Checklist ¡ 4 minute read
AI Service Catalog Template: The Inventory You Will Be Asked For
The first governance question is what AI systems you run, and most organisations cannot answer it. A catalog entry should record purpose, data used, models involved, decisions made, owner, risk level, and last review â enough that the entry answers the follow-up questions too.
The first governance question asked is what AI systems you run, and most organisations cannot answer it quickly. This template covers the catalog, drawn from FISTA Solutions' AI enablement governance work.
What does an entry contain?
Six fields that answer the questions that follow.
| Field | Why it is asked for |
|---|---|
| Purpose and decisions made | The core governance question |
| Data used and its basis | Privacy and compliance |
| Models and providers | Supply chain and change risk |
| Owner | Accountability |
| Risk level | Determines governance depth |
| Last reviewed | Whether it is being managed |
Scope
Define it widely or the catalog misses what matters.
- Systems built in-house included
- AI features inside purchased software included
- Tools built by individual teams included
- Pilots and experiments included with their status
- Retired systems marked rather than deleted
- Vendor systems making decisions about your customers included
- Scope definition written down so it is applied consistently
Core fields
Enough to answer the follow-up questions.
- Name and plain-language purpose
- Decisions or actions the system takes
- Whether it is customer-facing
- Whether outputs are reviewed by a person
- Business function it serves
- Date deployed
- Current status
Data and models
The fields that governance and security will ask for.
- Data categories used
- Lawful basis for processing
- Retention period applied
- Models and versions in use
- Providers and their subprocessors
- Processing locations
- Corpus or knowledge sources
Accountability
A name, with authority.
- Named business owner
- Named technical owner
- Confirmation the business owner can pause the system
- Approval record and date
- Risk assessment reference
- Escalation path reference
- Owner confirmed still in post at each review
Risk and governance
Drives how much of everything else applies.
- Risk level assigned using a documented method
- Criteria for each level defined
- Governance requirements mapped to each level
- Regulatory classification noted where applicable
- Evaluation and monitoring status recorded
- Known limitations noted
- Incidents linked to the entry
Maintenance
Generated where possible, reviewed where not.
- Registration required as part of deployment
- Fields generated from systems where possible
- Review cadence defined per risk level
- Owner confirms accuracy at each review
- Last-reviewed date visible on every entry
- Stale entries flagged automatically
- Catalog owner named
What are the most common failures?
Scope limited to in-house systems. Entries describing features rather than decisions. No named owner. Built by survey and never updated. And no risk level, so every system carries the same burden.
Who should own this?
A governance function owns the catalog; each system's business owner owns their entry's accuracy. A catalog maintained centrally without system owners drifts within months.
How often should it run?
Entries created at deployment, reviewed per risk level â quarterly for high, annually for low â and audited annually for completeness against deployment and provider usage records.
What evidence should it produce?
The catalog itself with review dates, completeness checks against provider usage, and the documented scope definition.
How do you find the systems you do not know about?
Provider billing, network egress to model endpoints, and expense records for AI subscriptions all reveal usage the catalog missed.
A sweep asking existing vendors whether they have added AI features usually finds several entries too. That category is the most commonly missing. See AI third party risk checklist.
What should you do first?
Start the catalog with the systems you know about and one column: who owns this. The gaps in that column are the first finding.
How FISTA Solutions helps
FISTA Solutions builds and operates production AI systems through AI agents, AI enablement, and forward deployed engineering: catalog scope including vendor AI features, entries recording decisions rather than features, and registration required as part of deployment, decisions documented with their reasoning, and handover that leaves your team able to maintain what was delivered. The record is 150+ projects for 50+ companies across 12+ countries.
To adapt this checklist to your environment, message FISTA on WhatsApp, or read what boards will ask about AI.
Share-ready article cover
Download the generated social format.
Clear answers
Questions raised by this field note.
Straightforward guidance for evaluating scope, fit, and the next step.
01What belongs in the catalog?
Every system where a model influences an outcome, including AI features inside purchased software and tools built by individual teams. Scope defined narrowly produces a catalog that misses the exposure.
02What should each entry record?
Purpose, what decisions it makes, data used, models and providers, owner, risk level, review date, and whether it is customer-facing. That set answers most follow-up questions.
03Why record decisions rather than features?
Because governance questions are about decisions. A regulator asks what decisions are automated, not what features exist, and an entry describing features cannot answer.
04How do you keep it current?
Generate what you can from deployment records and provider usage, and make catalog registration a step in the deployment process. Periodic surveys alone produce a catalog that is stale by the time it is finished.
05What is the risk level for?
Determining how much governance applies. A low-risk internal tool and a customer-facing decision system should not carry the same review burden, and the catalog is where that distinction lives.
Continue exploring
Related capabilities
Start with the hard problem
Need the outcome owned, not merely analyzed?
Tell us where delivery is constrained. Weâll map the fastest credible path from intent to verified production.