Inventory
Which systems, which providers, which users, which data, which purpose — fully and currently documented.
focus area · assess the inventory, classify the risks
In most companies AI has long been in use — often without an overview: browser tools in sales, assistants in office products, AI features in specialist software, pilot projects from departments. The AI audit records this inventory, evaluates it by law, security and benefit and delivers a prioritised action plan.
An audit pays off as soon as AI is used in the company without anyone knowing the complete list. Typical triggers are enquiries from the data protection officer, requirements from customers or certifiers, the AI literacy obligation under Art. 4 EU AI Act, an upcoming automation project — or simply the wish to know the costs and risks of existing tools.
We record all AI applications and AI features — procured, embedded or self-built — and evaluate them along five dimensions.
Which systems, which providers, which users, which data, which purpose — fully and currently documented.
Classification of every application into the risk classes; transparency and literacy obligations; contracts and data processing agreements.
Which personal data flows where; legal bases, deletion concepts, third-country transfers.
Access, permissions, logging, handling of trade secrets and prompt content.
Licence and usage costs per application against the actual contribution in the process.
Shadow AI arises when employees use helpful tools for which no rule exists. That is rarely ill intent but a sign of real need. The audit makes this use visible, assesses the risk and proposes which tools should be brought into regulated channels, replaced or discontinued.
Tone matters: we talk to departments as participants, not as suspects. Only then does the inventory become complete.
You receive an audit report with a complete AI inventory, risk classification per application, identified deviations and a prioritised action plan. The actions are concrete: adjust a contract, change a setting, replace a tool, run training, add to a policy.
The audit is a starting point, not an end point. The results flow directly into the Use Case Discovery, the AI Readiness Check and — if desired — into architecture planning and an AI strategy following the Sellium Method. The inventory becomes a reasoned plan for where AI should do more in your company and where it belongs restricted.
privacy first ai
The prohibitions and transparency obligations of the EU AI Act already apply; the high-risk obligations follow in 2027 and 2028. An audit creates the overview that regulators, customers and certifiers increasingly expect.
We evaluate tools by benefit and risk for your company — without ties to any provider.
Every finding is traceably evidenced and usable for data protection officers and auditors.
Results flow directly into the AI policy, training planning and Use Case Discovery.
process
A compact procedure with clearly defined results.
Definition of scope, contacts and information sources; alignment with data protection and IT security.
Interviews with departments, evaluation of licence and access data, review of contracts and system settings.
Classification of every application under the EU AI Act, data protection, security and economics; identification of deviations.
Presentation of results to management and stakeholders, prioritised action plan, handover of the AI inventory.
contact
Happy to help with anything AI. We will get back to you promptly.
We will get back to you shortly. If it is urgent, you can reach us at +49 371 524 99 140 or contact@sellium.ai.