Maintain it for the right conversations
Maintain the inventory for your AI committee, risk review, vendor oversight, audit prep, and examiner conversations. Do not treat this card as exam readiness by itself; it is the starting record that makes oversight possible.
- The AIEOG AI Lexicon defines an AI use-case inventory as a maintained record supporting governance, transparency, and risk management.
- The Lexicon is an optional shared-vocabulary tool, not a supervisory mandate.
- Use one row per AI-touched workflow. A use case is the task, not only the tool name.
Start with the 30-minute AI Inventory Sprint
Use this quick sprint to get the first usable register started before expanding into department-by-department review.
- Ask every department where AI, GenAI, embedded AI, or vendor AI features touch work today.
- Separate the workflow from the system name.
- Classify data class and risk tier separately.
- Assign one accountable owner.
- Record human review, evidence retained, last review date, and next review date.
Core register columns
Create one row per AI-touched workflow. Keep data class and risk tier separate so sensitive data does not automatically become a risk rating, and lower-data workflows are still reviewed when they can affect customers or regulated work.
Core register fields
| Column | What to record |
|---|---|
| Workflow | The actual task, not the system name. |
| Tool / vendor | Product, vendor, embedded feature, internal model, or public tool. |
| Use-case status | Proposed, sandbox, approved, restricted, retired, or blocked. |
| Data Class | Public, Internal, Confidential, NPI, or Regulated / exam-sensitive. |
| Risk Tier | Low, Medium, High, or Blocked. Keep this separate from data class. |
| Customer impact? | Yes / no. Include whether output may affect service, eligibility, pricing, fraud, collections, or communications. |
| Regulated workflow? | Lending, BSA/AML, fraud, complaints, marketing, HR, regulatory reporting, or none. |
| Owner | A person, not a committee or generic department. |
| Human review | None, sampled, mandatory, second-line, or committee approval. |
| Evidence retained | Prompt, output, ticket, reviewer note, approval, vendor review, or location. |
| Last reviewed | Date the row was last confirmed. |
| Next review | Date or cadence for the next review. |
Vendor-control add-on
For vendor or embedded AI features, add fields for the third-party control evidence reviewers will ask to see.
Third-party AI control fields
| Field | What to record |
|---|---|
| Due diligence status | Has InfoSec, Compliance, Risk, and the business owner reviewed the tool for this use? |
| Contract review | Does the agreement address confidentiality, audit, regulatory access, breach notice, and use limits? |
| Data-use terms | May the vendor use prompts, outputs, or bank data for model training or product improvement? |
| Model-training terms | Is training on bank/customer data prohibited or opt-out confirmed in writing? |
| Retention/deletion | How long are prompts and outputs retained, and how are they deleted? |
| Subcontractors | What subprocessors, hosted models, or infrastructure providers are involved? |
| Ongoing monitoring owner | Who reviews performance, incidents, complaints, and vendor changes? |
| Termination / data-return plan | How will access be revoked and bank data returned or deleted? |
Risk-tier guide
Tier on the highest factor that applies. The goal is consistency across departments, not false precision.
Simple tier definitions
| Tier | Definition |
|---|---|
| Low | Internal drafting, public or approved internal data, no customer impact, no regulated decision, approved tool, and human review before use. |
| Medium | Internal process support, customer-facing draft content, confidential internal data, or operational workflow support where human review is required. |
| High | Decision support for credit, fraud, BSA/AML, sanctions, complaints, regulatory reporting, customer-impacting workflows, or NPI used only in an approved private environment. |
| Blocked | Public AI tool with NPI, SAR/AML detail, examination-sensitive information, privileged material, security controls, or final regulated decisions. |
- Model-risk note: Where an AI use case informs quantitative, customer-impacting, or regulated decisions, evaluate whether model-risk controls apply under current guidance, including SR 26-2 where applicable. For generative AI workflows, maintain inventory, ownership, data controls, vendor oversight, human review, and review cadence even when the workflow is not treated as a formal model.
Sample rows
Use these examples to calibrate the first pass. They are deliberately simple so reviewers can see why the tier changes.
Starter examples
| Example | Use case | Data class | Risk tier | Required control |
|---|---|---|---|---|
| Low | Summarize public regulator press releases for internal training. | Public | Low | Human editor confirms accuracy before training use. |
| Medium | Draft customer email language using approved templates and no customer data. | Internal | Medium | Marketing and Compliance review before sending. |
| High | Analyze fraud patterns in an approved enterprise environment. | NPI / regulated | High | Mandatory review, vendor controls, evidence retention, quarterly review. |
| Blocked | Enter loan-file details or SAR investigation notes into a public AI tool. | NPI / SAR-sensitive | Blocked | Do not use. Escalate to AI Program Owner and Compliance. |
Next step: Download the editable AI Use-Case Inventory Spreadsheet
Use the spreadsheet companion at /downloads/artifact-ai-use-case-inventory-spreadsheet.xlsx to track owner, data class, risk tier, vendor status, human review, evidence retained, last review, and next review date.
- Adapt tier definitions, approval roles, cadence, data classes, and vendor-control fields before adoption.
- Keep enough history to show when use started, changed, stopped, or moved into a different control path.