A five-column spreadsheet of the AI tools staff actually use is the prerequisite for any policy or assessment, and it only works if built in an amnesty spirit.
Every organisation we assess already has an AI tool inventory. Nobody has written it down, and that is the whole problem. It exists as forty separate answers in forty separate heads: what the communications officer uses to draft newsletters, what the intern uses to summarise interview notes, what the finance lead pastes budget figures into after hours. Almost none of it is wrong to use. Almost none of it is visible to the people who would need to see it to write a policy, run an assessment, or answer a funder's question honestly.
The inventory is not a security exercise, and treating it as one is why most attempts at one fail. It is a boring administrative artefact, closer to a fixed-asset register than a compliance audit, and it only works if staff experience it that way.
We have written before about why a ban on AI tools is a measurement failure, not a control: prohibition does not reduce use, it only reduces what you can see. The inventory is the artefact that an honest, amnesty-framed conversation about shadow AI produces. Sector survey data (one industry benchmark, worth treating as directional rather than exact) puts AI tool use among nonprofits above ninety percent, with the large majority of that use happening individually, outside any shared workflow. That gap between near-universal use and near-zero visibility is precisely what the inventory exists to close. If staff believe naming a tool will get it taken away, they will not name it, and the inventory becomes a list of the tools you already knew about, which is to say, useless.
The inventory does not need to be sophisticated. It needs to be complete, current, and short enough that someone actually keeps it updated. For most organisations under 500 staff, a single spreadsheet with five columns does the job:
IT can own the spreadsheet. IT cannot populate it, because IT does not see most of what belongs on it. The programme officer using a tool to draft grant reports has never filed a ticket about it and has no reason to. Ownership has to sit with someone who has standing to ask every department head the same question every six months, and the authority to treat "I don't know yet" as an acceptable interim answer rather than one people quietly paper over.
Maintaining this costs real time: an initial pass to build it, then a recurring check-in, indefinitely, because tools change faster than policies do. Organisations that skip this step are not saving that time. They are deferring it to the worst possible moment, an audit, an incident, a funder's due-diligence question, when the answer has to be produced under pressure and with less honesty than a routine six-monthly ask would have got.
You cannot write a policy for tools nobody told you existed.
Everything downstream depends on it. A usage policy that names permitted tools by role is unenforceable if the register of actual tools in use does not exist. A readiness assessment scores current practice against a picture that, without this, is guesswork dressed up as data. The evidence file a board or funder eventually asks for starts here, because "what tools do you use, and for what" is the first question in nearly every version of that conversation we have seen.
Before commissioning any AI policy or assessment, build the five-column inventory first, even a rough and incomplete one; a policy without it is regulating a picture of your organisation that does not exist.
If this is the question on your desk, a thirty-minute call tells you whether the service fits, or that you do not need us yet.