An AI system inventory template for SMEs is the fastest way to turn scattered tools into a decision-ready register of owned systems, data flows, vendors and accountable owners. It applies to any SME already using AI-enabled tools without a shared record of what exists, who approved it, what data it touches, and what action should follow. The practical outcome is a single table the leadership team can use to decide whether to keep, control, replace, or stop each system. This article gives a weighted decision matrix, a threshold for action, the evidence to inspect, and a 30-day plan aligned with AI governance and AI risk assessment needs.
For the publisher’s context, see AI AUDIT home and the AI AUDIT blog. If you need a structured next step after the inventory, a guided SME AI audit helps convert the register into a prioritized action list.
Decision criteria
The inventory should answer one question: is the system controlled enough for the business to rely on it? For an AI audit for SMEs, each item should be judged on business purpose, data sensitivity, human oversight, vendor dependence, and traceability. The CNIL guidance is useful here because it ties AI use to data protection, accountability and control of processing activities CNIL AI guidance. The EU AI Act also supports a risk-based approach, with obligations that depend on the role and risk profile of the system EU AI Act text.
Owner: business lead with IT, legal or a named internal reviewer.
Evidence to inspect: contract, prompts or configuration, logs, data categories, human review step.
Decision threshold: if any core area is undocumented, the item moves to control or stop.
Matrix to complete
Use a weighted matrix from 1 to 5. Multiply each score by its weight, then total the result. The score does not replace judgment; it makes trade-offs visible.
| Criterion | Weight | Score 1-5 | Evidence to inspect | Owner | Alert threshold |
|---|---|---|---|---|---|
| Clear business purpose | 20% | Defined use case | Business lead | <3 | |
| Sensitive data exposure | 25% | Data classes, fields | DPO / IT | >3 | |
| Human oversight in practice | 20% | Review step, approval | Manager | <3 | |
| Vendor dependence | 15% | Contract, exit route | Procurement / Legal | >3 | |
| Traceability and logs | 20% | Usage history | IT / AI owner | <3 |
Decision threshold: 75/100 or above = keep with controls; 50-74 = control and remediate; below 50 = stop or replace. This supports AI governance and practical AI Act readiness because it creates a documented, reviewable control layer. The OECD AI principles also emphasize transparency, robustness and accountability, which are hard to demonstrate without an owned inventory OECD AI principles.
Interpretation
A useful inventory is not just a software list. It records decisions already made: who approved the system, on what basis, with which data, and when it will be reviewed again. That is why an AI system inventory template for SMEs should begin with visible tools, then map the data, vendors, and users behind each one.
Owner: one accountable person per system.
Evidence to inspect: launch date, business justification, incidents, monthly review notes.
Decision: if no evidence exists, do not assume the system is safe just because it is convenient.
For a practical format, compare the logic with an AI audit report example for SMEs and with a healthcare SME audit article, which shows how evidence changes when data sensitivity increases.
Action plan
A 30-day rollout can stay compact if each step has an owner, evidence and threshold.
Identify AI-enabled systems, automations and external services.
Owner: IT or operations lead.
Evidence: account list, contracts, integration list.
Decision: anything without an owner is marked unverified.Classify the data each system touches.
Owner: legal, privacy or compliance lead.
Evidence: field list, data categories, purpose.
Decision: if sensitive data is used without a strong need, reduce scope or stop.Score each item using the matrix.
Owner: business sponsor.
Evidence: filled matrix and rationale.
Decision: low scores trigger remediation first.Choose keep, control, replace or stop.
Owner: leadership team.
Evidence: threshold result and action note.
Decision: no item should remain “unknown” past the review date.Measure value after 30 days.
Owner: sponsor.
Evidence: number of systems inventoried, decisions taken, issues closed, controls added.
Decision: value is real only if the inventory changes behavior.
Hypothetical example
A SME in professional services uses an AI drafting assistant, a lead-scoring tool and an automatic call summary service. The inventory shows that the drafting assistant uses only public templates, the lead-scoring tool receives client files, and the call summary service processes recorded conversations.
Decision outcome:
- Drafting assistant: 84/100, keep with usage rules.
- Lead-scoring tool: 67/100, control and remove client-file inputs.
- Call summary service: 46/100, stop until legal and technical review is completed.
Evidence: vendor terms, configuration settings, access logs.
Owner: sales leader, IT, legal.
30-day value: fewer undocumented tools, clearer accountability, and a register ready for a broader AI audit for SMEs.
Questions and answers
Which evidence should be checked before deciding?
Check the contract, the data sent to the tool, log history, human review points, and whether the system can be removed without disrupting operations.
How should value be measured after 30 days?
Measure how many systems are inventoried, how many decisions were made, and how many risks were reduced. If the team only produced a document, the exercise is incomplete.
What concrete outcome should an SME obtain?
A live register that names each system’s owner, data types, vendor, evidence set and decision status. That is the minimum useful output before any deeper audit.