You Can't Govern What You Haven't Mapped

Chapter 01 · Act I — See ItPillar: AI Inventory & Maturity Baselining

Every AI governance conversation starts the same way. Someone from risk or compliance asks, 'How many AI systems are we running?' And someone from the business gives a number that's confidently wrong — not because anyone lied, but because the number only counts the AI the organization approved. It doesn't count the AI people are actually using.

That gap is where every governance program either earns its credibility or loses it in the first thirty days.

The Inventory You Have Isn't the Inventory You Need

Most organizations already have some version of an AI inventory. It usually lives in one of two places: a procurement record of formally licensed tools, or a list some risk team built by asking department heads to self-report. Both are useful. Neither is complete.

AI shows up in an organization in three distinct layers, and most inventories only catch one of them.

Sanctioned AI

The systems IT and procurement know about. These are formally approved, licensed, and tracked — the visible tip of the iceberg.

Embedded AI

The AI quietly running inside tools you already pay for — arriving via routine vendor updates with no new purchase or review.

Shadow AI

The AI employees adopted themselves, one browser tab away with no procurement step in between. Invisible to most inventories.

The Hidden Risk Surface

Most inventories only capture what's visible above the waterline — the formally approved, procured, and documented AI systems. But the bulk of real-world AI usage sits beneath the surface, untracked and ungoverned.

1/3

Sanctioned Layer

The fraction of actual AI risk surface that most governance programs cover

2/3

Ungoverned Exposure

Embedded and shadow AI that falls outside typical inventory and review processes

Why This Matters More for AI Than It Did for Software

A new AI capability can now appear inside an existing, already-approved tool via a routine vendor update — no new purchase, no new review, no new line in your asset register.

And the risk isn't just 'is this system secure' — it's 'what is this system deciding, and on what data.' Your inventory has to capture use, not just presence.

Traditional Software Risk

Is this system secure? Is it licensed? Is it in our asset register? These questions are necessary but no longer sufficient.

AI-Specific Risk

What is this system deciding? On what data? With what level of human oversight? These questions require a fundamentally different inventory approach.

Building the Map: Where to Actually Look

Effective AI discovery requires looking in places that traditional IT asset management never needed to check. Here are the five most productive discovery channels:

1

SaaS Spend & Expense Reports

Sub-$50-a-month AI tools rarely go through formal procurement. Expense reports and corporate card statements are a goldmine for shadow AI discovery.

2

Vendor Contract Renewals & Release Notes

Embedded AI usually arrives through a routine product update. Reviewing release notes and contract renewals specifically for AI-adjacent language surfaces what's already inside your approved stack.

3

Network & DLP Logs

Traffic to known GenAI domains tells you where shadow AI is being used — often revealing patterns that no survey or self-report would ever capture.

4

Blame-Free Employee Survey

A short survey framed around getting work done faster — not policing unauthorized use — surfaces the tools people actually rely on and the workflows they've quietly rebuilt around AI.

5

Procurement & Legal Questionnaire Archive

Vendor questionnaires reviewed specifically for AI-adjacent language reveal commitments and capabilities that may have been overlooked at the time of signing.

The Discovery Process at a Glance

This four-phase approach ensures that all three layers of AI — sanctioned, embedded, and shadow — are surfaced before any governance or risk assessment work begins. Skipping the collection and survey phases is the most common reason inventories remain incomplete.

Toolkit for This Chapter

Three artefacts operationalize everything above. Each is designed as a full working template that can be opened and used immediately — not a framework to be adapted over months, but a tool to be deployed in days.

1

AIMA-01

AI Governance Framework Primer — the model this whole inventory exercise is built on. Establishes the conceptual foundation and vocabulary for everything that follows.

2

AIMA-02

AI Governance Gap & Risk Assessment Template — turn the inventory into a scored risk picture. Converts raw discovery data into a prioritized view of governance gaps.

3

AIMA-03

AI Maturity Scoping Question Bank — the questions to ask before you run the assessment. Ensures the right stakeholders are engaged and the right scope is defined from the start.

Artefact Register

1

AIMA-01 — AI Governance Framework Primer

A practitioner-level introduction to the OWASP AI Maturity Assessment model: its lineage, its business-function layers, and why regulated use cases need it.

NIST AI RMFEU AI ActPresentation-ready
2

AIMA-02 — AI Governance Gap & Risk Assessment Template

A diagnostic tool for scoping an organization's AI risk exposure, including a risk heat map and a sequenced remediation roadmap.

Maturity ScorecardPresentation-ready
3

AIMA-03 — AI Maturity Scoping Question Bank

A ten-category set of exploratory questions to ask before running any AI maturity assessment, designed to surface the evidence gaps that a self-reported maturity score usually hides.

Pre-assessmentWorking Document
4

GRC-04 — Eight-Stage Cookie & Consent Deployment Workflow

End-to-end consent governance framework — discovery through ongoing monitoring — mapped across GDPR, CCPA, LGPD and India's DPDP Act, with block-until-consent technical controls.

Multi-jurisdictionField-tested

Coming Soon

From Inventory to Risk Picture

An inventory alone doesn't protect the organization. The value is in what you do with it — translating a list of AI systems into a scored, prioritized risk picture that governance teams can act on.

The AIMA-02 template is specifically designed to bridge the gap between Stage 2 and Stage 3 — taking the raw inventory output and applying a consistent scoring methodology so that the highest-risk systems rise to the top of the governance queue.

The Maturity Baseline: Knowing Where You Stand

Inventory tells you what AI you have. Maturity baselining tells you how well you're governing it. These are two distinct questions that require two distinct exercises — and most organizations conflate them, or skip the second entirely.

What Inventory Answers

  • Which AI systems are in use?
  • Who is using them?
  • Are they sanctioned, embedded, or shadow?
  • What data do they touch?
  • What decisions do they influence?

What Maturity Baselining Answers

  • Do we have policies covering these systems?
  • Are those policies enforced?
  • Do we have accountability structures in place?
  • Can we detect and respond to AI-related incidents?
  • Where are the most critical governance gaps?

The AIMA-03 Question Bank is the bridge between these two exercises — it's the set of scoping questions that ensures your maturity assessment is grounded in the actual inventory, not a theoretical model of what AI governance should look like.

What Comes Next

The next chapter in this series covers what to do once vendors are in the frame: vendor and third-party AI risk.

Once the internal inventory is complete and the maturity baseline is established, the governance perimeter expands outward. The AI your vendors are running — inside the tools they sell you, inside the services they deliver — becomes the next critical frontier.

Chapter 01 · Act I

AI Inventory & Maturity Baselining — map what you have before you govern it

Chapter 02 · Act I

Vendor & Third-Party AI Risk — extend the governance perimeter beyond your own walls

Act II — See Clearly

Risk assessment, classification, and the frameworks that turn inventory into action

Act III — Act on It

Policy, controls, accountability structures, and the operating model for sustained AI governance