MSP plan add-on · audit-ready

An AI vendor inventory for every client,
always current.

“Which AI services has your staff used, and how are they controlled?” is now a standard question on audits, insurance renewals and vendor questionnaires. Answer it with a register that builds itself from your monthly assessments.

Add-on to the MSP plan · CSV export · history kept while you subscribe

Who asks

The AI question now comes from four sides

Your clients get asked, and they pass the question to you.

Assessors

CMMC and HIPAA reviews look at how outside services are controlled. AI services are outside services.

Insurers

Renewal forms increasingly ask whether generative AI use is governed.

Big customers

Supplier security questionnaires now carry an AI section your client must answer.

Owners and boards

Leadership wants assurance the firm will not leak client data into a chatbot.

What you hand over

Three parts, one document per client

Updated by every assessment you run. Nobody maintains a spreadsheet.

Part 1 · Inventory

Each AI vendor and its data terms

  • Does it learn from user input, is there an opt-out, is there a private business tier
  • Risk rating and where the vendor keeps data
  • How it is handled: blocked, allowed with conditions, or approved
  • When it was first and last seen
Part 2 · History

A dated record of changes

Every assessment adds an entry with the number of AI vendors and the ones that came and went. It shows the control is reviewed over time, not once.

Part 3 · Cross-reference

Which requirement it supports

Mapped to CMMC Level 2 and NIST SP 800-171, the HIPAA Security Rule, the NIST AI Risk Management Framework, and the AI questions insurers ask.

Coverage

Requirements the register supports

This is the cross-reference included in every register. It is supporting evidence; it does not on its own make a client compliant and is not legal advice.

CMMC Level 2 / NIST SP 800-171 Rev. 2

ReferenceRequirementHow the register helps
3.1.20Verify and control/limit connections to and use of external systemsThe register lists every external AI service in use and the control applied to each.
3.13.1Monitor, control and protect communications at external boundariesDisallowed AI services are blocked at the firewall / DNS boundary by the daily feed.
3.13.6Deny network communications by default and allow by exceptionBlock-by-policy plus a per-client allowlist of sanctioned tools; exceptions are recorded in the register.
3.11.1Periodically assess risk to operations, assets and individualsEach audit rates every AI tool for risk, data sovereignty and data-training terms.
3.3.1Create and retain system audit logsAudits are produced from the client's DNS / firewall logs; the change log keeps the history.

HIPAA Security Rule (45 CFR 164)

ReferenceRequirementHow the register helps
164.308(a)(1)(ii)(A)Risk analysisInventory of AI services that could receive ePHI, with each vendor's data-use terms.
164.308(a)(1)(ii)(B)Risk managementThe control applied to each AI service (blocked, allowed with controls, sanctioned).
164.308(a)(1)(ii)(D)Information system activity reviewMonthly review of AI traffic: new, removed and high-risk tools.
164.308(b)(1)Business associate contractsFlags AI vendors used without enterprise or no-training terms, where a BAA is required before any ePHI is shared.

NIST AI Risk Management Framework 1.0

ReferenceRequirementHow the register helps
GOVERN 1.6Mechanisms are in place to inventory AI systemsThe register is the inventory of third-party AI tools in use.
GOVERN 6.1Policies address AI risks from third-party entitiesA written sector policy gives a verdict and reason for every AI tool.
MAP 4.1Legal and technology risks of third-party components are mappedData-training terms, data sovereignty and risk flags per vendor.
MANAGE 3.1Third-party AI risks are monitoredMonthly audits and the change log show new and removed AI vendors.

Cyber-insurance questionnaires

ReferenceRequirementHow the register helps
AI use policyDo you have an acceptable-use policy for AI tools?The applied sector policy with a verdict for every tool.
Generative AI controlsDo you restrict employee use of generative AI with company data?Blocked and allowed-with-controls tools, with the enforcement point.
Shadow IT monitoringDo you monitor use of unsanctioned cloud and AI services?Monthly audit results and the change log.
Example

A register for a fictional law firm

Branded for a fictional IT provider. Scroll inside the frame, or open it on its own page.

it-services.example.com / AI compliance register / Example Law LLP
The numbers

Two clients preparing for an audit cover the register. Everyone after that is profit.

You invoice
$150/mo

A typical fee per client to keep its AI vendor inventory audit-ready.

You pay us
$199/mo

The add-on, for every client on your plan.

You keep
$1,001/mo

Left over with 8 compliance-driven clients.

Figures are illustrations. Your own client prices decide the margin.

Pricing

One add-on for all your clients

Added to your MSP plan and charged with it.

This add-on

AI Compliance Register

An AI vendor inventory with history for each client, cross-referenced to common frameworks.
$199/mo
for every client on your MSP plan
  • Inventory of every AI vendor and its data terms
  • Dated history of every change
  • CMMC, HIPAA, NIST AI RMF and insurance cross-reference
  • CSV export for auditors and GRC tools
  • History kept for as long as you subscribe
Request this add-on
Added to your MSP subscription
Add-on

Monthly AI Usage Report

A one-page AI usage report for each client, every month, under your brand.
$149/mo
for every client on your MSP plan
  • A report per client each month
  • 15 extra assessment credits a month
  • Changes since last month, flagged tools first
  • Your branding and your recommendations
  • Print-ready, saves as PDF
About the usage report
Added to your MSP subscription

Usage report and compliance register together: $299/month. Full plan comparison on the pricing page.

Questions

About the compliance register

Preparing a client for a specific audit? Tell us which one.

Contact us
Will this make my client compliant?

No single document does that. The register is evidence of one control, how third-party AI use is identified and handled, which the client’s assessor weighs with everything else.

How does it stay up to date?

Each assessment you run for the client updates it. Vendors keep their first-seen and last-seen dates, and the history records what was added or removed each time.

What happens to older assessments?

Assessment files expire after 90 days, but the register keeps its own copy of each result, so the history stays complete while you are subscribed.

Can I give it to an auditor as a file?

Yes. Each register exports as CSV, and the full document prints or saves as PDF with your branding.

Who decides whether a tool is blocked?

The sector policy you choose for the client, such as healthcare, legal or defense. Tools the client approved are recorded as approved.

Do I need the MSP plan?

Yes. The register is an add-on to the MSP plan and covers every client on it.

Add it to your plan

Have the answer ready before the auditor asks.

Email us from your MSP account address with the number of clients and the frameworks they face. We switch the add-on on within one business day and add it to your subscription.

Or write to [email protected].