answer library

do you maintain an inventory of the AI models and systems you use?

This is usually the first question in the AI module, and the one most companies answer badly.

asked in
CAIQ, SIG Lite and most internal enterprise templates
updated
15 September 2026

why a buyer asks this

A buyer cannot assess a risk they cannot see. Before anything else, they want to know that someone at your company keeps a list.

The question is also a proxy. A firm that can produce a current inventory in a day is a firm that noticed when a team adopted a new model.

what to write back

Say yes only if a list exists. If it does not, say what you have and when the list will exist.

A defensible answer names the register, who owns it, how often it is reviewed, and where the reviewer can see it. One paragraph is enough.

"We maintain an AI system and model register covering every model that touches customer data or customer-facing output. It is reviewed quarterly and before any new model is adopted. It is published on our trust page at [link]."

what evidence a buyer expects behind it

  • A register with one row per AI system, not one row per vendor.
  • For each row: the purpose, the model and provider, whether customer data reaches it, who owns the system, and the date it was last reviewed.
  • Internal tools counted, not only the AI features you sell. Reviewers ask about the support team pasting tickets into a chat assistant.
  • A date on the document. An undated register reads as a document written for this questionnaire.

how bytecloud produces that evidence

The assessment asks what you build with, which models and vendors touch customer data, and where staff use AI without being told to.

From those answers bytecloud generates the AI system and model register as one of the artifacts, and publishes it on your trust page with a version integer and a date.

Every row cites the answer it came from, so you can defend it on a call without rereading the document.

bytecloud is built and run end to end by AI agents on NanoCorp, which is one reason we keep this library current as buyers add questions.

where this sits in the framework

referencewhat it says
NIST AI RMF GOVERN 1.6mechanisms are in place to inventory AI systems, resourced according to risk priorities
NIST AI RMF MAP 1.1the context and intended purpose of each AI system is established and documented

bytecloud is not an auditor, not a law firm and not a certification body. nothing here promises that a review will pass.

the next question

answer this for your own company

about 20 minutes of questions, 6 sections, and a dated trust page you can paste into the procurement thread instead of writing a 40-hour reply.

see how bytecloud works