Skip to main content
Services
Audit & Certification
ISO Gap AnalysisInternal AuditAudit PreparationAfter the AuditClose Nonconformities
Standards
ISO 9001 Quality ManagementISO 9001:2026 TransitionISO 14001 Environmental ManagementISO 45001 Occupational Health & SafetyISO 27001 Information SecurityISO 42001 AI ManagementISO 13485 Medical Devices
Industries & Support
Industry SolutionsMedical DevicesMechanical Engineering & ProductionIT, SaaS & AIManagement System MaintenanceExternal QMRQM Training
Industries
All IndustriesMechanical Engineering & ProductionAutomotive SuppliersLaser Optics, Photonics & SemiconductorsIndustrial Service ProvidersMedical DevicesIT, SaaS & AI
FundingFAQKnowledgeAboutContactSend emailCall now
DE/EN
Free Consultation
ISO 42001, AI & CompliancePublished: 10 July 2026

Build an AI Inventory: Template, Roles and Risk Classes under the EU AI Act

Create an enterprise AI inventory: required fields, owners, provider and deployer roles, risk classification and a sustainable review process.

An AI inventory is the authoritative list of AI systems, models and purchased AI capabilities used by an organisation. It supports ISO 42001, EU AI Act role assessment, risk management, supplier governance and training. It should include not only in-house models but also SaaS features, copilots, chatbots and AI embedded in business applications.

What belongs in the inventory

  • In-house AI products and models
  • External models and APIs
  • AI features in SaaS, HR, CRM or support systems
  • Generative assistants and copilots
  • Pilots, shadow AI and time-limited trials
  • Retired systems with remaining retention or evidence duties
Table 1: Build an AI Inventory: Template, Roles and Risk Classes under the EU AI Act
FieldPurpose
Name and purposeUnique identification and business use case
OwnerAccountability for approval, operation and review
RoleProvider, deployer, importer, distributor or other relevant role
DataInputs, outputs, personal or confidential data
Affected peopleWho may be influenced by output or decisions?
Risk classificationPreliminary class and rationale
Supplier / modelDependencies, versions and contractual context
ControlsApproval, human oversight, testing, monitoring and incident process
Review dateNext review and change trigger

Do not confuse role and risk class

The EU AI Act distinguishes actor roles and risk-based duties. The same technical solution can create different obligations depending on its use, modification and market role. Record what the organisation does first, then assess the legal role and risk class.

Automated classification based only on a product name is insufficient. Purpose, use context, affected people and decision impact matter.

Keeping the inventory current

  1. Connect procurement and approval to mandatory inventory registration
  2. Name an owner for each system
  3. Record changes to model, purpose, data and supplier
  4. Review periodically and after material changes
  5. Provide a shadow-AI reporting route and clear use rules

How Sternberg Consulting supports you

We structure AI inventory, risks, roles, evidence and internal review into a pragmatic AIMS. Learn more about ISO 42001 consulting.

Discuss your project

Frequently asked questions

Does ChatGPT belong in the inventory?

Yes, when it is approved, piloted or actually used. Purpose, data rules, owner and controls should be recorded.

Who maintains the inventory?

Central governance can coordinate, while each use case needs a business owner.

Is the inventory sufficient on its own?

No. It is the starting point for role analysis, risk and impact assessment, controls, training and monitoring.

Sources and further guidance

Next step

Let's talk.

Tell me where you stand and what you need.

Within 24 hours you receive a first assessment and a concrete meeting proposal — free and without commitment.

  • Reply within 24 hours
  • Personal assessment of your project
  • Funding eligibility checked on request

By submitting you agree to the processing of your details for answering your enquiry.