A PRACTICAL GUIDE FOR BUSINESS OWNERS
How to build an AI inventory for your business
Start with a list of tools and what people actually use them for. Add the information they handle, the systems they can access, and the person responsible for the next check. Record what is still unknown.
What is an AI inventory?
An AI inventory is a working record of the AI tools and features used for company work, their business uses, the information involved, and the roles responsible for them. It includes tools people adopted themselves and AI features inside software the business already owns.
Use one row per tool and use case. The same writing assistant used to draft public product descriptions and summarize a customer file deserves two rows because the information and review requirements differ.
An inventory makes the next questions visible. It does not prove a tool is secure, an account is configured correctly, or a business meets any legal obligation.
What should you record?
| Record | Useful detail | How to check it |
|---|---|---|
| Tool and account | Provider, product, plan, department, company or personal account. | Ask the administrator to identify the actual account and plan. |
| Business use | The task, the output, and who relies on it. | Walk through the process with the person doing the work. |
| Information | Categories such as public product details, customer records, or internal pricing. | Ask what is entered, attached, retrieved, or copied. Keep confidential examples out of the inventory. |
| Access | Connected email, files, CRM, shared drives, and permissions. | Have the relevant administrator review enabled connections and permissions. |
| Data handling | Whether retention and training settings have been reviewed for that plan. | Record the date and location of the applicable settings or provider terms. |
| Responsibility | Approval owner, human reviewer, and reporting contact roles. | Confirm the named roles know what they are responsible for. |
| Next action | One unanswered question, an owner role, and a review date. | Track the action through to evidence or a documented decision. |
The free CSV template includes these categories. Keep supporting evidence in your own approved workspace. A link to a restricted evidence record is more useful than copying sensitive material into a widely shared spreadsheet.
How do you build the first version?
- Set a manageable scope. Choose one business unit or workflow. Write down what is included so nobody mistakes a partial inventory for a company-wide review.
- Ask the people doing the work. Ask which tools they open, which features they use, and what information goes in. Include free tools and personal accounts used for work.
- Ask administrators about existing software. Check for AI features and connected services in email, CRM, document, accounting, or other business systems. A subscription list alone does not tell you what is enabled or used.
- Separate reports from evidence. “The team says this is disabled” is different from “the administrator checked this setting on this date.” Record unknowns openly. Confirm current terms for the actual plan.
- Assign the next checks. Give each open question an owner role and a review date. Review the record when tools, accounts, connections, or uses change.
For evidence that does not fit in the template, keep a companion note with four fields: what was checked, who checked it, when it was checked, and where the evidence is stored.
What does this look like in an established business?
These are illustrative situations, not client results or claims about a particular product.
- Light manufacturing: a sales team uses AI to draft quote responses. Record whether drawings, customer specifications, or internal pricing are involved, and who checks the response before it goes out.
- Insurance brokerage: staff use AI to summarize correspondence. Record the categories of customer information, account ownership, and the review needed before the summary informs client advice.
- Commercial real estate: a team uses AI to draft listing copy or summarize leases. Separate public marketing content from confidential lease information and confirm who checks factual statements.
For an owner preparing to hand over responsibilities, record who maintains the inventory and who can explain the important settings. That creates a clearer operational handoff. It does not establish sale readiness or predict a valuation.
How do you decide what to review next?
Start with the questions that could change a decision: what information enters a tool, what connected systems it can reach, who uses personal accounts, and whether someone reviews outputs that affect customers or employees.
Use the AI Exposure Check to organize what you know across tools, data, access, ownership, and oversight. Its published review order helps choose a starting point; it is not a measured risk score.
The next step may be to finish documentation or clarify ownership using tools you already have. If you need help gathering evidence and deciding what to change, Syndesi’s AI Risk and Readiness Review is an optional scoped engagement.
Sources and scope
The NIST AI Risk Management Framework 1.0, January 2023 provides broader context. Its Govern 1.6 outcome addresses maintaining an AI inventory; Govern 2.1 addresses responsibilities; Map 1.1 addresses the context in which AI is used. See the NIST framework page for updates.
The steps, examples, and template here are Syndesi’s practical starting approach. They are not a complete implementation of the NIST framework, a conformity assessment, or an endorsement by NIST.
Reference this guide
Syndesi. “How to build an AI inventory for your business.” AI Audit by Syndesi. Updated September 16, 2026.
https://ai-audit.tools/guides/ai-inventory
For corrections, email hello@syndesi.io with the page address and the point that needs attention.
