AI

AI Foundations – Building an Effective AI Inventory Program

Author:
Stacy Hagemann
Date:
September 10, 2026

Ever play a game where you are always behind, struggling to catch up, and wanting to take the lead? Unfortunately, this is the position of every Compliance, Governance, and Audit professional. Emerging technology trends will always hold the lead with cutting edge innovations. The current advancements in AI have this on full display as various organizations and governments around the world are trying to build, promote, and govern responsible and ethical AI use. 

Let’s imagine an organization with 1,000 employees, each one baking a cake or a pie. Some will follow the recipe step-by-step, while others may wing it with their measurements and ingredients. Now, turn that cake or pie into an AI model. With all the varieties of cakes and pies, there are even more AI models. Like our example, literally almost every employee in a company can easily find a use for AI and start building

It all comes down to you can’t govern what you don’t see.

While we never want to curb innovation, in the case of something so far reaching in use across an organization, gaining visibility, applying protocols and policies are imperative.  One additional growing layer of concern to this, is even if you don’t think many of your employees are building models or working with MCP servers there is a massive push by vendors across all different business sectors to develop AI Agents and MCP servers into their solutions. This table shows many of today’s business platforms outside of traditional IT technologies that are quickly developing AI Agents and MCP servers. 

Business Solution SectorsOffering MCP Servers
HRGreenhouse, Gusto, HiBob, Windmill, Workday
CRM(Customer Relationship Management)Salesforce, Zoho, HubSpot, Microsoft Dynamics 365
AccountingQuickBooks Online, Xero, NetSuite, SAP, Oracle Financials
CLM(Contract Lifecycle Management)Ironclad, Sirion Agentic, Agiloft, DocuSign (In Beta)
ProcurementSAP Ariba, Microsoft Dynamics 365, Coupa (Coming September 2026)

The need for AI Inventory is reaching a crucial point. The most apparent risk of shadow AI is something that has eluded your inventory process. You want to consider ways to make your program robust enough that it will surface the varieties of record and not miss arising vectors of development. 

Constructing an AI Inventory Program

Core Capabilities:

  • Discovery Points – SaaS, cloud, endpoints, browsers, networks, code repositories, vendor platforms
  • Single source of truth for all AI assets – AI Inventory
  • Relationships & Dependencies – map to applications, APIs, data sources, business processes, technology platforms
  • Lifecycle – development, deployment, and decommissioning
  • Ownership – assigned business and technical owners

Considerations:

Collection Attributes – model and version, provider, prompt templates, RAG data sources, deployment location, training source, embedding model, agent framework, MCP servers, external APIs, human approval, fine-tuning status, guardrails, drift monitoring, safety testing, red-team results, execution logs, business purpose, criticality, documentation.

Track Data – classification, sensitive exposure, personal or regulated, intellectual property, customer information, training datasets, retrieval sources, vector database, data residency.

Include Risk – business impact, regulatory classification, privacy and security risk, bias and hallucination risk, explainability, human oversight, third-party dependency, operational risk.

Governance and Oversight – approval workflows, policy management, exception management, risk acceptance, review cycles, model retirement, owner attestations, documentation management. 

Integrations – identity, security, data protection, cloud, dev tools, SaaS apps.

Regulatory Alignment – even if not required to adhere, choose one to align with as best practice. 

Third-Party Management – vendor, model provider, sub processors, data processing agreement (sharing/training), breach notification, rapid model updates, and transparency, contract terms, prompt logging, long term retention, security and privacy assessments, geography hosting. 

Business Outcomes – 

  • Visibility into models with, understand access capabilities, sensitive data access, external API calls, privileged credentials, modifying data, or executing actions. 
  • Facilitate appropriate protocols and policies, building guardrails.
  • Track and Trend AI assets, usage, and risk level.
  • Understand business unit usage and value
  • Determine assigned or unassigned ownership and completeness of review. 
  • Vendor modus operandi, contract terms and communication procedures.

Much like baking where a cookbook holds all the recipes, an AI inventory program holds all the information pertaining to your AI assets. This goes back to the adage “You can’t govern, what you don’t see.” AI Inventory should be the foundation to your AI program and working in tandem with your corporate policies. AI inventory will be an ongoing process that will never be complete. Running a program that is always looking and recording any new processes will ensure policies stay up to date and controls are adequately applied. 

This market is in continual development, please reach out to hello@sayers.com for assistance in understanding the most up to date options to suit your needs.

Subscribe to blog
By subscribing you agree to with our
Privacy Policy
Share
featured Resources

The Biggest Headlines in IT Consulting

Explore news articles, case studies, and more.
View All
Blog
AI Isn’t the Enterprise’s Biggest Challenge. Data Is.
Read More
Blog
Enterprise AI Resilience: Preparing for the Next Business-Critical Dependency
Read More
Blog
AI Identity Risk: The New Security Frontier CISOs Can’t Ignore
Read More