Model Inventory
A complete register of models in use with their purpose, owner, risk tier and validation status — the artifact everything else in model governance depends on.
Model risk management begins with knowing which models exist, and most organisations do not. Models are built by teams outside the data science function, embedded in vendor products, encoded in spreadsheets, and deployed as a scoring endpoint nobody registered.
The inventory records, per model: what it does, what decisions it influences, who owns it, what data it was trained on, when it was last validated, how it is monitored, and its risk tier.
Two definitional questions determine whether it is complete. What counts as a model — a rules engine encoding an underwriting policy carries model risk even though nobody calls it a model, and confining the definition to machine learning misses much of the exposure. And third-party models, where a vendor's scoring service influences your decisions and you cannot inspect it; the obligation does not transfer with the outsourcing, so the inventory must include it with whatever assurance is obtainable.
The architectural implication is that registration should be a precondition for deployment rather than a periodic survey. A model serving platform that refuses to serve an unregistered model produces a complete inventory as a by-product; a quarterly email requesting declarations does not.