How to build an AI inventory and risk register for a fashion company
An AI inventory is the first document regulators, auditors and boards will ask for. A step-by-step method for fashion brands and retailers, with the fields that matter.
KEY TAKEAWAYS Summary by the editors
- An AI inventory is an organised record of every AI system a company develops or uses, with its purpose, owner, data and risk classification.
- The European Commission published non-binding guidelines on the AI Act's definition of an AI system on 6 February 2025 to help companies decide which software is in scope.
- The NIST AI Risk Management Framework describes an AI system inventory as an organised database of artifacts relating to an AI system or model.
- ISO/IEC 42001:2023, published in December 2023, specifies requirements for an AI management system and is a common reference for structuring AI governance.
- A company can become a provider of a high-risk system under Article 25 of the AI Act if it rebrands, substantially modifies or repurposes a system, so the inventory should record modifications.
An AI inventory is a register of every AI system a fashion company builds, buys or uses, recording what it does, who owns it, which data it touches and how risky it is. The risk register attached to it records what could go wrong and what controls are in place. Together they are the foundation for EU AI Act compliance, for GDPR assessments and for any board discussion about AI, because no other governance step works without knowing what is in use.
Why does a fashion company need an AI inventory?
Fashion businesses rarely run one large AI system. They run dozens of small ones: a forecasting module in the planning suite, generative features in the design and DAM tools, recommendations on the webshop, a chatbot, translation in the PIM, candidate screening in HR. Much of this AI arrives as a feature update in software already licensed, without a procurement decision. An inventory turns that scattered picture into something that can be classified under the AI Act, matched to GDPR records and reported to leadership.
The inventory also answers a role question. Under the AI Act, obligations differ for providers and deployers. Article 25 states that a company becomes the provider of a high-risk system if it puts its own name or trademark on it, makes a substantial modification, or changes a system's intended purpose so that it becomes high-risk. Recording customisations is therefore not housekeeping; it can change who carries the legal duties.
What counts as an AI system?
The AI Act has its own definition of an AI system, and the Commission published non-binding guidelines on 6 February 2025 to help companies apply it. The guidelines explain how the legal definition applies in practice; they are not binding, and the Commission says it will update them as new use cases emerge. Borderline cases are common in fashion software, from rule-based replenishment to machine-learning forecasting. When in doubt, include the tool in the inventory and mark the classification as pending; it is cheaper to exclude later than to discover an omission during an audit.

How do you build the inventory step by step?
- Set scope and ownership. Name an accountable executive and a coordinator, and decide whether the register covers all entities and countries.
- Collect from four sources. Software licence lists, procurement and vendor contracts, a short survey of department heads, and IT logs of AI services in use, including browser-based generative tools.
- Record each system with standard fields (see the table below).
- Classify under the AI Act. Prohibited, high-risk, transparency duty or minimal risk, plus the company's role as provider or deployer.
- Link to GDPR records. Cross-reference the record of processing activities and any data protection impact assessment.
- Assess risks and controls in the risk register, with a rating and an owner for each risk.
- Set a review trigger. New tools, major vendor updates, new use cases and incidents should all prompt an update.
| Field | Example entry | Why it matters |
|---|---|---|
| System and vendor | Image generator in DAM, vendor X | Identifies the provider for questions and contracts |
| Business owner | Head of E-commerce Content | Accountability for use and changes |
| Intended purpose | Generate background variants for product images | Determines AI Act classification |
| Users and countries | Content team, EU and UK webshops | Scope of literacy duties and applicable law |
| Data used | Product photos; no personal data | GDPR relevance and confidentiality |
| Output use | Published on product detail pages | Triggers transparency or consumer law checks |
| AI Act class and role | Transparency (Article 50), deployer | Defines obligations |
| Customisation | None; standard configuration | Signals possible provider status if modified |
| Human oversight | Editor approves each image | Key control for most risks |
| Status and review date | Live; review in six months | Keeps the register current |
What goes into the risk register?
The risk register sits alongside the inventory and records specific risks per system. For fashion companies, recurring categories include:
- Regulatory: misclassification, missing disclosure of AI imagery or chatbots, prohibited uses such as workplace emotion recognition.
- Data protection: customer or employee data used without a legal basis or beyond its original purpose.
- Intellectual property: generated designs or images that resemble protected work, and uncertainty about rights in training data.
- Accuracy and brand: wrong product attributes, misleading fit information, off-brand tone.
- Bias: recommendations, sizing or hiring outputs that disadvantage groups.
- Confidentiality: unreleased collections, wholesale prices or partner data entered into external tools.
- Operational: vendor dependency, model changes without notice, outages in peak season.
Each risk needs a likelihood and impact rating, an existing control, a planned action and an owner. Keep the scale simple; a three-level rating applied consistently is more useful than a refined model nobody maintains.
Who should maintain the register?
Ownership works best as a hub and spoke: a central coordinator, often in legal, compliance or the data office, maintains the template and classification rules, while business owners in e-commerce, design, merchandising, HR and wholesale keep their entries current. Procurement should block new AI purchases until an entry exists, and IT should flag AI features arriving through updates.

What are common mistakes?
- Listing only stand-alone AI products and missing AI features inside ERP, PIM, HR and e-commerce platforms.
- Ignoring free or personal accounts on generative tools used by staff.
- Treating classification as permanent when use cases drift over time.
- Building a register in a spreadsheet nobody owns, which is out of date within a quarter.
A realistic first version can be built in weeks, not months, if the company accepts that it will be incomplete and improves it with each review. Its value lies less in the document itself than in the conversations it forces about what AI is used for and who is responsible.
Frequently asked questions
What is an AI inventory?
An AI inventory is a register of all AI systems a company develops, buys or uses, with each system's purpose, owner, data, users and risk classification. It is the starting point for AI Act and GDPR compliance.
Is an AI inventory required by the EU AI Act?
The Act does not use the term, but companies cannot classify their systems, meet transparency duties or support AI literacy without knowing which AI they use. In practice an inventory is the basic evidence of compliance work.
What is the difference between an AI inventory and a risk register?
The inventory records which AI systems exist and what they do. The risk register records what could go wrong with each system, how likely and serious it is, the controls in place and who owns follow-up actions.
Which standards help structure AI governance?
Common references include ISO/IEC 42001:2023 for AI management systems and the NIST AI Risk Management Framework, which describes the role of an AI system inventory.
One edition every weekday morning. Read in five minutes. Free for industry professionals.




