Training module

AI System Lifecycle & Inventory

Define AI system scope, set lifecycle boundaries, and maintain an AI system inventory aligned with ISO/IEC 42001

Artificial IntelligenceManagement System Manager
Abstract data streams and layered system timelines visualising the scope, lifecycle stages, and inventory of AI systems within a governed, traceable system landscape.

Create the reliable object of AI governance

AI governance depends on knowing which AI systems exist, where their boundaries sit, who owns them, what they depend on and when their records must change. This module shows how to build and maintain that inventory as practical ISO/IEC 42001 implementation evidence.

Overview

What this module is about

AI inventories often start as lists of tools, pilots, vendor features and use cases. They look complete until a real governance question appears: what exactly is the AI system, where does its boundary sit, who owns the record, and which change should trigger review?

This module teaches AI system lifecycle and inventory work as a practical management-system capability. Participants work through the evolving Northstar case to identify candidate AI systems, separate systems from components and ordinary automation, define boundaries and context of use, record lifecycle state, assign ownership, surface supplier and data dependencies, and maintain traceability to risk, controls, monitoring and assurance. The focus is implementation judgement, not generic AI awareness, legal classification, model development or MLOps.

Audience

Who it is for

Management system implementers and coordinators

Executives and department heads accountable for management system performance

Those responsible for processes, policies, assets, risks and controls

Auditors seeking insight into management-side practice, not audit technique

Consultants working on management system design, governance or improvement

Decision supportIs this module for you?

It is a good fit if you…

need to decide what counts as an AI system in your organisation.

work with AI pilots, embedded vendor features, GenAI use cases or regional tool variation.

need a maintained AI inventory that risk, controls, monitoring and assurance can rely on.

support ISO/IEC 42001 implementation, readiness, governance, audit preparation or customer assurance.

want practical templates for boundary, lifecycle, ownership and update-trigger decisions.

It may not be the best fit if you…

are primarily looking for general AI awareness or AI architecture fundamentals.

need a full AI risk, impact or harm assessment method.

want detailed operational control design, model validation, prompt engineering or MLOps practice.

need legal advice or a dedicated AI Act classification course.

already maintain a current, traceable AI inventory with clear boundaries, owners and review triggers.

Agenda

What is taught

6 parts
01AI system discovery and candidate triage

Separate AI systems from components, ordinary automation and informal tool use

Triage pilots, embedded vendor features and GenAI use cases

Clean duplicate records and mark unresolved candidates for follow-up

02AI system boundaries and context of use

Distinguish AIMS scope from object-level AI system scope

Map purpose, workflow, data, model or service, user role and human decision point

Record supplier interfaces and regional variation without turning the module into architecture training

03Lifecycle checkpoints and inventory evidence

Place systems in proposal, pilot, controlled deployment, change, monitoring, suspension or retirement states

Connect lifecycle state to evidence, approval and next decision needs

Recognise when pilot language hides real operational use

04Ownership, dependencies and supplier interfaces

Assign ownership for business purpose, system record, data, supplier interface and monitoring

Surface vendor AI features, model/service changes, configuration and retained responsibility

Define who must report changes that affect the inventory

05Inventory metadata that supports decisions

Design a lean inventory record that supports risk, controls, monitoring and assurance

Repair weak inventory entries with source links and quality rules

Use AI support to draft, compare and challenge records with human verification

06Change triggers, traceability and assurance limits

Route vendor, data, model/service, configuration and business-use changes to the right review action

Check traceability from inventory to risk assessment, controls, monitoring and management review

Prepare customer-safe assurance wording without overclaiming inventory completeness

Outcomes

Learning outcomes

01

Identify AI systems and unresolved candidates across pilots, embedded vendor features, automation and GenAI use

02

Define AI system boundaries, context of use and lifecycle state with enough evidence for downstream governance work

03

Build and maintain an AI inventory record with ownership, dependencies, metadata and update triggers

Distinguish between AIMS scope, AI system scope, AI components and AI-enabled work practices

Use lifecycle checkpoints to route proposal, pilot, deployment, change, suspension and retirement decisions

Check traceability from inventory to AI risk assessment, controls, monitoring, management review and assurance claims

Materials

The content and the assessment

Written module

The full content in writing, complete in itself. Videos are recorded for parts of it as an alternative way through, and the written module always carries everything.

Exercises

Graded work on the case organisation's own registers: structured answers checked against the encoded case, written answers scored against a rubric traced to it, with a trainer holding the final word on every assessed item.

On completion

The assessed exercises must be passed before the certificate is issued.

Scheduling

No public run of AI System Lifecycle & Inventory is scheduled at the moment. Tell us you are interested and we will let you know when the next one opens, or discuss running it in-house.

Case organisation

You work inside a company that already has the problem

Exercises run on one case organisation, carried across modules rather than restarted, so what you build here is what the next module finds.

Northstar Integrated Services AG is a group headquartered in Zurich, providing digital operations platforms and managed services to regulated organisations across Europe. It has not always been that. It began in 2008 as a field-operations firm of about twenty-five people, and what first forced documented decisions and named accountability on it was not growth but a single regulated customer. It now runs an acquired business in Poland and the Czech Republic through a subsidiary that kept its own legal identity, which is where the interesting failures live: group instruments rolled out operationally and never put in force by the governing bodies of the subsidiary itself.

Linked registers
Organisation and people, risks, objectives, policies and documents, findings and reviews, third parties, processes

Not a case study
Nothing is summarised for you; the evidence is where it would really be

It has a history
The organisation has a timeline, and modules enter it at different points, so a structure can be studied before it broke as well as after

It crosses borders
A Swiss parent, an acquired operating business in Poland and the Czech Republic under its own legal entity, and customers in several jurisdictions

Why it matters

Judgement is not trained on tidy examples, and it is not trained on a fresh one each week. Northstar is deliberately untidy, and modules enter it at different points of its history, so you see a governance structure being built, outgrown and rebuilt rather than a finished one. What you decide in one module is what the next one finds.

How we teach →

Delivery & dates

How this module reaches you

Delivered live online, combining conceptual framing, discussion, case work and direct interaction with the trainer. In-house and contextualised delivery is available on request.

No public run is scheduled at the moment. Most modules run on request as well as on the public calendar, so tell us the timing you need.

Want this module scheduled?

We will tell you when the next run is scheduled, or run this module in-house with your own case material.

Not sure it is the right module?

Describe your context in a short message and we will tell you honestly.

No obligation

Tell us what would work and we will come back with dates, or with an in-house proposal if you would rather run this for a group on your own management system.
About AI System Lifecycle & Inventory · HAM-AI-S-01

No account needed. We reply personally, usually within a working day. Sending is not switched on yet, so write to us in the meantime: contact us.

Decision support

Describe your role and your context in a short message and we will tell you honestly whether this module is the right one, or point you at a better fit.
About AI System Lifecycle & Inventory · HAM-AI-S-01

No account needed. We reply personally, usually within a working day. What happens to your message is set out in the privacy policy.