An AI vendor inventory for every client,
always current.
“Which AI services has your staff used, and how are they controlled?” is now a standard question on audits, insurance renewals and vendor questionnaires. Answer it with a register that builds itself from your monthly assessments.
Add-on to the MSP plan · CSV export · history kept while you subscribe
The AI question now comes from four sides
Your clients get asked, and they pass the question to you.
Assessors
CMMC and HIPAA reviews look at how outside services are controlled. AI services are outside services.
Insurers
Renewal forms increasingly ask whether generative AI use is governed.
Big customers
Supplier security questionnaires now carry an AI section your client must answer.
Owners and boards
Leadership wants assurance the firm will not leak client data into a chatbot.
Three parts, one document per client
Updated by every assessment you run. Nobody maintains a spreadsheet.
Each AI vendor and its data terms
- Does it learn from user input, is there an opt-out, is there a private business tier
- Risk rating and where the vendor keeps data
- How it is handled: blocked, allowed with conditions, or approved
- When it was first and last seen
A dated record of changes
Every assessment adds an entry with the number of AI vendors and the ones that came and went. It shows the control is reviewed over time, not once.
Which requirement it supports
Mapped to CMMC Level 2 and NIST SP 800-171, the HIPAA Security Rule, the NIST AI Risk Management Framework, and the AI questions insurers ask.
Requirements the register supports
This is the cross-reference included in every register. It is supporting evidence; it does not on its own make a client compliant and is not legal advice.
CMMC Level 2 / NIST SP 800-171 Rev. 2
| Reference | Requirement | How the register helps |
|---|---|---|
| 3.1.20 | Verify and control/limit connections to and use of external systems | The register lists every external AI service in use and the control applied to each. |
| 3.13.1 | Monitor, control and protect communications at external boundaries | Disallowed AI services are blocked at the firewall / DNS boundary by the daily feed. |
| 3.13.6 | Deny network communications by default and allow by exception | Block-by-policy plus a per-client allowlist of sanctioned tools; exceptions are recorded in the register. |
| 3.11.1 | Periodically assess risk to operations, assets and individuals | Each audit rates every AI tool for risk, data sovereignty and data-training terms. |
| 3.3.1 | Create and retain system audit logs | Audits are produced from the client's DNS / firewall logs; the change log keeps the history. |
HIPAA Security Rule (45 CFR 164)
| Reference | Requirement | How the register helps |
|---|---|---|
| 164.308(a)(1)(ii)(A) | Risk analysis | Inventory of AI services that could receive ePHI, with each vendor's data-use terms. |
| 164.308(a)(1)(ii)(B) | Risk management | The control applied to each AI service (blocked, allowed with controls, sanctioned). |
| 164.308(a)(1)(ii)(D) | Information system activity review | Monthly review of AI traffic: new, removed and high-risk tools. |
| 164.308(b)(1) | Business associate contracts | Flags AI vendors used without enterprise or no-training terms, where a BAA is required before any ePHI is shared. |
NIST AI Risk Management Framework 1.0
| Reference | Requirement | How the register helps |
|---|---|---|
| GOVERN 1.6 | Mechanisms are in place to inventory AI systems | The register is the inventory of third-party AI tools in use. |
| GOVERN 6.1 | Policies address AI risks from third-party entities | A written sector policy gives a verdict and reason for every AI tool. |
| MAP 4.1 | Legal and technology risks of third-party components are mapped | Data-training terms, data sovereignty and risk flags per vendor. |
| MANAGE 3.1 | Third-party AI risks are monitored | Monthly audits and the change log show new and removed AI vendors. |
Cyber-insurance questionnaires
| Reference | Requirement | How the register helps |
|---|---|---|
| AI use policy | Do you have an acceptable-use policy for AI tools? | The applied sector policy with a verdict for every tool. |
| Generative AI controls | Do you restrict employee use of generative AI with company data? | Blocked and allowed-with-controls tools, with the enforcement point. |
| Shadow IT monitoring | Do you monitor use of unsanctioned cloud and AI services? | Monthly audit results and the change log. |
A register for a fictional law firm
Branded for a fictional IT provider. Scroll inside the frame, or open it on its own page.
Two clients preparing for an audit cover the register. Everyone after that is profit.
A typical fee per client to keep its AI vendor inventory audit-ready.
The add-on, for every client on your plan.
Left over with 8 compliance-driven clients.
Figures are illustrations. Your own client prices decide the margin.
One add-on for all your clients
Added to your MSP plan and charged with it.
AI Compliance Register
- Inventory of every AI vendor and its data terms
- Dated history of every change
- CMMC, HIPAA, NIST AI RMF and insurance cross-reference
- CSV export for auditors and GRC tools
- History kept for as long as you subscribe
MSP plan
- 10 full shadow AI assessments a month
- White-label PDF: your logo, colour and contact details
- Your own introduction and recommendations
- Branded upload links for your clients
- Each report labelled with the client name
- Unused credits roll over to the next month
- Cancel any time, no lock-in
Monthly AI Usage Report
- A report per client each month
- 15 extra assessment credits a month
- Changes since last month, flagged tools first
- Your branding and your recommendations
- Print-ready, saves as PDF
Usage report and compliance register together: $299/month. Full plan comparison on the pricing page.
About the compliance register
Preparing a client for a specific audit? Tell us which one.
Contact usWill this make my client compliant?
No single document does that. The register is evidence of one control, how third-party AI use is identified and handled, which the client’s assessor weighs with everything else.
How does it stay up to date?
Each assessment you run for the client updates it. Vendors keep their first-seen and last-seen dates, and the history records what was added or removed each time.
What happens to older assessments?
Assessment files expire after 90 days, but the register keeps its own copy of each result, so the history stays complete while you are subscribed.
Can I give it to an auditor as a file?
Yes. Each register exports as CSV, and the full document prints or saves as PDF with your branding.
Who decides whether a tool is blocked?
The sector policy you choose for the client, such as healthcare, legal or defense. Tools the client approved are recorded as approved.
Do I need the MSP plan?
Yes. The register is an add-on to the MSP plan and covers every client on it.
Have the answer ready before the auditor asks.
Email us from your MSP account address with the number of clients and the frameworks they face. We switch the add-on on within one business day and add it to your subscription.
Or write to [email protected].