ComplianceData ManagementLow complexity
Shadow AI Inventory
Staff paste client data into personal AI accounts and browser extensions nobody approved, often on consumer terms that allow training and long retention.
How we approach it
Combine a short staff questionnaire with SSO, expense and network data to list the AI tools actually in use and the plan behind each. Classify each tool by the data it handles, the vendor's terms and where the data is processed. Sanction it, move it to a business plan or block it, and publish a short approved list.
Business value
Know which AI tools hold your data before a client or regulator asks
Technology stack
- Staff questionnaire
- SSO and CASB logs
- expense data
- vendor terms review
- DLP
Related service
AI Audit & Risk AssessmentFurther reading
Related use cases
- Cross-Industry · ComplianceAI Act ReadinessProhibited practices and the rules for general-purpose AI models already apply, high-risk duties follow, and many organisations still have no list of their AI systems.
- Cross-Industry · ComplianceAuditable Document GenerationRegulated outputs such as risk reports, suitability letters and audit findings need wording that can be reproduced and defended, which a free-writing model cannot guarantee.
- Cross-Industry · ComplianceRegulatory Horizon ScanningSee which proposed EU and national rules will affect the business, early enough to plan.