Skip to main content
LLM SquaredRequest call

AI inventory and shadow-AI sweep / For the risk or operations owner

Know which AI uses need a review.

In two weeks, turn an agreed set of vendor records and staff declarations into a sourced AI inventory, a list of unanswered questions and a review order your institution owns.

Start with the department or vendor group you can actually examine. The file distinguishes declared use, supporting evidence and the places you have yet to check.

Scope and fee are fixed in writing after one working session. The two-week window starts when the agreed records and reviewers are available.

The vendor list and the staff answer do not match.

A product release mentions a new assistant. One department reports an approved tool. Another describes a personal account. Your existing inventory has a vendor name, but no AI feature, data route or responsible reviewer.

This review reconciles those records. It leaves each unresolved declaration visible and names the person who must supply the answer. Keep your existing vendor-risk system; the reviewed file can support the records you already maintain.

Employee use

Reconcile approved-tool lists with staff declarations and agreed interviews. Record the account route, business purpose and categories of information involved.

Vendor features

Compare the supplied product list with release notes, vendor responses and terms. Keep undisclosed capabilities and missing responses open.

Delegated assistants

Record declared employee, vendor and customer assistant interactions within the agreed scope. Separate discovery from permission to act.

Coverage still unknown

Name the departments, vendors and evidence sources included, excluded or unanswered. A blank register is a missing answer, not proof that AI is absent.

The inventory, its reasons and its review queue.

One-page decision

The agreed boundary, uses needing review first, reasons for that order, unresolved data routes, accountable owner and next action.

Source-linked inventory

Tool or feature, vendor, business purpose, owner, account route, declared data categories, action capability and the source and version behind each field.

Coverage and questions register

Records checked, interviews completed, areas outside scope, conflicting declarations, unanswered vendor questions and the person responsible for each response.

Recorded institution review

Reviewer determination, accepted scope, corrections, unresolved items and the next review trigger. You keep the brief and its supporting records in portable files.

Supplied → Prepared → Reviewed

A staff declaration is Supplied. A source-linked register is Prepared. It becomes Reviewed when the named institution reviewer records a determination. Moving a row into the inventory does not approve the tool.

Four steps within the two-week scope.

  1. Agree the boundary

    Name the department or vendor group, records, interviews, handling route, owner and review date.

  2. Reconcile the sources

    Compare supplied inventories, approved tools, release records and declarations. Preserve conflicting answers and their versions.

  3. Set the review order

    Give the institution's reviewer the declared data routes, decision impact, action permissions and unanswered questions.

  4. Leave the file

    Record the reviewer response, corrections and remaining gaps. Agree what change would reopen the review.

Your team supplies permitted records, arranges the agreed interviews and assigns an accountable reviewer. Vendor replies or missing records can change the delivery date; broader coverage requires a written scope change.

Describe the workflow in the initial inquiry. Source documents use the separately agreed engagement handling route.

A record beside each scoping theme.

Source checked October 4, 2026: CSBS Core Examiner Guide, version 1.0, page 3; approved August 13, 2026.

These short theme labels summarize IS-1 through IS-8. The file mapping is our preparation method. CSBS released a discretionary framework on September 16, 2026; each state agency determines how to use it. The guide creates no new legal or supervisory requirements. Read its scope.

CSBS theme and the inventory record to inspect
ThemeRecord in your fileAnswer the reviewer still needs
IS-1. AI useCoverage register and declared uses.Which areas were checked, and which remain unknown?
IS-2. Identified systems and usesInventory rows linked to supplied versions.Which rows have supporting sources?
IS-3. Customer or decision impactPurpose, affected workflow and decision fields.Who reviews the affected output?
IS-4. External capabilitiesVendor, service and terms references.Which vendor answers are still missing?
IS-5. Embedded vendor AIFeature declarations and release sources.Which capabilities are undisclosed or unclear?
IS-6. Generative toolsDeclared tool and approved account route.Which source and output limits apply?
IS-7. Risk-based reviewReview order, reasons and reviewer fields.Has the institution accepted that order?
IS-8. Sensitive informationDeclared categories, recipients and handling references.Which data routes still need confirmation?

For credit unions, NCUA's AI resource describes supervision within its existing framework and points to risk-management resources. The CSBS cross-reference here is a preparation aid, rather than an NCUA requirement. Read the examiner preparation page.

Inspect the method before sharing a source.

Agent Access Lab separates a declared assistant from its permitted actions. The browser example runs on supplied inputs; it does not discover the tools your employees use. Approved-assistant packages provide a separate local evaluation route.

An inventory can point to a pilot acceptance review, a procedure review or a missing vendor answer. Evidence Refresh remains a separately scoped service proposal for later supplied changes.

The institution owns the decision.

Method boundaries cover permitted inputs, core access, execution, identity, financial action and claims; source handling explains where processing occurs.