Skip to content

The AI system register: what to actually track

6 min read by John Bagnall

An AI system register is the single, maintained inventory of every AI tool, model and feature your organisation uses or builds. It is the least glamorous part of AI governance and the most important: it is the foundation everything else sits on. The principle is simple, you cannot govern what you cannot see, and the register is how you see it. ISO 42001 expects one, the EU AI Act assumes you have one, and every control, policy and risk decision downstream depends on it being accurate.

Most organisations already have a half-hearted version: a spreadsheet someone started, listing the obvious tools and missing the rest. The gap between that and a register you can actually govern from is what this covers, specifically, what to track in it.

Why the register comes first

Every framework for AI governance starts in the same place. An AI Management System begins with an inventory. Risk classification needs something to classify. Finding your shadow AI is only useful if what you find lands somewhere durable. That somewhere is the register.

So it is not paperwork for its own sake. It is the working artefact that lets you answer, on any given day, three questions: what AI are we using, who owns each piece, and how is each one controlled. If you cannot answer those, you are not governing AI, you are hoping.

What to actually track

Here is the trap: people either track too little (a name and a link) or drown the register in fields nobody maintains. Track the columns that drive a decision.

FieldWhat it isWhy it earns its place
Name & descriptionThe tool and a plain-language line on what it doesAnyone should understand the entry without context
OwnerThe named person accountable for itUngoverned AI is AI nobody owns; this is where accountability becomes real
Built or bought, and vendorIn-house, or a third-party product and who supplies itMost AI risk now comes from tools you bought, not models you built
Business functionWhere and by whom it is usedTells you the blast radius if it goes wrong
Data it touchesInputs and outputs, and whether any is personal or sensitiveDrives your data-protection and confidentiality obligations
Risk tierIts internal classification, plus EU AI Act tier if relevantThe whole point: it decides how much control the system gets
Human oversightWhether a person checks outputs, or it runs unattendedSeparates an assistant from an autonomous system
Lifecycle statusTrial, in use, deprecated, retiredStops the register drifting from reality
Approval statusSanctioned, pending review, or prohibitedTurns the register into a live policy, not just a list
Last reviewedThe date its entry was last checkedMakes stale entries obvious at a glance

A few of these do the heavy lifting. Owner, data, risk tier and approval status are what turn a list into governance. The rest add context you will be glad of when a regulator, auditor or customer asks.

The minimum viable register

If that table looks like a lot, do not let it stall you. The smallest register that genuinely reduces risk has just six columns:

Name, owner, purpose, data it touches, risk tier, status.

That alone closes the three gaps most organisations have, visibility, accountability and classification, and gives you something defensible to build on. Every other field is depth you add as your AI use grows. A complete register of six columns beats a half-finished one of twenty.

Keeping it alive

A register’s value is entirely in whether it stays true. A snapshot that rots is worse than none, because it gives the appearance of control while hiding the gaps. Three things keep it alive:

  • An intake gate. New AI tools get added before they go live, not discovered months later. Make “is it in the register?” a step in adopting anything new.
  • A named maintainer. Someone accountable for the register as a whole, plus each system’s owner keeping their own entry accurate.
  • A review cadence. A regular sweep, quarterly is common, to catch tools that have changed use, gained autonomy, or should be retired. The last-reviewed date makes the overdue ones visible.

This is also where the register connects back to finding shadow AI: discovery is not a one-off cleanup, it is a habit the register institutionalises.

Common mistakes

  • Tracking tools, not uses. The same model can be low-risk in one workflow and critical in another. The unit of the register is the use, not the vendor.
  • No owner field. Without accountability per system, the register is a list nobody acts on.
  • A static spreadsheet. Built once, never reviewed, quietly wrong within a quarter. Ownership and a review cadence are what prevent this.
  • Missing the invisible AI. The AI features switched on inside tools you already pay for are the easiest to leave off and among the most common.

The short version

The AI system register is the inventory that makes AI governable: every system, with an owner, the data it touches, a risk tier and a status, kept current. Track the fields that drive a decision, start with the six that matter most, and give it an owner and a review cycle so it stays true. Get this right and everything downstream, classification, controls, policy, evidence, has something solid to stand on. Get it wrong and the rest is built on sand.

Want a fast read on where you stand? The free AI governance readiness assessment flags exactly these gaps in about ten minutes, no email required. When you want to build the register and the management system around it properly, talk to us.

For the full picture, see the AI governance guide.

Frequently asked questions

What is an AI system register?

An AI system register is a single, maintained inventory of every AI system, model, tool and AI-enabled feature an organisation uses or builds. It records what each one is, who owns it, what data it touches and how risky it is. ISO 42001 expects one, and it is the foundation the rest of an AI Management System is built on: you cannot govern what you cannot see.

What should an AI register include?

At minimum: a name and plain-language description, the accountable owner, whether it is built or bought and the vendor, the data it touches, a risk tier, its lifecycle status, and the date it was last reviewed. Fuller registers also record the business function it serves, the level of human oversight, the legal basis or DPIA reference, and its EU AI Act classification. Start with the minimum and add columns as your AI use grows.

How is an AI register different from a normal software or asset inventory?

A software asset inventory tracks licences and installations. An AI register tracks AI-specific risk: what a system decides, whose data it processes, how autonomous it is, and what could go wrong. The same tool can appear in both, but the AI register exists to answer governance and regulatory questions an IT asset list was never designed to answer.

Who is responsible for maintaining the AI register?

Each system has a named owner responsible for keeping its entry accurate, and someone accountable for AI governance overall owns the register as a whole and runs the review cycle. The register must be a living document with clear ownership, not a spreadsheet someone built once and abandoned, because an out-of-date register is worse than none: it looks like control while hiding the gaps.

How often should the AI register be updated?

Continuously as things change, plus a scheduled review. New AI tools should be added before they go live, via an intake gate, rather than discovered later. On top of that, review the whole register on a regular cadence, quarterly is common, to catch tools that have changed use, grown in autonomy, or should be retired. Each entry should carry a last-reviewed date so stale ones are obvious.


Building something you need to govern?

Start with a fixed-scope AI Opportunity & Risk Audit.

Meet an Expert