What is an AI model inventory?
An AI model inventory is a governed register of AI and machine-learning model artifacts used, developed, acquired or depended on by an organisation. It records model identity, version, purpose, ownership, source, deployment context, dependencies, risk information, lifecycle status and links to supporting evidence so models can be discovered, reviewed and governed consistently.
How is an AI model inventory different from an AI system inventory?
A model inventory focuses on model artifacts and versions. An AI system inventory focuses on complete AI-enabled applications, products, workflows and business uses, which can contain one or more models plus data, interfaces, rules, human processes and other components. The two inventories should connect rather than duplicate each other.
Which models should be included?
Scope is agreed during discovery and can include internally trained machine-learning models, fine-tuned models, open-source models, foundation models accessed through APIs, third-party models embedded in products, forecasting or optimisation models, and generative AI models that materially support business processes. Experimental assets can be included using a lighter lifecycle status when appropriate.
Does the inventory include third-party and vendor models?
Yes, when they are in scope. The record can capture provider, product, model or model-family information available to the organisation, business use, owner, contractual or data dependencies, known version information, risk context, documentation links and the limits of what can be independently verified.
What information is normally captured for each model?
Typical fields include a unique identifier, model name and version, purpose, business use, owners, provider or development team, artifact or endpoint location, data context, deployment environments, dependent systems, affected users, risk tier, evaluations, approvals, monitoring status, incidents, exceptions, review dates and lifecycle status. The exact data dictionary should match governance needs rather than collecting fields with no decision value.
Can DataConsultant discover models automatically?
Automation can support discovery where accessible model registries, MLOps platforms, cloud inventories, repositories, APIs or configuration sources expose reliable metadata. It is rarely sufficient on its own. Interviews, procurement records, application inventories, vendor reviews and business validation are often needed to find shadow, embedded or poorly documented models.
How do you handle duplicate, stale or orphaned model records?
The engagement can define canonical identifiers and reconciliation rules, compare records across technical and business sources, flag likely duplicates, validate lifecycle status with accountable owners and record unresolved items as exceptions. Records without a confirmed owner or current use should not be silently treated as active and governed.
Does an AI model inventory make us compliant with the EU AI Act or ISO/IEC 42001?
No. An inventory can support governance, documentation, accountability and evidence readiness, but it does not by itself establish compliance, conformity or certification. Applicability depends on the organisation, its role, the AI system, jurisdiction and other facts. Legal or certification conclusions should be obtained from appropriately qualified specialists.
How does NIST AI RMF relate to inventory work?
NIST AI RMF 1.0 includes an explicit Govern outcome calling for mechanisms to inventory AI systems according to organisational risk priorities. A model inventory can contribute model-level evidence to that broader governance capability and can link records to mapping, measurement and management activities.
How is the inventory kept current after the initial project?
The operating model should define event-driven update triggers and periodic reviews. Common triggers include a new model, material version change, new business use, provider change, deployment to production, risk reclassification, incident, exception, ownership change or retirement. Tool integration can be added where it improves reliability without obscuring accountability.
What do you need from us to begin?
Useful inputs include known model or AI lists, cloud and MLOps inventories, source repositories, application and vendor inventories, procurement information, architecture diagrams, policies, risk registers, model documentation, deployment records and access to business, AI, data, security, risk, legal, procurement and platform stakeholders.
How long does an AI model inventory engagement take?
Timeline is confirmed after scoping. It depends on the number of business units and platforms, model volume, quality of existing records, access to repositories and registries, third-party dependencies, stakeholder availability, evidence quality and whether operating-model design, tooling integration or remediation is included.
How is AI model inventory consulting priced?
DataConsultant uses scope-led pricing for this service rather than publishing an unverified fixed fee. A quote can be prepared after the number of model sources, expected inventory scale, business units, discovery depth, risk fields, workshops, tooling integrations, documentation requirements and implementation support are understood.
Can the inventory connect to our existing GRC, CMDB, catalog or MLOps tools?
Yes, where the available APIs, exports, identifiers and governance model support it. The design can define which system should be authoritative for each field, how records are reconciled, what should be synchronised, and which decisions still require human validation.