The AI Register Your Clients Will Ask For Before Your Regulator Does
Very soon you will be asked something like this by your clients - do you use AI in delivering our services? Which tools? What happens to our data when you do? This usually means they are completing a due diligence pack or performing an audit - which means they will want an answer in a few days!
Suddenly you realise you cannot answer, not because of the time pressure, but because no-one has any of this written down anywhere.
This guide builds the two documents that answer those questions: a six-column AI register and a one-page usage policy. No code. No consultants. Ninety minutes of work, and the next questionnaire becomes a copy-paste exercise.
Who Is Asking, and What They Ask
Four groups are asking. Each asks a slightly different question, and the exact wording matters, because the wording tells you what evidence they want.
Clients
Procurement teams have added AI to their supplier questionnaires. It usually sits inside the annual due diligence pack, or arrives as an addendum to the data processing agreement. The question looks something like this:
"Does your organisation use artificial intelligence or machine learning tools in the delivery of the services? If yes, list the tools, describe the categories of personal or confidential data processed by each, and confirm whether any tool makes or influences decisions about individuals."
Insurers
Professional indemnity and cyber insurers have started asking about AI at renewal. They are pricing the risk of tools they cannot see. Expect something like:
"Do you use AI tools in the course of business? If so, confirm whether client data or personal data is entered into such tools, and describe the controls in place to prevent unauthorised disclosure."
Larger partners
If you subcontract for a bigger firm, their obligations become yours. Their regulator or their clients are asking them, so they ask you. This one usually arrives as a contract variation or a "supplier standards" email:
"As a condition of continued engagement, suppliers must maintain a record of AI tools used in connection with our work and provide it on request. Suppliers must not input our confidential information into AI tools without prior written consent."
Your own team
The fourth group is inside the building. Your team wants to do the right thing and currently has no way to know what that is. The question arrives one at a time, usually in private:
"Am I allowed to use ChatGPT for this? A candidate has emailed asking what we do with their CV. What do I tell them?"
Four audiences, one underlying request: show us you know what AI your business uses, what data it touches, and who is in charge of it. Answer that, and you can answer all four.
Why You Can't Answer It Today
The reason is not negligence. It is how the tools arrived. Nobody bought an AI platform. AI turned up one person at a time: a £20-a-month subscription expensed here, a personal login there, a free tier someone signed up for to finish a proposal on a Sunday. Each decision was small and rational. Nobody was ever asked to make the big one.
So there is nothing to point at. No approved list, because nobody was asked to approve. No record of what data goes where, because nobody was asked to record it. No owner, because ownership was never assigned. The questionnaire is not exposing recklessness. It is exposing that adoption happened without anyone deciding anything.
That is fixable, and fixable quickly, precisely because the estate is small. You do not have an enterprise AI problem. You have a dozen subscriptions and a gap in the paperwork.
The Register
The register is a table, not a system. Six columns, one row per tool. A spreadsheet is fine. What matters is that it exists, it is current, and it has an owner. Here is one for a fictional 14-person recruitment firm:
| Tool | Who uses it | What data goes in | Influences a decision about a person? | Owner | Last reviewed |
|---|---|---|---|---|---|
| ChatGPT (Team workspace) | 6 consultants | Candidate CV summaries, job spec drafts | Yes - feeds shortlisting | Ops manager | 1 Jul 2026 |
| Otter.ai | All 14 staff | Interview recordings and transcripts | Yes - interviews inform placements | Ops manager | 15 Jun 2026 |
| Notion AI | 4 delivery staff | Internal process docs, meeting notes | No | Ops manager | 1 Jun 2026 |
| Canva Magic Studio | 1 marketing person | Stock images, public job ads | No | Marketing lead | 20 May 2026 |
Tool. The product and the tier, because they differ. "ChatGPT" is not an answer; "ChatGPT Team workspace, business data excluded from training" is. The free tier and the business tier of the same product carry completely different data terms.
Who uses it. Named people or a named team, not "various". When the insurer asks who has access, "the six consultants" is an answer. "Some of the team" is not.
What data goes in. The honest version. Not "documents" but "candidate CVs, client job specs, interview notes". This column takes the most courage, because it is where you write down what is actually happening.
Influences a decision about a person? Yes or no. This is the column that changes your external answers. A tool that summarises CVs influences who gets shortlisted. A tool that drafts interview questions influences who gets hired. A tool that makes social posts does neither. Wherever the answer is yes, that row needs a named human review step, which is where the policy comes in.
Owner. One named person per tool, who keeps the row current and can answer questions about it. Not a department. A person.
Last reviewed. A date. When the next questionnaire lands, a review date from this quarter tells the reader the register is alive. A date from two years ago tells them it is theatre.
Four rows is a fine start. You are not cataloguing every experiment. List the tools that touch client work or client data first. The image generator your marketing assistant uses for internal slides can wait.
The Policy, Six Headings
The policy is one page. Six headings, with actual wording below, written to be lifted and adapted. It is deliberately plain: if your team cannot repeat it back after one read, it will not survive contact with a deadline.
1. Approved tools
The only AI tools approved for client work are those listed in the AI register, on the accounts named there. Personal accounts are not approved for client work. If you want to use a new tool on client work, ask the register owner first; adding it takes ten minutes.
2. What never gets pasted
The following never goes into an AI tool, on any account: client personal data not covered by our engagement terms, anything marked confidential, payroll or HR records, references, and passwords or access credentials of any kind. If you are unsure whether something counts, it counts. Ask first.
3. Human review where a decision affects a person
AI can draft, summarise, and shortlist. It does not decide. Where a decision affects a person - hiring, rejection, promotion, pricing to a named client, anything contractual - a named human reviews the AI output and makes the call. Their name goes on the decision, not the tool's.
4. Client data and confidentiality
Client data goes into an AI tool only if the register row for that tool says it does, and only on the business account listed there. Where a client's contract restricts AI processing, that client's data does not go in at all. When a client asks what we use, answer from the register, not from memory.
5. Who to tell when it goes wrong
If you think client or personal data has gone into the wrong tool, or AI output has gone to a client unreviewed, tell the register owner the same day. You will not be blamed for reporting it. You will be in difficulty for sitting on it.
6. Review cadence
The register is reviewed on the first Monday of every quarter, and the policy with it. New tools are added the week they are adopted, not at the next review. If either document is more than three months old, treat it as out of date.
Get both documents as a fill-in template
The blank six-column register and the full policy wording above, ready to adapt to your business. Enter your details and it downloads immediately.
No spam. Unsubscribe any time.
How to Answer the Questionnaire
This is where the register earns its keep. Take the question types from section one. Each now has an answer you can give without a meeting, a scramble, or a survey of the team.
| The question | The answer you can now give |
|---|---|
| "Do you use AI in delivering our services?" | "Yes. Four tools, all listed in the attached register with owners and review dates." |
| "Which tools, and what data do they process?" | Columns one and three of the register, attached verbatim. |
| "Does AI make or influence decisions about individuals?" | "Two tools influence candidate decisions. Both operate under mandatory human review, and the reviewer is named in our policy." |
| "What controls prevent unauthorised disclosure?" | "The attached policy: an approved-tools list, a never-pasted list, and a named owner per tool." |
| "Who is accountable?" | "The register names an owner per tool, and one register owner overall. Real people, with phone numbers." |
Notice what happened. The questionnaire stopped being an investigation and became a document retrieval exercise. A procurement questionnaire has a date on it; the register is how you meet the date.
90 Minutes This Week
- 30 min - build the register. Send the team one message: "What AI tools do you use for work, and what do you put into them?" List what comes back in the six columns. Do not audit laptops. Ask, and make it safe to answer honestly.
- 30 min - adapt the policy. Take the six headings from section four, change the nouns to fit your business, and delete anything you will not actually enforce.
- 30 min - brief the team. Read the policy out loud, take questions, and name the register owner out loud too. Then email both documents to whoever asked.
Done: ninety minutes, and the next questionnaire is a copy-paste exercise.
Some of this is also becoming a legal expectation. The Data (Use and Access) Act 2025 changed how automated decision-making is regulated under the UK GDPR, and the ICO is updating its AI guidance as a result. If that applies to you, confirm your position with your DPO or a solicitor.
In my consulting work, the AI governance conversation increasingly starts with a forwarded email: a client questionnaire, an insurance form, a partner's new supplier terms. The firms that struggle are not the ones using AI recklessly. They are the ones using it sensibly but invisibly, with nothing written down. When we build the register, the surprise is never the number of tools. It is column four: the realisation that something someone regarded as admin is influencing decisions about people. That single column changes the insurance answer, the client answer, and usually one or two internal habits. Do the 90 minutes before the questionnaire arrives, not the week after. For the wider question of which tools deserve a place on the register at all, see the AI Ecosystem Decision guide, and for what those tools should be costing you, AI Cost Routing.
Where to Start
The next step is not a 40-page governance framework, and it is not a procurement exercise for a GRC platform. It is 90 minutes this week: one table, one page, one team briefing. If the questionnaire has already landed, do it tomorrow morning.
If you read this and realised you could not answer those four questions today, you are in the same position as most firms we work with. The difference, in a week's time, is that you will have the two documents, and they will not.
Sources
- Data (Use and Access) Act 2025 (2025 c. 18), Part 5, Chapter 1, automated decision-making - legislation.gov.uk
- ICO, Guidance on AI and data protection - ico.org.uk AI hub
- ICO, Our plans for new and updated guidance - confirming new guidance work following the Data (Use and Access) Act - ico.org.uk
The register is the easy half.
Deciding which decisions a machine is allowed to make in your business is the hard half, and that's what the Executive session covers.
View Executive AI Strategy - £249/seat