Implementation Kit
AI Inventory Template and Risk Classification Matrix
Everything needed to stand up a working AI inventory: the register itself, a scoring matrix that turns three inputs into a risk tier, a shadow-AI discovery survey, and a procurement checkpoint. Fill the register, score every system, assign an owner and a review date.
Who this is for: The GRC or risk lead running the first pass at an AI inventory, plus the procurement reviewer who has to keep it current.
1. AI inventory register
SpreadsheetThe master list. One row per AI system, with the three scoring inputs, the resulting tier, a named owner, and a next-review date.
Template
| System name | Business owner | Vendor / provider | Deployment type | Primary use case | Data processed | Data sensitivity (1-3) | Decision impact (1-3) | Regulatory exposure (1-3) | Risk tier | Regulatory frameworks | Date added | Last reviewed | Next review |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| <system> | <name, role> | <vendor or "in-house"> | API / SaaS / self-hosted / embedded | <what it does> | <data categories> | 1-3 | 1-3 | 1-3 | Minimal / Limited / High / Unacceptable | <e.g. EU AI Act, GDPR> | YYYY-MM-DD | YYYY-MM-DD | YYYY-MM-DD |
Worked example
| System name | Business owner | Vendor / provider | Deployment type | Primary use case | Data processed | Data sensitivity (1-3) | Decision impact (1-3) | Regulatory exposure (1-3) | Risk tier | Regulatory frameworks | Date added | Last reviewed | Next review |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Resume Screener | Dana Portillo, Head of Talent | Greenhouse + in-house model | Embedded | Ranks inbound applicants for recruiter review | Candidate CVs, contact details, work history | 3 | 3 | 3 | High | EU AI Act (Annex III), GDPR, NYC Local Law 144 | 2026-02-11 | 2026-08-30 | 2026-11-30 |
| Support Copilot | Marcus Lee, Support Ops | Zendesk AI | SaaS | Drafts agent replies from the knowledge base | Customer tickets, order metadata | 2 | 2 | 1 | Limited | GDPR | 2026-03-04 | 2026-09-01 | 2027-03-01 |
| Contract Summarizer | Priya Anand, Legal Ops | Anthropic API | API | Summarizes NDAs for the legal queue | Counterparty names, commercial terms | 2 | 1 | 1 | Minimal | none identified | 2026-05-19 | 2026-09-01 | 2027-03-01 |
Acceptance criteria
- ✓Every AI system found through any discovery method has a row, including embedded vendor features and department-level subscriptions.
- ✓Each row has a named individual as business owner, not a team or a function.
- ✓All three scoring inputs are populated with a 1 to 3 value, and the risk tier matches what the scoring matrix produces from them.
- ✓Every row has a next-review date within the review cadence set for its tier (high-risk reviewed at least quarterly).
2. Risk classification scoring matrix
SpreadsheetThe rule that turns data sensitivity, decision impact, and regulatory exposure into a defensible tier. Score each dimension 1 to 3, then apply the aggregation rule.
Template
| Dimension | Score 1 | Score 2 | Score 3 |
|---|---|---|---|
| Data sensitivity | <no personal or confidential data> | <personal data, no special categories> | <special-category, health, financial, or children's data> |
| Decision impact | <informational only, human acts independently> | <influences a consequential decision, human decides> | <drives or makes a consequential decision about a person> |
| Regulatory exposure | <no sector AI rule applies> | <general rules apply (privacy, consumer)> | <named high-risk use or sector AI regime applies> |
Aggregation rule: any dimension at 3 makes the system at least High. All dimensions at 1 is Minimal. Otherwise take the highest dimension score: 2 is Limited. A prohibited use case (social scoring, untargeted scraping for facial recognition, and the rest of the EU AI Act Article 5 list) is Unacceptable regardless of scores.
Worked example
| Dimension | Score | Rationale |
|---|---|---|
| Data sensitivity | 3 | Processes candidate CVs, which include special-category data in many applications |
| Decision impact | 3 | Ranking materially shapes which candidates a recruiter reviews first |
| Regulatory exposure | 3 | Employment screening is an EU AI Act Annex III high-risk use, and NYC Local Law 144 applies |
| Result | High | Three dimensions at 3; not a prohibited use, so High rather than Unacceptable |
Acceptance criteria
- ✓The score definitions are adapted to your own data categories and regulated decisions, not left generic.
- ✓The aggregation rule is written down and applied consistently, so two assessors scoring the same system land on the same tier.
- ✓Prohibited use cases are checked separately and route to Unacceptable regardless of the numeric scores.
3. Shadow-AI discovery survey
DocumentSurfaces AI tools that never went through procurement. The amnesty framing is the point: people answer honestly when disclosure has a clear, penalty-free path to approval.
Template
Send to all staff. Keep it short. Lead with the amnesty.
Intro (amnesty language): We are building a list of the AI tools people use day to day so we can support them properly. This is not an audit. Nothing you report here will be held against you or your team. Anything you flag gets a fast review and, in most cases, a route to formal approval.
Questions:
- Which AI tools or assistants do you use for work, including ones accessed through a personal account or a free tier?
- What do you use each one for?
- What kind of information do you put into it? (No customer names or confidential data in this answer, just the category.)
- Did the tool come through IT or procurement, or did you start using it directly?
- Would your work be disrupted if the tool were switched off tomorrow?
- Anything else we should know about how AI shows up in your team's work?
Worked example
Response from M. Okafor, Finance:
- ChatGPT (personal Plus account), and the AI summary feature in our BI tool.
- ChatGPT for drafting board-pack commentary and cleaning up spreadsheet formulas. BI summaries for the monthly revenue readout.
- ChatGPT: rough figures and draft narrative text. BI tool: whatever is already in the warehouse.
- Neither came through IT. The BI feature switched on automatically in an update.
- Yes for ChatGPT, the commentary drafting saves about a day a month. The BI summary I could do without.
- Two other people in Finance use the same ChatGPT workflow.
Triage: ChatGPT use with draft financial narrative is a data-handling risk. Route to approved enterprise tenant, add to register as Limited. BI summary feature: confirm data stays in region, add as Minimal.
Acceptance criteria
- ✓The survey went to all staff, not just engineering or a sample.
- ✓Every disclosed tool has been triaged and either added to the inventory register or explicitly ruled out with a reason.
- ✓Respondents who disclosed a tool received a follow-up with an approval path, so the amnesty promise held.
4. Vendor AI capability checklist
SpreadsheetA procurement gate. Run it against any new tool or contract renewal so AI features are caught before they are live, not discovered in the next inventory sweep.
Template
| # | Check | Answer | Flag if |
|---|---|---|---|
| 1 | Does the product include any AI, machine learning, or "intelligent" feature, now or on the roadmap? | Y / N | Y and not yet in the register |
| 2 | Does any AI feature process our customer or employee personal data? | Y / N | Y |
| 3 | Does an AI feature influence a decision about a person (access, pricing, eligibility, ranking)? | Y / N | Y |
| 4 | Can AI features be disabled, and are they off by default? | Y / N | N |
| 5 | Does the vendor state whether our data trains their models? | Y / N | N, or training not opt-out |
| 6 | Is there a model or system card, or equivalent documentation? | Y / N | N for anything above Minimal |
| 7 | Does the contract cover change notification for AI features? | Y / N | N |
Worked example
| # | Check | Answer | Note |
|---|---|---|---|
| 1 | AI or ML feature present or planned? | Y | "Smart routing" plus a summarization beta |
| 2 | Processes personal data? | Y | Support tickets contain customer names |
| 3 | Influences a decision about a person? | N | Routing is internal workload allocation only |
| 4 | Can AI features be disabled, off by default? | N | Summarization beta is on for all workspaces |
| 5 | Vendor states training use of our data? | Y | Contractual opt-out available, not the default |
| 6 | Model or system card available? | N | Requested from vendor, outstanding |
| 7 | Contract covers AI change notification? | N | Flag to Legal for the renewal redline |
| Outcome | Add as Limited. Disable summarization beta pending review. Legal to add change-notice and training opt-out clauses. |
Acceptance criteria
- ✓The checklist is a required step in procurement and renewal workflows, with a named owner for sign-off.
- ✓Any flagged answer creates a follow-up action with an owner and a due date.
- ✓Tools that pass through the checkpoint are added to the inventory register on the same day.
Governance controls this kit produces evidence for
Completing the artifacts above gives you a head start on the evidence requirements for these controls.
The register and procurement checkpoint are the intake record showing every AI system was catalogued and triaged before or shortly after going live.
The scoring matrix and the per-system scores are the documented, repeatable risk-classification method with rationale for each tier.
The shadow-AI survey results and the vendor capability checklist evidence an active process for finding and classifying unsanctioned and embedded third-party AI.
The completed register doubles as the algorithm register: system, purpose, owner, data, and review date in one place.
The "data processed" and "data sensitivity" columns record where personal and special-category data enters AI systems.
This kit backs one playbook. Read the full guidance for the reasoning behind each artifact.
Decide what to implement next
Assess your governance gaps, then create an action plan with owners and target dates. Build and export without an account; sign in when you want to save your plan.
Start the AI governance assessment →