An AI register that's still true next month.
Not a project. Not an audit. A loop your organisation runs on. Most governance work is episodic — a gap analysis, a scramble before an audit, a register that's stale the week after it's built. Moustr is built the other way round: a small recurring cycle, owned by named people at defined cadences, that keeps the estate known and accountable.
Every day it runs, the record gets more valuable. Every day it stops, the estate drifts back into the dark. That asymmetry is what makes this a must-have rather than a nice-to-have.
Four stages. One record. Everyone reads from the same place.
- Stage 1Discoveralways-on, read-only
- Stage 2Confirma human owns it
- Stage 3Governobligations and exceptions
- Stage 4Proveevidence on demand
↻ Any material change re-triggers the loop
Three sources brought together, not one scan: machines observe, people explain, vendors' own published statements fill the gaps. The discovery engine, the reconciliation logic and the record are all our own code, not a third-party dashboard with a logo on it.
Why a loop and not a project: a project ends and its output decays — a consultant's register is stale the week the invoice is paid. A loop has no end state, it has a steady state, and a source that goes quiet is noticed rather than silently lost.
Four stages is a description. This is the thing.
A guided walkthrough of the product itself — new AI tools surfacing, the issues ranked for you, an owner and contract recorded against a tool, and the report you hand to your board. No sign-up, no sales call.
What the register actually looks like.
- Every AI tool in use, new ones waiting for a decision, and what needs attention first.
- One record per tool: the owner, the purpose, the risk assessment, the agreement and the contract dates.
- Progress across five milestones, and the Governance Report that proves it.
about ninety seconds
The tour runs on moustr.com itself. Nothing third-party loads.
What each stage actually does.
| Stage | What happens | Who does the work |
|---|---|---|
| DiscoverLIVE | Continuous observation of the estate — service signals from what you include, enriched with what vendors publish about AI in their products, plus contract and DPA details entered by hand or imported in bulk. Agentless by default and read-only. New AI is picked up as it appears. Trigger: always on. | The machine |
| ConfirmLIVE | A candidate becomes a governed record when a named human stands behind it. Your governance lead assigns an owner — dated, attributed and kept. Centralised assignment is deliberately the faster route to a maintained register: one person deciding beats twenty people being chased. Owner self-confirmation is on the roadmap, and adds attestation weight rather than speed. Trigger: new system found, or material change. | Governance lead |
| GovernLIVE | Each confirmed use is mapped to its obligations — EU AI Act risk screening and your own internal policy. Each system carries an owner and a status, and contract dates come with reminders. Act screening runs at tool level and shows its reasoning. Trigger: continuous, re-fired by change. | Governance lead, with the system pre-doing the mapping |
| ProveLIVE — EXPORTS EXPANDING | Evidence is collected once, kept current, and assembled on demand — board and audit reports, a full export, and the facts behind the AI section of a customer questionnaire — all from the same record, with sources attached where they exist. Trigger: consumed on demand. | The record assembles. Humans approve. |
Risk is assessed on how a system is used, never on what the tool is called. The same model in a marketing draft and in a hiring decision are two different obligations, and any product that labels the tool rather than the use will get that wrong every time.
An operating model only counts if every stage has a named human at a defined cadence.
Here is the whole organisation's involvement. Note how little of anyone's time it takes — that is the design constraint, not a marketing claim.
| Cadence | Who, and what they do | Cost |
|---|---|---|
| ContinuousThe machine | Discovery runs, ownership reminders go out, and anything overdue is flagged. No human cadence needed. | 0 people |
| Daily | Governance lead or analyst checks one number and anything new. Done before half nine. | 1 person · ~5 min |
| Weekly | Governance lead works the review queue down. CISO sees exceptions only, watching unowned trend to zero. Compliance lead sees coverage and gaps. | 2–3 people · ~20–30 min |
| Monthly | CIO sees what changed, including outside IT. Procurement and finance get contract and DPA expiry reminders by email or Teams. | 2–3 people · ~15 min |
| Quarterly | The board gets a report on demand. Legal reviews obligations. An auditor gets the same report, with its method and limits stated. | consumers, not operators |
| Event-driven | Business owners, only when something they own needs attention: a reminder by email, not a project. | minutes per year |
The rule underneath this: the accountable few check in because the number changes under them. Everyone else is left alone until something needs their attention, then handed a clean document with the decision already framed. Nobody is asked to adopt a habit that doesn't pay them back inside their own job.
You don't install an operating model. You grow one.
Three phases. Each stands alone, each is worth having on its own, and each creates the demand for the next.
- Weeks 0–4trialSee what's running
- Months 2–4OwnershipOwned and understood
- Months 4–6EvidenceReady on demand
- OngoingSteady stateThe loop runs
Phase 1 · trial
Observation switched on. Agentless by default, and the identification mode set with you. Within days the candidate catalogue fills — known tools, likely tools, unknown signals, embedded AI.
Done looks like: an honest number, the surprises named, and the gap between assumed and actual on one page. Board-meeting material on its own.
Phase 2 · Ownership
Owners are assigned, purpose and data use recorded, and reminders do the chasing. Risk screening starts — per use, not per tool — and anything left unowned is flagged as overdue.
Done looks like: each system found has a named owner and a risk position. "Unowned → 0" becomes the CISO's weekly headline.
Phase 3 · Evidence
Contract and DPA terms are recorded against each system, expiry reminders go out ahead of renewals, and what vendors publish about AI in their products sits alongside.
Done looks like: one record serves audit, board and customers without anyone duplicating the work.
A 30-day trial covers phase one and starts phase two.
A list, a framework, and the record between them.
Discovery tools give you a list. Compliance platforms give you a framework. Moustr gives you The AI Record: the AI in use across your business, named, owned and evidenced.
The same systems, each with a named owner, a purpose, a data position and the evidence behind it. One is still open, and the record says so.
| System | Where it was seen | Owner | Purpose | Data position | Evidence |
|---|---|---|---|---|---|
| AI writing assistant | Marketing, 21 users | Anna Visser, Head of Marketing | Campaign copy drafts | No customer data | Classified 12 Aug, approved by A. Visser |
| Meeting transcription | Sales, 8 users | Lars Holm, Sales Director | Call notes | Customer conversations | Classified 12 Aug, approved by L. Holm |
| Code assistant | Engineering, 34 users | Priya Nair, Head of Engineering | Code completion | Source code | Classified 14 Aug, approved by P. Nair |
| Image generator | Marketing, 5 users | Anna Visser, Head of Marketing | Social visuals | No personal data | Classified 15 Aug, approved by A. Visser |
| Unrecognised AI service | Finance, 3 users | Being assigned | Not yet known | Unclassified | Flagged 16 Aug, open |
Illustrative example, not customer data.
Already have a list from a scanner or a spreadsheet? Check what it can prove.
What it replaces, and what it sits beside.
Replaces
- The AI inventory spreadsheet nobody can keep current
- The AI section of a security questionnaire, answered from the record rather than assembled from scratch
- An annual readiness assessment that decays on delivery
- Asking three departments what they use, then reconciling the answers
- Ownership held in someone's head or an email thread
Sits beside
- GRC platforms — keep yours; Moustr is where its AI inventory comes from
- SAM and ITSM — Moustr covers what never went through procurement
- DLP and CASB — those inspect content; Moustr never reads it
- Your ISMS — the AI inventory and ownership evidence that ISO 42001 asks for, alongside 27001
Moustr does not remediate, block or revoke, and it is not a GRC platform or an audit. It supplies what all of them were missing: The AI Record, a current, named, owned and evidenced record of the AI actually in use.
Where the regulation attaches.
Obligations land at the Govern stage, on the confirmed use rather than on the tool. EU AI Act screening runs at tool level and shows its reasoning, and the inventory, ownership and evidence that ISO 42001 asks for build up as you run the loop, rather than as a separate exercise.
Moustr does not certify compliance and does not give legal advice. It produces the evidence your legal, compliance and audit people need to assess and demonstrate their own position.