AI inventory
Finding the AI already in use: models built in house, scoring and decision engines inside vendor platforms, and generative AI tools staff use every day. For each, the purpose, data, owner and the people affected.
AI is already making or shaping decisions about your customers and staff, often inside tools nobody thinks of as AI. JPDP's guideline on automated decision-making and profiling brings much of that under the PDPA. We find what is running, sort it by risk, and put in the governance that lets you keep using it with confidence.
Practical AI governance for organisations that use AI, whether built in house, bought from a vendor or used by staff through generative AI tools. We build the inventory, tier each use by risk, set the policies and controls that fit each tier, and align the whole programme to the PDPA, sector guidance and, where you want certification, ISO/IEC 42001.
On 30 April 2026 JPDP released its guideline on automated decision-making and profiling. It requires privacy notices to tell individuals when their data is subject to automated decision-making or profiling, and explicit consent where sensitive personal data is involved, and under the DPIA guideline automated decision-making triggers an impact assessment at any volume. In banking, the AICB industry framework sets seven principles for governing AI, as guidance rather than law. Most organisations cannot yet say where AI is being used on personal data, which makes every one of those expectations hard to meet.
Scoped to where you are. Organisations starting out need the inventory and a policy; those with material AI use need tiering, validation and oversight; some want ISO/IEC 42001 certification.
Finding the AI already in use: models built in house, scoring and decision engines inside vendor platforms, and generative AI tools staff use every day. For each, the purpose, data, owner and the people affected.
Sorting each use by how much it can affect people and the business, so the high-risk uses get validation and oversight and the low-risk ones are not buried in process.
Mapping each automated decision or profile to the ADMP guideline: notice wording, explicit consent where sensitive data is involved, and whether a DPIA is needed, which for automated decision-making it usually is.
The guideline leans on transparency rather than mandating human review of every decision, so where and how a human reviews, overrides or audits is a choice you must make and justify. We help you make it deliberately and document it.
An AI policy, accountability at board and management level, an approval route for new AI uses, and practical rules for staff use of generative AI tools, including what data may never be pasted into one.
For organisations that want certification, a gap assessment against ISO/IEC 42001, the AI management system standard, and the documentation and controls to get ready for an independent audit.
Most organisations underestimate their AI use by a wide margin, because so much of it sits inside vendor tools. The inventory is the foundation for every other control.
Tiering means a credit decision engine and a meeting summariser are not governed the same way. Controls stay proportionate and the business keeps its pace.
When a customer asks why they were declined, or JPDP asks how an automated decision works, you have the notice, the DPIA and the oversight design ready.
Due diligence questions, contract terms and ongoing monitoring for AI inside bought-in systems, where much of the real exposure sits.
PDPA, sector guidance such as the AICB framework and ISO/IEC 42001 overlap heavily. A single programme mapped to each avoids three parallel efforts.
Orbix runs AI governance, ADMP and ISO/IEC 42001 courses. Where your team needs to carry the programme, the training component is HRD Corp claimable.
Interviews and a survey across business units, IT and procurement to find AI in use, including inside vendor platforms and staff tools.
Each use recorded with its owner, data and affected people, then tiered by risk with your agreement.
The high-risk uses assessed against the ADMP and DPIA guidelines, sector guidance and, if relevant, ISO/IEC 42001.
Policy, roles, approval route, oversight design and vendor controls, sized to your tiers.
Notice wording, DPIAs for the highest-risk uses, and the records that show the programme is operating.
A maintained inventory, a review calendar and board reporting your team runs from then on.
Every AI use found, with purpose, data, owner, vendor and affected individuals.
Each use tiered, with the controls and validation depth each tier requires.
High-risk uses assessed against the ADMP guideline, DPIA triggers and any sector framework that applies.
Policy, accountability, approval route, generative AI rules and board reporting.
Human oversight design and ADMP notice wording for the uses that need them.
Where in scope, the gaps to certification and the plan to close them.
We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.
Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.
Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.
Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.
Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.
There is no standalone AI Act in force. What does apply is the PDPA wherever AI uses personal data, including JPDP's April 2026 guideline on automated decision-making and profiling, plus sector rules such as BNM's policy documents on technology risk and outsourcing. Industry frameworks such as the AICB framework for banks are guidance, but supervisors and customers increasingly expect them.
No. It leans on transparency: telling individuals that automated decision-making or profiling is used, and explicit consent where sensitive personal data is involved. Human oversight is a design decision you should make deliberately for each use and be able to justify, which is part of what we help you do.
Yes. Responsibility for decisions about your customers and staff stays with you when the model belongs to a vendor. Vendor AI is usually where the inventory finds the most surprises.
Not by law. It is useful when customers, partners or regulators want independent assurance of how you govern AI, or when AI is central to your product. Many organisations adopt the framework without certifying, and we will tell you which fits.
That is usually the first quick win. Clear rules on approved tools, what data may never be entered, and how outputs are checked reduce the most common real-world risk faster than any other control.
No. Certification has to come from an independent certification body. We prepare you for the audit.
Tell us where you think AI is used today, in house, through vendors or by staff, and what prompted the question. We will come back with a scope for discovery and a fixed quotation.