AI Use Case Inventory
Complete, continuously updated registry of AI, GenAI, RAG, Copilot, and agentic systems in use across the enterprise.
Shadow AI deployed inside SaaS tools consumes regulated data without governance review.
Automated discovery pipeline that reconciles cloud, SaaS, and code repositories against a governed AI inventory.
- Q1.1
Does your organization maintain a complete inventory of AI, GenAI, RAG, Copilot, and agentic systems currently in use?
Includes shadow AI, embedded vendor features, and internally built agents.
Evidence: Export from AI system registry, CMDB tags, procurement records.
- Q1.2
Are AI use cases classified by risk tier, data sensitivity, and regulatory scope?
Aligned to internal risk taxonomy and applicable regulation (EU AI Act, NIST AI RMF).
Evidence: Risk classification policy and per-use-case classification records.
- Q1.3
Is the inventory continuously updated as new AI capabilities are deployed?
Automated discovery vs. periodic manual attestation.
Evidence: Discovery pipeline logs, attestation cadence records.