AI Governance & AI Register
Structure instead of sprawl
We are building a company-wide structure for the controlled use of artificial intelligence: inventory review, AI registry, clear roles, and comprehensible approval processes.
Non-binding · 15 minutes · Free






What is AI governance?
AI governance is the corporate-wide structure with which a company controls the use of artificial intelligence: which AI systems are used, who is responsible for them, how new systems are tested and approved, and how changes are implemented. A central tool is the AI register – the list of all AI systems deployed.
Services
What is included in a
AI governance?
We are building the structure with which your company can use artificial intelligence in a legally compliant way:

Vera Schmidt
Managing Director, mip Consult GmbH
Non-binding · 15 minutes · Free
our approach
How do we build your AI governance?
From the initial consultation to the operational AI registry – in four comprehensible steps.
Step 01
Free initial consultation
We offer companies a free initial consultation by phone regarding general AI-related questions and what specific advice we can provide.
Step 02
AI Quick-Check
In a short consultation session, we analyze together which AI systems are already being used in the company, which data protection and compliance risks exist, and whether there is a need for action regarding the GDPR or the EU AI Act.
Step 03
Customized offer
Based on the AI Quick Check, we will create a personalized quote for you or recommend one of our consulting packages.
Step 04
Start of consulting
After signing the consulting agreement, our experts will begin the consulting process.
Prices & Packages
What does the establishment of AI governance cost?
We build your AI governance as a separate project or provide ongoing support – tailored to the size and use of AI in your company.
Price on request
The scope and price depend on the size of your company and the number of employees employed.
AI systems. In the free initial consultation, we will discuss your needs; after that, you will receive a personalized quote.
Lawyers from Eggert & Partner Lawyers · Service in Germany
Frequently asked questions about AI governance and AI registers
What should be included in an AI registry?
An AI registry records each AI system deployed within the company, including its purpose, providers, affected data, responsible department, risk classification, and release status. It serves as the basis for any further review and the first place an oversight authority or auditor looks.
Is an AI registry legally required?
An internal AI registry is not generally required. The EU AI Act (Regulation (EU) 2024/1689), however, links documentation and registration obligations to the role and risk class of the system. Without an inventory, it is not possible to determine which of these obligations your company is subject to; therefore, the registry comes first.
Who in the company is responsible for AI governance?
The responsibility lies with the management. In practice, operational coordination is handled by a designated person or a committee, often in conjunction with data protection, information security, and IT. This role can also be filled externally, see External AI Officer.
How does the AI register differ from the list of processing activities?
The list of processing activities under Article 30 of the GDPR describes the processing of personal data. The AI register describes AI systems, even those without personal reference, with regard to functionality, risk, and disclosure. Both overlap, but do not replace each other and are best managed in concert.
How does the approval process for a new AI system work?
A department reports the planned deployment, the system is organized and reviewed, open issues are resolved, the decision is documented, and the system is entered into the registry. We jointly determine how the process looks in detail; more about this can be found in the introduction of AI systems.
How often must AI governance be reviewed?
There is no fixed legal deadline. It is useful to have regular reviews and a case-by-case assessment: new systems, changed functions, a change of provider, or new regulatory requirements. We set the frequency together with you and we will adhere to it in the AI policies.






