Back to templates
    Template

    AI system register

    A three-sheet register: every AI system with its two roles and its owner, one impact assessment per system, and the Annex A statement of applicability.

    Compliance5 Sept 20263 min read

    ISO/IEC 42001:2023Regulation (EU) 2024/1689
    On this page
    Download the template

    ai-system-register.xlsx · 11 kBLicensed CC BY 4.0

    What this is

    The inventory an AI management system cannot be scoped without. Clause 4.3 asks for the boundaries and applicability as documented information. Clause 4.1 asks the organisation to determine its roles in relation to the AI systems it develops, provides or uses 1. Three sheets carry the answer: what runs, what it does to people, and which Annex A controls apply.

    How to use it

    1. Delete the nine example rows across the three sheets before the first entry.
    2. Fill the Systems sheet from what actually runs, not from a procurement list. See the companion playbook, section 3.1.
    3. Answer both role columns. The organisational role is the one clause 4.1 asks for; its note names six without closing the list: AI providers, AI producers, AI customers, AI partners, AI subjects and relevant authorities 2. The AI Act role is the legal one, decided separately.
    4. Set the class column from the decision test. Article 6(2) catches the Annex III areas, and Article 50 duties reach systems that are not high-risk 3. The reasoning belongs in the AI use-case triage form, whose row ID this register cites.
    5. Write one impact assessment per system on the second sheet. Clause 6.1.4 asks for the consequences to people, to groups and to society, documented and fed back into the risk assessment 4.
    6. Judge every Annex A control on the third sheet. Clause 6.1.3 asks for a justification for every inclusion and exclusion, and control A.7.5 Data provenance is the row most often left blank 5.
    7. Set the last review date on every system row, and diary the next one.

    What good looks like

    Five of the thirteen Systems columns, from the workbook.

    IDNameOrganisational roleAI Act roleAI Act class
    AIS-001Screening and ranking of job applications3. AI customer2. Deployer2. High-risk, Annex III
    AIS-002Support assistant drafting replies for agents3. AI customer2. Deployer4. Transparency duty, Art. 50
    AIS-003Demand forecast built in-house for logistics planning2. AI producer1. Provider5. Other

    Fields

    FieldRequiredMeaningCommon mistake
    Organisational roleyesThe role clause 4.1 asks the organisation to determineCopying the AI Act role into it
    AI Act roleyesProvider, deployer, both, or outside the ActReading provider duties onto a deployer
    AI Act classyesWhich tier of duties the row carriesAn impression, not the triage answer
    System owner, oversight owneryesThe two accountable roles, never peopleOne name in both cells
    Impact assessment IDyesThe record on the second sheetA system row with no assessment
    Triage row IDyesThe decision that let the system inA register row no decision produced
    Applicable, JustificationyesThe Annex A judgement and its reasonA reason that fits any organisation

    Download

    • File: ai-system-register.xlsx (xlsx, 11 KB) — four sheets: Read first, Systems, Impact assessments, Controls.
    • Markdown variant: the same sheets in plain markdown, at content/templates/assets/_ai-system-register.md.
    • Licence: CC BY 4.0 — reuse and adapt with attribution to GRCIDE.
    • Version: 1.0, 2026-09-05. No personal data, no organisation names, invented example rows.

    References

    1. ISO/IEC. Information technology — Artificial intelligence — Management system. ISO/IEC 42001:2023. Read from a licensed copy of the English text, 2026-09-05. https://www.iso.org/standard/42001
    2. European Parliament and Council. Regulation (EU) 2024/1689 (AI Act), consolidated text of 27 July 2026. CELEX 02024R1689-20260727. Read 2026-09-05. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:02024R1689-20260727

    Clause and Annex A numbers and titles are reproduced as printed; every requirement is paraphrased. Review intervals are organisational choices.

    Standards and certification names are the property of their respective owners. GRCIDE is an independent publication, not affiliated with, authorized, sponsored or endorsed by ISO, IEC, NIST or any other standards body.

    Sources

    1. 1ISO/IEC 42001:2023 clauses 4.1 and 4.3, licensed copy · verified 2026-09-05
    2. 2ISO/IEC 42001:2023 clause 4.1, licensed copy · verified 2026-09-05
    3. 3EU Publications Office CELEX 02024R1689-20260727 Art. 6(2) and Art. 50(1) to 50(4) · verified 2026-09-05
    4. 4ISO/IEC 42001:2023 clause 6.1.4, licensed copy · verified 2026-09-05
    5. 5ISO/IEC 42001:2023 clause 6.1.3 and Annex A control A.7.5, licensed copy · verified 2026-09-05