Meridian Freight & Distribution is a fictional company. This register is a worked example built to show the format and the reasoning, and it does not describe any Red Tree Labs client or engagement.
This page shows what the output of a first AI governance exercise looks like when it is finished. The subject is a fictional mid-sized freight forwarding and distribution business with roughly 200 employees, four warehouse locations, and in-house customs brokerage. The exercise took one working session with the operations director, the IT manager, and the controller.
The purpose of the exercise is narrow. It establishes what AI is already in use, who is accountable for each system, and how a failure would become visible. It is not a compliance audit, and it does not attempt to score the organization against a framework.
What the inventory found
Seven systems were identified. Two were purpose-built. Three arrived as features inside software the company already licensed. Two were in use without a decision having been made.
| System | Category | Data it touches | Exposure | Risk |
|---|---|---|---|---|
| Customs document extraction | Purpose-built | Commercial invoices, packing lists, bills of lading | Regulatory filings, duty calculation | High |
| Rate quote assistant | Purpose-built | Historical rates, lane data, customer pricing | Revenue, customer commitments | High |
| Public chatbot used for customer correspondence | In use without a decision | Customer names, shipment details, occasional contract terms | Confidentiality, contractual exposure | High |
| TMS carrier-selection recommendations | Vendor feature | Shipment and carrier performance data | Cost, service commitments | Medium |
| Meeting transcription and summary tool | In use without a decision | Internal discussions, occasional customer calls | Confidentiality | Medium |
| Accounting platform invoice-coding suggestions | Vendor feature | Vendor invoices, GL coding | Financial accuracy | Medium |
| Marketing copy drafting | Vendor feature | No customer or operational data | None material | Low |
The two systems nobody had decided to adopt were the ones that generated the most discussion. Neither was the result of carelessness. Both were people solving a real problem with a tool that was available to them.
Ownership and controls, as recorded
For each system, the register records an owner, a definition of correct operation, a verification method and interval, and the handling procedure for uncertain output. The three high-risk systems are shown in full below. Definitions are deliberately specific: a criterion that cannot be checked is not a criterion.
| System | Category | Owner | Correct operation means | Verification | Exception handling |
|---|---|---|---|---|---|
| Customs document extraction | Purpose-built | Customs compliance manager | HS code, value, quantity, country of origin, and consignee extracted correctly on every document accepted without review | Weekly sample of 25 documents against source, stratified to include each major customer and any new document format | Any field failing validation rules, or any unrecognized layout, routes to the brokerage queue with the failing field marked |
| Rate quote assistant | Purpose-built | Pricing manager | Quote falls within approved margin bands for the lane and reflects current carrier contracts | Monthly review of 20 issued quotes against contract terms, plus automatic flag on any quote outside band | Quotes outside band, or on lanes with no contract on file, require pricing manager approval before issue |
| Public chatbot correspondence use | In use without a decision | Operations director | Not an approved system; no customer or contract data is to be entered | Quarterly confirmation during team review, alongside an approved internal alternative being available | Not applicable. The use is being replaced rather than governed |
Findings
The highest-risk item was not a built system. The customs extraction and rate quote systems were designed with review steps and were working as intended. The unreviewed use of a public chatbot for customer correspondence created the larger exposure, because contract terms had been pasted into a service the company had no agreement with. This is a common pattern. Governance attention follows the systems an organization built, while the unmanaged exposure usually sits in the tools it did not.
Two systems had no owner. The carrier-selection recommendations and the invoice-coding suggestions were both in daily use, both influenced money, and neither had a named person responsible for judging whether they were working. In both cases the vendor had enabled the capability and the company had simply started relying on it.
One system was measured at the wrong level. The customs extraction process was reported at an overall accuracy figure above ninety-five percent. Broken out by document type, one recently onboarded customer whose invoices arrive as scans was substantially below that, and those errors were concentrated in valuation fields. The aggregate figure had been accurate and not useful.
One control existed only in practice. Staff routinely reviewed unusual rate quotes, but nothing in the system required it and nothing recorded it. A control that depends on an experienced person choosing to apply it does not survive that person taking a week off.
In this exercise, the purpose-built systems were governed better than the ones that arrived on their own. The exposure was concentrated in tools that entered the business without a decision.
Prioritized actions
Actions are ordered by exposure reduced per unit of effort, not by risk rating. Two of the seven systems required no action at all, which is a normal and useful result.
| Action | Effort | Addresses |
|---|---|---|
| Provide an approved internal assistant for customer correspondence and state plainly what may not be entered into public tools | 1 to 2 weeks | Confidentiality and contractual exposure |
| Report extraction accuracy by document type and customer rather than in aggregate | 2 to 3 days | Undetected degradation in valuation fields |
| Make the rate quote approval step a required workflow state rather than a habit | 3 to 5 days | Dependence on individual vigilance |
| Assign named owners to the two vendor-provided systems and define what correct operation means for each | 1 day | Unowned systems affecting cost and financial accuracy |
| Review the transcription tool against customer confidentiality obligations and decide whether to approve or replace it | 2 to 3 days | Confidentiality |
| No action: marketing copy drafting and invoice-coding suggestions, once owned, are low consequence and adequately reviewed | None | — |
What this exercise does not do
It is worth being clear about the limits of a one-session inventory, because a register like this can create more confidence than it has earned.
It does not verify that the controls it records are actually operating. It captures what people believe to be true about systems they own, and belief and practice diverge over time. It does not constitute a conformity assessment against any framework or standard, and it should not be presented to a customer or auditor as one. It also reflects a single point in time. The inventory above will be incomplete within a quarter, because vendors will add capabilities and staff will adopt tools, which is why the review interval matters more than the initial document.
For the reasoning behind the structure of this register, see a practical reading of the NIST AI Risk Management Framework.