Pillar 1 of 7
AI Use Case Inventory
Complete, continuously updated registry of AI, GenAI, RAG, Copilot, and agentic systems in use across the enterprise.
Not sure where to start?
Take the 10-minute Executive Scan first for a directional readiness snapshot, then return here for the full 21-question assessment across all 7 pillars.
Q1.1
Does your organization maintain a complete inventory of AI, GenAI, RAG, Copilot, and agentic systems currently in use?
Includes shadow AI, embedded vendor features, and internally built agents.
3 — Defined
Ad HocEmergingDefinedControlledAuditable
Documented, repeatable, partially enforced.
Attach evidence (placeholder)PDF, policy doc, log export, screenshot.
Q1.2
Are AI use cases classified by risk tier, data sensitivity, and regulatory scope?
Aligned to internal risk taxonomy and applicable regulation (EU AI Act, NIST AI RMF).
3 — Defined
Ad HocEmergingDefinedControlledAuditable
Documented, repeatable, partially enforced.
Attach evidence (placeholder)PDF, policy doc, log export, screenshot.
Q1.3
Is the inventory continuously updated as new AI capabilities are deployed?
Automated discovery vs. periodic manual attestation.
3 — Defined
Ad HocEmergingDefinedControlledAuditable
Documented, repeatable, partially enforced.
Attach evidence (placeholder)PDF, policy doc, log export, screenshot.
Complete all questions to continue.
Prefer to explore the framework first? View framework