Documentation

/

Blog

[Part 2] ISO/IEC 42001 — Where Do I Even Start? What Comes First?

July 31, 2026

[Part 2] ISO/IEC 42001 — Where Do I Even Start? What Comes First?

In Part 1, we discussed the groundwork organizations should complete before beginning their ISO/IEC 42001 journey. This includes understanding how the standard views AI, defining the scope of the AI management system, and identifying relevant interested parties.

So, where should the actual implementation begin?

You could start by drafting an AI policy and management guidelines. You could also develop AI ethics guidelines or begin with AI risk and impact assessments.

All of these are valid starting points. Ideally, an organization should begin in an area where it already has confidence, experience, and relevant materials.

However, if you are unsure where to begin, I recommend starting by identifying the AI assets within your organization and building an AI inventory.

What Is an AI Inventory?

An AI inventory is a structured system of record used to identify the AI systems and use cases an organization develops, provides, purchases, or uses, and to manage their purpose, ownership, data, relationships, risks, and operational status.

Put simply, it should answer the following question:

What AI is operating within our organization, for what purpose, under whose responsibility, and using which data and models?

The term “AI inventory” does not appear explicitly in ISO/IEC 42001. However, Annex A control A.4, “Resources for AI systems,” requires organizations to identify and document AI system components and assets, data resources, tool resources, system and computing resources, and human resources.

Organizations need to understand which AI systems exist and how they are being used before they can define the management scope or determine which AI assets should undergo risk and impact assessments. In this sense, an AI inventory is a practical foundation for implementing ISO/IEC 42001.

The following stages outline how an organization can manage and progressively expand its AI inventory.

Step 1: Identify the Organization’s AI Assets

The first question to answer is:

What AI assets exist within our organization?

The scope should not be limited to LLMs.

  • AI systems and use cases: customer support chatbots, document summarization, recommendation systems
  • AI models: LLMs, embedding models, internally developed or fine-tuned models
  • AI execution resources: agents, apps, chat interfaces, workflows, and automations
  • AI integration resources: MCP servers, tools, external APIs, and SaaS services
  • AI knowledge resources: prompts, knowledge bases, RAG pipelines, and vector databases
  • Data resources: training, validation, and production data, documents, and personal data
  • Operational resources: cloud infrastructure, databases, logs, and monitoring systems
  • Responsible parties: system owners, operators, and external providers

As organizations build more agentic AI systems and AI workflows, they also create more API keys and secrets. This can leave credentials that are unauthorized, unmanaged, or no longer used but never revoked. These assets should also be identified. The inventory should not store the secret values themselves; it should record which systems use them, who manages them, and where they are securely stored.

You do not need to discover every asset perfectly from the outset. Start with core AI systems or key products that directly affect customers, then expand the scope gradually.

Step 2: Structure Asset Relationships and Responsibilities

Once AI assets have been identified, the next step is to add management context and structure the relationships between them.

Registering asset names alone does not provide enough information to understand how an AI system operates or what risks it creates. The same LLM may be used by several agents and services, while a single agent may access multiple data sources, MCP servers, and external APIs.

An AI inventory should therefore capture each asset’s purpose, owner, operational status, data usage, external providers, and relationships with other AI assets.

It should help answer questions such as:

  • What business function does this AI asset support?
  • Who owns and operates it?
  • How is it connected to other agents, models, MCP servers, and tools?
  • Is it currently in development, validation, production, or retirement?

The purpose of an AI inventory is not to register as many assets as possible. Its real value lies in understanding the role each AI asset plays within the organization and how those assets are connected.

Step 3: Assess Risks and Impacts for Each Asset

Once AI assets and their relationships become visible, the scope of AI risk and impact assessments becomes more concrete.

For example, tools provided by the same MCP server may carry very different risks. A tool that only reads information is not equivalent to one that creates, modifies, or deletes data. Likewise, an agent that uses only public documents should not be managed at the same level as an agent with access to a database containing personal data.

Risks and impacts should be assessed based on the AI system’s purpose, users, models, data, permissions, external connections, and potential consequences. The AI inventory provides the foundation for those assessments.

Step 4: Determine the Appropriate Controls

After assessing risks and impacts, the organization should determine controls appropriate to the results.

For example, a tool capable of modifying or deleting data in an external system may require least-privilege access, user approval, execution logging, or dual confirmation for critical actions.

Not every AI system requires the same controls. Controls should be selected according to each system’s purpose, data, permissions, and level of impact.

The purpose of AI governance is not to prevent AI use. It is to help the organization use AI responsibly with a clear understanding of the associated risks.

Ultimately, Expand into an AI Control Tower

An AI inventory is not a document that is completed once and then left unchanged.

AI technology continues to evolve rapidly. Organizations introduce new models, build new agents and workflows, and connect additional MCP servers and external AI services. The data, permissions, and relationships of existing systems also continue to change.

Organizations must therefore continuously discover new AI assets, update the inventory, and reassess risks and impacts when changes occur.

An AI Control Tower is a management framework that brings these activities together and operates them continuously in one place.

An AI Control Tower is an AI governance framework that provides an integrated view of the organization’s AI systems and related resources, manages asset relationships and accountability, and supports risk, impact, and control decisions.

An AI Control Tower does not necessarily control or block every AI system directly. Its purpose is to provide integrated visibility across the organization’s AI environment and continuously answer questions such as:

  • What AI exists within our organization?
  • What is it connected to, and who is responsible for it?
  • What risks and impacts does it create?
  • Which controls are needed, and what should be improved first?

The overall journey can be summarized as follows:

Identify → Inventory → Assess → Govern → AI Control Tower

An AI Control Tower is not a separate feature added at the final stage. It represents a mature operating model in which the organization repeatedly identifies assets, manages them through an inventory, assesses risks and impacts, and determines appropriate controls.

No organization begins with a fully developed AI Control Tower. The practical approach is to identify critical AI assets, build an inventory within a manageable scope, and progressively connect it to assessment and governance processes.

Beyond AI Inventory: Building an AI Control Tower with QueryPie AIP

If an organization’s use of AI is still limited, it can begin with documents, spreadsheets, or an existing asset management system.

However, as the number of AI assets grows and the relationships between cloud services, agents, MCP servers, workflows, and external systems become more complex, keeping the inventory current through manual work alone becomes increasingly difficult. As we have learned from operating information security management systems, the more assets an organization manages, the harder it becomes to maintain centralized visibility. Assets that fall outside that visibility can introduce new risks.

QueryPie AIP supports the management framework needed to address this challenge. It can automatically discover AI-related resources through cloud APIs, while external AI SaaS services and other resources that cannot be discovered automatically can be registered and managed in the same place.

The scope is not limited to LLMs. AI systems, agents, MCP servers and tools, workflows, knowledge resources, data, external APIs, and their relationships can all be managed through a unified inventory.

Discovered AI assets can then be connected to risk and impact assessments. Based on the assessment results, QueryPie AIP can also provide guidance on controls the organization should consider, such as least privilege, user approval, and execution logging.

This enables the organization’s AI management framework to evolve beyond a simple asset list into an AI Control Tower that provides a unified view of the AI environment.

Are you unsure where to begin identifying AI assets, how to manage discovered assets and assess their risks, how to launch your organization’s AI transformation, how to build a safe and responsible AI environment, or how to begin preparing for ISO/IEC 42001? Contact QueryPie.

Drawing on our experience preparing for ISO/IEC 42001 and other security certifications and operating an AI management system, QueryPie will work with your organization to design a practical path for managing AI assets and the connected IT and data assets, assessing risks and impacts, and progressively developing your AI management framework into an AI Control Tower.


#QueryPie #ISOIEC42001 #AIInventory #AIControlTower #AIGovernance