Microsoft Teams

What a Good AI System Inventory Looks Like

Every ISO 42001 audit starts in the same place: show me every AI system in scope. Not the ones you remember building — every one, including the third-party tools someone signed up for with a company email and never told IT about. A weak inventory is the single most common reason an AIMS falls over at the first surveillance audit.

  • Risk-tiered
  • Owner assigned per system
  • Discoverable, not just declared
  • Living, not a one-off spreadsheet
Book a Scoping Call Back to resources

What actually belongs in the inventory

Most first-draft inventories only list the AI features a product team deliberately built. That's the easy half. The harder — and more audit-relevant — half is everything that arrived sideways: a SaaS vendor who quietly added an AI feature to a tool you already pay for, or an employee who connected an AI app to their Microsoft 365 account using OAuth, with nobody in security ever approving it.

Built AI

Features and models your own team developed or fine-tuned — the ones everyone already knows about.

Embedded AI

Third-party AI capability inside tools you already use — a vendor's own AI feature, not something you chose separately.

Shadow AI

AI apps connected via OAuth consent by individual staff, discoverable from Entra enterprise app consents — never formally approved, but live and touching your data anyway.

Inventory fields that actually work

A spreadsheet with just a system name and an owner isn't an AI inventory an auditor will accept — ISO 42001 expects enough detail to assess risk from the entry itself, without opening a separate document.

System name & purpose

What it is and what business decision or output it affects — plain language, not a vendor's marketing description.

Data touched

What categories of data the system processes — personal, health, financial, confidential — the same classification your privacy programme already uses.

Risk tier

A documented rating (e.g. minimal / limited / high), not a gut feeling — and the reasoning behind it, since that's what an assessor actually checks.

Human oversight point

Where and how a human reviews or can override the system's output before it reaches a customer or informs a decision about them.

Owner & review date

A named accountable person, not a team distribution list, and a date it was last confirmed still accurate.

Cross-mapped evidence

Which Annex A controls and — where relevant — EU AI Act risk tier this entry evidences, so one inventory update updates every framework it touches.

Where inventories fall over

Declared, not discovered

Relying on teams to self-report what AI they're using guarantees an incomplete list. Shadow AI — tools connected via personal OAuth consent — needs to be found, not waited for.

Built once, never revisited

An inventory frozen at go-live stops being evidence the moment a new model version ships or a vendor changes their AI feature. It needs a review cadence, not a launch date.

No risk reasoning, just a label

"High risk" written next to a system with no explanation of why reads as a guess to an auditor. The reasoning is the evidence — the label alone isn't.

Related

ISO 42001 Full AI governance certification ISO 42001 vs NIST AI RMF vs EU AI Act How the frameworks map together Free AI Governance Checklist Score your readiness in 12 minutes

Not sure what AI is actually running in your tenant?

Checkpoint's discovery reads Entra enterprise app consents to surface candidate AI systems you didn't manually add.

Book a Scoping Call

Free monthly digest

Get the monthly Australian compliance digest

Practical updates on ISO 27001, Essential Eight, Privacy Act and AI governance — delivered once a month. No spam, unsubscribe any time.

No spam. Unsubscribe any time. We never share your email.