Build an AI Inventory: Template, Roles and Risk Classes under the EU AI Act
Create an enterprise AI inventory: required fields, owners, provider and deployer roles, risk classification and a sustainable review process.
An AI inventory is the authoritative list of AI systems, models and purchased AI capabilities used by an organisation. It supports ISO 42001, EU AI Act role assessment, risk management, supplier governance and training. It should include not only in-house models but also SaaS features, copilots, chatbots and AI embedded in business applications.
What belongs in the inventory
- In-house AI products and models
- External models and APIs
- AI features in SaaS, HR, CRM or support systems
- Generative assistants and copilots
- Pilots, shadow AI and time-limited trials
- Retired systems with remaining retention or evidence duties
Recommended template fields
| Field | Purpose |
|---|---|
| Name and purpose | Unique identification and business use case |
| Owner | Accountability for approval, operation and review |
| Role | Provider, deployer, importer, distributor or other relevant role |
| Data | Inputs, outputs, personal or confidential data |
| Affected people | Who may be influenced by output or decisions? |
| Risk classification | Preliminary class and rationale |
| Supplier / model | Dependencies, versions and contractual context |
| Controls | Approval, human oversight, testing, monitoring and incident process |
| Review date | Next review and change trigger |
Do not confuse role and risk class
The EU AI Act distinguishes actor roles and risk-based duties. The same technical solution can create different obligations depending on its use, modification and market role. Record what the organisation does first, then assess the legal role and risk class.
Automated classification based only on a product name is insufficient. Purpose, use context, affected people and decision impact matter.
Keeping the inventory current
- Connect procurement and approval to mandatory inventory registration
- Name an owner for each system
- Record changes to model, purpose, data and supplier
- Review periodically and after material changes
- Provide a shadow-AI reporting route and clear use rules
How Sternberg Consulting supports you
We structure AI inventory, risks, roles, evidence and internal review into a pragmatic AIMS. Learn more about ISO 42001 consulting.
Frequently asked questions
Does ChatGPT belong in the inventory?
Yes, when it is approved, piloted or actually used. Purpose, data rules, owner and controls should be recorded.
Who maintains the inventory?
Central governance can coordinate, while each use case needs a business owner.
Is the inventory sufficient on its own?
No. It is the starting point for role analysis, risk and impact assessment, controls, training and monitoring.