ZYNAGI Governance Foundation

AI Inventory for Governance, Risk, and Compliance

An AI inventory is the foundation of governance. You cannot govern AI systems you cannot enumerate — and most organizations cannot enumerate the AI systems they are running.

Build Your AI Inventory

TL;DR — Key Takeaways

  • An AI inventory is the foundational component of AI governance — without it, governance, risk assessment, and compliance monitoring cannot function.
  • Hidden AI use creates risk: shadow AI tools access sensitive data without oversight, vendor compliance is unassessed, and executive visibility is absent.
  • Inventory fields include tool name, department, owner, use case, data type, vendor, BAA and SOC 2 status, approval status, renewal date, and risk score.
  • Healthcare and financial services organizations face specific inventory requirements due to PHI, fiduciary obligations, and regulatory compliance demands.
  • Organizations without AI inventories typically discover AI tools through incidents rather than through systematic review — a reactive posture that compounds risk.

Executive Summary

AI governance begins with a single, deceptively simple question: What AI tools is your organization using? For most organizations, the answer is incomplete. Clinical documentation tools, patient communication platforms, CRM systems with embedded AI, scheduling automation, revenue cycle tools, marketing platforms, and employee-adopted general-purpose AI tools are deployed across departments — often without central visibility.

An AI inventory is the structured record that answers this question. It documents every AI tool deployed across the organization, capturing the information required to assess risk, evaluate vendor compliance, monitor usage, and provide executive oversight. It is not an IT asset management function — it is a governance control.

Organizations that maintain AI inventories can govern. Organizations that do not maintain inventories discover AI exposure through incidents: a vendor data breach revealing unassessed tools, a compliance audit finding AI systems without BAAs, or a board inquiry about AI usage that leadership cannot answer.

What Is an AI Inventory?

An AI inventory is a current, accurate, and comprehensive record of every AI tool deployed across an organization. It captures not just the tool name, but the contextual information required for governance: who owns it, what data it accesses, who the vendor is, what compliance obligations apply, and what governance status the tool holds.

Governance Principle

An AI system that is not in the inventory is an AI system that is not governed. The inventory is not a tracking exercise — it is the foundational governance control that makes risk assessment, vendor management, compliance monitoring, and executive reporting possible.

Unlike traditional software inventories, an AI inventory must capture information specific to AI risk: data sensitivity, vendor AI capabilities, model training practices, human oversight requirements, and governance approval status. These fields provide the context required to evaluate whether an AI tool is being used safely and compliantly.

Why Hidden AI Use Creates Risk

AI tools are adopted through multiple pathways — many of which bypass formal IT, compliance, or executive review. Individual departments adopt AI-enabled software for specific operational needs. Employees use general-purpose AI tools like ChatGPT, Claude, or Copilot for work tasks. Vendors embed AI capabilities into existing software without notification. Acquired organizations bring their own AI ecosystems.

This creates shadow AI — AI tools that the organization is using but has never formally assessed, authorized, or documented. Shadow AI creates compounding risk:

Data Exposure

Shadow AI tools may access PHI, financial data, or confidential information without BAA coverage or data protection review.

Vendor Risk

Unassessed vendors may have inadequate security controls, problematic data retention practices, or undocumented sub-processors.

Compliance Risk

AI tools operating without compliance review may violate HIPAA, SEC regulations, state privacy law, or professional responsibility rules.

Operational Risk

AI tools that the organization cannot enumerate cannot be monitored for reliability, accuracy, or failure — creating operational dependencies without oversight.

The risk created by shadow AI is not theoretical — it is the risk that organizations discover through incidents. A vendor breach that exposes data processed by an AI tool the organization did not know it was using. A compliance audit that finds AI systems without BAAs. A board member asking what AI the organization uses and leadership having no answer.

AI Inventory Fields

A comprehensive AI inventory captures the following fields for every AI tool deployed across the organization. These fields provide the information required for governance, risk assessment, and compliance monitoring.

Tool Name

The specific name and version of the AI tool or AI-enabled software.

Example: Dragon Medical One, ChatGPT Enterprise, Salesforce Einstein

Department

The department or functional area where the AI tool is deployed.

Example: Clinical Operations, Revenue Cycle, Marketing, IT

Owner

The individual responsible for the AI tool within the organization.

Example: Director of Clinical Informatics, VP of Operations

Use Case

The specific operational purpose for which the AI tool is used.

Example: Clinical documentation, patient communication, lead scoring

Data Type

The categories of data the AI tool accesses, processes, or transmits.

Example: PHI, PII, financial data, confidential business information

Vendor

The third-party vendor providing the AI tool or service.

Example: Microsoft, Nuance, OpenAI, Salesforce

BAA Status

Whether a Business Associate Agreement is in place (required for PHI access).

Example: BAA executed, BAA pending, not applicable

SOC 2 / Security

The security certification and compliance posture of the vendor.

Example: SOC 2 Type II, ISO 27001, not certified

Approval Status

The governance approval status of the AI tool.

Example: Approved, Pending Review, Prohibited, Shadow AI

Renewal Date

The contract renewal or license expiration date for the AI tool.

Example: 2026-12-31, Month-to-month, Annual

These ten fields provide the minimum information required for governance. Organizations in regulated industries may add fields for specific compliance obligations — FDA classification for clinical AI, SEC registration for financial AI, or privilege designation for legal AI.

Industry Examples

Healthcare Organizations

A hospital system's AI inventory might include: clinical documentation AI (Dragon, DAX), patient communication platforms with AI chatbots, revenue cycle automation tools, scheduling optimization AI, radiology AI for image analysis, EHR-embedded AI features, and employee use of general-purpose AI tools. Each tool must be inventoried with BAA status, data type (PHI vs. non-PHI), and clinical accountability designation.

For DSOs, the inventory must span all practice locations and address acquisition integration — ensuring that AI tools brought in through acquisitions are identified and assessed.

Financial Services

A financial advisory firm's AI inventory might include: CRM-integrated AI for lead scoring, portfolio analysis tools with AI capabilities, client communication platforms, compliance monitoring AI, and employee use of general-purpose AI tools. Each tool must be inventoried with data type (client financial data, PII), vendor compliance posture, and SEC compliance status.

For financial advisory firms, the inventory must address fiduciary obligations, regulatory reporting requirements, and client data protection standards.

Building Your AI Inventory

Building an AI inventory is not a one-time project — it is an ongoing governance process. The initial inventory build establishes the baseline; ongoing maintenance ensures the inventory remains accurate as new AI tools are adopted.

1. Department Survey

Survey all departments to identify AI tools currently in use. Include software with embedded AI capabilities that may not be recognized as AI.

2. Vendor Audit

Review vendor contracts and software inventories to identify AI capabilities in existing tools. Contact vendors to confirm AI features and data handling practices.

3. Employee Assessment

Survey employees on general-purpose AI tool usage. Identify shadow AI through anonymous reporting to capture tools adopted without formal review.

4. Field Documentation

For each identified tool, document the ten inventory fields. Assign initial risk scores based on data sensitivity and vendor posture.

5. Governance Review

Review inventory with governance committee. Assign approval status. Flag prohibited tools and schedule vendor assessments for unassessed tools.

6. Continuous Maintenance

Establish ongoing inventory updates for new AI deployments. Conduct quarterly full inventory audits to identify shadow AI.

Once the inventory is established, it becomes the foundation for the broader AI governance framework — feeding risk assessments, vendor reviews, compliance monitoring, and executive reporting through the governance platform.

Connecting Inventory to Governance

An AI inventory is not a standalone document. It is the foundation that enables every other governance function to operate:

Risk Assessment

The inventory provides the list of AI tools to assess, ensuring no tool is missed in risk evaluation.

Vendor Management

Inventory vendor data feeds vendor registry and watchlist monitoring.

Policy Enforcement

Inventory approval status drives policy enforcement and employee training requirements.

Compliance Monitoring

BAA status and data type fields enable compliance monitoring and audit readiness.

Industry Considerations

Healthcare Organizations

Healthcare AI inventories must capture BAA status for all AI vendors, PHI data type classification, clinical accountability for AI-assisted decisions, and multi-location coverage for DSOs and health systems.

Financial Advisory Firms

Financial services AI inventories must capture client data type, fiduciary obligation triggers, SEC compliance status, and vendor data handling practices for AI tools used in advisory and client communication workflows.

Law Firms

Legal AI inventories must capture privilege designation, confidentiality classification, professional responsibility triggers, and vendor data protection practices for AI tools used in research and document review.

Multi-Location Businesses

Multi-location AI inventories must span all locations, address acquisition integration of unassessed AI tools, and centralize vendor governance while accommodating location-level operational variation.

Governance Checklist

  • Department survey completed across all functional areas
  • Vendor audit conducted to identify embedded AI capabilities
  • Employee assessment completed to identify shadow AI
  • All ten inventory fields documented for each AI tool
  • Initial risk scores assigned based on data sensitivity
  • Governance committee review completed
  • Approval status assigned for each tool
  • Prohibited tools identified and removal planned
  • Vendor assessments scheduled for unassessed tools
  • Ongoing inventory maintenance process established
  • Quarterly full inventory audit scheduled
  • Inventory integrated with risk assessment process

Frequently Asked Questions

Next Step

Ready to assess your AI risk?

ZYNAGI helps organizations identify governance gaps, compliance exposure, and operational risk across AI systems.