Modules/AI Governance

AI System Register

by Formiti's Global DPO Team

The central inventory of all AI systems within the organisation, serving as the master record for risk classification, ownership, lifecycle status, and regulatory alignment under the EU AI Act.

Who uses this module?

AI Governance Leads, DPOs, System Owners, Technical Owners, Legal Counsel.

What governance problem does it solve?

Most organisations cannot answer the fundamental question: 'What AI systems do we operate, and what risk do they pose?' The AI System Register provides a structured, auditable inventory that forms the foundation for all downstream governance activities.

What are the key workflows?

  • Register AI systems with structured metadata (purpose, scope, department, jurisdiction)
  • Classify risk under EU AI Act (Prohibited, High-Risk, Limited, Minimal)
  • Assign business and technical ownership
  • Track lifecycle status (Draft, In Review, Approved, Production, Retired)
  • Manage AI Bill of Materials (AIBOM) with component-level provenance tracking
  • Trigger and manage multi-tier review and approval workflows
Workflow sequence
1

Register AI systems with structured metadata (purpose, scope, department, jurisdiction)

2

Classify risk under EU AI Act (Prohibited, High-Risk, Limited, Minimal)

3

Assign business and technical ownership

4

Track lifecycle status (Draft, In Review, Approved, Production, Retired)

5

Manage AI Bill of Materials (AIBOM) with component-level provenance tracking

6

Trigger and manage multi-tier review and approval workflows

What evidence and reporting does it produce?

Built-in outputs for accountability and regulatory readiness

Complete AI system inventory with risk classifications

AIBOM documentation per system

Ownership and accountability records

Lifecycle status dashboard

Review and approval audit trails

How does it connect to other Privacy360 modules?

  • Anchor record for all AI Governance modules (Assessments, Remediation, Suppliers, Evidence, Monitoring)
  • Links to ROPA entities for data processing context
  • DPIA status tracked per system
  • Review workflows enforce segregation of duties

What are some example use cases?

Customer Ops

A governance lead registers a new customer-facing chatbot, classifies it as Limited Risk, documents its AIBOM, and assigns ownership before submitting for Standard review.

Scenario 1
Privacy Team

A technical owner updates the AIBOM after switching from one LLM provider to another; the platform flags a material change and triggers a review reopen.

Scenario 2
Privacy Team

During an EU AI Act readiness audit, the register produces a complete inventory of 12 AI systems with risk classifications, ownership, and approval status.

Scenario 3

See the operational platform in action

Book a demo to see how Privacy360 brings assessments, records, consent, contracts, AI governance, training and evidence into one operational system tailored to your programme.

Privacy-first website: We do not use tracking cookies, advertising pixels, or third-party analytics on this site. Read our Privacy Notice.