AIPolicyTracker
Process Owner: AI governance lead Continuous

AI system inventory and classification

Ensures the organisation knows every AI system it builds, buys or embeds, who owns it, what it is for and which legal risk tier it falls into, so that obligations can be assigned rather than discovered after the fact.

Duties satisfied
1
done properly, does the work
Duties supported
10
contributes; the duty needs more
Jurisdictions
7
Evidence items
3

How is it implemented?

A central register is populated through intake forms, procurement gates, code and vendor scans and periodic attestations from business units. Each entry records the owner, purpose, users and affected people, the jurisdictions it operates in, the models and vendors involved, the personal-data involvement and the current lifecycle status. A classification step assigns a risk tier using the organisation's own criteria and the categories defined by applicable law, and the tier drives which further controls apply. Shadow-AI discovery and a rule that nothing goes live without a register entry keep the inventory current.

Which legal duties does it serve?

Satisfies means the control, operated properly, does the work the duty asks for. Supports means it contributes but the duty needs more. The official text decides; open it before relying on either.

European Union 3 duties

Australia 1 duty

Colorado (United States) 1 duty

South Korea 2 duties

Texas (United States) 1 duty

United Kingdom 1 duty

United States 2 duties

What evidence shows it is operating?

Evidence this control produces
EvidenceTypeWhat it shows
AI system registerRegister entryOne row per system with owner, purpose, risk tier, jurisdictions, vendors and status.
Risk-tier classification sign-offApproval or sign-off recordReviewer confirmation of the assigned tier and the rationale.
AI intake and classification procedureProcedure or standard operating process

Owner: AI governance lead. Frequency: continuous.

Which risks does it address?

Subdomains of the MIT AI Risk Repository, with the incidents the AI Incident Database has recorded under each. Counts are live; they say how often a risk has materialised, not how well this control prevents it.

Which standards clauses does it correspond to?

Clause numbers only. A reference means the standard asks for overlapping work, so evidence may be reusable; it never means the standard discharges a legal duty.

Framework references
FrameworkReferenceNoteConfidence
ISO/IEC 42001Clause 4.1, 4.3, 8.1; Annex A.6.2.2, A.9.4Editorial mapping to scope, operational planning and intended-use records.medium
NIST AI RMFMAP 1.1, 1.5; GOVERN 1.6high
MITRE ATLASAML.M0023 AI Bill of Materialslow

Cite this record

AIPolicyTracker (2026). “AI system inventory and classification”. https://aipolicytracker.org/controls/ai-system-inventory (accessed 24 September 2026). Data licensed CC BY 4.0.

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.

Frequently asked questions

Which legal duties does "AI system inventory and classification" satisfy?
It is recorded as satisfying 1 and supporting 10 duties across European Union, Australia, Colorado (United States), South Korea, Texas (United States), United Kingdom and United States. A mapping means the control, operated properly, does the work the duty asks for; the official text decides whether it is enough.
What evidence shows this control is operating?
AI system register, Risk-tier classification sign-off and AI intake and classification procedure. Owner: AI governance lead. Frequency: continuous.