Building AI System
Repository &
Governance Framework
Responsible AI Summit 2025
Table of Contents
01 AI-Enabled Applications
04 Inventory Ready
02 AI Scan Report 05 AI Risk Assessment
Finding AI Applications in
03 AI facts & Stats
06 Your Asset Inventory
Global Business –
07 How to Protect It?
What % of Large Enterprises
Applications are 42% report active use of AI in some
business processes.
AI-enabled or
marketed as AI? AI Washing
Many vendors label products with “AI”
without substantive use.
Reality Check
Actual AI/ML usage across all apps is often
far lower than marketing claims. Audit Approach
Measure by inventory- search for true
AI libraries or documented models, not
just keyword.
How many apps in your IT
landscape do you think
have genuine AI
Components?
AI Scan Report
Sector Website Detected AI Technologies Type of AI Notes
Personalized product recommendations; customer
Amazon India AWS Personalize, Amazon Lex Recommendation engine, Chatbot
support chatbot.
E-commerce
AJIO Recommendation ML Recommendation engine Personalized style recommendations.
Dynamic pricing, dispatch Forecasts demand; implements surge pricing and
Ola Demand prediction ML
optimization dispatch.
Cab Service
Uber India ETA prediction, surge pricing ML Route & pricing optimization Machine learned ETA and dynamic pricing models.
Netflix India Netflix recommendation engine Recommendation engine Proprietary ML models for personalized suggestions.
Entertainment
Amazon Prime
AWS Personalize Recommendation engine Uses AWS ML for content suggestions.
Video
Image recognition, Menu item recognition; personalized restaurant
Zomato Computer vision, recommendation
recommendation ML suggestions.
Food
Swiggy Logistics ML, ETA prediction Delivery optimization Route planning and delivery time estimates.
Some eye-opening AI
While AI offers transformative opportunities, it
simultaneously raises profound regulatory, ethical, and
Facts & Stats security challenges.
01 Regulatory
Impact 02 Privacy
Violation 03 Security
Concern
Italy fined OpenAI €15 million Swedish school fined €20k 72% of CISOs fear generative
for GDPR breaches. for using facial-recognition. AI tools could cause security
breaches.
04 Data
Ethics 05 Economic
Opportunity 06 High
Fines
75% of tech professionals AI-related tech is booming: Under the EU AI Act 2024,
rank data privacy as a top WEF projects 170 million new violations can incur up to 7%
ethical concern. jobs by 2030. of global turnover in penalties.
AI Updates around the World
AI is reshaping global policy and job markets, with new regulations, public investments, and infrastructure
initiatives driving both innovation and accountability.
AI Job Global AI IndiaAI Mission &
Market Regulations Portals
The WEF Future of Jobs Report The EU AI Act enforces strict Launched in 2024 with a ₹10,371
2025 projects 170 million new rules on high-risk AI systems, Cr budget, the IndiaAI Mission,
jobs by 2030, with AI/ML while U.S. Executive Orders on AI along with the AIKosha data
specialists and data scientists focus on safety and portal and IndiaAI Compute
among the fastest-growing governance development. Portals.
roles.
Inventory Ready – As AI functionalities expand, it's crucial to catalog their
capabilities, map their context, and document high-risk uses
Identify Functionalities
to ensure effective governance and minimize potential risks.
01 Catalog AI
Functions 02 Context
Mapping
03 Stakeholder
Impact
For each identified AI system, Determine data List who uses it and who is
note what it does. inputs/outputs and affected impacted.
processes.
04 High-risk
Use Cases 05 Documentation
Cross-reference functionalities Document each AI app’s
with known risk categories. purpose, algorithms, and data
classification.
AI Risk Assessment - Scope & Questions
S. No. Key Focus Area Scope and Assessment Questions
High-risk AI (per step 5) needs thorough vetting; low-impact AI may need lighter review. Follow
01 Scale evaluation to risk
frameworks (e.g. NIST AI RMF, ISO 23894).
02 Key risk dimensions Assess Accuracy, Fairness (Bias), Privacy, Security, Transparency, and Safety.
Is data legally obtained and of good quality? Are people’s privacy rights protected (consent,
03 Data & privacy
anonymization)?
04 Bias & ethics Are protected groups over/under-represented? What steps are taken to detect and mitigate bias?
05 Transparency Can outputs be explained? Are end-users informed they’re interacting with AI?
06 Security & robustness Is the model protected from adversarial attacks or theft? Is there a plan for failure or rollback?
07 Accountability Who is responsible if the AI causes harm? Are governance roles (owner, reviewer) clear?
08 Regulatory requirements For high-risk cases, check compliance checklists (e.g. EU AI Act’s seven high-level requirements
Finding AI Applications in Your
Asset Inventory
Method Pros Cons Best Use
Time-consuming -
Uncovers AI hidden inside
Developers might You build your own apps or
Developer Surveys custom apps - Developers
underreport or miss have data science teams.
can flag future AI plans.
embedded libraries.
Very thorough for internal Resource-intensive - Won’t You develop a lot in-house
Code Inspection code - Detects AI even if find AI inside black-box and can afford code
undocumented. SaaS. scanning.
Needs mature network
Can detect real usage of AI
monitoring tools - You want real-time tracking
Log & Network Monitoring APIs - Catches systems not
Privacy/legal concerns if or spot unknown AI use.
officially documented as "AI".
mishandled.
Global Business – How to Protect It?
Multi-Jurisdictional Policy Harmonization
Compliance Establish a unified internal AI policy on ethics,
Ensure compliance with regional laws and stay privacy, and security, to be overseen by an AI
updated on emerging AI frameworks. governance council.
Adopt Highest Standards Monitor Evolving Laws
Use GDPR/AI Act principles globally as a Stay updated on AI safety acts, emerging
baseline. guidelines and national initiatives.
Intellectual Property & Export
Data Governance
Use Standard Contractual Clauses or Binding
Controls
Corporate Rules for cross-border data transfers. Protect your AI models and data under
Implement data localization. international IP laws. Be aware of export control
rules on advanced AI chips or software.
Thank You!
Global Business – How to Protect It
Multi-Jurisdictional Policy Harmonization
Compliance Establish a unified internal AI policy on ethics,
Ensure compliance with regional laws (GDPR, privacy, and security, with local adaptability,
NIST, DPDP, PIPL) and stay updated on emerging and oversee it through a global AI governance
AI frameworks such as EU AI Act. council.
Adopt Highest Standards Monitor Evolving Laws
Use GDPR/AI Act principles globally as a Stay updated on AI safety acts, emerging
baseline. E.g., if it’s compliant with EU, it often guidelines (OECD AI principles, UNESCO), and
exceeds requirements elsewhere. national initiatives.
Intellectual Property & Export
Data Governance
Use Standard Contractual Clauses or Binding
Controls
Corporate Rules for cross-border data transfers. Protect your AI models and data under
Implement data localization where required by international IP laws. Be aware of export control
local regulations. rules on advanced AI chips or software.