Tier 1: Foundation controls
High-risk AI use case inventory
A centralized register of high-risk AI systems and use cases, including where they are used, who owns them, and what obligations and controls apply.
Board-defensible evidence
- Inventory schema with required fields (system name, business owner, technical owner, purpose, impacted stakeholders, geography, vendor involvement, data types, model type, deployment location) and a defined completeness standard.
- System-of-record exports showing when each entry was created and last reviewed, who attested to accuracy, and the workflow used to onboard new AI systems before production use.
- Cross-reference evidence tying inventory entries to procurement records, vendor contracts, model cards, DPIAs or AI impact assessments, and security risk assessments, including traceable IDs or links.
- Controls coverage report showing which required controls apply to each inventory entry (testing, monitoring, incident response, human oversight) and which are pending, waived, or implemented with compensating controls.
- Periodic governance review minutes or attestation logs showing that risk, legal, and compliance reviewed the inventory on a defined cadence and addressed gaps, duplicates, or shadow AI discoveries.
Why this matters
If you cannot produce a complete, current inventory on demand, regulators and auditors will assume governance is reactive and incomplete.
How ready is your board on foundation controls?
Twelve questions, scored across all four tiers, with your gaps named — or take the whole framework into your next meeting.