Skip to content

Free resource for AI governance

Free AI register template for Australian businesses

An editable inventory for the AI tools people actually use. Record the owner, purpose, data, approval, controls and next review date in one working spreadsheet.

Reviewed September 2026. Name and work email are required for the browser download. You are not added to a mailing list. General information only, not legal or compliance advice.
File
Editable Excel workbookWorks in Excel, Sheets and Numbers
Structure
Twelve working fieldsOne row per tool or system
Examples
Prepared sample rowsReplace them with your own
Email
No mailing listPrivacy terms stay visible

Get the resource

Start with a register that is ready to fill

The fields, example rows and instructions are already in place. Replace the examples with the tools used across your organisation.

AI inventory workbook

One working view of tools, owners and controls

The workbook opens in Excel, Google Sheets or Numbers. It includes the twelve fields, worked examples to replace and a How to use tab explaining what each field captures.

The download starts in your browser. We also try to email a copy, but do not add you to a mailing list. Submitted details are handled under our privacy policy.

  • Twelve governance and review fields
  • Worked examples to replace
  • A dedicated How to use tab
Starting template only. Review it against your own obligations before relying on it.

Get the Excel workbook

Enter your details and the file starts downloading in this browser.

Download
Starts in your browser
Mailing list
You are not added

Free starting template. General information only, not legal or compliance advice.

Register anatomy

Twelve fields that turn a tool list into a control

Each field answers a practical question about ownership, use, data, permission or review.

Identity

What it is and who owns it

Tool or system
The product, feature or model in use.
Owner
The person accountable for its use and review.
Department
The team using it in day to day work.

Use

What happens in practice

Use case
The work the tool supports in plain terms.
Data entered
The information supplied to the tool.
Vendor or account type
The provider and whether the account is managed, paid or personal.

Risk

What needs attention

Personal information involved
Whether personal information is handled in this use.
Sensitive information involved
Whether health, biometric or other sensitive information is involved.
Risk level
The organisation's current low, medium or high assessment.

Control

What has been decided

Approval status
Approved, conditional or unapproved.
Controls
The practical rules or technical controls that reduce risk.
Review date
When the entry was reviewed or is next due.

Worked example

What one complete record looks like

This is illustrative only. The workbook contains several prepared rows to replace with your own tools and decisions.

Illustrative register entry

ChatGPT (OpenAI)

Approved
Owner
Operations Manager
Department
Operations
Use case
Drafting emails and internal documents
Data entered
Internal text, no client data
Personal information
No
Risk level
Low
Controls
Staff briefing; no client data rule
Review date
2026-09-01
Illustrative only. The workbook includes additional examples and the full twelve field structure.

Review cycle

A short review routine keeps the register useful

Update the register whenever a tool changes. If no stricter cadence applies, a quarterly sweep is a practical default for catching new accounts, stale entries and expanded use.
  1. Discover

    Check for new tools

    Ask each team lead whether any new AI tools have been introduced since the last review. Add a row for each one.

  2. Reconcile

    Confirm each tool is still in use

    Remove or archive rows for tools that have been discontinued. A stale register is worse than no register.

  3. Verify

    Review vendor changes

    Check whether any vendors have updated their data handling practices, terms, or pricing tier since the last review.

  4. Decide

    Reassess approval and risk

    Confirm that the approval status and risk level for each tool still reflect current use. Usage sometimes expands beyond what was originally assessed.

  5. Schedule

    Update the review date

    Set the next review date for each row. Tools with higher risk levels may warrant more frequent review.

How it fits

The register records reality. Other records answer different questions

It is most useful where staff already use AI, client or personal information may be involved, the team is growing, or customers ask for evidence of AI governance.

An AI policy sets the rules for staff. This register records the tools and uses that exist. A dedicated AI risk register goes further by recording individual risk events, likelihood, consequences, controls and residual risk. Some smaller organisations keep a risk level and controls in this register instead of maintaining a separate risk record.

The template works best when leadership already has a reasonable picture of current AI use. If people are using tools that are not visible to the business, the spreadsheet will reflect that discovery gap rather than close it. An AI usage review is a better starting point in that situation.

FAQ

Frequently asked questions

Practical answers about the register, the spreadsheet and the review cycle.

An AI register should include, at minimum, each AI tool or system in use, who owns it, which department uses it, the use case, what data is entered, whether personal or sensitive information is involved, the vendor or account type, approval status, risk level, controls in place, and a review date. The template provided here covers all of these columns.

Build the baseline

A register is useful when it reflects the tools people actually use

Start with the spreadsheet, then verify it with the team and give every material tool a named owner and review date.
General information only, not legal or compliance advice