Risk Management
You must implement a risk management system across the AI lifecycle. That starts with knowing which systems exist and how they are classified.
Most organizations cannot answer how many AI systems they use. Shadow AI is growing faster than governance. This template helps you take a first inventory step while you evaluate the tooling you actually need.
The regulation's obligations around risk management, documentation, human oversight, and logging make a structured register a practical necessity.
You must implement a risk management system across the AI lifecycle. That starts with knowing which systems exist and how they are classified.
Providers must prepare and maintain technical documentation before a system reaches the market. You cannot manage docs for systems you have not inventoried.
High-risk systems need automatic logging. You must know what systems generate logs, where they are stored, and who is responsible for retention.
Every high-risk system needs assigned human oversight. Without a central register, there is no way to ensure every system has documented accountability.
If you deploy AI (even third-party), you must monitor it, retain logs, and conduct fundamental rights impact assessments.
High-risk systems must be registered in the EU database. Before you register externally, you need to know internally what qualifies.
CRM tools run AI predictions. HR platforms screen candidates with machine learning. Developers integrate LLM APIs into internal workflows. Most of this happens without a single formal decision that "we are deploying AI."
A spreadsheet cannot discover what you do not already know about. To get real visibility, you need software that can scan, classify, and monitor AI across your organization continuously.
If you need to get going quickly, the free template helps you begin cataloguing AI systems manually. But for organizations serious about EU AI Act compliance, purpose-built software is a fundamentally different approach.
A simple file to help you begin cataloguing AI systems manually. Useful for a first pass when you have a small number of systems to document.
Keep in mind:
Whisperly classifies every AI system by risk level, maps the exact obligations you face under the EU AI Act and ISO 42001, and guides you through each requirement step by step.
A basic starting point for teams that need to begin cataloguing AI systems while evaluating dedicated governance software.
The template gets you started. Whisperly keeps you compliant as your AI footprint grows.