Ask a leadership team how many AI systems their company runs and the answer is usually a handful. Ask the teams themselves and the list grows quickly: writing assistants, meeting transcription, AI features switched on inside the CRM, a forecasting spreadsheet someone built with a plug-in. This unofficial "shadow AI" is where most risk hides.

What to record for each system

  • What it does and which business process it supports.
  • Who owns it, and who supplied it.
  • What data goes in, especially personal or confidential data.
  • What decisions it influences, and whether a person reviews them.
  • Where it is used: only in India, or with customers abroad as well.

How to find the hidden ones

Combine three sources. First, a short survey asking every team which AI tools they use, framed as help rather than policing. Second, a review of software subscriptions and expense claims. Third, a check of AI features inside the platforms you already pay for, which are often enabled by default.

Turning the list into action

Once you have the inventory, rank each system by the sensitivity of its data and the weight of the decisions it affects. The few at the top deserve a proper risk assessment; the rest may need nothing more than an approved-use guideline. Keep the inventory alive by adding a simple step to software purchasing: no new AI tool without an entry in the register.