THE SHORT ANSWER

An AI use inventory records each system or use case, its purpose, owner, users, vendor or model, data, permissions, affected people, output, decision role, risk tier, controls and lifecycle status. It should include embedded and experimental AI, not only systems called AI products.

Find explicit, embedded and informal use

Look beyond chatbots. Search, CRM, advertising, fraud, support, productivity suites and vendor products may contain AI features. Include pilots, spreadsheets that call models, automations, agents and employee-created workflows.

Record enough context to make a decision

Minimum inventory fields
FieldQuestion
Purpose and ownerWhat outcome is intended, and who answers for it?
Data and permissionsWhat enters the system, and what can it access or change?
People and decision roleWho is affected, and does AI assist, recommend or act?
Evidence and controlsWhat tests, approvals, review and monitoring exist?
LifecycleIs it proposed, testing, live, paused or retired?

Use more than a one-time survey

  1. Ask business owners about workflows and purchases.
  2. Review vendor and software inventories.
  3. Inspect integrations, API usage and privileged service accounts.
  4. Provide a safe route to declare experiments.
  5. Reconcile the list during procurement, launch and access reviews.

Make the inventory part of change

Require updates when purpose, model, data, permissions, vendor or deployment context changes. An old entry can create false assurance; record the last review and next decision.

Use the inventory as the input to the AI use-case risk assessment.

Evidence & context: National Institute of Standards and Technology · International Organization for Standardization

Sources & further reading

  1. NIST AI RMF Playbook

    National Institute of Standards and Technology. Suggested actions for using AI RMF 1.0. It is voluntary, not a checklist or certification, and NIST states that it will be updated after the framework revision.

  2. ISO/IEC 42001 explained: What it is, why it matters, and how it works

    International Organization for Standardization. Official overview of the AI management-system standard and its continual-improvement approach. Certification scope and a management system do not by themselves prove that a specific AI use is safe, fair or legally compliant.

Examples and exercises are illustrative unless attributed to a source. No independent expert review is claimed.

A correction, a counterexample or an experience worth sharing?

Join the conversation ↗