The common failure
Procurement lists usually capture vendors, not systems. One model subscription may support several use cases with different users, data, decisions and risks. Conversely, a single business workflow may combine embedded SaaS AI, a private retrieval layer and multiple model providers.
Use the workflow as the unit
Create one record for each distinct purpose and operating boundary. Record business and technical owners, users and affected people, deployment, model and provider, source data, personal or sensitive data, outputs, automated actions, human oversight, monitoring, incidents and review dates. Keep legal classification in a separate reviewed field so an engineering guess is not mistaken for counsel’s conclusion.
Find the hidden systems
Interview workflow owners and administrators. Ask where text is generated, ranked, summarised, scored or used to trigger an action. Review browser tools, SaaS features, APIs, spreadsheets and internal automations. Include experiments that touch real data even when they are not called “production”.
Make it operational
Every inventory row needs an owner, last review, next review and incident route. Link the row to architecture, evaluation and provider records. The inventory then becomes the index for change control rather than a compliance spreadsheet that expires after the workshop.