From Inventory to Audit Pack: The Framework

Every deployment named, mapped and defensible.

The Bridge From The Problem

The preceding page established the perimeter: ISO 37301 absorbs AI into the operator's certified compliance system, clause by clause. This page shows the machinery that makes it happen — the three artifacts through which each deployment enters that perimeter, comes under control, and produces evidence the certifier can examine. They are presented in sequence because that is how they are built: nothing is mapped before it is named, nothing is audited before it is mapped.

The AI Registry

Governance begins with naming what exists. FINMA Guidance 08/2024 sets the expectation explicitly: institutions maintain an inventory of AI deployments and classify them by risk. Most operators in the target segments — family offices, asset managers, fiduciaries — have neither.

The AI Registry is that inventory, engineered as a control artifact rather than a spreadsheet. Each deployment is recorded with its function, the process it touches, the data it processes, the personnel who operate it, and the vendor behind it. Each entry carries a risk classification aligned with the supervisory expectations. Nothing is omitted because nothing is assessed — vendor tools, embedded AI in third-party platforms, ad hoc use of generative assistants, experimental pilots.

The registry answers the first question every auditor, correspondent bank and supervisory organization asks: what AI does this firm actually run?

The Clause Mapping Matrix

Inventory alone controls nothing. Guidance 08/2024 expects governance controls proportionate to the risk each deployment carries — testing and monitoring, documentation, explainability, independent review.

The Clause Mapping Matrix converts those expectations into the certified perimeter. Every registry entry is traced to the ISO 37301 clauses that govern it:

Clause 4.6 — Risk Assessment

The deployment enters the compliance risk assessment, classified and prioritized like any other compliance exposure.

Clause 8.2 — Operational Controls

Operational controls are embedded around the deployment: what is permitted, what is monitored, what triggers review.

Clauses 9.1.4 and 9.1.5 — Reporting and Record-Keeping

The deployment's performance and incidents are reported and recorded, producing the documented oversight trail the regulator expects.

Clause 5.3.2 — Compliance Function

The compliance function owns the mapping, not the IT function, not the individual user.

Clause 7.2 — Competence

The personnel operating the tool hold defined competence for its governed use.

The matrix is the correspondence between what the firm runs and what the certificate covers. Where a deployment has no mapped controls, the gap is visible, owned and scheduled for closure — not discovered during the audit.

The Certification-Ready Audit Pack

Evidence scattered across inboxes is not evidence. The audit pack consolidates what the certifier's auditor will examine: the registry, the mapping matrix, the control documentation, the competence records, the reporting trail.

The pack is structured to the audit, not reconstructed for it. Independent review — the final expectation in Guidance 08/2024 — is satisfied by the certification audit itself: the accredited certifier examines the system that contains the AI, and the certificate states its scope.

Close

Three artifacts, built in sequence, owned by the operator, examined once. The organization runs AI that is inventoried, controlled and defensible — and the certificate says so to every party entitled to ask: the correspondent bank, the counterparty, the supervisory organization, the accredited certifier.

Read The Engagement →