A credible AI inventory example is not a list of software licences. It is a defensible record of how an AI system is used, who is accountable for it, what risks it creates, and which evidence supports the organisation’s compliance position. If a regulator, auditor or board member asks whether a recruitment tool is properly governed, a spreadsheet containing only the supplier name and contract renewal date will not answer the question.
For compliance teams, the inventory is the operational starting point for the EU AI Act and ISO/IEC 42001. It turns scattered procurement records, DPIAs, technical documents and policy statements into a system of record that can be assessed, monitored and evidenced.
Why an AI inventory must go beyond an application register
Many organisations begin with a discovery exercise: identify every tool that contains, uses or produces AI. That is necessary, but it is only the first layer. A usable inventory must distinguish between a general-purpose AI model, an AI-enabled business application, an internally developed system and a conventional automated rule. Each has different owners, supplier dependencies and legal obligations.
It must also record the organisation’s role. Under the EU AI Act, obligations differ materially between providers, deployers, importers, distributors and authorised representatives. A UK or European employer using a third-party candidate-screening product will commonly be a deployer. That does not remove its responsibilities. It changes the evidence it needs to obtain, maintain and act upon.
The difference matters because classification is not a label applied once at procurement. It is a documented decision that must be revisited when the intended purpose, data sources, deployment context or supplier model changes. An inventory that cannot show the decision trail is difficult to defend.
AI inventory example: candidate screening system
Consider a mid-sized employer using a supplier-hosted tool to rank applicants for operational and professional roles. The system extracts information from CVs, compares candidates against role criteria, produces a ranking and presents a recruiter with reasons for the score. Recruiters make the final shortlist decision.
The following is the level of record a governance team should expect to maintain.
| Inventory field | Example record | | — | — | | System name | TalentRank Candidate Screening | | Business purpose | Supports recruiter review by ranking applicants against approved job criteria | | Business owner | Director of People Operations | | Technical owner | Head of HR Technology | | AI governance owner | Data Protection Officer, with Compliance oversight | | Supplier and hosting | Third-party SaaS provider; EU-hosted production environment | | Organisation’s role | Deployer of a third-party AI system | | Users affected | Job applicants and internal recruiters | | Inputs | CVs, application forms, role descriptions and recruiter-selected criteria | | Outputs | Candidate relevance score, ranking, stated scoring factors and exception flags | | Decision consequence | Influences access to interview; recruiter retains authority for final decision | | EU AI Act preliminary classification | Potential high-risk system: employment, workers management and access to self-employment use case requiring legal assessment | | Data protection status | DPIA required or reviewed; special-category data minimised and restricted | | Review cycle | Quarterly monitoring, plus review before material change |
This entry gives senior stakeholders a concise operational picture. It is not yet sufficient evidence of compliance. The record needs linked assessments, controls and artefacts that demonstrate the organisation has governed the risk rather than merely described it.
Classification should show reasoning, not just a result
For this use case, the assessment should examine whether the system falls within the employment-related high-risk category in Annex III of the EU AI Act. Candidate recruitment and selection are particularly sensitive because an AI-assisted ranking can materially affect an individual’s access to work.
The governance record should state the intended purpose supplied by the vendor, the organisation’s actual use, who can override a recommendation and whether the output is used to exclude applicants automatically. It should also record the jurisdictional scope. A UK-only deployment may not be directly subject to all EU AI Act obligations, but an organisation recruiting EU-based candidates or operating through an EU establishment should not rely on a simplistic geographic assumption.
A preliminary classification can be marked as pending legal validation. What matters is that the basis, owner, date and required follow-up are visible. A red, amber or green status without underlying rationale is board-friendly but audit-poor.
The evidence linked to the record
For a high-risk or potentially high-risk deployment, the inventory entry should connect to a proportionate evidence pack. The precise documentation depends on the organisation’s role, contract terms and system capability. A deployer cannot create the provider’s technical documentation, but it can require relevant information, retain it and test whether the system can be used lawfully and safely.
The candidate-screening record should therefore link to the supplier’s instructions for use, conformity and registration information where applicable, contractual commitments, security documentation, model or system change notices, DPIA, procurement assessment and internal approval record. It should also link to the operational controls applied by the employer.
Those controls may include documented human oversight instructions, approved role criteria, recruiter training, a process for challenging or overriding scores, access controls, retention rules and periodic fairness testing. If the supplier cannot explain which factors influence ranking, cannot provide meaningful change notification, or prohibits appropriate assurance activity, that is not simply a procurement inconvenience. It is a governance finding requiring escalation.
The EU AI Act’s deployer obligations are particularly relevant here. Article 26 requires deployers of high-risk AI systems to take appropriate technical and organisational measures, use systems in accordance with instructions, assign human oversight to competent individuals and monitor operation. The inventory should translate these broad duties into named actions, due dates and retained evidence.
A practical entry might show that the Head of Talent Acquisition owns recruiter training, the DPO owns the DPIA review, HR Technology owns supplier change monitoring, and Compliance owns the legal classification decision. Shared accountability is common. Unnamed accountability is not.
Connect the inventory to risk management and ISO/IEC 42001
An inventory is valuable when it drives work. For the recruitment example, the risk assessment should address foreseeable harms such as discriminatory ranking, inappropriate use of protected characteristics, automation bias, insufficient explanation to candidates, data leakage and degradation after a supplier model update.
Each risk requires a treatment decision. For example, automation bias may be reduced through mandatory human review, recruiter training and a system design that prevents automatic rejection based solely on the score. Discrimination risk may require pre-deployment testing, regular outcome analysis, a documented escalation threshold and supplier commitments to support investigation.
ISO/IEC 42001 provides the management-system discipline around this activity. The organisation should establish governance objectives, define roles, assess AI risks, implement controls, monitor performance, conduct internal audits and review outcomes at management level. The inventory provides traceability across those activities: from the AI system, to its risk assessment, to controls, to monitoring results and corrective actions.
Do not treat an ISO/IEC 42001 programme as a separate documentation exercise. If the inventory has one status, the risk register another, and the board pack a third, the organisation has created reconciliation work instead of assurance. A single governed record should feed all three.
Monitor changes that invalidate the original assessment
The most common inventory failure is staleness. The original assessment may have been sound, but the system has changed: the supplier replaces a model, adds video analysis, expands data retention, introduces a generative AI feature or makes scoring more autonomous. Any of these changes can alter the risk profile and legal assessment.
For the candidate-screening system, define material-change triggers in advance. Examples include a new data category, a new source of training or operational data, changed ranking logic, expansion into another country, removal of recruiter review, a security incident, or a statistically significant shift in hiring outcomes. Each trigger should generate a review task, not an informal email thread.
Monitoring also needs measurable indicators. The organisation might track override rates, adverse-impact signals, complaints, supplier incidents, overdue training, missing attestations and the age of risk assessments. Metrics are useful only if a threshold leads to an accountable response. Reporting that shows a concern without a corrective-action owner is reporting theatre.
Build the record for an audit, not a demonstration
An auditor will typically ask straightforward questions: what systems are in scope, why is each classification justified, who approved deployment, what evidence was reviewed, which controls operate, and how does the organisation know they remain effective? The inventory should allow each answer to be retrieved without reconstructing the story from inboxes and disconnected folders.
This is where purpose-built governance software has an advantage over a spreadsheet. A platform such as Endaxi AIG can maintain the inventory alongside classification workflows, risk treatments, evidence, control ownership and regulatory reporting. The objective is not to buy a larger toolset. It is to remove the gap between a compliance decision and the proof that the decision has been implemented.
Start with the systems that influence people, safety, access to essential services, financial outcomes or security decisions. A complete inventory will take time, but a credible first record for each priority system gives the organisation something more useful than an ambition statement: a clear line of accountability, evidence and action.

