
What counts as an AI system
Register anything that makes or supports automated decisions or generates outputs from data:- In-house models — recommendation engines, scoring models, fraud detection, forecasting
- Third-party AI products — AI customer-service platforms, HR screening tools, credit scoring services, content generation tools
- Embedded AI features — AI capabilities inside SaaS products your teams already use
Third-party AI tools belong in the inventory too. Your organization may be the data controller even when the model belongs to a vendor. Vendor-provided systems link to Vendor Risk for integrated assessment.
Registering a system
Create the entry
Under AI Governance → Inventory → Register system, add the system manually — or via API from your ML platform so new models register automatically. Discovery can also flag AI services detected among your connected systems.
Assign ownership
Every system needs a business owner (accountable for the use case) and a technical owner (accountable for the model’s behavior). Ownerless systems are flagged on the governance dashboard.
Document purpose and data
Capture what the system is for, what it decides or produces, and the personal data it touches — see the fields below.
Classify
Complete the risk classification questionnaire to assign an EU AI Act risk tier and the obligations that follow.
What each entry captures
| Field group | Contents |
|---|---|
| Identity & ownership | System name, version, vendor (if third-party), business owner, technical owner |
| Purpose | The business process supported, the decisions or outputs produced, who is affected by them |
| Data inputs | Personal data categories processed, data subjects affected, source systems from the data map |
| Training data provenance | Origin of training datasets, the legal bases or consents the data was collected under, and any minimization or anonymization applied before training |
| Documentation | Model cards — standardized documentation of purpose, performance characteristics, known limitations, and privacy risk profile |
Keeping the inventory current
- Data input monitoring — TruePrivacy watches the data flows feeding registered systems. If a model starts receiving data categories not present in its original registration, an alert triggers a review and a possible DPIA update.
- Periodic attestation — owners are prompted on a schedule to confirm the entry still reflects reality.
- Change history — every edit to an inventory entry is versioned, so you can show regulators what you knew and when.