Most of these arrive as a feature of something you bought rather than as a project anyone called AI. That is exactly why they are missing from the register.
Retail AI touches more people, more often, than in almost any other sector, and it does so in public. A pricing model behaving oddly is a news story rather than an internal incident, and reputational damage arrives long before regulatory action does.
The estate is also unusually federated. Marketing bought a personalisation engine, operations bought forecasting, loss prevention bought something with a camera, and HR bought screening — often without a shared record. That is not a failure of process so much as a consequence of how retail technology gets purchased, and it is why discovery matters more here than governance frameworks do.
One register across a federated estate
Marketing, operations, loss prevention and HR systems in the same place — usually the first time anyone has seen the whole picture, because no single procurement record contains it.
Vendor and data source mapping
Which third party sits behind each system and what data flows into it, so a vendor question becomes a scoped list rather than a week of discovery.
Data types recorded per system
Including biometric and personal data, so the systems carrying the heaviest obligations stand out from the forecasting models.
Human oversight and explainability
Recorded per system: what drives the decision and who can overrule it — the question you need answered before anyone asks how a price or a flag was set.
EU AI Act classification per system
Each system classified by what it is used for, with the reasoning stored alongside it, so employment screening and customer-facing tools are triaged properly.
Adoption and ROI per system
Cost to deliver, running cost and adoption tracked against the objective each system was meant to serve.
Marketing, operations, loss prevention and HR systems in the same place, which is usually the first time anyone has seen the full picture.
Anything touching biometric data flagged as the distinct regulatory problem it is, rather than sitting in a list beside a forecasting model.
Recorded per system: what drives the decision, who can overrule it, and what a customer would be told if they asked.
Which matters in a sector where the first question often comes from a journalist rather than a regulator.
CXO Ready is an aid, not an assurance. It helps you structure your thinking, record what you have done and see where the gaps are. It does not make you compliant, and nothing it produces is legal advice or a regulatory opinion. Scores are indicative. Responsibility for compliance stays with your organisation, and decisions with legal consequences should be taken with a qualified adviser.
Before you start
It records the data types each system uses, so anything touching biometric data is visibly separated from the forecasting and personalisation models. Lawful basis, DPIA status and human oversight are captured against those systems specifically, which is what you need in front of you before deciding whether a deployment is justified.
Not in itself under the EU AI Act, which does not list it in Annex III. The exposure is elsewhere: consumer fairness, and whether pricing varies by characteristics that would be discriminatory if stated openly. The governance question is whether you can explain what drove an individual price — and most retailers currently cannot.
Surveys, framed as amnesty rather than audit. Retail estates are federated by nature, so no central procurement record will show you everything. Ask teams what they use and what it does, and expect to find several systems nobody at the centre knew about — that is the normal result, not a sign of a badly run business.
Not for your use of it. A vendor may be the provider under the EU AI Act while you are the deployer, and deployers carry their own obligations around human oversight, monitoring and informing affected people. You also cannot delegate the UK GDPR accountability for decisions made about your customers.
With the customer-facing systems and anything involving biometrics or employment screening. Those carry the heaviest obligations and the highest reputational exposure. Forecasting and supply chain models matter commercially but are rarely where the regulatory risk sits, so they can follow.
More in the full FAQ, or ask us directly.