What is an AI systems inventory?
It is a structured record of the AI systems an organisation develops, provides or uses, together with the information needed to understand and govern them.
It is not merely a technology list. It should help answer what each system does, why it is used, who is responsible, which people may be affected and what initial attention it requires.
Why should a business know which AI it uses?
Without an inventory, basic questions become difficult: which providers handle data, which systems influence decisions, where transparency may be required and which uses may fall under the AI Act?
Before controls can be applied, the organisation needs visibility.
Which systems should be included?
Do not limit the inventory to major corporate solutions.
- Systems developed internally
- Tools purchased from suppliers
- AI embedded in other applications
- AI features added to existing software
- Generative assistants
- Pilot systems
- Relevant tools used informally by teams
What minimum information should it contain?
Avoid beginning with sixty columns. An overcomplicated inventory is often abandoned.
A first version may record the system name, purpose, responsible area, provider, affected people, data used, role in decisions, initial classification and review owner. That is already enough to begin working.
A simple inventory example
Imagine that ALFA uses a generative assistant for internal drafting, a CV screening tool and a customer-service chatbot.
Even before a complete assessment, the inventory shows that the recruitment system deserves higher priority, while the assistant requires a review of its use and data and the chatbot requires a transparency check.
The purpose is not to complete every assessment immediately. It is to see that different systems need different levels of attention.

Who should maintain the inventory?
The inventory should not belong solely to IT. AI may appear in Human Resources, Marketing, Operations, Procurement, Legal and other functions.
A central owner can coordinate it, but business areas must provide and validate the information for the systems they use.
What happens after creating the inventory?
The inventory enables the organisation to classify systems, assess risks, check regulatory obligations, review suppliers, define controls and prioritise work.
It becomes the point that connects governance decisions and evidence to each real system.
Common mistakes when inventorying AI systems
Common mistakes include recording only systems labelled as AI, ignoring embedded features and pilots, collecting too much information too early, failing to assign owners and treating the inventory as a one-off spreadsheet.
The inventory should be simple enough to use and strong enough to support decisions.
Why the inventory must remain alive
Systems change, suppliers update products, purposes expand and new data or functions appear. The inventory therefore needs review triggers and periodic maintenance.
It is not a photograph taken once. It is a living control that helps the organisation understand its AI landscape over time.
Do not begin by trying to document everything
Start with the most important areas. Speak to the teams, locate the systems, record the minimum useful information and then prioritise.
Start the Céntrika assessment →
Use the Céntrika assessment to obtain an initial view of your organisation’s AI governance, risk and compliance.
The assessment provides initial guidance and does not replace a specific evaluation.
