Free practical resource

Free AI System Inventory Template

Build one reliable register of the AI your organisation actually uses. This free Excel starter helps you document AI tools, embedded AI features, APIs, internally developed systems and agents — together with ownership, data, decision role, oversight, risk, evidence and review dates.

No email gate · Editable Excel workbook · 3 fictional examples · Dropdowns + automatic review status · Published by Evidelis / Ingenii OÜ

AI governance starts with visibility

Policies and risk assessments are difficult to operate if nobody can answer a basic question: which AI systems and AI-enabled tools are actually in use? A practical AI inventory gives management one place to see the system, purpose, owner, provider, data, decision role, oversight, governance status and next review date.

Know what exists

✓ Include standalone tools, embedded features, APIs, agents and internal systems.

✓ Record purpose rather than only the product name.

Know who owns it

✓ Assign a business owner for every material AI use.

✓ Capture primary users and people who may be affected.

Know what happens next

✓ Record risk, approval status, evidence and review dates.

✓ Revisit the record after material changes.

What to include in an AI system inventory

The Evidelis starter uses twenty practical fields. The goal is not to collect everything — it is to capture the facts needed to make and revisit governance decisions.

Field groupWhat to recordWhy it matters
Identity & purposeSystem ID, AI system/tool, system type, business purposeDistinguishes a specific governed use from a vague product list.
OwnershipBusiness owner, provider/vendor, primary users, affected people/groupsMakes accountability and stakeholder impact visible.
Data & capabilityData categories, AI capability/modelHelps route privacy, security, procurement and technical review.
Decision & oversightDecision role, human oversightShows how much authority the AI has and where human review sits.
Governance decisionRisk tier, governance status, approval/decision dateCreates a reviewable record of the current decision.
Evidence & lifecycleLast review, next review, automatic review status, evidence/links, notesKeeps the inventory live instead of becoming a one-off spreadsheet.

How to build the inventory without turning it into a six-month project

1 · Start with known tools
List the AI products, copilots, models, APIs and automations already approved or purchased.
2 · Look for embedded and shadow AI
Ask teams which AI features they actually use inside existing SaaS products, browser tools and workflows.
3 · Separate tools from use cases
The same tool can support very different activities. Record enough purpose detail to understand the governed use.
4 · Prioritise higher-impact uses
Flag uses that affect people, material decisions, sensitive information, customer commitments or business-critical outputs.
5 · Link evidence
Keep vendor reviews, approvals, risk assessments and specialist advice in their source locations and link them from the inventory.
6 · Set the next review date
Review after material change and on a defined cadence. The starter automatically flags due-soon and overdue records.
Do not confuse an internal risk tier with a legal classification. The inventory helps route governance work. Legal, privacy, security and sector-specific classification should be performed where applicable by the appropriate specialist process.

Five discovery prompts for finding AI you do not already know about

Team workflows

Which tools draft, summarise, classify, transcribe, score, recommend, generate or automate work?

Existing SaaS

Which products have added AI features that users can switch on without a separate procurement event?

Customer-facing processes

Where does AI influence content, service, decisions, recommendations or communications seen by customers?

People decisions

Where does AI influence recruitment, performance, scheduling, access, eligibility or other decisions affecting individuals?

Data movement

Where are employees putting internal, confidential, personal or customer data into AI-enabled tools?

Agents & automation

Which workflows allow AI to take actions, call tools, update records or trigger downstream processes?

Common AI inventory mistakes

Only listing purchased AI products

AI often arrives as an embedded feature inside software the organisation already uses.

Tracking a vendor but not the use

A product name alone does not explain purpose, decision impact, data, owner or controls.

No review date

Providers, models, terms, data flows and business purposes change. An inventory without review triggers becomes stale quickly.

Inventory is the visibility layer. Governance needs the decision layer too.

The free starter gives you a practical AI register. Evidelis AI Governance connects that inventory to acceptable-use rules, tool approval, use-case risk assessment, vendor review, human oversight, regulatory screening, incidents, literacy evidence and quarterly management review.

Get the complete AI Governance toolkit — €129 one-time

Editable Word + Excel · Single Organisation License · Secure Stripe checkout · instant digital delivery after consent · no subscription.

See full product details →

Related free resources

AI Risk Assessment Template

Turn one AI use case into a documented risk and approval decision.

Get the Excel template →

AI Acceptable Use Policy

Give employees practical rules for approved tools, data, outputs, agents and incidents.

Get the Word template →

AI Governance Framework

See how ownership, inventory, approvals, risk, oversight and evidence fit together.

Read the framework guide →

Frequently asked questions

What should an AI system inventory include?

A useful AI inventory should identify the system or tool, business purpose, accountable owner, provider, users, affected groups, data categories, AI capability, decision role, human oversight, risk tier, governance status, evidence and review dates.

Should embedded AI features and AI agents be included?

Yes. Include material AI-enabled features inside wider software, third-party AI services, APIs, internally developed AI and agents or automations that materially rely on AI outputs.

Should every experimental AI tool be included?

Use a proportionate scope, but do not exclude pilots simply because they are temporary. If an experiment uses organisational data, affects a material process, interacts with customers, makes or supports decisions, or creates meaningful risk, it belongs in the governance inventory.

Is an AI inventory the same as a risk assessment?

No. The inventory tells you what exists and its current governance status. A risk assessment examines a particular use case in more depth, including risks, controls, evidence, residual risk and approval decision.

Does this template make an organisation compliant?

No. It is an internal governance aid, not legal advice, certification or a legal AI-system classification. Use specialist legal, privacy, security and sector processes where applicable.