Module · AI Model Inventory

    You cannot govern an estate you have not counted.

    Nearly every AI governance failure we review starts the same way: the institution did not know how many systems it was running, who owned them, or which jurisdiction's rules applied. The inventory is the first control, and every other AI control depends on it.

    You choose the AI. Cabier orchestrates the trust.

    Intake and lifecycle

    One declaration produces every jurisdictional classification the institution owes.

    01

    Declaration

    Every AI system entering the estate is declared with purpose, owner, jurisdiction of use and data classes touched.

    02

    Classification

    Risk tier assigned per jurisdiction — EU AI Act category, SR 11-7 model tier, OSFI E-23 rating — from one declaration.

    03

    Validation

    Independent review before production. Self-assessment is not accepted as validation evidence.

    04

    Approval

    A named executive signs the deployment. The signature and its scope are recorded, not implied.

    05

    Monitoring

    Drift, eval regression, incident rate and evidence completeness tracked continuously against the approved scope.

    06

    Retirement

    Decommissioning is a controlled event with evidence retention obligations preserved.

    Inventory explorer — published sample

    Search and filter an illustrative estate of eight systems. Select a record to see its accountable owner, residency, classification and the evidence bound to it.

    Risk tier

    Status

    Record · AIS-0114

    Credit adjudication assistant

    Accountable owner
    Chief Credit Officer
    Model family
    Frontier general-purpose model, vendor-hosted
    Hosting and residency
    EU region, single-tenant inference
    Jurisdictions of use
    EU, UK
    Classification
    High risk · In production
    Last independent validation
    12 May 2026

    Evidence bound to this record

    • Evaluation resultsEV-24118 · v3

      Credit-memo faithfulness eval, 480-file holdout set

      Control MLC-04 · captured 12 May 2026 · reviewed by Independent validation

    • Human oversight recordsEV-24120 · v11

      Adjudicator amendment log with sign-off scope

      Control AIG-03 · captured Continuous · reviewed by Chief Credit Officer

    Illustrative, non-client sample. Evidence specifications, effectiveness grading and the full inventory schema are released under engagement.

    Evidence viewer

    Six evidence classes bound to the control they satisfy, versioned and time-aware.

    Evaluation results

    Benchmark and task-specific eval runs with version, dataset and date. Reruns are versioned, never overwritten.

    Fairness and bias testing

    Protected-attribute analysis where the use case makes it applicable, with methodology recorded.

    Red-team findings

    Adversarial and prompt-injection results, severity, and the remediation that closed each finding.

    Grounding and factuality

    Citation fidelity and grounded-answer rates for retrieval-backed systems.

    Human oversight records

    Where a human reviewed, what they saw, what they changed, and whether they signed.

    Vendor attestations

    Supplier declarations for third-party models, treated as claims requiring confirmation.

    AI incident register

    AI failures are operational incidents. They run through the same register, the same materiality logic and the same supervisory clocks as everything else.

    Detection

    How the failure surfaced — monitoring, human report, downstream control or customer complaint.

    Materiality

    Assessed against the same materiality logic used for cyber and operational incidents.

    Containment

    Whether the system was quarantined, restricted or left running under supervision, and who decided.

    Notification

    Which supervisory clocks started, in which jurisdictions, and when each was met.

    Root cause

    Model, data, prompt, integration, oversight failure or scope creep — categorised, not narrated.

    Closure

    Control change, evidence refresh and score impact recorded to the vault.

    The inventory feeds the AI Trust Score, which feeds the Operational Resilience Score. No dimension is scored from a self-assessed status.