Governance foundation · System inventory
AI System Inventory & Risk Classification
A usable AI inventory preserves disputed records and source limits, then gives every classified system an accountable owner, evidence-backed tier, and trigger for review.
Procurement may show one list while teams are working with another. We reconcile sanctioned, reported, and embedded AI use, then record each system's owner, intended use, data, actions, affected work, evidence, and review tier. Unresolved entries stay unresolved until an accountable person can settle them.
A reconciled system inventory, explainable classifications, and a named maintenance cycle prepare your governance owner for procurement, supplier, or system changes.


Some of the 500+ brands we've worked with
See all referencesSteps, gates, and who decides
How we work
A list is only the beginning. Each candidate system needs an accountable owner, enough intended-use evidence for a reasoned tier, and a clear route back into review when something changes.
Open the approved discovery routes
We compare procurement and technology records with reported use, then mark missing sources, duplicate candidates, and conflicting entries. Nothing is silently reconciled when an owner still needs to decide which record is right.
- AI assist
- Approved records are compared for likely duplicates, mismatched owners, and blank fields. A specialist checks every flag.
- Human gate
- Which discovery sources has your governance owner approved, and which channels remain unavailable? Your governance owner decides which discovery channels are representative enough to use.


Give every candidate its own record
For each system or use case, we capture ownership, intended use, data, actions, affected workflows, and the source behind the entry. Gaps remain visible so a reviewer can distinguish an incomplete record from a low-risk one.
- AI assist
- Available sources let the model draft owner, use, data, action, and evidence fields for review.
- Human gate
- Is the intended-use evidence sufficient to take this system into classification, or must the record remain incomplete? Your governance owner confirms the recorded owner and intended use before classification begins.


Make the tier explainable
We apply the agreed rubric and keep the rationale, supporting evidence, confidence, and exceptions beside the proposed tier. If the evidence does not support a decision, the entry stays unresolved.
- AI assist
- Only the agreed rubric is applied to prepare a proposed tier and rationale for the governance owner.
- Human gate
- Does the record support this tier clearly enough for your governance owner to approve it? Your governance owner approves the tier or sends the record back for more evidence.


Attach the next review
Every classified system receives a reviewer, a review date, and the changes that should reopen the decision. Procurement events and material design changes then have a defined route back into the register.
- AI assist
- Observed procurement and system changes give the model candidate refresh triggers for the owner's review.
- Human gate
- Are a review owner and change trigger named for every classified system? Your governance owner assigns the reviewer and confirms the trigger for each record.


Named artifacts you keep
What you get
You receive a register your team can keep using after handoff. It preserves disputed entries, source limits, classification reasoning, and overdue review work instead of smoothing them into a reassuring total.


Dataset
AI system identity and review-status inventory
The field model for system identity, ownership, use, data, actions, affected parties, evidence, classification, and review status.


Matrix
Populated ownership and evidence register
Known systems and use cases with their owners and source evidence, including records that remain disputed or incomplete.


Risk register
Risk-tier rationale and exception scorecard
Agreed classification logic and the resulting tiers, with rationale, exceptions, and evidence confidence retained for review.


Roadmap
Review and record-refresh schedule
Named reviewers, dates, and material-change triggers for keeping the register current after procurement or system changes.
Scope and honest limits
When to bring us in
Bring this in when the central AI register no longer matches what procurement, technology teams, and business owners can see in practice.
A good fit when
- AI use appears in team workflows, but the central register has no entry linking the tool to an owner, intended use, or source.
- Existing entries name a system, yet ownership, data paths, intended use, or the affected workflow are too incomplete for classification.
- A risk tier was approved once, but no review date or supplier-change trigger brings the system back when its evidence goes stale.
- Procurement records, technology inventories, and team reports disagree, so approved discovery routes cannot produce one reconciled system list.
- Known systems have separate entries, but some records still lack the owner, intended use, data, actions, or affected parties needed for review.
- A proposed risk tier exists, yet its rationale, supporting evidence, confidence, or exceptions cannot be followed by the governance owner.
- Classified systems have review dates, but supplier and system changes do not consistently return the affected record to a named reviewer.
Better handled as other work when
- You want certainty that every hidden, unreported, or embedded AI use has been found, although discovery covers only the approved channels and access we were given.
- You need us to make the legal or regulatory classification, while that determination remains with your qualified authority.
- You need remediation or ongoing register operation beyond the agreed inventory work, but this engagement ends after the maintenance cycle is handed over.
If one of these is closer to your situation, start here instead: Explore governance services
Advice from people who build
We've worked with more than 500 brands since Zeo started in 2011. The people helping you decide where AI fits, and where it doesn't yet, are senior engineers and strategists who build and operate production AI systems. The advice stays grounded in work that actually shipped.
Tools we use
Tools behind this work
Airtablethe record base giving every system its own owner, tier, and review date
Credo AIthe registry that reconciles reported systems against shadow AI it detects on its own
Holistic AIthe discovery layer that finds AI use across the ecosystem before anyone self-reports it
Next step
Reconcile the AI use your teams can see


Before you decide




























