AI Tools Inventory

Type: control artefact First seen: 2026-03-18 Last updated: 2026-05-17

Definition

A tagged, owner-mapped register of all AI tools and systems in use within an organisation, with stakeholder mapping per tool. The emerging baseline evidence artefact for both supervisory and AI Act obligations [S-2025-11-19-bcbs-othp90].

Origin

Named explicitly as a step in the BCBS ten-step playbook (step 4: AI tools inventory; step 5: stakeholder mapping) [S-2025-11-19-bcbs-othp90]. Parallel emergence in EU AI Act Annex IV documentation requirements for high-risk systems.

How it connects to other concepts

Practical applications

ECB position (echoed in practitioner commentary): institutions should maintain catalogues of all AI and ML models — internal models and generative AI tools — supervised by the CRO under Three Lines of Defence for AI.

AI Assurance Pathway artefacts that operationalise the inventory [S-2026-05-06-paul-ai-data-pathway]:

  • AI System Inventory template.
  • AI Use-Case Intake Form.
  • Tool Registry & Approval Workflow.
  • Model Validation Report (mappable to AI Act Annex IV).
  • AI Logging & Evidence Specification (Art 12).
  • Drift Monitoring Plan.
  • AI Vendor DDQ.

As an opening intervention, the inventory is often the single highest-leverage control to deliver in early engagements because it surfaces shadow AI, vendor concentration, and 2LoD coverage gaps simultaneously.

Tensions / variants

  • Scope variants: model-only inventory vs. extended inventory covering foundation models + prompt sets + agent tool registries + retrieval corpora. The wider scope is needed for agentic AI but is not yet uniformly required by supervisors.
  • Ownership variants: inventory under CDO (operational ownership) vs. CRO (risk ownership) — see Model Risk Management and Agentic AI Tensions.

Sources

  • [[