A maintainable AI inventory is a routing layer for governance work, not a spreadsheet expected to hold every assessment. A customer-support assistant that only drafts replies is not the same use once it can read identity documents, issue refunds and send messages. Even if its vendor and model remain unchanged, the new data, authority and reach should reopen the record and change its review route.
Key operating rules
Inventory one AI-enabled use in its workflow and action context, not merely its model or vendor.
Keep discovery compact, then link deeper evidence when exposure or an override requires it.
Set the provisional tier from the highest material rating rather than averaging severe exposure away.
Reopen the record when purpose, data, permissions, ownership, dependencies, scale, controls or incidents change materially.
Use internal tiers to route governance work, never as substitutes for applicable legal classifications.
What belongs in a practical AI inventory?
The record unit should be one AI-enabled use within a defined purpose, workflow, user group and output-to-action path. That unit reflects how official frameworks examine people, context, data, outputs and oversight, while NIST also describes inventories as useful for maintenance, incident response, individual queries and portfolio questions. Split records when purpose, affected parties, input sensitivity, action authority, deployment exposure or accountable ownership differs materially; otherwise one row can conceal substantially different risks.
Link shared vendor, model, application, data-source and integration records instead of copying them.
Link assessments, tests, controls, incidents and approvals as evidence with their own owners and histories.
Make each use record answer who owns it, what it does, whom it affects and where deeper review belongs.
Which fields keep intake useful but manageable?
A useful intake record needs enough information to identify ownership, context and the correct route, while leaving comprehensive assurance work in linked artefacts. NIST, OECD and the UK recording standard cover overlapping subjects such as purpose, users, impacts, suppliers, data, oversight, dependencies, lifecycle and mitigations. The following compressed field set is an editorial design for enterprise discovery, not a template prescribed by those sources.
Use identity — Stable ID and plain-language name.
Ownership — Accountable business role and technical role able to change or stop the use.
Purpose and boundaries — Workflow, intended outcome and prohibited or out-of-scope uses.
People — Intended users and affected parties, recorded separately.
Inputs and sensitivity — Data categories, sources and highest handling classification.
Outputs and authority — Recipients and whether the use suggests, recommends, initiates or executes action.
Providers and dependencies — Linked vendors, models, permissions, integrations and downstream systems.
Controls and evidence — Current review, access, testing, monitoring, fallback, correction and evidence links.
Lifecycle and dates — Controlled state, last material change, last review and next risk-based review.
Ratings and rationale — Four ratings, provisional tier, overrides, unknowns and owner's evidence sentences.
Obligations status — Link to separate legal, privacy, security, contractual and sector review.
Record categories and the highest applicable handling classification rather than every data column. Describe what happens after an output instead of merely naming the output. A control entry should say what is intended and point to test or operating evidence; its presence alone does not demonstrate effectiveness. Detailed impact assessments, validation reports, vendor reviews, incidents, approvals and monitoring plans should become conditional linked artefacts, preserving one discoverable source of routing information without duplicating assurance files.
How can owners explain inherent exposure?
Owners can explain inherent exposure by rating consequence, autonomy, scale and sensitivity against three concrete levels, then adding one use-specific evidence sentence for each rating. This exact combination is ModelFold's practical internal triage proposal, synthesised from broader characteristics in the cited sources. NIST, OECD, Canada and the UK do not prescribe or endorse this rubric, its anchors or its later tier rule.
Consequence — Level 1: local, readily reversible inconvenience or low-value rework. Level 2: a material operational, financial, customer, employee or reputational effect needing deliberate recovery. Level 3: a credible effect on rights, important opportunities or services, health or safety, livelihood, critical operations, or another severe or difficult-to-reverse outcome.
Autonomy — Level 1: suggestions a person chooses whether to use. Level 2: ranking, routing, recommending, personalising or bounded initiation with limited or later review. Level 3: external actions, record or permission changes, resource commitments, or material influence over consequential decisions without effective case-by-case approval.
Scale — Level 1: a bounded pilot or small internal group with little downstream reuse. Level 2: repeated use across a function, segment or material workflow with meaningful volume or several consumers. Level 3: enterprise-wide, public, cross-market, high-volume, real-time or deeply integrated use capable of propagating correlated effects.
Sensitivity — Level 1: public, synthetic or approved non-confidential information without privileged access. Level 2: internal or confidential business data, ordinary personal information, customer content or bounded authenticated access. Level 3: highly sensitive or regulated data, credentials, secrets, privileged material, protected characteristics or proxies, precise monitoring data, or access that can change important protected records.
Rate the actual proposed or operating use, not a provider's generic product. Ask what could credibly happen if the output were wrong, misused, unavailable or acted on as designed; how far the system can move before informed intervention; how broad and connected the exposure is; and what it can receive, infer, expose or change. Mark missing facts as unknown and route them for resolution rather than turning assumptions into reassuring scores.
How should the ratings set the review route?
Set the provisional route from the highest material dimension: all Level 1 ratings produce Tier 1; any Level 2 with no Level 3 produces Tier 2; and any Level 3 produces Tier 3. This non-averaging rule and the three routes are editorial design choices, not scoring formulas validated by NIST or OECD. Each organisation should calibrate the anchors, decision rights and review depth against its risk tolerance and applicable obligations.
Escalate for out-of-tolerance activity, potentially severe affected-party impact or difficult reversibility.
Escalate for sensitive data with broad access, ineffective human control or cascading dependencies.
Escalate for material incidents, applicable obligations, unresolved facts or missing evidence that prevents a sound decision.
Rate inherent exposure before crediting controls, then record controls separately and examine their design and evidence during review. The reviewer can document residual risk, conditions and the accountable decision after that examination. This separation is another operating proposal because organisations use risk terminology differently. It prevents a claimed approval step, human check or access restriction from quietly lowering exposure before anyone establishes whether the control works in the actual workflow.
Adaptable internal review routes
Internal tier and route
Minimum review
Decision and evidence
Monitoring and reopening
Tier 1 — Registered
Owner confirms the record, boundaries, standard controls and operating instructions.
Standard policy path with owner rationale and control attestation.
Risk-based attestation; reopen on material change.
Tier 2 — Assessed
Cross-functional review of affected parties, data, oversight, vendors, testing, fallback and correction.
Named owner decides with targeted assessment, control evidence, residual-risk conditions and monitoring plan.
Defined indicators and evidence refresh; reassess on events.
Tier 3 — Enhanced Review
Independent challenge and relevant expertise test necessity, alternatives, authority, reversibility, controls, incidents and exit.
Policy-named authority explicitly approves, constrains or stops the use, supported by applicable assessments and findings.
Closer exposure-based monitoring; reopen immediately after incidents, control failure or scope change.
Maintain a parallel obligations track for legal, regulatory, contractual, privacy, security, labour, records and sector questions. Internal Tier 1–3 labels only route organisational work; they do not determine whether a use is lawful, prohibited, legally high-risk or subject to a particular duty. Qualified organisational owners must assess applicability independently, and their findings may require a different review, impose conditions or stop a use regardless of its internal tier.
What changes when an AI use expands?
A change in data, authority or reach can move the same underlying service to a different tier. Consider a fictional pilot that retrieves approved help content and drafts replies for trained support employees, who edit and send them. Account decisions, exceptions, unsupervised sending, payment data, identity documents, credits and account changes are outside scope. The ratings below illustrate this article's method; they are not measured outcomes or external validation.
Consequence — Bounded drafting pilot: Level 2 because a wrong reply could materially misstate policy and require customer remediation. Expanded proposal: Level 3 because wrong actions could affect customer funds, account access and difficult-to-reverse service outcomes.
Autonomy — Bounded drafting pilot: Level 1 because the assistant drafts and an employee decides what to send. Expanded proposal: Level 3 because it would issue refunds, change accounts and send without case-by-case approval.
Scale — Bounded drafting pilot: Level 1 because it covers one trained team and a limited message class. Expanded proposal: Level 3 because it would operate at high volume across regions with connected downstream effects.
Sensitivity — Bounded drafting pilot: Level 2 because it uses ordinary customer and internal account context in an authenticated system. Expanded proposal: Level 3 because it adds identity documents, payment-dispute details and account-write access.
Result — The bounded drafting pilot is provisionally Tier 2 because Level 2 is its highest material rating. Reopen the record before expansion and route the changed use to Tier 3 plus the obligations track.
Keep source links, required pre-send review, blocked write actions, access controls, sampling, a complaint path and manual fallback in the pilot's control record; do not use their mere presence to reduce inherent ratings. The expanded proposal still requires evidence, independent challenge and an accountable decision. Enhanced review may narrow or stop it rather than endorse autonomous consequential action. The original approval cannot travel with materially changed permissions, data, autonomy and scale.
The inventory earns trust when a change in data, authority or scale changes the route—not merely the row.
How do you keep the inventory current after launch?
Keep the inventory current through event-driven reopening, risk-based owner attestation and visible exception queues. Define who maintains it, what coverage means and how owners report changes. Discovery signals should come from several operating processes, but coverage figures remain indicators rather than proof of completeness. An unregistered use can still exist outside procurement, the application catalogue or any other single feed.
Discovery feeds: workflow intake, procurement and renewals, architecture review, access and integration administration, subscriptions, model and data processes, owner attestations, support cases, incidents and complaints.
Reopening triggers: material changes to purpose, ownership, users, affected parties, geography, data, retention, permissions, outputs, human review, vendor, model, integration, volume, controls, evidence, incidents, obligations, pause, replacement or retirement.
Work queues: missing owners, unknown ratings, unresolved overrides, overdue decisions, changed uses awaiting review, missing control evidence, vendor changes and incomplete retirement evidence.
Combine those triggers with owner attestation at an interval chosen for the use. Higher exposure, faster change, recent incidents or weaker evidence may justify closer review, but there is no defensible universal quarterly or annual cadence. Keep the portfolio dashboard small: records and affected parties by tier and lifecycle, missing fields, overdue decisions, open exceptions and control gaps, routing time, and retirement closure. Use these measures to direct follow-up, not declare the inventory complete.
Days 1–10: define the use-record unit, minimum schema, ownership rule, lifecycle states and discovery feeds.
Days 11–20: test the rubric on a varied sample, compare rationales and calibrate anchors and overrides.
Days 21–30: launch owner attestations, material-change triggers, stale-record queues and a compact portfolio dashboard.
Treat retirement as a controlled state rather than deleting the row. Preserve the owner, shutdown decision, access removal, migration, dependency closure and evidence required by organisational policy, without inventing a universal retention period. The whole method remains an internal routing proposal, not a compliance determination. Before consequential or high-stakes uses proceed, involve appropriate domain expertise, accountable human review and qualified legal, compliance, privacy, security, procurement, records, labour and sector owners.
AI inventory and risk-tiering questions
What fields should an AI system inventory include?
Include identity, business and technical owners, purpose, boundaries, users, affected parties, inputs, outputs, authority, dependencies, controls, lifecycle, ratings, dates and obligations status. Keep assessments, tests and approval evidence in linked artefacts rather than copying them into the discovery row.
How do you create an AI risk-tiering framework?
Define anchored levels for consequence, autonomy, scale and sensitivity, with one evidence sentence per rating. Set the provisional tier from the highest material level, apply explicit upward overrides and calibrate the method to organisational tolerance and obligations.
Should an AI inventory track models, vendors or use cases?
Use one primary record for each AI-enabled use in its workflow and action context. Link shared model, vendor, application, data and assurance records so common evidence is maintained once without hiding contextual differences.
How often should an AI inventory be updated?
Reopen it whenever a material change or incident occurs, then add owner attestation at a risk-based interval. Higher exposure or faster change may warrant closer review, but no universal cadence suits every use.
Does an internal AI tier determine whether a system is legally high-risk?
No. Internal tiers route organisational review, while qualified owners must assess applicable legal, regulatory, contractual, privacy, security, labour, records and sector requirements separately.
References and sources
This article was researched using the following sources:
We report on how AI actually lands inside a business. Our work starts from named sources, separates what we found from what we think, and uses AI assistance for research and drafting under documented editorial controls. We are not a substitute for individual expert review.
A practical guide to assigning AI standards, funding, delivery, risk and operations, then turning pilot evidence into portfolio and strategy decisions.
A practical method for setting capability-level information limits, tool permissions, approvals, refusals, evidence and release tests for AI assistants.