Skip to main content

AI governance guide

AI Governance for Small Business: A Practical Starter

AI governance for small business can be a short set of rules about tools, data and accountability. It can answer four questions: who approves tools, what data goes in, how outputs are checked and who is accountable. Below, I set out a light starter structure for founder-led companies.

Black and silver combination padlock on a white surface
On this page
  1. What AI governance means for a small business
  2. Why founder-led companies need a light version
  3. AI governance for small business: a starter structure in seven steps
  4. What a one-page AI policy should cover
  5. What to check before approving a new AI tool
  6. Where the NIST AI Risk Management Framework fits
  7. Who should own AI governance in a growing company
  8. Common failure points to design around
  9. Frequently asked questions

What AI governance means for a small business

AI governance is the set of decisions, rules and owners that control how a company chooses, uses and checks AI.

In a large enterprise the term often points to committees, audits and formal risk registers. A founder-led company can often start with something lighter. A single page of rules and a named owner can cover a good deal at that size.

This article groups the work into four themes. Tools cover which AI products are approved, and data covers what may go into them. Quality is how outputs are checked, and accountability is who answers when something goes wrong.

Good governance supports responsible AI use at work. It lets people use AI where it helps, with data, quality and accountability kept in view.

Legal and contractual duties can also apply, depending on your industry, your clients and the data you hold. Ask a qualified professional what applies to you.

Why founder-led companies need a light version

AI use can spread through a company before anyone decides how it should be used. People may try free tools, paste in work material and share what seems to work.

One problem I work on is 'Everyone is talking about AI, but nobody knows where to use it'. The symptoms I list include AI experimentation everywhere, employees using random tools and no governance. I cover that pattern in AI without a strategy.

A light version suits the size of the company. It also suits the pace of change. Tools change quickly, so rules that name specific products can go stale. Rules written around data and outcomes can last longer.

Ungoverned AI use can look like this:

  • Client or employee data pasted into tools nobody has reviewed.
  • AI-written material sent to customers without a check.
  • Overlapping tools bought by different teams.
  • No record of which tools are in use or who approved them.
  • A decision that rests on an AI output nobody verified.
Rack-mounted servers with green status lights

AI governance for small business: a starter structure in seven steps

This AI governance framework for a small company is a general starting outline. Adapt it to your size, data and industry.

  1. Name one accountable owner

    Pick one senior person who answers for AI use across the company. Operations leadership is a natural home for the role. It should not default to whoever knows the tools best.

  2. List the AI tools already in use

    Ask every team which AI tools they use and for what. Include free and personal accounts used for work. You can't govern what you haven't listed. Pair the list with an AI readiness assessment to see where use should go next.

  3. Set data rules

    Sort your data into simple classes, such as public, internal and confidential. State which classes may go into which tools. Name data that stays out of AI tools unless approved, such as confidential client material and personal information.

  4. Create one approval path for new tools

    Give people a single route to request a new tool. Check where the data goes, who can see it and what the contract says about reuse of inputs. The checks further down help. Record the decision.

  5. Require a human check on outputs

    Decide which outputs need review before use. Anything customer-facing, financial or affecting a person's job is a sensible starting set. Record who reviewed it.

  6. Explain the rules and invite disclosure

    Walk staff through the rules in plain language, with examples of acceptable and unacceptable use. Invite people to report tools they already use, without blame.

  7. Plan for incidents and review the rules

    Decide what people do when something goes wrong and who they tell. Review the rules on a regular schedule, because tools and use both change.

What a one-page AI policy should cover

A short policy turns the steps above into rules people can follow. Adapt each starting rule to your company, your clients and your contracts.

Policy sectionQuestion it answersStarting rule to adapt
Purpose and scopeWho and what does this cover?Applies to all staff, contractors and every AI tool used for company work.
Approved toolsWhich tools may people use?Use only tools on the approved list. Request others through the approval path.
Data rulesWhat may go into a tool?Confidential and personal data stay out unless the tool is approved for that class.
Human reviewWho checks the output?A named person reviews customer-facing and financial output before use.
DisclosureWhen do we say AI was used?Tell clients and staff when AI shaped the work, if your contracts or values call for it.
AccountabilityWho answers for AI use?The named owner reports to the leadership team.
IncidentsWhat if something goes wrong?Report it to the owner straight away.
ReviewHow does the policy stay current?The owner reviews the policy on a set schedule and after any incident.

What to check before approving a new AI tool

An approval path works when the reviewer knows what to look for. These questions apply to any AI tool, whoever supplies it.

Where the data goes

Find out where inputs are stored and processed. Check whether that fits your contracts and the data rules you set.

What happens to your inputs

Ask whether the supplier keeps your inputs and whether it can use them to improve its own models. Ask how you can have them deleted.

Who can access the tool

Check how accounts are created and removed, and whether you can see who uses the tool. Shared logins make later review hard.

What records exist

Ask what logs the tool keeps. Records of who used it and when help you investigate an incident.

What the contract says

Read the terms on data use, liability and confidentiality. Have a qualified professional review terms for sensitive use.

How you would leave

Check that you can export your data and stop using the tool without losing work you depend on.

Where the NIST AI Risk Management Framework fits

The NIST AI Risk Management Framework is a framework to better manage AI risks to individuals, organizations and society. It has four core functions: Govern, Map, Measure and Manage. Version 1.0 was released on January 26, 2023.

This article does not summarize the framework, and the starter structure above is not a version of it. If your company handles sensitive data or serves regulated clients, read the framework itself and take professional advice.

Who should own AI governance in a growing company

A senior operational leader is often a sensible owner of AI governance in a growing company. That leader needs authority to approve or refuse tools, and time to keep the tool list current.

The owner keeps the tool list, decides on approvals, answers staff questions and reports to the leadership team. The role can take less time when the rules are clear. It can grow heavy when nothing is written down.

The founder can set the stance. Routing every approval through the founder can recreate the founder bottleneck.

Technology and AI decisions sit inside my Fractional COO engagement. My Fractional COO + AI Transformation engagement adds AI governance, alongside AI opportunity assessment, vendor selection and implementation oversight.

If your company needs rules like these, you can start a conversation about your own setup.

Hand ticking boxes on a checklist with a pencil

Common failure points to design around

AI governance can fail in several familiar ways. Some come from rules that are hard to follow. Watch for these:

  • A long policy that nobody reads.
  • A blanket ban that pushes AI use out of sight.
  • An approval process so slow that people work around it.
  • No owner, so nobody keeps the tool list current.
  • No review of outputs, so errors reach customers.
  • Rules that ignore how people actually work.
  • A policy written once and never revisited.

Frequently asked questions

What is AI governance?

AI governance is the set of rules, roles and checks that control how a company chooses and uses AI tools. In a small company the core questions are simple. Who approves tools, what data may go in, how outputs are checked and who is accountable?

Does a small company need an AI policy?

A small company should consider an AI policy once staff use AI tools on company or client work. A one-page policy can be enough to start. It gives people clear rules and gives the company a record of what was agreed.

What should an AI policy cover?

An AI policy can cover scope, approved tools, data rules, human review, disclosure, accountability, incidents and periodic review. The table above gives a starting rule for each section. Adapt them to your industry and contracts.

Who should own AI governance in a growing company?

AI governance in a growing company should have one named owner, usually a senior operational leader. The owner needs authority to approve or refuse tools. The founder sets the stance but should not approve every request.

Should a small company ban AI tools?

A small company can find a blanket ban on AI tools hard to enforce. People may keep using tools out of sight, and the company can lose track of what is in use. Clear rules and an approved list are one alternative.

What is the NIST AI Risk Management Framework?

The NIST AI Risk Management Framework is a framework to better manage AI risks to individuals, organizations and society. Its four core functions are Govern, Map, Measure and Manage. Version 1.0 was released on January 26, 2023.

Talk about AI in your company

I work with a small number of founder-led companies. If AI use in your company needs structure, let's talk.

Book a conversation