policies & oversight
risk assessment
measurement
INVENTORY
Compliance / Governance inventory

Every AI governance framework stands on the inventory

Pick any framework for managing AI risk: they all begin the same way, with knowing what AI is in use, by whom, for what. Skip that layer and everything above it is architecture on sand. This page is about pouring the foundation, and keeping it poured.

Start the inventory free
The universal step one

Why frameworks converge on "know your AI"

Risk-management frameworks, phrased generically, all route through the same early gates. Each gate consumes the inventory.

Mapping the context

Frameworks ask organizations to map where AI touches their operations and stakeholders. A map of systems nobody listed is not a map; the inventory supplies the territory.

Measuring the risk

Measurement needs units: which system, which data, which users. The audit's per-tool rows, with risk flags and dated training verdicts, are those units pre-assembled.

Managing and governing

Policies, review boards and approval gates act on known systems. Shadow AI is precisely the set your governance cannot act on, which makes shrinking it the first governance KPI.

The framing to steal for your board deck: the inventory is not a compliance chore inside the framework, it is the substrate the framework runs on. Everything else is a function of its completeness.

Static vs living

The binder inventory vs the living inventory

Most organizations have attempted an AI inventory once. The failure mode is always the same: it was a project, not a process.

The binder version

  • Built by interview and spreadsheet over six weeks, complete for roughly a day.
  • Misses embedded features and everything adopted after the last interview.
  • Update mechanism: someone remembers to ask again, eventually.
  • Governance value decays monthly; audit value decays faster.

The living version

  • Regenerated quarterly from network logs against a register maintained daily, 20,399 classified domains at present.
  • Catches new tools, new subdomains and changed vendor verdicts as deltas between runs.
  • Update mechanism: the calendar. No memory required.
  • Each run is also evidence: dated, repeatable, fileable.

The living inventory costs a morning per quarter. The binder cost six weeks and was wrong by month two. This is the rare governance upgrade that is also a cost cut.

Anatomy

What a governance-grade inventory records

Per system, the fields governance actually consumes, and where the audit supplies them.

FieldGovernance useSource in the audit
System identityThe unit every decision attaches toTool domain plus category and subcategory
Who uses itScoping for training, oversight and accountabilityPer-user or per-device breakdown
Usage intensitySeparates pilots from dependenciesHits and user counts per period
Data postureFeeds risk assessment and privacy analysisTraining verdict with check date, sovereignty flag
Approval stateThe governance status itselfSanctioned split against your approved list
Red flagsEscalation triggersRisk level and abusive-purpose flags
Change since last periodThe living partDeltas between quarterly reports

The inventory's own data footprint stays small: hostnames, identities, timestamps. Uploads are discarded after each run; reports are deletable before their 90-day expiry.

The cadence

A year of quarterly inventory, in practice

What each quarter's run contributes once the loop is standing.

Q1

Baseline and triage

First full report; abusive flags blocked, top tools gated for sanctioning, owners assigned per category.

Q2

Policy takes effect

Sanctioned list published; the split becomes the adoption metric. Deltas show whether governance changed behavior.

Q3

Drift management

Changed vendor verdicts between runs feed renewal decisions; new tools get gated within the quarter they appear.

Q4

The annual story

Four PDFs tell the board a measured narrative: exposure found, decisions made, trend bending the right way.

Ownership

Who owns the inventory, and what each role does

The loop survives when three roles each hold one piece. It dies when all three assume another has it.

Security or IT: the runner

Owns the export and the upload, quarterly, same window. Twenty minutes of mechanics per run, documented in the runbook once. The walkthrough is the runbook's first draft.

Compliance or the CISO: the reader

Owns the triage, the decision minutes and the filing. Presents the delta slide wherever governance reports; the compliance officer page details the evidence chain.

The business: the decider

Department owners answer for their category's tools: keep and contract, or drop. Governance that skips this role produces lists nobody follows.

The foundation document, rendered

The sample report is a governance inventory in finished form: systems, users, postures, flags, dated. Read it before your next framework workshop.

Open the sample report
Anti-patterns

Three ways governance inventories go wrong

Inventorying only the approved

A register of sanctioned tools is a shopping list, not an inventory. The governance object is the gap between approved and observed, which only measurement reveals.

Perfection before publication

Teams delay the inventory until it can be complete, which is never. Publish the observed list with its stated scope; completeness grows by cadence, not by waiting.

Inventory without consequence

If findings never change a contract, a block rule or a policy line, the loop decays into reporting theater. Every run should close with at least one decision minuted.

The consequence engine is the sequence on detect before you block: inventory, sanction, block, verify. Governance is that loop with minutes attached.

FAQ

Governance inventory questions

Is a quarterly inventory enough for AI governance?

It is the workable floor. The register behind each run updates daily, so quarterly snapshots inherit current classifications; high-churn organizations step up to monthly.

Which framework does this support?

Any of them, phrased generically: mapping, measuring and managing all consume the same inventory substrate. The audit is framework-agnostic evidence.

Do we need new tooling to maintain it?

No. Exports from your existing DNS filter, proxy or firewall plus the audit cover the loop. The per-source mechanics live in the guides.

How does the inventory handle brand-new tools?

Roughly 300,000 domains are screened daily, so new tools enter the register continuously. The unmatched-domain count in each report keeps the residual visible.

What goes to the board from all this?

Four numbers per quarter: tools found, high-risk count, sanctioned share, delta versus last quarter. One slide, dated PDFs behind it.

What does the standing loop cost?

A morning per quarter plus report pricing: $99 single, packs at $66 and $60, or plan allowances for monthly cadence. Details on pricing.

Pour the foundation this quarter

Whatever framework your organization lands on, it will ask for the inventory first. Have it waiting.

Run the free audit