Open resource, CC BY 4.0
AI model inventory template
A register for the AI systems in your organisation, built to satisfy ISO 42001 and to answer the DPDP question about automated processing.
The table itself
This is the artifact, not a preview of it. Search across every column, filter it down, print what you filtered. Nothing is sent anywhere and there is no email step.
Showing 13 of 13 rows
| Field | What to record | Why it is asked | Maps to |
|---|---|---|---|
| Model name and version | Identifier and the version actually in production | You cannot govern what you cannot name | ISO 42001 clause 8 |
| Business owner | A named person, not a department | Ownerless models never get reviewed | ISO 42001 clause 5 |
| Purpose | The decision or output it produces, in one sentence | Purpose limitation is the basis of every other control | DPDP, ISO 42001 |
| Build type | In house, fine tuned, or third party API | Determines how much of the risk you actually control | NIST AI RMF Govern |
| Training data lineage | Sources, and whether personal data is present | Drives the privacy and consent position | DPDP, GDPR Article 22 |
| Personal data used | Yes or no, and which categories | Triggers notice, consent and DPIA duties | DPDP, GDPR |
| Automated decision | Does the output affect a person without human review | This is the specific thing regulators ask about | DPDP, GDPR Article 22 |
| Human oversight | Who can overrule it, and how that is recorded | Oversight that is not recorded did not happen | ISO 42001, EU AI Act |
| Bias testing | Method, date last run, and the result | Untested is a finding on its own | NIST AI RMF Measure |
| Performance monitoring | What is monitored and the drift threshold | Models degrade quietly | ISO 42001 clause 9 |
| Risk classification | Your tier, and the reasoning | Drives the depth of every other control | EU AI Act, ISO 42001 |
| Third party dependency | Provider, contract terms and what happens if withdrawn | Concentration risk is real and rarely assessed | ISO 42001 clause 8 |
| Review date | When it was last reviewed and when it is next due | Turns the inventory into a live document | ISO 42001 clause 9 |
Fill one row per model, including models you call as an API. The third party ones are the entries most often missing when an auditor asks.
Where the facts come from
Nothing here is our opinion dressed up as a rule. Every line traces back to a published source, cited so you can check it.
- ISO/IEC 42001:2023
- NIST AI Risk Management Framework 1.0
- DPDP Act 2023, on automated processing of personal data
What people use it for
Answering the question every auditor now asks, which is simply: what AI do you have and who owns it.
Licence
Published under Creative Commons Attribution 4.0. Copy it, cut it about, put it in your own audit pack, sell the work you do with it. Credit Threatsys and you are within the licence. There is no email gate and there never will be.
More open resources
- India compliance registryEvery cyber security obligation an Indian organisation can be held to, in one table, with the regulator and the trigger against each.Open it
- CERT-In directions readiness checklistThe April 2022 directions turned into checks you can actually run, including the log retention and clock sync duties people miss.Open it
- DPDP compliance timelineWhat the DPDP Act asks for, in the order you have to do it, with the dependencies that decide what you can start today.Open it
Why an inventory is the first AI governance control
Every AI governance conversation that starts with policy ends up back at the same question: which models are actually in use here, and by whom. Almost no organisation can answer it, because adoption happened through individual teams and expense cards rather than through procurement.
You cannot assess risk in a system you have not enumerated, you cannot answer a customer's question about whether their data trains a model, and you cannot respond to a regulator's question about automated decision making. All three start with the list.
The list is also the cheapest control available. It costs coordination rather than technology, and it converts an unbounded worry into a bounded set of decisions.
What to record against each model
What it is and who owns it, as a named person. Whether it is a third party API, a hosted model, or something running on your own infrastructure, because the risk profile differs sharply.
What data goes into it, which is the field that matters most. Specifically whether personal data, customer content or confidential material reaches it, and under what contract terms regarding training and retention.
What decisions it influences, and whether a human reviews the output before it takes effect. A model that drafts an email and a model that approves a claim are not comparable regardless of their technical similarity.
Where it runs and where the data goes, which is a residency question with legal weight for Indian organisations.
What happens when it is wrong, which is the question that most usefully separates experiments from systems that need governance.
The risks worth assessing, in order
Data leaving. The most common concrete incident is confidential material pasted into a third party service under terms nobody read. This is a contract and awareness problem before it is a technical one.
Decisions without accountability. Where a model influences an outcome affecting a person, somebody has to own that outcome. Under the DPDP Act, personal data processed through such a system carries the same obligations as anywhere else, including purpose limitation and the ability to honour rights.
Supply chain. A model accessed through an API is a third party with access to whatever you send it, and belongs in your vendor assessment on that basis.
Output reliability, which gets the most attention and is frequently the least consequential of the four when a human reviews before action.
How to keep it current
Attach the inventory to an existing process rather than creating a new one. The two that work are procurement, which catches anything with a contract, and change management, which catches anything that reaches production.
Neither catches individual adoption of free tools, which is where most shadow usage lives. The realistic control there is a clear, short policy about what may be pasted into what, plus an easy sanctioned option, because prohibition without an alternative produces concealment rather than compliance.
Review quarterly. This field moves fast enough that an annual review describes a landscape that no longer exists.
Not sure where to start?
Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.












