AI Governance Institute
All governance templates →How do we inventory and classify AI systems by risk level?

Implementation Kit

AI Inventory Template and Risk Classification Matrix

Everything needed to stand up a working AI inventory: the register itself, a scoring matrix that turns three inputs into a risk tier, a shadow-AI discovery survey, and a procurement checkpoint. Fill the register, score every system, assign an owner and a review date.

Who this is for: The GRC or risk lead running the first pass at an AI inventory, plus the procurement reviewer who has to keep it current.

Download the kit (Markdown) ↓4 artifacts. Every table also copies as CSV.

1. AI inventory register

Spreadsheet

The master list. One row per AI system, with the three scoring inputs, the resulting tier, a named owner, and a next-review date.

Template

System nameBusiness ownerVendor / providerDeployment typePrimary use caseData processedData sensitivity (1-3)Decision impact (1-3)Regulatory exposure (1-3)Risk tierRegulatory frameworksDate addedLast reviewedNext review
<system><name, role><vendor or "in-house">API / SaaS / self-hosted / embedded<what it does><data categories>1-31-31-3Minimal / Limited / High / Unacceptable<e.g. EU AI Act, GDPR>YYYY-MM-DDYYYY-MM-DDYYYY-MM-DD

Worked example

System nameBusiness ownerVendor / providerDeployment typePrimary use caseData processedData sensitivity (1-3)Decision impact (1-3)Regulatory exposure (1-3)Risk tierRegulatory frameworksDate addedLast reviewedNext review
Resume ScreenerDana Portillo, Head of TalentGreenhouse + in-house modelEmbeddedRanks inbound applicants for recruiter reviewCandidate CVs, contact details, work history333HighEU AI Act (Annex III), GDPR, NYC Local Law 1442026-02-112026-08-302026-11-30
Support CopilotMarcus Lee, Support OpsZendesk AISaaSDrafts agent replies from the knowledge baseCustomer tickets, order metadata221LimitedGDPR2026-03-042026-09-012027-03-01
Contract SummarizerPriya Anand, Legal OpsAnthropic APIAPISummarizes NDAs for the legal queueCounterparty names, commercial terms211Minimalnone identified2026-05-192026-09-012027-03-01

Acceptance criteria

  • Every AI system found through any discovery method has a row, including embedded vendor features and department-level subscriptions.
  • Each row has a named individual as business owner, not a team or a function.
  • All three scoring inputs are populated with a 1 to 3 value, and the risk tier matches what the scoring matrix produces from them.
  • Every row has a next-review date within the review cadence set for its tier (high-risk reviewed at least quarterly).

2. Risk classification scoring matrix

Spreadsheet

The rule that turns data sensitivity, decision impact, and regulatory exposure into a defensible tier. Score each dimension 1 to 3, then apply the aggregation rule.

Template

DimensionScore 1Score 2Score 3
Data sensitivity<no personal or confidential data><personal data, no special categories><special-category, health, financial, or children's data>
Decision impact<informational only, human acts independently><influences a consequential decision, human decides><drives or makes a consequential decision about a person>
Regulatory exposure<no sector AI rule applies><general rules apply (privacy, consumer)><named high-risk use or sector AI regime applies>

Aggregation rule: any dimension at 3 makes the system at least High. All dimensions at 1 is Minimal. Otherwise take the highest dimension score: 2 is Limited. A prohibited use case (social scoring, untargeted scraping for facial recognition, and the rest of the EU AI Act Article 5 list) is Unacceptable regardless of scores.

Worked example

DimensionScoreRationale
Data sensitivity3Processes candidate CVs, which include special-category data in many applications
Decision impact3Ranking materially shapes which candidates a recruiter reviews first
Regulatory exposure3Employment screening is an EU AI Act Annex III high-risk use, and NYC Local Law 144 applies
ResultHighThree dimensions at 3; not a prohibited use, so High rather than Unacceptable

Acceptance criteria

  • The score definitions are adapted to your own data categories and regulated decisions, not left generic.
  • The aggregation rule is written down and applied consistently, so two assessors scoring the same system land on the same tier.
  • Prohibited use cases are checked separately and route to Unacceptable regardless of the numeric scores.

3. Shadow-AI discovery survey

Document

Surfaces AI tools that never went through procurement. The amnesty framing is the point: people answer honestly when disclosure has a clear, penalty-free path to approval.

Template

Send to all staff. Keep it short. Lead with the amnesty.

Intro (amnesty language): We are building a list of the AI tools people use day to day so we can support them properly. This is not an audit. Nothing you report here will be held against you or your team. Anything you flag gets a fast review and, in most cases, a route to formal approval.

Questions:

  1. Which AI tools or assistants do you use for work, including ones accessed through a personal account or a free tier?
  2. What do you use each one for?
  3. What kind of information do you put into it? (No customer names or confidential data in this answer, just the category.)
  4. Did the tool come through IT or procurement, or did you start using it directly?
  5. Would your work be disrupted if the tool were switched off tomorrow?
  6. Anything else we should know about how AI shows up in your team's work?

Worked example

Response from M. Okafor, Finance:

  1. ChatGPT (personal Plus account), and the AI summary feature in our BI tool.
  2. ChatGPT for drafting board-pack commentary and cleaning up spreadsheet formulas. BI summaries for the monthly revenue readout.
  3. ChatGPT: rough figures and draft narrative text. BI tool: whatever is already in the warehouse.
  4. Neither came through IT. The BI feature switched on automatically in an update.
  5. Yes for ChatGPT, the commentary drafting saves about a day a month. The BI summary I could do without.
  6. Two other people in Finance use the same ChatGPT workflow.

Triage: ChatGPT use with draft financial narrative is a data-handling risk. Route to approved enterprise tenant, add to register as Limited. BI summary feature: confirm data stays in region, add as Minimal.

Acceptance criteria

  • The survey went to all staff, not just engineering or a sample.
  • Every disclosed tool has been triaged and either added to the inventory register or explicitly ruled out with a reason.
  • Respondents who disclosed a tool received a follow-up with an approval path, so the amnesty promise held.

4. Vendor AI capability checklist

Spreadsheet

A procurement gate. Run it against any new tool or contract renewal so AI features are caught before they are live, not discovered in the next inventory sweep.

Template

#CheckAnswerFlag if
1Does the product include any AI, machine learning, or "intelligent" feature, now or on the roadmap?Y / NY and not yet in the register
2Does any AI feature process our customer or employee personal data?Y / NY
3Does an AI feature influence a decision about a person (access, pricing, eligibility, ranking)?Y / NY
4Can AI features be disabled, and are they off by default?Y / NN
5Does the vendor state whether our data trains their models?Y / NN, or training not opt-out
6Is there a model or system card, or equivalent documentation?Y / NN for anything above Minimal
7Does the contract cover change notification for AI features?Y / NN

Worked example

#CheckAnswerNote
1AI or ML feature present or planned?Y"Smart routing" plus a summarization beta
2Processes personal data?YSupport tickets contain customer names
3Influences a decision about a person?NRouting is internal workload allocation only
4Can AI features be disabled, off by default?NSummarization beta is on for all workspaces
5Vendor states training use of our data?YContractual opt-out available, not the default
6Model or system card available?NRequested from vendor, outstanding
7Contract covers AI change notification?NFlag to Legal for the renewal redline
OutcomeAdd as Limited. Disable summarization beta pending review. Legal to add change-notice and training opt-out clauses.

Acceptance criteria

  • The checklist is a required step in procurement and renewal workflows, with a named owner for sign-off.
  • Any flagged answer creates a follow-up action with an owner and a due date.
  • Tools that pass through the checkpoint are added to the inventory register on the same day.

Governance controls this kit produces evidence for

Completing the artifacts above gives you a head start on the evidence requirements for these controls.

MGV-002
MGV-002

The register and procurement checkpoint are the intake record showing every AI system was catalogued and triaged before or shortly after going live.

HOC-001
HOC-001

The scoring matrix and the per-system scores are the documented, repeatable risk-classification method with rationale for each tier.

PRC-014
PRC-014

The shadow-AI survey results and the vendor capability checklist evidence an active process for finding and classifying unsanctioned and embedded third-party AI.

SCT-009
SCT-009

The completed register doubles as the algorithm register: system, purpose, owner, data, and review date in one place.

DGC-002
DGC-002

The "data processed" and "data sensitivity" columns record where personal and special-category data enters AI systems.

This kit backs one playbook. Read the full guidance for the reasoning behind each artifact.

Decide what to implement next

Assess your governance gaps, then create an action plan with owners and target dates. Build and export without an account; sign in when you want to save your plan.

Start the AI governance assessment →