ISO 9001:2026 was published on 16 September. See what changed →


Building an AI System Inventory: The Most Overdue Step for Australian Small Businesses

Ask most small business owners which AI tools are being used across their business, and the honest answer is usually a guess. Not because nobody cares, but because nobody has ever actually looked. That gap, between what’s really happening and what leadership can see, is the starting problem every AI governance effort runs into, and it’s also the most overdue fix. Before a business can write a sensible AI policy, assess vendor risk, or move toward ISO 42001, it needs one thing first: an honest, written AI system inventory. This post covers what that inventory actually needs to capture, why most businesses have never built one, and how to put one together without a compliance department.

Why this is the step everyone skips

It’s an easy step to skip because it doesn’t feel urgent. Writing a policy feels like progress. Building a register of tools feels like admin. But a policy written before the inventory exists is really just a guess dressed up as a document, it can only govern the AI usage someone already knew about.

Recent workforce data backs up why the gap is bigger than most owners assume. Microsoft’s 2025 Work Trend Index found that 52 percent of employees already use AI tools their employer never provided (source: Airia’s summary of the Microsoft 2025 Work Trend Index). If a business has never asked the question, there is no reason to assume its own numbers are any lower.

What an AI system inventory actually needs to capture

This doesn’t need to be complicated, and it doesn’t need software to start it. According to ISO 42001’s documentation requirements, a proper AI system record captures a specific, short list of attributes for each tool in use (source: Knowlee’s ISO 42001 checklist):

  • Purpose and intended use, what the tool is actually being used for, in plain terms.
  • Who uses it, which roles or people rely on it day to day.
  • What data goes into it, client details, financial figures, or anything else typed or uploaded.
  • Known limitations, anywhere the tool has been wrong, misleading, or needed correction before.
  • A named owner, one person responsible for that tool, even in a five-person business.
  • Its current status, actively used, trialled once and abandoned, or under review.

How to actually build one, without a compliance team

Start with a conversation, not a form

The fastest way to build a first draft of this inventory is to ask staff directly: what AI tools do you actually use, and for what? A five-minute conversation with each person will surface more real usage than any policy memo ever will, because it removes the fear that admitting to using a tool means getting in trouble for it.

Write down what you find, even if it’s incomplete

An inventory with six known tools and an honest note that says “there may be more we haven’t found yet” is worth far more than no inventory at all. The goal at this stage is visibility, not perfection. Gaps can be closed later; an inventory that doesn’t exist yet can’t be improved.

Revisit it on a set schedule

AI tools change fast, and a business that builds this list once and never returns to it will be back to guessing within a year. Tying a quick review to an existing habit, a quarterly check-in, a management meeting, keeps the inventory honest without adding a whole new process.

What changes once the business can actually see its own AI usage

An honest inventory is what makes everything that follows possible. It’s the difference between a policy that says “use AI responsibly” and one that names the three tools actually in use and sets real rules for each. It’s what lets a business assess whether a specific AI vendor’s terms of service are actually acceptable, rather than assessing vendor risk in the abstract. And it’s the first thing a genuine AI incident process needs to exist against, since a business can’t investigate a problem with a tool it didn’t know was in use.

The bottom line

Most small businesses don’t have an AI governance problem because they’ve made bad decisions about AI. They have one because nobody has ever written down what’s actually happening. Building an honest AI system inventory, even a rough first draft, is the single most overdue step most Australian small businesses can take, and it’s the step every other part of ISO 42001 readiness depends on. Start with a conversation this week, write down what you learn, and revisit it before the tools change again.

Sources

Airia — Shadow AI Statistics: Key Data Points Every CISO Needs in 2026 (summarising Microsoft’s 2025 Work Trend Index)

Knowlee — ISO 42001 Checklist (2026): 38 Controls for AI Management



Leave a Reply

Your email address will not be published. Required fields are marked *