Someone asks how many AI systems the organisation runs. You know the answer is more than the list you can produce, because procurement went through cards, because three teams built something over a weekend, and because half your SaaS vendors added AI features without telling anyone.
The gap between what you can evidence and what is actually running is the whole problem. It is not that governance is hard — it is that governance has no object to attach to until the register exists.
Every AI system, model and vendor tool in one place, with purpose, data touched, vendor and integration mapped per entry.
Short surveys across the business bring unsanctioned tools into the register before they arrive as an incident report.
A named business owner and a named technical owner per system, because accountability for AI usually falls into the gap between those two roles.
Each system classified by what it is used for, with the reasoning recorded, so the answer holds up when someone asks why.
Not the number of AI systems, but whether you can produce an accurate list on demand and say who owns each one. That is the question that arrives without warning, and the one that is hardest to answer retrospectively.
CXO Ready is an aid, not an assurance. It helps you structure your thinking, record what you have done and see where the gaps are. It does not make you compliant, and nothing it produces is legal advice or a regulatory opinion. Scores are indicative. Responsibility for compliance stays with your organisation, and decisions with legal consequences should be taken with a qualified adviser.
Before you start
Days for the systems you already know about. The unknown portion depends on how many parts of the business you need to survey, and that is usually where the real estate turns up — most organisations find between two and four times what they expected.
Yes, and this is the most commonly missed category. An AI summarisation feature in a tool your HR team uses is processing personal data and making inferences, whether or not you procured it as AI. Record it by the use it is put to rather than by how it was bought.
No. A CMDB records what is deployed; this records what each AI system does, who is accountable, what data it touches and how it scores against regulatory expectations. They answer different questions and most organisations keep both.
By making it the thing people are asked about rather than a periodic exercise. Owners are named per system, gaps generate tasks against those owners, and scores move when evidence changes — so the register is maintained as a side effect of the governance process rather than as a separate chore.
More in the full FAQ, or ask us directly.
Other roles