Skip to content
IC
All posts

AI governance

The AI register: the audit artefact every framework now assumes you have

Auditors, regulators, and insurers now open with the same request: show me the list of your AI systems. What an AI register is, what ISO 42001, NIST AI RMF, the EU AI Act, and Australian government policy expect it to contain, and how to keep one alive.

Mathew Sayed Mathew Sayed
· · 9 min read

There is a question that now opens almost every AI-related audit, insurer review, and enterprise customer questionnaire, and it is not a hard question. It is: show me the list. Which AI systems are in use, who owns each one, what data they touch, and what oversight applies. It is the same question asset auditors have asked about servers, software licences, and third-party suppliers for decades, asked about a new class of asset.

Most organisations cannot answer it. IBM’s 2025 Cost of a Data Breach report found 63 per cent of organisations have no AI governance policy at all, that unsanctioned shadow AI was a factor in 20 per cent of breaches, and that breaches involving high levels of shadow AI cost an average of USD 670,000 more than the baseline. Some 97 per cent of AI-related breaches occurred in organisations without proper AI access controls. None of those numbers describes an exotic threat. They describe organisations that did not know what they were running.

The fix has an unglamorous name: an AI register. This piece makes the case that the register is now the foundational artefact of AI governance, shows how every serious framework and a growing list of government policies converge on it, and sets out what a defensible one contains. It is deliberately practical, because the register is the rare governance control that a mid-market organisation can stand up in weeks, not quarters.

What an AI register is, and what it is not

An AI register is a maintained, owned record of every AI system your organisation uses, builds, or embeds, with enough information per entry to govern it: what it does, who is accountable, what data it processes, how much autonomy it has, and what controls apply.

It is worth being precise about what it is not, because the term gets stretched:

  • It is not a procurement list. Procurement captures what you bought. The register captures what is in use, which includes the free tier your marketing team adopted, the AI features your existing SaaS vendors switched on, and the model a developer wired into an internal tool. In our shadow AI discovery work, the gap between the procurement view and the observed view is routinely three to five times.
  • It is not a model card library. Model documentation describes systems from the inside. The register describes them from the governance perspective: ownership, data exposure, risk tier, oversight. An entry should be readable by an auditor, a director, or an insurer in under a minute.
  • It is not a one-off audit deliverable. A register with a completion date and no owner is a snapshot, and AI estates change monthly. The register is a control only while it is alive, which is a point we return to at the end because it is where most registers fail.

The academic literature on algorithmic accountability lands on the same conclusion from a different direction: transparency instruments only produce accountability when they are maintained, specific, and tied to a named responsible party. A list nobody owns is theatre.

Every framework now assumes the register exists

The striking thing about the current standards and regulatory landscape is not that any one instrument mandates an AI inventory. It is that all of them quietly presuppose one. You cannot perform the obligations without the list, and auditors have noticed.

InstrumentWhere the register requirement lives
ISO/IEC 42001:2023The AI system inventory is the spine of the management system: clause 6.1.2 risk assessment and 6.1.4 impact assessment are performed per system in scope, and the Annex A controls on lifecycle and data governance assume a defined population of systems
NIST AI RMFGOVERN function: maintaining an inventory of AI systems, resourced according to risk priorities, is an explicit subcategory, and the MAP function cannot start without it
EU AI ActArticle 49 requires providers, and in defined cases deployers, to register high-risk systems in the public EU database before they are placed on the market, with the Annex III obligations landing from August 2026 (with parts of the timeline under proposal to shift to late 2027)
Australian Commonwealth policyThe policy for responsible use of AI in government requires agencies to publish AI transparency statements and designate accountable officials, with mandatory requirements phasing in through 2026 including AI impact assessments and Chief AI Officer appointments
APRA CPS 230The register of material service providers must capture the operational reliance your AI vendors now represent; our CPS 230 mapping walks through how AI tooling lands in it
Voluntary AI Safety Standard (Australia)The guardrails on accountability, transparency, and record-keeping all resolve, in practice, to knowing and documenting which systems you deploy

Two entries in that table deserve expansion, because they carry the direction of travel.

ISO 42001 makes the register the certification spine. As we noted in our 42001 readiness guide, the inventory built in the first weeks of a readiness program becomes the reference point for every subsequent step: risk assessment per system, impact assessment per system, control selection per system. Certification auditors test the management system by sampling from the register. If the register is incomplete, the management system is incomplete by construction, no matter how good the policy documents look.

The EU AI Act makes registers public infrastructure. Article 49 does not just ask organisations to keep internal lists. It requires registration of high-risk systems into an EU-wide public database, with Annex VIII fields covering identity, purpose, capabilities, and conformity evidence. For Australian firms, the reach question is real and we have covered it separately, but the deeper signal is architectural: the world’s most consequential AI law decided that the primary accountability instrument is a register. Regulators elsewhere copy architecture.

Governments are building their registers in public

If you want to see where private-sector expectations land in three years, watch what governments now require of themselves.

The United Kingdom made its Algorithmic Transparency Recording Standard mandatory for central government departments: every algorithmic tool that materially assists decisions gets a published record. The Netherlands and Finland went earlier, with Amsterdam and Helsinki publishing public algorithm registers in 2020. The United States required federal agencies to publish annual AI use case inventories. And Australia’s own policy for responsible AI in government requires transparency statements from every agency, with the 2026 mandatory phase adding impact assessments and accountable officers, even as the December 2025 National AI Plan stepped back from mandatory economy-wide guardrails in favour of technology-neutral regulation and an advisory AI Safety Institute.

Read those two Australian facts together, because the combination is the actual policy signal for mid-market organisations. The absence of an Australian AI Act does not mean the absence of expectations. It means the expectations arrive through existing channels: privacy and consumer law enforced by existing regulators, APRA prudential standards for the regulated, and, most powerfully, procurement. Government agencies that must publish transparency statements and run impact assessments will push those requirements into their supply chains, the same way CPS 234 obligations cascade from APRA-regulated entities to their vendors today. If you supply government or the regulated, the register requirement is coming to you by contract, not by statute, and contract moves faster.

What a defensible register contains

The register earns its keep through the fields, and the discipline is proportionality: enough per entry to govern, little enough that maintenance survives contact with a busy quarter. The core schema we use:

  • System and version. What it is, including embedded AI features inside existing SaaS, which are the most commonly missed class.
  • Owner. A named person, not a team. Accountability that is shared is accountability that is absent.
  • Purpose and users. What it does, for whom, and whether outputs face customers, staff, or decisions about people. Decisions about people move an entry up every risk tier that exists.
  • Data classes touched. Mapped to your data classification. This single field is what converts the register from inventory to risk instrument, and it is the field the IBM breach numbers vindicate: shadow AI incidents disproportionately exposed customer personal information.
  • Model and provider. Who runs the model, where, under what data-use terms, and what your exit looks like.
  • Autonomy level. Does it draft, decide, or act? A system that takes actions through tools and integrations is a different governance object from one that produces text a human reviews, a distinction our agent authorisation work treats at length.
  • Human oversight point. Where a person reviews, approves, or can intervene, stated specifically enough to audit.
  • Risk tier and applicable controls. Your internal tiering, plus mappings the outside world asks about: ISO 42001 scope, EU AI Act classification where relevant, CPS 230 materiality where regulated.
  • Review date and status. When the entry was last verified against reality, by whom, with what result.

Populating it starts with discovery, not with a form. The observed estate, from SSO logs, expense data, network telemetry, and browser extensions, is the ground truth; the declared estate is a subset. Run discovery first, reconcile, then interview the gaps. Expect the first pass to be humbling. Everyone’s is.

The failure mode is staleness, and the fix is structural

Nearly every organisation that attempts a register produces one. Nearly every register we inherit is dead on arrival: a spreadsheet, completed for an audit or a board request, unowned and untouched since. A stale register is arguably worse than none, because it produces confident wrong answers, and confident wrong answers are what auditors and regulators punish hardest.

Keeping it alive is a structural problem with a structural fix:

  1. Give it an owner with standing. The register belongs to whoever owns AI and information risk, in our engagements the fractional AI and information risk officer, and it appears in their board reporting, which creates the incentive to keep it true.
  2. Wire it into intake. Every procurement request, vendor review, and internal build proposal creates or updates an entry before approval, not after deployment. If the register is not in the path, it will not be on the map.
  3. Re-run discovery on a cadence. Quarterly at minimum. The delta between observed and registered is itself a governance metric worth reporting, because it measures how fast your organisation adopts AI outside its own processes.
  4. Automate the evidence where you can. Manual attestation is the expensive part, and it is exactly the layer we are building the Digital CISO Agent to draft: continuous collection of what is actually running, reported against the frameworks you answer to, with a named human accountable for the conclusions. That work is in development with design partners rather than on sale, and the register is the artefact it is designed to keep honest.

Where to start

If your organisation could not produce the list this week, that is the finding, and it is a tractable one. A workable register for a mid-market estate is a two-to-four week exercise: discovery, reconciliation, a schema like the one above, and an owner. It is also the first concrete deliverable of our AI governance posture assessment, precisely because everything else in AI governance, risk assessment, policy, monitoring, board reporting, inherits its scope from the register. Auditors open with show me the list because the list is where governance either exists or does not. Build it before someone else’s questionnaire builds it for you.

Sources and further reading

Get started

Bring AI risk under board oversight in two weeks.

A thirty-minute discovery call costs nothing. We confirm fit, scope, and timing, then issue a fixed-fee statement of work within two business days.