Insights · Guide III

The AI register

One record per system, owned and reviewed. A template, and what the ICO and ISO/IEC 42001 expect of it.

Figure 1 One record in the register

Identity

Name
What people call it, and the product behind it
Supplier or builder
Who provides it and under which contract
Version in use
And the date it went live

Purpose

Process served
The piece of work it sits in
Decision informed
And who makes that decision
Status
Evaluating, pilot, production or retired

Data

What goes in
Personal data? Special category?
Where it is processed
And where it is stored
Training use
Whether inputs train the supplier’s model

Lawful basis

Per operation
A lawful basis for each processing operation
DPIA
Reference and date
Automation
None, supports a person, or decides

Risk and controls

Main risks
Accuracy, bias, security, confidentiality
Human review
Who checks, and before what
Fallback
What happens if it is switched off

Ownership and evidence

Business owner
A named person, not a team
Measure
Against the baseline taken before
Next review
A date, and the last outcome

Eighteen fields in six groups. Every one has an answer or a named person finding it. Source: Vardonne, drawing on ICO guidance and ISO/IEC 42001

What the ICO expects

The ICO’s guidance on AI and data protection is under review following the Data (Use and Access) Act, but it remains the published position.1 Two expectations shape the register directly. On lawful basis: “You must break down and separate each distinct processing operation, and identify the purpose and an appropriate lawful basis for each one.”1 On impact assessment: in the vast majority of cases, the use of AI will involve processing likely to result in a high risk, and will therefore trigger the legal requirement to carry out a DPIA.1

Automated decision-making is where the guidance is moving. The ICO consulted on draft guidance about automated decision-making and profiling between 31 March and 29 May 2026, and says an AI and automated decision-making code of practice awaits government secondary legislation.2,3 The “Automation” field in the record is there so that a change in the rules is a query on the register, not a search of the firm.

The management system around it

ISO/IEC 42001 specifies requirements for establishing, implementing, maintaining and continually improving an AI management system. It is meant for organisations that provide or use AI-based products or services, and it uses the Plan-Do-Check-Act method.4 It shares the common management-system structure of ISO 27001 and ISO 9001, so a firm that already runs one of those has much of the machinery.

Figure 2 Where the register sits in the cycle
Plan, Do, Check, Act around an AI management systemPDCAAIMS
Plan
Scope, policy, risk assessment, objectives. The register is built here.
Do
Controls operated: DPIAs, human review, supplier terms.
Check
Measures, incidents and the register reviewed on a rhythm.
Act
Corrections made, systems retired, the policy improved.

Source: ISO4

Keeping it alive

Review the register monthly in the operating rhythm, whenever a system changes, and after any incident. Retire records rather than deleting them: the history of what was used, and why it stopped, is evidence an auditor or evaluator will ask for.

Sources

  1. Guidance on AI and data protection (under review following the Data (Use and Access) Act; main update 15 March 2023, some pages updated since). Information Commissioner’s Office, read 21 September 2026.
  2. Consultation on draft guidance about automated decision-making, including profiling (31 March to 29 May 2026). Information Commissioner’s Office, March 2026.
  3. AI and biometrics strategy update. Information Commissioner’s Office, March 2026.
  4. ISO/IEC 42001:2023, Artificial intelligence: Management system. ISO, December 2023.