AI for Government
Capable · M8 · lesson 8 of 43 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
AI Use Case Inventory and Documentation (OMB M-24-10)
📖
now learning

AI Use Case Inventory and Documentation (OMB M-24-10)

15 min

Learning Objectives

After completing this lecture, you will be able to:

  • Understand the key concepts of ai use case inventory and documentation (omb m-24-10) in a government context
  • Participate in structured workshop activities with real-world scenarios
  • Use downloadable templates for immediate workplace application
  • Identify next steps for applying these concepts in your role

Key Topics Covered

-
How to document AI use cases

-
Classification requirements

-
The federal AI use case inventory

-
Hands-on documentation exercise

Why This Matters for Government

Government agencies face unique challenges when it comes to AI adoption. This lecture addresses these challenges head-on by providing analysts, project leads, team supervisors with the knowledge and frameworks needed to navigate AI in the public sector responsibly and effectively.

As part of the L2 (AI Practitioner) curriculum, this lecture builds on the foundational principle that every AI system in government ultimately serves citizens. Whether you are working with AI tools daily or setting strategy for your agency, understanding ai use case inventory and documentation (omb m-24-10) is essential for responsible, effective government AI adoption.

======================================================================

TRANSCRIPT: AI Use Case Inventory and Documentation (OMB M-24-10)

======================================================================

Chapter: 3

What you will learn:

  • OMB M-24-10 requirements for AI inventory and documentation
  • What information must be documented for each AI use case
  • How to create and maintain an AI inventory
  • Documentation standards and templates
  • Privacy and transparency considerations
  • How inventory documentation supports governance

OMB M-24-10, "Advancing Governance, Innovation, and Risk Management for Agency Use of Artificial Intelligence," sets specific requirements for federal agencies around AI inventory and documentation. But many agencies treat this as a checkbox: create a spreadsheet, list your AI systems, file it away, never look at it again.

That's missing the point. An AI inventory isn't bureaucratic overhead--it's the foundation for everything else you do. When you document your AI systems comprehensively, you create organizational visibility. You make it possible for your governance structures to actually govern. You enable measurement, incident response, and continuous improvement.

This lecture teaches you what OMB requires you to document, why each piece of documentation matters, and how to create an inventory that's actually useful. By the end, you'll understand how to inventory your agency's AI systems in a way that drives responsible governance.

WHY THIS MATTERS FOR GOVERNMENT

Before OMB M-24-10, many agencies had no idea how many AI systems they were actually operating. Systems were scattered across departments and divisions. Different teams were using different technologies for similar purposes, duplicating effort and creating inconsistency. When something went wrong, there was often no central record of what systems existed or how they worked.

OMB M-24-10 changed this. Agencies must now maintain a central inventory of AI systems, document what they do, who they affect, and how they're governed. This inventory serves multiple purposes: it demonstrates compliance with OMB requirements; it enables measurement and monitoring; it prevents harmful systems from operating under the radar; it allows learning and best practice sharing across departments.

An effective inventory transforms how an agency governs AI. It moves from reactive governance (responding to problems when they emerge) to proactive governance (knowing what you're operating and ensuring it meets standards before problems emerge).

WHAT OMB M-24-10 REQUIRES

OMB M-24-10 requires agencies to:

  • Establish a Chief AI Officer or equivalent responsible for AI governance
  • Establish governance structures to oversee AI systems
  • Maintain an inventory of AI systems currently in use or in development
  • Conduct impact assessments for systems that are safety-impacting or rights-impacting
  • Document and report on AI systems using specified standards

For the inventory specifically, OMB requires that agencies document:

  • System name and description: What is the system called? What does it do?
  • Agency and office: Which agency component operates this system?
  • System status: Is it in development, deployed, or retired?
  • AI techniques used: What machine learning or AI methods does it employ?
  • Data sources: What data does the system use?
  • System's intended use: What is the system designed to do?
  • Performance metrics: How is the system measured?
  • Risk classification: Is it safety-impacting, rights-impacting, or other?
  • Responsible official: Who is accountable for this system?
  • Approval and monitoring: Has it been approved? Is it being monitored?

Additionally, OMB requires agencies to document the impact assessments conducted for safety-impacting and rights-impacting systems.

CREATING A COMPREHENSIVE AI INVENTORY

Building an inventory is a multi-step process:

Step 1: Define what counts as an AI system

As we discussed in the MAP lecture, you need a clear definition. Government-wide, OMB defines it broadly: any system using machine learning, statistical models, or other computational methods to make or support decisions falls within scope.

Step 2: Communicate the inventory effort

Announce the inventory project to all agency components. Explain what you're doing and why. Ask for voluntary reporting initially.

Step 3: Distribute questionnaires

Create a simple questionnaire asking about AI systems. Make it as easy as possible to respond. Ask:

  • What systems do you use to automate decisions?
  • What systems help you analyze data?
  • Do you use any AI services (cloud-based or SaaS)?
  • What commercial software with AI capabilities do you use?

Step 4: Conduct follow-up interviews

For systems reported, conduct detailed interviews with system owners. Document additional details. Find systems that weren't reported initially.

Step 5: Audit cloud accounts and SaaS subscriptions

Review your organization's cloud accounts (AWS, Azure, Google Cloud) and SaaS subscriptions. Identify AI services being used. Add to inventory.

Step 6: Consolidate and deduplicate

You'll probably find that multiple departments are using the same system, or that a system was reported under different names. Consolidate. Establish a single canonical name for each system.

Step 7: Validate with system owners

Check back with people responsible for each system. Confirm information is accurate. Add missing details.

Step 8: Classify and prioritize

Classify systems by risk level (safety-impacting, rights-impacting, other). Prioritize rights-impacting and safety-impacting systems for impact assessment and documentation.

Step 9: Establish maintenance process

Decide how the inventory will be kept current. Who updates it? How often? What triggers updates? (New system deployment? System changes? Annual review?)

DOCUMENTATION REQUIREMENTS FOR HIGH-RISK SYSTEMS

OMB focuses particular documentation attention on systems that are safety-impacting or rights-impacting. For these systems, you must create an impact assessment documenting:

Technical Specifications:

  • What are the input data and outputs?
  • What machine learning model or algorithm is used?
  • What are the model's performance characteristics?
  • Has the model been tested? What were the results?
  • How often is the model retrained or updated?

Data Documentation:

  • What data is used to train the model?
  • How representative is the training data of the real-world population?
  • Are there known data quality issues?
  • How is data updated and refreshed?

Risk Assessment:

  • What are potential failure modes?
  • What is the impact if the system fails?
  • What is the likelihood of failure?
  • What harm could the system cause?
  • Who would be affected by failures?

Fairness and Equity Assessment:

  • Has the system been tested for disparate impact?
  • Do outcomes differ across demographic groups?
  • If differences exist, are they justified?
  • What is the plan for addressing unfairness if found?

Transparency and Explanation:

  • Can the system explain its outputs?
  • Do people affected by the system understand how decisions are made?
  • Is there an appeal or override mechanism?

Governance and Oversight:

  • Who is responsible for this system?
  • What monitoring is in place?
  • What is the incident response process?
  • How frequently is the system reviewed?
  • What conditions would trigger escalation or shutdown?

DOCUMENTATION STANDARDS AND TOOLS

OMB provides guidance on documentation standards, but implementation varies. Key approaches:

Spreadsheet-based inventory: Simple but limited. Works for smaller numbers of systems (under 50). Difficult to keep linked information synchronized. Limited query and analysis capability.

Database or inventory management system: Better for larger numbers of systems. Enables linking related documents (impact assessments, monitoring reports). Supports querying and analysis. Examples: MongoDB, PostgreSQL, custom-built systems.

AI governance platforms: Specialized tools designed for AI governance (Trustworthy AI, Responsible AI tools from vendors). These often integrate inventory, impact assessment, monitoring, and incident response capabilities.

Most agencies start with spreadsheets, then graduate to databases or platforms as the inventory grows.

Suggested inventory fields:

System name | Agency | Owner | Status | AI Technique | Risk Classification | Last Review Date | Impact Assessment Completed | Monitoring Status | Notes

INVENTORY MAINTENANCE AND EVOLUTION

Overview

An inventory created once and never updated becomes stale and useless. Effective inventory requires:

Regular Review Cadence:

  • Quarterly: Review for new systems, systems moved to production, systems retired
  • Annually: Full review of all systems, update of risk classifications if needed, update of monitoring status

Change Management:

  • When a system is deployed, it's added to inventory
  • When a system's scope expands (used for new purposes), risk classification is reviewed
  • When a system is retired, its entry is marked as archived but retained for historical record

Escalation Process:

  • If a system's risk classification changes, escalate to governance leadership
  • If a system shows performance problems, escalate and update documentation
  • If systems show common problems, patterns are analyzed and governance is updated

Use of Inventory Data:

  • Governance boards use inventory to identify systems for impact assessment
  • Measurement teams use inventory to identify what systems to monitor
  • Leaders use inventory to identify where investments in governance are needed
  • Researchers and auditors use inventory to understand agency AI footprint

PRACTICAL USE CASE 1: Large Federal Agency

A large federal agency begins OMB M-24-10 inventory process. Initial survey uncovers 47 systems. Further investigation (cloud account audit, interviews) identifies 23 additional systems. Total: 70 systems.

Classification: 8 rights-impacting, 4 safety-impacting, 58 other.

Next steps:

  • Impact assessments required for 12 high-risk systems (6-12 month timeline)
  • Monitoring plans for all high-risk systems (1-2 months)
  • Governance board review of all systems (ongoing, quarterly)
  • Inventory updates as systems change (ongoing)

Result: Agency now has visibility into its AI footprint. Governance can target resources effectively.

PRACTICAL USE CASE 2: Compliance Audit

An OMB inspector general audit of an agency's AI governance begins with the inventory. The audit finds:

  • 15 systems operating that are not in the inventory
  • 6 systems in the inventory that are no longer deployed
  • 8 systems whose risk classifications seem incorrect
  • 12 systems with no documented monitoring
  • 3 systems with no identified responsible official

The audit triggers:

  • Immediate update of inventory to include missing systems
  • Impact assessments for systems that should have been classified as high-risk
  • Establishment of monitoring for all systems
  • Assignment of clear ownership
  • Process improvements to prevent future inventory gaps

ANTI-PATTERNS AND MISUSE RISKS

Risk 1: Inventory Without Action

Creating an inventory that is complete and documented but then doing nothing with it. The inventory becomes an inert artifact, checked off for compliance, never actually used for governance.

Avoid by: Using the inventory actively. Governance boards should review it regularly. Use it to identify systems that need measurement. Use it to track progress on impact assessments. Make it a living, actively-managed resource.

Risk 2: Gaming the Classification

Systems are intentionally under-classified to reduce documentation burden. A rights-impacting system is labeled "other" to avoid impact assessment.

Avoid by: Having clear classification criteria and supporting judgments with evidence. Having governance oversight of classifications. Spot-checking classifications for accuracy.

Risk 3: Inventory Sprawl

Too many systems in the inventory because the definition of "AI system" is too broad. Every predictive calculation is included. The inventory becomes unwieldy and loses value.

Avoid by: Having a clear, reasonable definition of AI system. Systems must involve machine learning or statistical model, not just ordinary calculations. Apply the definition consistently.

Risk 4: Incomplete Documentation

High-risk systems are inventoried but the required documentation is missing. Impact assessments haven't been completed. Monitoring plans haven't been created. The inventory shows gaps rather than solutions.

Avoid by: Having a governance process that requires documentation as a condition of system deployment. Systems can't go into production until required documentation is complete.

PRACTICE AND REFLECTION PROMPTS

Prompt 1: Inventory Your Systems

List all AI systems you're aware of in your area. For each, document: name, purpose, owner, data sources, risk classification. Start building your local inventory.

Prompt 2: OMB Template Application

Take one of your systems and fill out the OMB-required fields: system name, agency, owner, status, AI technique, risk classification, last review, etc.

Prompt 3: Impact Assessment Design

For a high-risk system, outline what you would include in an impact assessment. What technical specs matter? What fairness information is essential?

Prompt 4: Inventory Process Design

Design the process for creating and maintaining an AI inventory in your agency. How would systems be identified? How would information be updated? Who would own the inventory?

Prompt 5: Communication Strategy

You're rolling out an inventory process. How would you communicate to different stakeholders (technical teams, leadership, compliance)? What would you emphasize for each audience?

KEY TAKEAWAYS

  • OMB M-24-10 requires AI inventory. Federal agencies must maintain a documented inventory of AI systems.
  • Inventory serves governance. It's not compliance theater--it's the foundation for effective governance.
  • High-risk systems require detailed documentation. Safety-impacting and rights-impacting systems need impact assessments.
  • Inventory must be comprehensive. Include all AI systems, including cloud-based and SaaS services often overlooked.
  • Inventory must be maintained. Created once doesn't work. Regular review and updates are essential.
  • Inventory enables action. Use it to identify systems needing measurement, guidance, or escalation.
  • Classification and documentation are linked. How you classify a system determines what documentation is required.

GLOSSARY

AI Inventory -- Comprehensive catalog of all AI systems in an organization, documenting key information about each.

Impact Assessment -- Formal documentation of an AI system's purpose, data, risks, fairness implications, and management approach.

Risk Classification -- The process of determining whether a system is safety-impacting, rights-impacting, or lower-risk.

System Owner -- The person designated as responsible for a specific AI system's operation and compliance.

Responsible Official -- The designated person accountable for a system's governance and performance.

The inventory process connects all the governance concepts you've learned: GOVERN (who makes decisions), MAP (what systems exist), MEASURE (how they perform), MANAGE (what to do about problems), and classify (how intensive governance should be).

Creating a good inventory is often the first concrete step an agency takes toward mature AI governance. It forces asking hard questions: What are we actually operating? Who owns it? Is it working as intended? Does it meet our standards?

Those questions, multiplied across your entire AI footprint, become the foundation for change.

Assess your organization's inventory maturity:

Do you have a centralized inventory of AI systems? If yes, is it current? If no, what's preventing it?

For high-risk systems, are impact assessments complete? What gaps exist?

Who owns the inventory? How is it maintained? Is it a one-time artifact or a living resource?

If the inventory were complete and accurate, what would you learn about your AI footprint? Would that knowledge change your governance approach?

This lecture has covered OMB M-24-10 inventory and documentation requirements. An effective inventory is organizational infrastructure--it enables every other governance function.

In the next lecture (2.3.5), we'll explore minimum risk management practices: the specific safeguards and controls that OMB requires agencies to implement for responsible AI systems.

A strong inventory is prerequisite for effective minimum practices. You can't implement safeguards for systems you don't know about. You can't measure what you haven't inventoried.

End of Transcript

Source: GOVT.CLUB

Visit: https://govt.club/learn/lectures/l2/234-ai-use-case-inventory-and-documentation-omb-m-24-10.html

Government AI CLUB Certification Program

Level 2: AI Ready | AI Use Case Inventory and Documentation (OMB M-24-10) | Lecture 2.3.4

A GOVT.CLUB initiative

<- 2.3.3 Your Agency's AI Governance Structure
2.3.5 Risk Classification: Safety-Impacting vs. Rights-Impacting ->

Start Your CLUB Certification

This lecture is part of L2: AI Practitioner -- 40 hours of comprehensive government AI training.

Explore CLUB Certification

L2
2.3.1 -- NIST AI RMF: The GOVERN Function
60 min - Video + Workshop

L2
2.3.2 -- NIST AI RMF: MAP, MEASURE, MANAGE
60 min - Video + Workshop

L2
2.3.3 -- Your Agency's AI Governance Structure
60 min - Reading + Discussion