ZYNAGI Governance Foundation
AI Inventory for Governance, Risk, and Compliance
An AI inventory is the foundation of governance. You cannot govern AI systems you cannot enumerate — and most organizations cannot enumerate the AI systems they are running.
Build Your AI InventoryTL;DR — Key Takeaways
- An AI inventory is the foundational component of AI governance — without it, governance, risk assessment, and compliance monitoring cannot function.
- Hidden AI use creates risk: shadow AI tools access sensitive data without oversight, vendor compliance is unassessed, and executive visibility is absent.
- Inventory fields include tool name, department, owner, use case, data type, vendor, BAA and SOC 2 status, approval status, renewal date, and risk score.
- Healthcare and financial services organizations face specific inventory requirements due to PHI, fiduciary obligations, and regulatory compliance demands.
- Organizations without AI inventories typically discover AI tools through incidents rather than through systematic review — a reactive posture that compounds risk.
Executive Summary
AI governance begins with a single, deceptively simple question: What AI tools is your organization using? For most organizations, the answer is incomplete. Clinical documentation tools, patient communication platforms, CRM systems with embedded AI, scheduling automation, revenue cycle tools, marketing platforms, and employee-adopted general-purpose AI tools are deployed across departments — often without central visibility.
An AI inventory is the structured record that answers this question. It documents every AI tool deployed across the organization, capturing the information required to assess risk, evaluate vendor compliance, monitor usage, and provide executive oversight. It is not an IT asset management function — it is a governance control.
Organizations that maintain AI inventories can govern. Organizations that do not maintain inventories discover AI exposure through incidents: a vendor data breach revealing unassessed tools, a compliance audit finding AI systems without BAAs, or a board inquiry about AI usage that leadership cannot answer.
What Is an AI Inventory?
An AI inventory is a current, accurate, and comprehensive record of every AI tool deployed across an organization. It captures not just the tool name, but the contextual information required for governance: who owns it, what data it accesses, who the vendor is, what compliance obligations apply, and what governance status the tool holds.
Governance Principle
An AI system that is not in the inventory is an AI system that is not governed. The inventory is not a tracking exercise — it is the foundational governance control that makes risk assessment, vendor management, compliance monitoring, and executive reporting possible.
Unlike traditional software inventories, an AI inventory must capture information specific to AI risk: data sensitivity, vendor AI capabilities, model training practices, human oversight requirements, and governance approval status. These fields provide the context required to evaluate whether an AI tool is being used safely and compliantly.
Why Hidden AI Use Creates Risk
AI tools are adopted through multiple pathways — many of which bypass formal IT, compliance, or executive review. Individual departments adopt AI-enabled software for specific operational needs. Employees use general-purpose AI tools like ChatGPT, Claude, or Copilot for work tasks. Vendors embed AI capabilities into existing software without notification. Acquired organizations bring their own AI ecosystems.
This creates shadow AI — AI tools that the organization is using but has never formally assessed, authorized, or documented. Shadow AI creates compounding risk:
Data Exposure
Shadow AI tools may access PHI, financial data, or confidential information without BAA coverage or data protection review.
Vendor Risk
Unassessed vendors may have inadequate security controls, problematic data retention practices, or undocumented sub-processors.
Compliance Risk
AI tools operating without compliance review may violate HIPAA, SEC regulations, state privacy law, or professional responsibility rules.
Operational Risk
AI tools that the organization cannot enumerate cannot be monitored for reliability, accuracy, or failure — creating operational dependencies without oversight.
The risk created by shadow AI is not theoretical — it is the risk that organizations discover through incidents. A vendor breach that exposes data processed by an AI tool the organization did not know it was using. A compliance audit that finds AI systems without BAAs. A board member asking what AI the organization uses and leadership having no answer.
AI Inventory Fields
A comprehensive AI inventory captures the following fields for every AI tool deployed across the organization. These fields provide the information required for governance, risk assessment, and compliance monitoring.
Tool Name
The specific name and version of the AI tool or AI-enabled software.
Example: Dragon Medical One, ChatGPT Enterprise, Salesforce Einstein
Department
The department or functional area where the AI tool is deployed.
Example: Clinical Operations, Revenue Cycle, Marketing, IT
Owner
The individual responsible for the AI tool within the organization.
Example: Director of Clinical Informatics, VP of Operations
Use Case
The specific operational purpose for which the AI tool is used.
Example: Clinical documentation, patient communication, lead scoring
Data Type
The categories of data the AI tool accesses, processes, or transmits.
Example: PHI, PII, financial data, confidential business information
Vendor
The third-party vendor providing the AI tool or service.
Example: Microsoft, Nuance, OpenAI, Salesforce
BAA Status
Whether a Business Associate Agreement is in place (required for PHI access).
Example: BAA executed, BAA pending, not applicable
SOC 2 / Security
The security certification and compliance posture of the vendor.
Example: SOC 2 Type II, ISO 27001, not certified
Approval Status
The governance approval status of the AI tool.
Example: Approved, Pending Review, Prohibited, Shadow AI
Renewal Date
The contract renewal or license expiration date for the AI tool.
Example: 2026-12-31, Month-to-month, Annual
These ten fields provide the minimum information required for governance. Organizations in regulated industries may add fields for specific compliance obligations — FDA classification for clinical AI, SEC registration for financial AI, or privilege designation for legal AI.
Industry Examples
Healthcare Organizations
A hospital system's AI inventory might include: clinical documentation AI (Dragon, DAX), patient communication platforms with AI chatbots, revenue cycle automation tools, scheduling optimization AI, radiology AI for image analysis, EHR-embedded AI features, and employee use of general-purpose AI tools. Each tool must be inventoried with BAA status, data type (PHI vs. non-PHI), and clinical accountability designation.
For DSOs, the inventory must span all practice locations and address acquisition integration — ensuring that AI tools brought in through acquisitions are identified and assessed.
Financial Services
A financial advisory firm's AI inventory might include: CRM-integrated AI for lead scoring, portfolio analysis tools with AI capabilities, client communication platforms, compliance monitoring AI, and employee use of general-purpose AI tools. Each tool must be inventoried with data type (client financial data, PII), vendor compliance posture, and SEC compliance status.
For financial advisory firms, the inventory must address fiduciary obligations, regulatory reporting requirements, and client data protection standards.
Building Your AI Inventory
Building an AI inventory is not a one-time project — it is an ongoing governance process. The initial inventory build establishes the baseline; ongoing maintenance ensures the inventory remains accurate as new AI tools are adopted.
1. Department Survey
Survey all departments to identify AI tools currently in use. Include software with embedded AI capabilities that may not be recognized as AI.
2. Vendor Audit
Review vendor contracts and software inventories to identify AI capabilities in existing tools. Contact vendors to confirm AI features and data handling practices.
3. Employee Assessment
Survey employees on general-purpose AI tool usage. Identify shadow AI through anonymous reporting to capture tools adopted without formal review.
4. Field Documentation
For each identified tool, document the ten inventory fields. Assign initial risk scores based on data sensitivity and vendor posture.
5. Governance Review
Review inventory with governance committee. Assign approval status. Flag prohibited tools and schedule vendor assessments for unassessed tools.
6. Continuous Maintenance
Establish ongoing inventory updates for new AI deployments. Conduct quarterly full inventory audits to identify shadow AI.
Once the inventory is established, it becomes the foundation for the broader AI governance framework — feeding risk assessments, vendor reviews, compliance monitoring, and executive reporting through the governance platform.
Connecting Inventory to Governance
An AI inventory is not a standalone document. It is the foundation that enables every other governance function to operate:
Risk Assessment
The inventory provides the list of AI tools to assess, ensuring no tool is missed in risk evaluation.
Vendor Management
Inventory vendor data feeds vendor registry and watchlist monitoring.
Policy Enforcement
Inventory approval status drives policy enforcement and employee training requirements.
Compliance Monitoring
BAA status and data type fields enable compliance monitoring and audit readiness.
Industry Considerations
Healthcare Organizations
Healthcare AI inventories must capture BAA status for all AI vendors, PHI data type classification, clinical accountability for AI-assisted decisions, and multi-location coverage for DSOs and health systems.
Financial Advisory Firms
Financial services AI inventories must capture client data type, fiduciary obligation triggers, SEC compliance status, and vendor data handling practices for AI tools used in advisory and client communication workflows.
Law Firms
Legal AI inventories must capture privilege designation, confidentiality classification, professional responsibility triggers, and vendor data protection practices for AI tools used in research and document review.
Multi-Location Businesses
Multi-location AI inventories must span all locations, address acquisition integration of unassessed AI tools, and centralize vendor governance while accommodating location-level operational variation.
Governance Checklist
- Department survey completed across all functional areas
- Vendor audit conducted to identify embedded AI capabilities
- Employee assessment completed to identify shadow AI
- All ten inventory fields documented for each AI tool
- Initial risk scores assigned based on data sensitivity
- Governance committee review completed
- Approval status assigned for each tool
- Prohibited tools identified and removal planned
- Vendor assessments scheduled for unassessed tools
- Ongoing inventory maintenance process established
- Quarterly full inventory audit scheduled
- Inventory integrated with risk assessment process
Frequently Asked Questions
Next Step
Ready to assess your AI risk?
ZYNAGI helps organizations identify governance gaps, compliance exposure, and operational risk across AI systems.