MindForge Toolkit
The AI inventory
The AI inventory is where a firm records what AI it uses and keeps that record current. It is one of the seventeen areas in the MindForge AI Risk Management Toolkit, the Singapore industry's practices for the AIRG. This guide sets out the MindForge practice, the AIRG expectation it meets, and the evidence it produces. I wrote the AIRG, and the inventory is the one control I would build first, because every other control only reaches the AI the inventory records.
What the AIRG expects
The AIRG expects a financial institution to keep an accurate, up-to-date inventory of its AI use cases, so that AI risk can be aggregated across the firm and controls applied consistently. It is a standard of outcome: the firm must be able to show it knows where its AI is. The AIRG says what the inventory is for; it does not prescribe the system. For how the inventory works with materiality and the lifecycle controls, see the AIRG in practice.
What MindForge says to do
The Toolkit treats the inventory as a repository of core attributes with two jobs: keeping AI within the scope it was approved for, and giving management an enterprise-wide view for monitoring and decisions. It is pragmatic about the system itself. A firm can extend an existing asset inventory with AI-specific fields, link several existing registers to function as one, or build a dedicated system. What matters is that the information is captured, not which tool holds it.
The six core attributes
MindForge sets a minimum of six attributes to record for each AI use case:
- Purpose and scope - the intended uses, users and jurisdictions, and whether it touches customers or regulators. This is the central job: keeping AI to its approved purpose.
- Type of AI - regression, generative, agentic, computer vision, and the input and output modality, because many risks are specific to the type.
- Data used - the data types, their provenance, and sensitivities, distinguishing training data from operational data such as user input or RAG content.
- Risks and mitigations - the materiality rating, the AI-specific risks, and the controls against them, linked to the risk register rather than duplicated where that register already holds them.
- Status and governance - the use-case owner, the lifecycle status, the approvals or exemptions granted, and the evaluations done, so a firm can tell whether something was deployed with the approvals it needed.
- Third-party AI information - licence type, provider, foundation-model version, and vendor disclosures such as AI Cards.
Firms record every use case, including the very low-risk ones, so the enterprise-wide picture is complete; the depth recorded can scale with materiality.
Keeping it current
An inventory is only useful if it is maintained, so MindForge defines three roles: the use-case owner, accountable for entering and updating their own entries; an AI-specific reviewer, who checks an entry is accurate and complete; and an inventory owner, usually a control function such as model or technology risk, accountable for the inventory's overall health and its schema. Basic information is recorded at the start of the lifecycle and the rest before deployment, with periodic check-ins to keep it current. Post-deployment evaluations double as a control on the inventory itself, flagging where a live system has drifted from what was recorded.
In practice
What good looks like. One enterprise-wide view of your AI (whether or not it is a single system), the six core attributes recorded for every use case before deployment, the three maintenance roles named and filled, and a schema someone owns and reviews. The low-risk use cases are in it too, so the picture is complete.
Evidence to hold:
- An export of the inventory with the six attributes populated, reconciled against your model, vendor and IT registers.
- The maintenance procedure and the named use-case owner, reviewer, and inventory owner.
- A decommissioning log, and evidence that post-deployment evaluation flags drift from recorded attributes.
How banks do it
The MindForge Implementation Examples show the pattern in practice: banks such as DBS and Prudential each built a central repository that gives a firm-wide view of their AI, feeding risk monitoring and deployment approvals rather than sitting as a static list.
My take
You cannot govern what you cannot find. Most firms have a spreadsheet, not an inventory - which tells you everything.
The inventory is the control I would build first, and the one most often faked. MindForge's six attributes are what turn a spreadsheet of model names into something you can actually govern from. (From my book, AI Risk Management for Directors.)
Work with me
I train and advise financial institutions on building a working AI inventory and the rest of the AIRG programme. See the courses and workshops, read more on AI risk management, or get in touch.
A guide in The MindForge AI Risk Management Toolkit, area by area. See also the AIRG, MindForge and CRI mapping.