Skip to content

Free resource · AI inventory

Free AI register template for Australian businesses

An editable inventory for Australian organisations. Record who owns each tool, the work it supports, the data it touches, whether it is approved, the controls around it and when it must be reviewed again.

Name and work email required to unlock the browser download · starting template only · general information, not legal or compliance advice

What it is

Inventory before assurance

What an AI register is

A live operating inventory that connects each AI tool to an owner, an approved use and a review decision.

An AI register is a structured inventory of every AI tool or system your organisation uses. For each tool it records the owner, the department, the use case, what data is entered, whether personal or sensitive information is involved, the vendor arrangement, whether the tool has been approved, the risk level, controls in place, and the next review date.

The register gives whoever is responsible for AI governance a reliable reference point. Without it, AI use tends to spread across the business invisibly, and no one can say with confidence what tools are in use, what data they touch, or whether they have been assessed.

The register works alongside your AI policy. The policy says what is allowed; the register tracks what you actually have. If you do not yet have a policy, start there, then use this register to record the tools assessed against it.

Format
Editable workbookcontext
Core fields
Twelvecontext
Review cadence
At least quarterlycontext

Who it is for

Governance fit

Who needs an AI register

Any organisation where staff use AI tools in their work should maintain a register. In practice, that now covers most small and midsized Australian businesses. It is especially relevant if your organisation:
Privacy

Handles personal information

The Privacy Act requires you to understand and control how personal information is handled, including by third party AI tools your staff use.
Duty

Has professional obligations

Legal, financial, medical and similar practices face specific duties around client data. A register helps demonstrate appropriate oversight.
Scale

Is growing its team

As you add staff, informal AI use spreads quickly. A register establishes a baseline and keeps new starters aligned.
Assurance

Works with enterprise clients

Many larger clients and procurement processes now ask suppliers to demonstrate AI governance. A register is a practical starting point.

Download

Editable Excel

Download the template

Start with a prepared workbook, then replace the illustrative rows with the tools your organisation actually uses.

AI inventory workbook

A practical register, ready to adapt

A branded, editable Excel workbook. It opens in Excel, Google Sheets or Numbers, with the twelve columns set up, worked examples to delete, and a "How to use" tab explaining what each column captures. Replace the examples with one row per AI tool in use.

  • Twelve governance and review fields
  • Worked examples to replace
  • A dedicated How to use tab
Starting template only · general information, not legal or compliance advice

Get the editable spreadsheet

Enter your details to unlock the browser download. We will also try to email a copy. No spam.

Free. A starting template, not legal advice. Have it reviewed before you rely on it.

Register anatomy

Twelve fields

What columns it should include

The template uses these twelve columns. Each addresses a specific question that matters for risk, privacy, and governance oversight:
The twelve fields in the AI register template
Register field
Tool or system
Owner
Department
Use case
Data entered
Personal information involved
Sensitive information involved
Vendor or account type
Approval status (approved / conditional / unapproved)
Risk level
Controls
Review date

Distinctions

Rules · inventory · risk

AI register vs AI policy vs AI risk register

These records reinforce each other, but they answer different governance questions.
Rules

AI policy

The policy sets the rules for how staff may use AI, covering which tools are approved, what data they can enter, when human review is required, and what is prohibited. It is a governance document. If you do not have one, download the free AI policy template first.
Read more
Inventory

AI register (this template)

The register is an inventory of what your business actually uses. It records each tool, its owner, the data it touches, its approval status, and the controls in place. It is updated regularly as tools are added, changed, or retired. The policy says what is allowed; the register tracks what you have.
Risk record

AI risk register

A risk register is a separate document focused specifically on identified risks, covering what could go wrong, the likelihood and consequence, the controls in place, and the residual risk. Some organisations maintain a dedicated AI risk register; others fold risk into the AI register itself. The risk level and controls columns in this template provide a lightweight version of that function.

Illustrative rows

Illustrative only

Example entries

These are illustrative examples showing how common AI tools might appear in a completed register. They are not real client entries. Adapt the details to reflect how your business actually uses each tool.
Illustrative AI register entries
ToolOwnerDeptUse caseData enteredPISIVendorStatusRiskControlsReview date
ChatGPT (OpenAI)Operations ManagerOperationsDrafting emails and internal documentsInternal text, no client dataNoNoOpenAI (paid team plan)ApprovedLowStaff briefing; no client data rule2025-09-01
Microsoft CopilotIT ManagerAllEmail drafting, summarising meetings, code suggestionsInternal emails and documents via M365YesNoMicrosoft (M365 Business)ApprovedMediumM365 data boundary enabled; DLP policy applied2025-09-01
Claude (Anthropic)Marketing LeadMarketingContent drafting and research summarisationInternal briefs, no personal informationNoNoAnthropic (Pro plan)ApprovedLowNo client or personal data in prompts2025-09-01
Otter.aiSales ManagerSalesMeeting transcriptionMeeting audio, participant namesYesNoOtter.ai (Business plan)ConditionalMediumParticipants notified; recordings deleted after 30 days2025-09-01
Zapier AIOperations ManagerOperationsAutomated lead routing and CRM updatesContact names, email addressesYesNoZapier (Team plan)ConditionalMediumPrivacy notice updated; data minimisation applied2025-09-01

PI = personal information involved. SI = sensitive information involved. Illustrative only.

Review cycle

Repeatable control

How to review the register quarterly

A quarterly review keeps the register accurate and prevents tool sprawl from going undetected. Work through these steps each quarter:
  1. Discover

    Check for new tools

    Ask each team lead whether any new AI tools have been introduced since the last review. Add a row for each one.
  2. Reconcile

    Confirm each tool is still in use

    Remove or archive rows for tools that have been discontinued. A stale register is worse than no register.
  3. Verify

    Review vendor changes

    Check whether any vendors have updated their data handling practices, terms, or pricing tier since the last review.
  4. Decide

    Reassess approval and risk

    Confirm that the approval status and risk level for each tool still reflect current use. Usage sometimes expands beyond what was originally assessed.
  5. Schedule

    Update the review date

    Set the next review date for each row. Tools with higher risk levels may warrant more frequent review.

Escalation

Close the discovery gap

When to get help

The register is strongest when it is fed by a reliable picture of what people actually use.

The register template works well for businesses that have a reasonable picture of their AI use. If you suspect staff are using tools that your leadership team does not know about, the register will reflect that gap rather than close it. In that case, a usage review is the more useful starting point.

Clients

Client perspective

What our clients say

Independent feedback from teams we have helped move from uncertainty to a working operating model.
VibeZero reviewed BuildScore end to end before our public launch. What impressed us most was the rigour: a clear scope of work up front, tightly controlled access that they wound back the moment the job was done, and a written report so precise that our own independent verification confirmed every finding, line for line. They didn't just point at problems. Every issue came with a practical fix, sequenced so we could ship safely, and they handed over their testing tools so the value outlasted the engagement. Professional, responsive and security-first at every step. We'd recommend Josh and the VibeZero team to any founder who wants confidence in what they're shipping.
Stacey BlackwellDirector, BuildScore
Josh and the VibeZero team turned a mess of ideas into a working product faster than I thought possible. They actually listened to what we needed, didn't overcomplicate things, and delivered something our team could use straight away. Genuinely one of the best tech experiences I've had as a business owner.
Natasja KleinmanFounder, Flexi Tribe

FAQ

Five answers

Frequently asked questions

Practical answers about the register, the spreadsheet and the review cadence.

Build the baseline

A register is useful when it reflects the tools people actually use

Start with the spreadsheet, then verify it with the team and give every material tool a named owner and review date.
General information · not legal or compliance advice