# AI system inventory and classification

- **Record type**: Control
- **Kind**: Process
- **Owner**: AI governance lead
- **Frequency**: Continuous
- **Duties served**: 11

## What the control achieves

Ensures the organisation knows every AI system it builds, buys or embeds, who owns it, what it is for and which legal risk tier it falls into, so that obligations can be assigned rather than discovered after the fact.

## How it is typically implemented

A central register is populated through intake forms, procurement gates, code and vendor scans and periodic attestations from business units. Each entry records the owner, purpose, users and affected people, the jurisdictions it operates in, the models and vendors involved, the personal-data involvement and the current lifecycle status. A classification step assigns a risk tier using the organisation's own criteria and the categories defined by applicable law, and the tier drives which further controls apply. Shadow-AI discovery and a rule that nothing goes live without a register entry keep the inventory current.

## Evidence it produces

- AI system register (register_entry): One row per system with owner, purpose, risk tier, jurisdictions, vendors and status.
- Risk-tier classification sign-off (approval_record): Reviewer confirmation of the assigned tier and the rationale.
- AI intake and classification procedure (procedure)

## Legal duties this control serves

- Provide contestability, supply-chain transparency and records (guardrails 7 to 9) — Australian Voluntary AI Safety Standard, Australia (supports): https://aipolicytracker.org/obligations/australia-vaiss-contestability-supply-chain-records
- Do not deploy or provide AI for prohibited practices — EU AI Act, European Union (supports): https://aipolicytracker.org/obligations/eu-ai-act-prohibited-practices
- Deployers, distributors and importers must assume provider duties when they rebrand or substantially modify high-risk AI — EU AI Act, European Union (supports): https://aipolicytracker.org/obligations/eu-ai-act-art-25-value-chain-becoming-provider
- Providers must document and register a conclusion that an Annex III system is not high-risk — EU AI Act, European Union (satisfies): https://aipolicytracker.org/obligations/eu-ai-act-art-6-4-non-high-risk-assessment-documentation
- AI business operators must notify users in advance that a product or service runs on high-impact or generative AI — Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust, South Korea (supports): https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-31-advance-notice-of-high-impact-and-generative-ai
- Operators of high-impact AI must establish and operate a risk management plan — Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust, South Korea (supports): https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-34-high-impact-ai-risk-management-plan
- Establish accountability and governance for AI — UK AI regulation framework, United Kingdom (supports): https://aipolicytracker.org/obligations/uk-principles-accountability-governance
- Deployers must publish a statement about the high-risk AI systems they use — Colorado AI Act, Colorado (United States) (supports): https://aipolicytracker.org/obligations/us-colorado-ai-act-deployer-public-statement
- Health-care providers must disclose the use of AI in patient services — Texas Responsible AI Governance Act (TRAIGA), Texas (United States) (supports): https://aipolicytracker.org/obligations/us-texas-responsible-ai-governance-act-traiga-health-care-ai-disclosure
- Map context, intended use and potential impacts (Map) — NIST AI RMF, United States (supports): https://aipolicytracker.org/obligations/us-nist-ai-rmf-map
- Publish an annual AI use-case inventory — OMB M-25-21, United States (supports): https://aipolicytracker.org/obligations/us-omb-m-25-21-use-case-inventory

## Standards clauses it corresponds to (clause numbers only)

- ISO/IEC 42001:2023: Clause 4.1, 4.3, 8.1; Annex A.6.2.2, A.9.4 — Editorial mapping to scope, operational planning and intended-use records.
- NIST AI RMF 1.0: MAP 1.1, 1.5; GOVERN 1.6
- MITRE ATLAS: AML.M0023 AI Bill of Materials

## MIT AI Risk Repository subdomains addressed

6.5, 7.4

## Provenance

- **Record page**: https://aipolicytracker.org/controls/ai-system-inventory
- **Official source**: none recorded — this record is incomplete, see https://aipolicytracker.org/gaps
- **Review status**: pending review
- **Confidence**: medium
- **Facts last confirmed**: never confirmed against the official source
- **Retrieved**: 2026-09-24
- **Licence**: https://creativecommons.org/licenses/by/4.0/

> This record is a structured summary with a link to the official text. It is not legal advice. Open the official source before relying on any date or duty. How current each record type must be is published at https://aipolicytracker.org/verification; what a record must carry at all is published at https://aipolicytracker.org/coverage.
