Discover · fixed-scope engagement

AI Use Inventory

Two to three weeks. One register. Every AI use, its owner, and what it can reach.

Why uses, not systems

Most AI inventories list systems. The risk lives in uses.

One team uses Copilot to summarize project meetings. Another uses it to summarize employee misconduct interviews.

Same licence. Same configuration. Same line in your asset register.

Different people affected. Different obligations. Different evidence if anyone asks.

Whatever inventory you have today almost certainly counts that as one thing.

Illustrative example of the register — not client data.
AI useOwnerAffectsDataCan act?Unknown
Interview summaryHR DirectorEmployeesHR recordsNoRetention
Support copilotVP SupportCustomersCRMDraftsTraining
Finance agentCFOVendorsERPYesApproval limit
What you get

Three deliverables, one register.

The AI Use Register

For every AI use in scope:

  • What it does, in plain language
  • Which systems it depends on
  • Who owns it in the business, by name
  • Whether you build it, supply it, deploy it, or use it — because the obligations differ
  • Who could experience a result from it
  • What data it can reach
  • Whether it can act on its own — change a record, send something externally, approve something, start another process
  • Where it operates, and where the people it affects are

The unknowns register

What could not be established, who owns closing each gap, and by when. Recorded, not omitted.

The workload profile

How much AI use exists, how much of it needs deeper assessment, and where the complexity sits. This is what scopes anything that follows.

What you won't get

You will not get a maturity score.

Every platform in this market gives you a risk rating or a maturity level. This engagement will not.

You will get an assessment of what the evidence supports, an explicit statement of what it does not, and what would resolve it.

A composite number is the one thing you cannot trace back to its evidence when someone asks you to.

Where it leads

It stands on its own. It also scopes what follows.

The register stands on its own — as a security baseline, a governance starting point, or an answer to a board question you can't currently answer.

It is also the scope baseline for ISO/IEC 42001 certification work, and the input that scopes it.

The Method

How Renzo establishes the baseline.

01

Discover

Find AI uses across functions — not simply the AI systems you purchased.

02

Attribute

Assign a named business owner to each one.

03

Trace

Systems, data, affected parties, geography and autonomous actions.

04

Challenge

Separate what is known from what is assumed from what is unknown.

05

Baseline

A defensible register, and a clear view of what needs deeper assessment.

How it runs

Delegated discovery. A defensible close.

Discovery is delegated across the functions that actually use AI, each with a named owner and a due date. Nobody answers for the whole organization. The engagement closes on a defensible register, not a percentage complete.

Led directly by Ramon J. Matos — CISSP, ISO/IEC 42001 Lead Implementer.

Start with what you actually have

Discuss an AI Use Inventory.

We'll tell you whether it needs an executive, an architect, or neither — and we'll say so if it's the last one.