You cannot govern AI you have not cataloged. The AI system inventory is a structured registry of every AI and ML system in your organization — the models you build, and the third-party AI tools you buy — with the ownership and data context that every downstream assessment builds on.
AI system inventory showing registered systems with owners and risk status

What counts as an AI system

Register anything that makes or supports automated decisions or generates outputs from data:
  • In-house models — recommendation engines, scoring models, fraud detection, forecasting
  • Third-party AI products — AI customer-service platforms, HR screening tools, credit scoring services, content generation tools
  • Embedded AI features — AI capabilities inside SaaS products your teams already use
Third-party AI tools belong in the inventory too. Your organization may be the data controller even when the model belongs to a vendor. Vendor-provided systems link to Vendor Risk for integrated assessment.

Registering a system

1

Create the entry

Under AI Governance → Inventory → Register system, add the system manually — or via API from your ML platform so new models register automatically. Discovery can also flag AI services detected among your connected systems.
2

Assign ownership

Every system needs a business owner (accountable for the use case) and a technical owner (accountable for the model’s behavior). Ownerless systems are flagged on the governance dashboard.
3

Document purpose and data

Capture what the system is for, what it decides or produces, and the personal data it touches — see the fields below.
4

Classify

Complete the risk classification questionnaire to assign an EU AI Act risk tier and the obligations that follow.

What each entry captures

Field groupContents
Identity & ownershipSystem name, version, vendor (if third-party), business owner, technical owner
PurposeThe business process supported, the decisions or outputs produced, who is affected by them
Data inputsPersonal data categories processed, data subjects affected, source systems from the data map
Training data provenanceOrigin of training datasets, the legal bases or consents the data was collected under, and any minimization or anonymization applied before training
DocumentationModel cards — standardized documentation of purpose, performance characteristics, known limitations, and privacy risk profile
If consent is the legal basis for training data, link the consent records from Consent Management. TruePrivacy alerts you when a training data source has no documented legal basis.

Keeping the inventory current

  • Data input monitoring — TruePrivacy watches the data flows feeding registered systems. If a model starts receiving data categories not present in its original registration, an alert triggers a review and a possible DPIA update.
  • Periodic attestation — owners are prompted on a schedule to confirm the entry still reflects reality.
  • Change history — every edit to an inventory entry is versioned, so you can show regulators what you knew and when.
An inventory that only covers the data science team’s models is incomplete. Survey business teams for AI features switched on inside SaaS tools — these are the systems most likely to process personal data unnoticed.