Describe the system
Record the use case, owners, provider, model, lifecycle stage, users, and intended purpose.
Capture ownership, purpose, technology, data, decisions, risk, controls, incidents, review dates, and lifecycle status in a consistent record that teams can review and improve.
Create one structured record, check its completeness, then export it for review or consolidation into a broader register.
Record the use case, owners, provider, model, lifecycle stage, users, and intended purpose.
Capture data types, affected people, decisions, automation, oversight, controls, incidents, and geography.
Use the completeness score, action priorities, CSV, JSON, and print view to support governance follow-up.
Complete the fields below. Required fields support a dependable minimum record; optional fields improve traceability.
0% of tracked fields completed
The score measures whether essential inventory fields are populated. Section weights reflect practical governance importance: identity, ownership, technology, purpose, people and decisions, data, deployment, risk and controls, and lifecycle management.
Thresholds: 85–100 strong record; 70–84 operationally useful; 50–69 partially documented; below 50 early-stage record.
It does not establish legal compliance, model accuracy, fairness, security, safety, or business value. A complete but incorrect record can still score highly. Validate entries against contracts, architecture, testing evidence, logs, incident records, and accountable owners.
Use the output as a starting point for governance review, not as a substitute for risk assessment, impact assessment, legal advice, or technical assurance.
Include systems that generate, rank, predict, recommend, classify, optimize, or materially support decisions using machine learning, generative AI, statistical models, or rules combined with AI components. Apply your organisation’s approved definition where available.
Create separate records when models have different owners, purposes, data, decisions, risk profiles, providers, deployment contexts, or lifecycle stages. Closely related models may be grouped only when governance responsibilities and controls are genuinely shared.
Record the product, vendor, feature, model or service where known, contract owner, connected data, users, deployment geography, controls, and supplier dependencies. Do not omit embedded AI simply because the organisation did not build it.
Use your internal classification framework. Consider potential impact on people, rights, safety, finances, access to services, legal obligations, operational resilience, security, reputation, and the reversibility of outcomes.
Set a review cadence based on risk and change frequency. Review after material model updates, supplier changes, new data sources, significant incidents, scope expansion, regulatory change, or changes to automation and human oversight.
No. It creates an inventory record and completeness score. Higher-risk systems may require privacy, security, human-rights, safety, legal, model, or algorithmic impact assessments.
Document approval gates, access controls, testing, monitoring, logging, human review, fallback processes, incident response, supplier assurance, data quality checks, prompt or output restrictions, and periodic validation.
Record confirmed or suspected failures, harmful outputs, complaints, security events, privacy events, bias concerns, outages, overrides, control breaches, and near misses. Link to formal incident records where your process permits.
It shows how much of the minimum record has been populated using fixed section weights. It does not rate system quality, compliance, safety, or effectiveness.
Yes. With JavaScript enabled, records can be added to browser-local storage, searched, filtered, imported from CSV, and exported. Those local records remain on the current browser unless cleared.
The page does not call an external API. Browser exports and local inventory features run locally. Standard form submission is processed by the deployed PHP page for validation and non-JavaScript results.
Address decommissioning approval, replacement services, supplier exit, data export and deletion, retention obligations, user communications, model access removal, integration shutdown, audit evidence, and residual monitoring.