AI system register
A three-sheet register: every AI system with its two roles and its owner, one impact assessment per system, and the Annex A statement of applicability.
Compliance5 Sept 20263 min read
On this page
ai-system-register.xlsx · 11 kBLicensed CC BY 4.0
What this is
The inventory an AI management system cannot be scoped without. Clause 4.3 asks for the boundaries and applicability as documented information. Clause 4.1 asks the organisation to determine its roles in relation to the AI systems it develops, provides or uses 1. Three sheets carry the answer: what runs, what it does to people, and which Annex A controls apply.
How to use it
- Delete the nine example rows across the three sheets before the first entry.
- Fill the Systems sheet from what actually runs, not from a procurement list. See the companion playbook, section 3.1.
- Answer both role columns. The organisational role is the one clause 4.1 asks for; its note names six without closing the list: AI providers, AI producers, AI customers, AI partners, AI subjects and relevant authorities 2. The AI Act role is the legal one, decided separately.
- Set the class column from the decision test. Article 6(2) catches the Annex III areas, and Article 50 duties reach systems that are not high-risk 3. The reasoning belongs in the AI use-case triage form, whose row ID this register cites.
- Write one impact assessment per system on the second sheet. Clause 6.1.4 asks for the consequences to people, to groups and to society, documented and fed back into the risk assessment 4.
- Judge every Annex A control on the third sheet. Clause 6.1.3 asks for a justification for every inclusion and exclusion, and control A.7.5 Data provenance is the row most often left blank 5.
- Set the last review date on every system row, and diary the next one.
What good looks like
Five of the thirteen Systems columns, from the workbook.
| ID | Name | Organisational role | AI Act role | AI Act class |
|---|---|---|---|---|
| AIS-001 | Screening and ranking of job applications | 3. AI customer | 2. Deployer | 2. High-risk, Annex III |
| AIS-002 | Support assistant drafting replies for agents | 3. AI customer | 2. Deployer | 4. Transparency duty, Art. 50 |
| AIS-003 | Demand forecast built in-house for logistics planning | 2. AI producer | 1. Provider | 5. Other |
Fields
| Field | Required | Meaning | Common mistake |
|---|---|---|---|
| Organisational role | yes | The role clause 4.1 asks the organisation to determine | Copying the AI Act role into it |
| AI Act role | yes | Provider, deployer, both, or outside the Act | Reading provider duties onto a deployer |
| AI Act class | yes | Which tier of duties the row carries | An impression, not the triage answer |
| System owner, oversight owner | yes | The two accountable roles, never people | One name in both cells |
| Impact assessment ID | yes | The record on the second sheet | A system row with no assessment |
| Triage row ID | yes | The decision that let the system in | A register row no decision produced |
| Applicable, Justification | yes | The Annex A judgement and its reason | A reason that fits any organisation |
Download
- File:
ai-system-register.xlsx(xlsx, 11 KB) — four sheets: Read first, Systems, Impact assessments, Controls. - Markdown variant: the same sheets in plain markdown, at
content/templates/assets/_ai-system-register.md. - Licence: CC BY 4.0 — reuse and adapt with attribution to GRCIDE.
- Version: 1.0, 2026-09-05. No personal data, no organisation names, invented example rows.
Related
- Playbook: ISO/IEC 42001: an AI management system that fits the ISMS
- Template: AI use-case triage form
- Briefing: EU AI Act for security governance
- Radar: ISO/IEC 42006:2025 completes the certification route
References
- ISO/IEC. Information technology — Artificial intelligence — Management system. ISO/IEC 42001:2023. Read from a licensed copy of the English text, 2026-09-05. https://www.iso.org/standard/42001
- European Parliament and Council. Regulation (EU) 2024/1689 (AI Act), consolidated text of 27 July 2026. CELEX 02024R1689-20260727. Read 2026-09-05. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:02024R1689-20260727
Clause and Annex A numbers and titles are reproduced as printed; every requirement is paraphrased. Review intervals are organisational choices.
Standards and certification names are the property of their respective owners. GRCIDE is an independent publication, not affiliated with, authorized, sponsored or endorsed by ISO, IEC, NIST or any other standards body.
Sources
- 1ISO/IEC 42001:2023 clauses 4.1 and 4.3, licensed copy · verified 2026-09-05
- 2ISO/IEC 42001:2023 clause 4.1, licensed copy · verified 2026-09-05
- 3EU Publications Office CELEX 02024R1689-20260727 Art. 6(2) and Art. 50(1) to 50(4) · verified 2026-09-05
- 4ISO/IEC 42001:2023 clause 6.1.4, licensed copy · verified 2026-09-05
- 5ISO/IEC 42001:2023 clause 6.1.3 and Annex A control A.7.5, licensed copy · verified 2026-09-05
Related
- AI use-case triage form
Template
- EU AI Act for security governance
Briefing
- GRC automation patterns
Reference