Free Tool
AI Inventory & Risk Register
Document which AI tools your organization uses, what data flows through them, and assess their risk classification.
This tool provides general guidance based on the information you provide. It is an initial starting point, not a substitute for professional assessment. Every organization's environment is unique — results should be reviewed with a qualified advisor before making compliance or security decisions.
Who this tool is for
This assessment is for any organization where AI tools arrived before an AI policy did — which today is most of them. It is written for the people who have just realized they do not know what is in use: executives who found out marketing has been feeding customer lists into a chatbot, compliance leads who need an inventory before a privacy assessment, IT managers fielding requests to approve yet another AI-enabled SaaS feature, and procurement teams evaluating vendors whose products now include AI by default. It applies equally to a small agency and a regulated enterprise; the questions are about governance practices, not scale.
What it measures — and what “in scope” means
Six questions establish the state of your AI governance: how many AI or machine-learning tools are in use, whether you know what data each one processes, whether policies govern AI use, whether tools have been assessed against regulatory requirements, whether there is human oversight of AI-driven decisions, and whether any AI output affects decisions about individuals — hiring, credit, eligibility, pricing. The result classifies your overall risk posture using the structure of the NIST AI Risk Management Framework (govern, map, measure, manage) and the EU AI Act's risk tiers, and tells you which governance step to take next. "In scope" means every tool with AI capability that touches your data, including features embedded in software you already licensed.
What your result is not
The result is a governance maturity read, not a legal determination of your obligations under the EU AI Act, MODPA, or any sector rule, and not a technical assessment of any specific model. It does not build the inventory for you — it tells you whether you have one and how much risk the gaps carry. A low-risk classification does not mean a particular tool is safe to use with sensitive data; that requires reviewing the vendor's terms, data handling, and training practices.
Frequently asked questions
QWhat counts as an AI tool for inventory purposes?
Anything that generates content, makes predictions, classifies data, or automates decisions using a model — standalone chatbots, coding assistants, AI features inside CRM, email, HR, and analytics platforms, and vendor products that process your data with AI.
QWhat is shadow AI?
AI tools employees adopt without approval or oversight. It is rarely malicious; it is usually someone trying to work faster. The governance problem is that nobody knows what data went where. The related articles cover discovery and cost.
QWhich framework should a small organization use for AI governance?
NIST AI RMF is voluntary, well-documented, and scales down. Start with an inventory and an acceptable-use policy; add impact assessments for high-risk uses.
QDoes the EU AI Act apply to U.S. companies?
It can, if your AI systems are placed on the EU market or their output is used in the EU. Most small U.S. organizations are deployers of low- or limited-risk systems, but that still carries transparency duties.
QIs the inventory stored anywhere?
No. The assessment runs in your browser and nothing is saved or transmitted.
Related reading
Tool and guide maintained by Ashwameth J Ravilla, CISSP, CISA, CDPSE, CMMC RP (CPN 72949) · Last updated September 2026.
Need a Deeper Analysis?
This tool gives you a starting point. For a comprehensive, professional assessment tailored to your specific environment, schedule a consultation.
Schedule a Scope Call