AI System Register
by Formiti's Global DPO Team
The central inventory of all AI systems within the organisation, serving as the master record for risk classification, ownership, lifecycle status, and regulatory alignment under the EU AI Act.
Who uses this module?
AI Governance Leads, DPOs, System Owners, Technical Owners, Legal Counsel.
What governance problem does it solve?
Most organisations cannot answer the fundamental question: 'What AI systems do we operate, and what risk do they pose?' The AI System Register provides a structured, auditable inventory that forms the foundation for all downstream governance activities.
What are the key workflows?
- Register AI systems with structured metadata (purpose, scope, department, jurisdiction)
- Classify risk under EU AI Act (Prohibited, High-Risk, Limited, Minimal)
- Assign business and technical ownership
- Track lifecycle status (Draft, In Review, Approved, Production, Retired)
- Manage AI Bill of Materials (AIBOM) with component-level provenance tracking
- Trigger and manage multi-tier review and approval workflows
Register AI systems with structured metadata (purpose, scope, department, jurisdiction)
Classify risk under EU AI Act (Prohibited, High-Risk, Limited, Minimal)
Assign business and technical ownership
Track lifecycle status (Draft, In Review, Approved, Production, Retired)
Manage AI Bill of Materials (AIBOM) with component-level provenance tracking
Trigger and manage multi-tier review and approval workflows
What evidence and reporting does it produce?
Built-in outputs for accountability and regulatory readiness
Complete AI system inventory with risk classifications
AIBOM documentation per system
Ownership and accountability records
Lifecycle status dashboard
Review and approval audit trails
How does it connect to other Privacy360 modules?
- Anchor record for all AI Governance modules (Assessments, Remediation, Suppliers, Evidence, Monitoring)
- Links to ROPA entities for data processing context
- DPIA status tracked per system
- Review workflows enforce segregation of duties
What are some example use cases?
A governance lead registers a new customer-facing chatbot, classifies it as Limited Risk, documents its AIBOM, and assigns ownership before submitting for Standard review.
A technical owner updates the AIBOM after switching from one LLM provider to another; the platform flags a material change and triggers a review reopen.
During an EU AI Act readiness audit, the register produces a complete inventory of 12 AI systems with risk classifications, ownership, and approval status.
Related modules
AI Assessments
A 13-section EU AI Act and GDPR assessment wizard that scores prohibited practice, high-risk, GPAI and transparency outcomes with evidence.
AI Remediation
Turn AI assessment findings into assigned, dated remediation tasks with evidence requirements — so gaps close between assessment cycles.
AI Suppliers
Track AI-specific supplier commitments — AI terms, no-training guarantees, transparency documentation — across the AI supply chain.
AI Evidence
One indexed repository linking every compliance artefact to the AI system, assessment, task or supplier it evidences.
AI Monitoring
Log post-deployment incidents, anomalies and compliance drift against each AI system, with severity, escalation and resolution tracking.
AI System Register guides
Practical articles from Formiti's Global DPO team on running this work well.