Building Your First AI System Inventory
Deliberate Academy Editorial Team
Reviewed for accuracy and professional relevance
You're 7 lessons in — don't lose your progress.
Sign up free to save where you are and earn a verified certificate when you pass.
- Explain why an unclassified or incomplete AI system inventory is the single most common starting gap in this field
- Identify the minimum fields a usable first-pass AI inventory entry must include
- Apply a triage approach to prioritizing which systems to review first when a full inventory does not yet exist
- Recognize why "we don't have a complete inventory yet" is an honest and useful starting answer, not a failure to report
A newly appointed compliance professional asks their organization for a list of AI systems currently in use. The honest answer, more often than not, is that no complete list exists — AI capabilities have arrived embedded in dozens of existing software platforms, adopted informally by individual teams, and layered into products no single person tracks centrally. This is not a sign of an unusually disorganized organization. It is the default starting condition almost every organization is in, and building the first inventory is consistently the single most valuable early step in this field.
What a Usable First-Pass Inventory Entry Needs
A minimum viable inventory entry should record: the business function the system serves; whether it processes personal data; whether it makes or materially influences a decision about an individual, and in what domain (employment, credit, healthcare, and similar sensitive domains warrant particular attention); whether the system was built in-house or provided by a vendor; and whether a documented risk classification currently exists for it. A blank answer to that last field is an acceptable and informative entry — it tells you exactly where the real gap is, which is the entire point of the exercise.
Do not let the absence of a complete inventory delay starting one. A partial inventory with five honestly assessed systems is more useful than no inventory at all, and it is normal — not a failure — for a first pass to surface more open questions than confirmed answers.
A compliance professional is building their organization's first AI system inventory and cannot determine whether a documented risk classification exists for three of the eight systems identified so far. What is the correct way to handle those three entries?
Select one answer.
Triaging When You Cannot Review Everything at Once
When an inventory surfaces more systems than can be reviewed in depth immediately, sort them into rough priority tiers using an initial screen, before applying any formal classification methodology: systems that plausibly touch employment, credit, insurance, benefits eligibility, or biometric processing are priority one; customer-facing systems with limited decision authority are priority two; and internal productivity tools with no bearing on decisions about individuals are priority three. This triage is not a substitute for eventually reviewing every system — it is how a compliance team with limited capacity makes defensible progress instead of being paralyzed by the size of the full task.
Building a First Inventory Under Regulatory Time Pressure — European Retail Bank
Context
A newly appointed Head of AI Compliance inherited an organization with no consolidated AI system inventory. An internal survey identified 41 distinct AI systems in active use across underwriting, customer service, fraud detection, HR, and marketing — of which only 3 had any documented risk classification. The bank's primary regulator had signaled that AI governance would be a focus area in an upcoming supervisory review, expected in 90 days.
Action
Rather than attempting to classify all 41 systems with equal rigor in the available time, she applied the triage approach: systems plausibly touching credit, employment, or biometric processing were prioritized first; customer-facing systems with limited decision authority second; and internal productivity tools deprioritized as almost certainly minimal-risk. She assembled a small cross-functional working group to produce a one-page classification record and gap list for each priority-one system.
Outcome
Within the 90-day window, the bank had documented risk classifications for the 14 priority-one systems, including the underwriting and HR tools most likely to be scrutinized, with an initial remediation plan for the gaps identified. The remaining 27 systems were placed on a scheduled classification calendar. When the supervisory review began, the bank could produce classification records and remediation plans rather than an unclassified inventory — a materially stronger position than having no process in place at all.
Why does this lesson describe an unclassified AI system inventory as the single most common starting gap in this field, rather than an unusual sign of organizational disorganization?
Select one answer.
Exercise
Your Task
Build a one-page AI inventory for your organization, or a plausible organization if you do not have direct access to one. List five to ten AI systems currently in use or under evaluation. For each, record the five fields from this lesson: business function, personal data processing, individual decision impact and domain, in-house or vendor-provided, and whether a documented risk classification exists. Sort the list into the three priority tiers from this lesson.
Success looks like
- Every listed system has an honest entry for all five fields — a blank classification status is an acceptable and informative answer
- At least one system is flagged as priority-one based on touching employment, credit, insurance, or biometric processing
Watch out for
- Assuming a system is low-priority because it is internally described as an "assistant" or "helper tool" — the internal label has no bearing on its actual risk profile
- Treating the absence of a classification record as a minor administrative gap rather than the primary compliance exposure it represents
Hint
Start with any system that touches hiring, lending, insurance, benefits eligibility, or biometric identification — these are the domains most likely to surface a genuine priority-one finding.
- An unclassified or incomplete AI system inventory is the default starting condition for most organizations, not a sign of unusual disorganization.
- A minimum viable inventory entry records business function, personal data processing, individual decision impact and domain, in-house-versus-vendor origin, and current classification status.
- A blank or "unknown" classification status is a genuinely useful, honest finding — not a reason to exclude a system from the inventory.
- When a full inventory cannot be reviewed at once, triage by likely risk domain first — employment, credit, biometric, and similarly sensitive systems before lower-stakes internal tools.
- Building a first, honestly incomplete inventory under time pressure is consistently more valuable than delaying until a perfect, fully classified inventory can be produced.