Manage the portfolio, not a stack of separate invoices
A company that has picked up five or ten AI tools over time rarely has a problem with any one of them on its own. The problem is the total: nobody sees every contract in one place, nobody is clearly responsible for a given tool, and the renewal decision gets made a week before payment because nobody thought about it earlier. The fix is not a one-off check on a single tool. It is a recurring review of the whole portfolio, run by a named owner, that ends in a decision every time.
That owner should be one named person, or a small group with visibility across departments, typically an operations or IT lead working with finance. Without one name attached, the review does not happen in practice; spreading responsibility across every team lead usually means nobody does it. The owner does not need to judge the output quality of every tool. They need the mandate to ask any department for its account list, its pricing model, and the name of whoever actually uses the tool day to day.
Where the unplanned costs actually appear
Five situations account for most of the unplanned spend in an AI tool portfolio, and none of them requires the company to do anything obviously wrong. They just require nobody checking regularly.
Unused seats in a team licence are the most common case: a company buys access for a whole team, part of that team never opens the tool, and the seats stay active after people leave or change roles. Duplicate capability across two services happens when two departments independently solve a similar need, such as summarising documents or generating images, with two different tools, each unaware of the other. Usage-based billing without a cap is a particular risk for tools priced by tokens, API calls, or processed data units, where one unusual month of activity can move the bill significantly. Purchases made outside the approved process, where a department puts a tool on a company card without IT or procurement knowing, mean the contract and its data-processing terms never went through review. Automatic renewals are a risk on their own: without visibility into renewal dates, a company keeps paying for a tool nobody consciously decided to keep using.
None of these situations goes away after a single intervention. They recur as teams, roles and usage patterns change, which is why a repeating review is the only approach that actually holds, not a one-off audit.
Artefact: a recurring review schedule for the AI tool portfolio
The schedule below splits the review into steps with their own frequency. The “Decision” column describes what the review should force, not a specific number, which each company fills in against its own portfolio.
| Review step | Frequency | Who runs it | What is checked | Decision the review forces |
|---|---|---|---|---|
| Active account inventory | Quarterly | Portfolio owner | Every active AI tool, seats assigned, department contact | Add any tool found outside the record to the central list |
| Seat utilisation check | Monthly for large licences, quarterly for the rest | Portfolio owner with IT | Ratio of assigned seats to actually used seats over the period | Release unused seats or reduce licence scope at renewal |
| Overlap review | Twice a year | Portfolio owner with department leads | Whether two or more tools solve the same task for different teams | Consolidate to one tool, or record a documented reason both remain |
| Uncapped usage check | Monthly for metered tools | Portfolio owner with finance | Usage trend against the prior period, whether a cap is set | Set or adjust a cap if usage is rising without explanation |
| Off-process purchase check | Quarterly | Portfolio owner with procurement or finance | New card charges that match AI tool spend | Bring the tool into standard approval, or end it if there is no clear justification |
| Renewal date check | Monthly, 60 days ahead of each date | Portfolio owner | Upcoming automatic renewal dates and notice periods | Decide to renew, change scope, or cancel with enough notice |
The schedule only works if the output of each step lands somewhere. A shared spreadsheet or a simple internal log is enough, as long as the owner records the date, the finding and the decision after every review. Without that record, the company ends up asking the same questions again a year later, because nobody remembers what was already checked.
Fitting the review into how the company already runs
The portfolio review should not run as an isolated task that one person does while everyone else ignores it. It works better attached to a rhythm the company already has: quarterly steps next to the regular budget review, monthly steps next to the monthly cost close. NIST’s AI Risk Management Framework describes its Govern function as the organisational practices and accountability structures needed to manage AI across a company, and a recurring portfolio review with a named owner fulfils exactly that function at the purchasing and operations level, not only at the level of technical risk for a single model.
It is also worth being clear about what the schedule does not do. It does not set a ceiling on how many tools a company may run, or what an acceptable budget looks like. It does not decide whether a specific tool is the right fit for its purpose either; that decision belongs to the initial selection process. What the schedule does is make sure the portfolio as a whole comes back regularly to someone with the mandate to decide, and that a finding does not stop at “we noticed a problem” without a decision attached.
Companies weighing whether a given AI subscription is even worth its price in the first place should read what deploying an AI tool actually costs a company, which covers the one-off cost picture this article deliberately does not repeat. The off-process purchase risk described above overlaps with wider questions about securing AI use across the enterprise and with what happens when a tool bought outside review starts handling company data, covered in is it safe to put company data into ChatGPT. Duplicate capability across two tools is easiest to picture concretely against Microsoft Copilot’s free chat versus the Microsoft 365 business add-on, where two overlapping options sit inside the same vendor relationship.
Sources and limits
NIST’s AI Risk Management Framework and its Govern function describe a general approach to managing AI within an organisation. They are not a sector standard, not specific to the Czech Republic, and they do not prescribe a review interval for a tool portfolio. The NIST AI RMF Playbook describes itself as voluntary suggestions rather than a mandatory checklist, and this article cites it on that basis. The specific frequencies, thresholds and decision points in the schedule above are a CIAD recommendation built from the general principle of recurring review; they are not a measured value or a requirement from any cited source. Every company needs to work out which steps of the schedule fit its own number of tools and its internal approval rules; this article does not make that determination for you.
Frequently asked questions
Who should own the review of a multi-tool AI budget in a small company?
One named person or a small group with visibility across departments, typically an operations or IT lead working with finance. In a small company this can be the managing director or an operations manager, provided they set aside recurring time for it. Without a named owner the review rarely happens in practice, because no single person treats it as their job.
Should the portfolio review happen monthly, or is quarterly enough?
It depends on how many tools you run and how quickly usage changes. A company with many usage-metered accounts needs a shorter interval than one with a handful of stable flat-fee licences. What matters most is that the interval is fixed and actually kept, not that it is as short as possible.
How do we spot a duplicate tool when a different department manages it?
You cannot spot it without a central list, which is why the first step is an inventory of every active AI tool, who bought it, and what it is for. Once two tools sit side by side on that list with the same stated purpose, that is a signal to verify overlap, not an automatic reason to cancel either one.
Why is it risky to let departments buy AI tools outside the approved process?
Because there is then no single place to add up total spend, check contract terms, or confirm what company data is going into the tool. A purchase made outside the process also typically skips whatever security and data review would otherwise happen before a contract is signed.
Is this worth doing if we only use two or three AI tools?
Yes. The principle of a recurring review applies at any scale; a small portfolio just means a simpler schedule and fewer steps to combine into one short meeting. The risk from an unused account or a forgotten renewal does not depend on how many tools you run, it depends on whether anyone reviews them regularly. Two unreviewed tools can generate the same hidden cost pattern as ten.
SOURCES AND VERIFICATION
reviewed Lukáš Dlouhý ·