Pillar 1 of 7

AI Use Case Inventory

Complete, continuously updated registry of AI, GenAI, RAG, Copilot, and agentic systems in use across the enterprise.

Not sure where to start?

Take the 10-minute Executive Scan first for a directional readiness snapshot, then return here for the full 21-question assessment across all 7 pillars.

Start Executive Scan →
Q1.1

Does your organization maintain a complete inventory of AI, GenAI, RAG, Copilot, and agentic systems currently in use?

Includes shadow AI, embedded vendor features, and internally built agents.

3Defined
Ad HocEmergingDefinedControlledAuditable

Documented, repeatable, partially enforced.

Attach evidence (placeholder)PDF, policy doc, log export, screenshot.
Q1.2

Are AI use cases classified by risk tier, data sensitivity, and regulatory scope?

Aligned to internal risk taxonomy and applicable regulation (EU AI Act, NIST AI RMF).

3Defined
Ad HocEmergingDefinedControlledAuditable

Documented, repeatable, partially enforced.

Attach evidence (placeholder)PDF, policy doc, log export, screenshot.
Q1.3

Is the inventory continuously updated as new AI capabilities are deployed?

Automated discovery vs. periodic manual attestation.

3Defined
Ad HocEmergingDefinedControlledAuditable

Documented, repeatable, partially enforced.

Attach evidence (placeholder)PDF, policy doc, log export, screenshot.

Prefer to explore the framework first? View framework