Offer · Information Security & Governance

AI inventory and AI Act readiness

Get control of which AI solutions the organisation actually uses, what risks they carry and which requirements need handling.

AI registerAI ActRole and requirement assessmentReadiness assessmentAction plan

Who it is for and when

AI is already in use in many organisations — sometimes through centrally introduced solutions such as Microsoft Copilot, sometimes through standalone AI services, and sometimes as features built into systems you already have.

That means the first question should rarely be ”which AI policy do we need?”. A better start is: ”which AI are we actually using, for what, and with which information?”

Kristensson i Skåne AB helps you inventory the organisation’s use of AI, assess the relevant roles and risks, and create a practical way forward for the AI Act, data protection, information security and AI governance.

The AI Act mainly began to apply on 2 August 2026, when the transparency requirements among others came into force. Certain rules for high-risk systems apply later — from December 2027 and August 2028 depending on the type of system. That makes it important to understand which use cases the organisation actually has before building governance around them.

The offer suits organisations that, for example:

  • use several AI services but lack a consolidated picture,
  • have introduced Microsoft Copilot, ChatGPT or other generative AI solutions,
  • have AI features in business systems or SaaS services,
  • want to understand which parts of the AI Act are relevant,
  • need to get control of so-called shadow AI,
  • want to build AI governance without creating yet another separate compliance project,
  • need to connect the AI Act with the GDPR, information security and supplier management,
  • want a concrete basis for decisions about continued AI use.

It can also be a suitable first step ahead of a larger AI programme.

What we do

  1. Scope and source material. We go through the organisation, the systems, the known AI services and the existing governance.
  2. Interviews and inventory. Relevant people across the business, IT, data protection, information security and other functions are involved.
  3. Assessment and prioritisation. We analyse the use cases and the organisation’s shared governance.
  4. Result and management walkthrough. You get the register, the assessment and a prioritised roadmap, which we go through together.

What is included

Scope and start-up

We start by understanding the business, which AI initiatives are known today and which parts of the organisation need to be covered.

Together we establish which use cases, business areas and systems are in scope.

AI inventory

We map the organisation’s known use of AI. For each relevant use case we document, for example:

  • the AI system or service,
  • the supplier,
  • the area of use,
  • the responsible business unit or system owner,
  • which information is processed,
  • whether personal data is involved,
  • which integrations exist,
  • which people or business processes are affected,
  • whether the AI system only supports, or can also make or execute decisions.

The result is a first structured AI register the organisation can continue to maintain.

Role and requirement assessment

We assess at a high level the organisation’s role for each relevant use case and which parts of the AI Act need analysing further. That can be about the difference between being:

  • a provider,
  • a deploying organisation,
  • an importer or distributor,
  • an actor further down the AI value chain.

We also identify which use cases need deeper classification or a specific legal assessment.

The work follows the AI Act’s current application timetable. Not all AI systems are subject to the same requirements and not all use cases are high risk. The European Commission describes the regulation explicitly as risk-based.

Data protection and information security

The AI Act is not the only relevant regulation. We therefore also look at questions such as:

  • personal data and any DPIA,
  • information classification,
  • sensitive or confidential information,
  • suppliers’ use of customer data,
  • logging and traceability,
  • permissions,
  • integrations,
  • third-party risk,
  • human oversight,
  • incident and deviation handling.

The aim is to reuse the organisation’s existing processes where possible rather than building a separate AI governance system.

Current state and readiness assessment

We compare the current state with the governance and control judged relevant for the organisation’s use. That can cover, for example:

  • ownership and responsibility,
  • AI policy and instructions,
  • approval of new AI use cases,
  • supplier assessment,
  • risk assessment,
  • transparency,
  • documentation,
  • human oversight,
  • training,
  • follow-up.

The assessment shows what already works and what needs building or improving.

Prioritised action plan

We do not finish with a long list of requirements. The identified activities are prioritised by, for example, what has to be handled now, what should be built into existing processes, which use cases need deeper analysis and what can wait.

What you get

After the engagement you normally have:

  • a documented AI register,
  • a first classification of the use cases,
  • identified owners and responsibilities,
  • the relevant AI Act, GDPR and security questions documented,
  • a readiness assessment,
  • identified governance gaps,
  • a prioritised action plan,
  • a summary suited to management,
  • a proposal for how the AI work can be maintained.

Scope and price

The scope and timetable are set by the size of the organisation and the number of use cases.

The price varies from engagement to engagement and depends on the scope. You get an estimated cost proposal and, where possible, a fixed price.

What do you need to contribute?

Above all, access to the relevant people and to existing documentation. That can be a system register, a supplier register, an AI policy, information classification, DPIAs, the purchasing process or other relevant governing documents.

We try to use what you already have rather than requesting documentation purely for the sake of the engagement.

After the inventory

The AI inventory can stand on its own. It can also be followed by, for example:

  • AI policy and working instructions,
  • deeper AI Act assessments,
  • a DPIA,
  • supplier reviews,
  • AI governance,
  • training,
  • technical security measures,
  • ongoing follow-up.

Kristensson i Skåne AB’s existing AI Act service already starts from the same principle: inventory the use, identify the owners, assess the risks, and only then build the right governance.

How it works

  1. A first conversation. We listen to your situation and explain how we usually set up the work. You get our assessment straight away, free of charge.
  2. A proposal with scope and price. A short written proposal with what is included, what you get, who does the work and what it costs.
  3. Delivery and handover. We work together with your organisation, report continuously and hand over so that you can maintain the result yourselves.

Frequently asked questions

Does every company need an AI register?

There is no general requirement for every organisation to hold a register in exactly the form described here. We use it as a practical governance tool for getting control of AI systems, use cases, roles and risks.

Is this a complete legal AI Act assessment?

Not necessarily. The readiness assessment identifies which questions are relevant and which use cases need deeper legal or technical analysis. Those deeper pieces can be agreed separately.

Can you help with the GDPR as well?

Yes. AI use that involves processing personal data also needs assessing under the GDPR, and for some use cases a DPIA becomes relevant.

Can we start even if we do not know which AI services are in use?

Yes. That is often the very reason to start with an inventory.

Get control of the organisation’s use of AI

Contact us