AI governance in practice: from inventory to EU AI Act classification and ongoing assurance
A practical operating model for AI governance, covering how to inventory AI systems, classify them under the EU AI Act, run the right assessments, and keep them under control as they change.
By Federico Marengo·AI Governance Partner, White Label Consultancy
Most AI governance programmes are still a policy nobody reads, and that's the problem this guide is trying to solve. The EU AI Act sets obligations by risk tier, supervisory authorities expect demonstrable oversight, and employees are adopting AI tools faster than most governance functions can track.
This guide sets out that workflow so you see what you have, classify it, assess it, and govern it day to day. The guide also maps to how the Pritect AI governance suite is built, and to how it connects to the data protection and risk work you already run.
Start with an inventory
The first failure mode is invisibility. AI arrives through systems you build, systems you procure, and systems employees adopt on their own. A governance programme only covering the systems you build misses most of the risk.
A usable AI inventory records, for each system, what it does, who owns it, what data it touches, whether it is built or bought, and where it sits in your organisation. Shadow AI discovery matters here: a marketing team running customer data through a free generative tool is both a data protection and a security exposure, and you cannot manage it until it is on the list.
Classify against the EU AI Act
Once a system is on the inventory, classify it. The EU AI Act sorts AI systems into prohibited, high-risk, limited-risk, and minimal-risk, and the obligations follow the tier.
Most of the weight falls on high-risk systems, which include the uses listed in Annex III, for example AI used to filter job applications and evaluate candidates, or to determine access to essential services. Limited-risk systems, such as a customer-facing chatbot, mainly carry transparency obligations, meaning you have to tell people they are dealing with AI.
Two practical points decide how much work follows. First, identify your role: provider and deployer obligations differ, and many organisations are both, for different systems. Second, treat classification as a living attribute. A minimal-risk tool used to summarise internal notes becomes something else when used to screen candidates, so re-classifying on material change is now crucial.
Assess: a DPIA and a model risk assessment are not the same thing
When an AI system is high-risk and processes personal data, two assessments are in play and people often confuse them.
- A Data Protection Impact Assessment (DPIA) asks whether the processing is necessary and proportionate, and what the risks are to the rights and freedoms of the people whose data is used.
- A model or AI risk assessment asks whether the system itself is fit: is it accurate, robust, explainable, free from unacceptable bias, and subject to meaningful human oversight.
The two overlap, but one doesn't substitute for the other. The efficient approach is to run them on the same record, so the system description, data categories, and supplier are entered once and the two assessments share that foundation rather than diverging.
Govern AI in the workplace, day to day
Most AI risk looks like an employee pasting confidential data into a consumer tool, or a manager quietly using an AI system to rank people. Day-to-day governance is mostly about three things:
- Clear rules for what staff may and may not put into AI tools, written in plain language and actually communicated.
- Human oversight that is real: a named person who can understand, question, and override the system's output, especially for high-risk uses.
- A route to register new AI so adoption goes through governance.
This is where governance either becomes part of how the organisation works or stays a poster on the wall. Tooling helps by making the compliant path the easy path: register a system in a few minutes, get its obligations back automatically, and assign the oversight owner there and then.
Monitor and report
Classification and assessment are point-in-time. AI systems drift: models are retrained, providers change behaviour, and use cases expand. High-risk systems carry post-market monitoring obligations, and serious incidents have reporting timelines you do not want to be discovering during an incident.
A working programme keeps each system under review on a cadence, tracks its obligations to completion, and rolls the position up into a view leadership can actually read: how many AI systems are in scope, how many are high-risk, which assessments are outstanding, and where the residual risk sits.
See AI system inventory, EU AI Act classification, assessments, and shadow AI discovery in the Pritect AI governance suite.
This is also the clearest example of why a unified platform matters: a single new AI system touches AI governance, data protection, cybersecurity, and enterprise risk at once. Our unified workflow follows exactly that path, from classification to a board-ready view, on one record.
