources.
- Product code: search for API calls to model providers
- SaaS admin consoles: AI features enabled by default after vendor updates
- Expense and procurement records: AI tools bought on cards
- Data pipelines: scoring, ranking or classification steps
- Internal tooling: scripts and automations built by individual teams
Keeping it current
An inventory built once and never updated is worse than none, because it creates false assurance. Tie updates to events that already happen.
- Add an AI question to your existing change-approval process
- Review at each vendor security review or renewal
- Reconcile quarterly against actual API spend
- Require registration before any model reaches production
Common audit findings
What assessors flag
- Third-party and embedded AI missing entirely
- Entries with no named owner
- Risk classification recorded with no supporting reasoning
- No deprecation path, so retired models stay listed as live
- Inventory maintained in a spreadsheet nobody has opened in six months
Key takeaways
- Inventory is the foundation of every AI governance framework.
- Record owner, purpose, data, classification and lifecycle status.
- Most gaps are embedded vendor AI and shadow experiments.
- Tie updates to existing processes or it will go stale.
Frequently asked questions
Do we include AI features inside SaaS tools we buy?
Yes. If it processes your data or affects your decisions, it belongs in the inventory even though you did not build it.
How granular should entries be?
One entry per system with a distinct purpose and risk profile. Do not create an entry per model version; track versions within the entry.
Who should own the inventory?
A named individual, usually in security, engineering leadership or GRC. Shared ownership consistently means no ownership.
Is a spreadsheet enough to start?
To start, yes. It stops scaling once you need approval workflows, evidence and change history tied to each entry.
Get audit-ready in 8 to 12 weeks
Certifyi pairs the platform with a named compliance lead, at published pricing from $8,000/year.
Book a 20-min deal readiness call