Free resource · AI inventory
Free AI register template for Australian businesses
An editable inventory for Australian organisations. Record who owns each tool, the work it supports, the data it touches, whether it is approved, the controls around it and when it must be reviewed again.
What it is
What an AI register is
An AI register is a structured inventory of every AI tool or system your organisation uses. For each tool it records the owner, the department, the use case, what data is entered, whether personal or sensitive information is involved, the vendor arrangement, whether the tool has been approved, the risk level, controls in place, and the next review date.
The register gives whoever is responsible for AI governance a reliable reference point. Without it, AI use tends to spread across the business invisibly, and no one can say with confidence what tools are in use, what data they touch, or whether they have been assessed.
The register works alongside your AI policy. The policy says what is allowed; the register tracks what you actually have. If you do not yet have a policy, start there, then use this register to record the tools assessed against it.
- Format
- Editable workbookcontext
- Core fields
- Twelvecontext
- Review cadence
- At least quarterlycontext
Who it is for
Who needs an AI register
Has professional obligations
Is growing its team
Works with enterprise clients
Download
Download the template
AI inventory workbook
A practical register, ready to adapt
A branded, editable Excel workbook. It opens in Excel, Google Sheets or Numbers, with the twelve columns set up, worked examples to delete, and a "How to use" tab explaining what each column captures. Replace the examples with one row per AI tool in use.
- Twelve governance and review fields
- Worked examples to replace
- A dedicated How to use tab
Register anatomy
What columns it should include
| Register field |
|---|
| Tool or system |
| Owner |
| Department |
| Use case |
| Data entered |
| Personal information involved |
| Sensitive information involved |
| Vendor or account type |
| Approval status (approved / conditional / unapproved) |
| Risk level |
| Controls |
| Review date |
Distinctions
AI register vs AI policy vs AI risk register
AI policy
AI register (this template)
AI risk register
Illustrative rows
Example entries
| Tool | Owner | Dept | Use case | Data entered | PI | SI | Vendor | Status | Risk | Controls | Review date |
|---|---|---|---|---|---|---|---|---|---|---|---|
| ChatGPT (OpenAI) | Operations Manager | Operations | Drafting emails and internal documents | Internal text, no client data | No | No | OpenAI (paid team plan) | Approved | Low | Staff briefing; no client data rule | 2025-09-01 |
| Microsoft Copilot | IT Manager | All | Email drafting, summarising meetings, code suggestions | Internal emails and documents via M365 | Yes | No | Microsoft (M365 Business) | Approved | Medium | M365 data boundary enabled; DLP policy applied | 2025-09-01 |
| Claude (Anthropic) | Marketing Lead | Marketing | Content drafting and research summarisation | Internal briefs, no personal information | No | No | Anthropic (Pro plan) | Approved | Low | No client or personal data in prompts | 2025-09-01 |
| Otter.ai | Sales Manager | Sales | Meeting transcription | Meeting audio, participant names | Yes | No | Otter.ai (Business plan) | Conditional | Medium | Participants notified; recordings deleted after 30 days | 2025-09-01 |
| Zapier AI | Operations Manager | Operations | Automated lead routing and CRM updates | Contact names, email addresses | Yes | No | Zapier (Team plan) | Conditional | Medium | Privacy notice updated; data minimisation applied | 2025-09-01 |
PI = personal information involved. SI = sensitive information involved. Illustrative only.
Review cycle
How to review the register quarterly
Discover
Check for new tools
Ask each team lead whether any new AI tools have been introduced since the last review. Add a row for each one.Reconcile
Confirm each tool is still in use
Remove or archive rows for tools that have been discontinued. A stale register is worse than no register.Verify
Review vendor changes
Check whether any vendors have updated their data handling practices, terms, or pricing tier since the last review.Decide
Reassess approval and risk
Confirm that the approval status and risk level for each tool still reflect current use. Usage sometimes expands beyond what was originally assessed.Schedule
Update the review date
Set the next review date for each row. Tools with higher risk levels may warrant more frequent review.
Escalation
When to get help
The register template works well for businesses that have a reasonable picture of their AI use. If you suspect staff are using tools that your leadership team does not know about, the register will reflect that gap rather than close it. In that case, a usage review is the more useful starting point.
Clients
What our clients say
VibeZero reviewed BuildScore end to end before our public launch. What impressed us most was the rigour: a clear scope of work up front, tightly controlled access that they wound back the moment the job was done, and a written report so precise that our own independent verification confirmed every finding, line for line. They didn't just point at problems. Every issue came with a practical fix, sequenced so we could ship safely, and they handed over their testing tools so the value outlasted the engagement. Professional, responsive and security-first at every step. We'd recommend Josh and the VibeZero team to any founder who wants confidence in what they're shipping.
Josh and the VibeZero team turned a mess of ideas into a working product faster than I thought possible. They actually listened to what we needed, didn't overcomplicate things, and delivered something our team could use straight away. Genuinely one of the best tech experiences I've had as a business owner.
FAQ
Frequently asked questions
Build the baseline