Identity
- Name
- What people call it, and the product behind it
- Supplier or builder
- Who provides it and under which contract
- Version in use
- And the date it went live
Purpose
- Process served
- The piece of work it sits in
- Decision informed
- And who makes that decision
- Status
- Evaluating, pilot, production or retired
Data
- What goes in
- Personal data? Special category?
- Where it is processed
- And where it is stored
- Training use
- Whether inputs train the supplier’s model
Lawful basis
- Per operation
- A lawful basis for each processing operation
- DPIA
- Reference and date
- Automation
- None, supports a person, or decides
Risk and controls
- Main risks
- Accuracy, bias, security, confidentiality
- Human review
- Who checks, and before what
- Fallback
- What happens if it is switched off
Ownership and evidence
- Business owner
- A named person, not a team
- Measure
- Against the baseline taken before
- Next review
- A date, and the last outcome
Eighteen fields in six groups. Every one has an answer or a named person finding it. Source: Vardonne, drawing on ICO guidance and ISO/IEC 42001
What the ICO expects
The ICO’s guidance on AI and data protection is under review following the Data (Use and Access) Act, but it remains the published position.1 Two expectations shape the register directly. On lawful basis: “You must break down and separate each distinct processing operation, and identify the purpose and an appropriate lawful basis for each one.”1 On impact assessment: in the vast majority of cases, the use of AI will involve processing likely to result in a high risk, and will therefore trigger the legal requirement to carry out a DPIA.1
Automated decision-making is where the guidance is moving. The ICO consulted on draft guidance about automated decision-making and profiling between 31 March and 29 May 2026, and says an AI and automated decision-making code of practice awaits government secondary legislation.2,3 The “Automation” field in the record is there so that a change in the rules is a query on the register, not a search of the firm.
The management system around it
ISO/IEC 42001 specifies requirements for establishing, implementing, maintaining and continually improving an AI management system. It is meant for organisations that provide or use AI-based products or services, and it uses the Plan-Do-Check-Act method.4 It shares the common management-system structure of ISO 27001 and ISO 9001, so a firm that already runs one of those has much of the machinery.
- Plan
- Scope, policy, risk assessment, objectives. The register is built here.
- Do
- Controls operated: DPIAs, human review, supplier terms.
- Check
- Measures, incidents and the register reviewed on a rhythm.
- Act
- Corrections made, systems retired, the policy improved.
Source: ISO4
Keeping it alive
Review the register monthly in the operating rhythm, whenever a system changes, and after any incident. Retire records rather than deleting them: the history of what was used, and why it stopped, is evidence an auditor or evaluator will ask for.
Sources
- Guidance on AI and data protection (under review following the Data (Use and Access) Act; main update 15 March 2023, some pages updated since). Information Commissioner’s Office, read 21 September 2026.
- Consultation on draft guidance about automated decision-making, including profiling (31 March to 29 May 2026). Information Commissioner’s Office, March 2026.
- AI and biometrics strategy update. Information Commissioner’s Office, March 2026.
- ISO/IEC 42001:2023, Artificial intelligence: Management system. ISO, December 2023.