Where the data goes
Find out where inputs are stored and processed. Check whether that fits your contracts and the data rules you set.
AI governance guide
AI governance for small business can be a short set of rules about tools, data and accountability. It can answer four questions: who approves tools, what data goes in, how outputs are checked and who is accountable. Below, I set out a light starter structure for founder-led companies.
AI governance is the set of decisions, rules and owners that control how a company chooses, uses and checks AI.
In a large enterprise the term often points to committees, audits and formal risk registers. A founder-led company can often start with something lighter. A single page of rules and a named owner can cover a good deal at that size.
This article groups the work into four themes. Tools cover which AI products are approved, and data covers what may go into them. Quality is how outputs are checked, and accountability is who answers when something goes wrong.
Good governance supports responsible AI use at work. It lets people use AI where it helps, with data, quality and accountability kept in view.
Legal and contractual duties can also apply, depending on your industry, your clients and the data you hold. Ask a qualified professional what applies to you.
AI use can spread through a company before anyone decides how it should be used. People may try free tools, paste in work material and share what seems to work.
One problem I work on is 'Everyone is talking about AI, but nobody knows where to use it'. The symptoms I list include AI experimentation everywhere, employees using random tools and no governance. I cover that pattern in AI without a strategy.
A light version suits the size of the company. It also suits the pace of change. Tools change quickly, so rules that name specific products can go stale. Rules written around data and outcomes can last longer.
Ungoverned AI use can look like this:
This AI governance framework for a small company is a general starting outline. Adapt it to your size, data and industry.
Pick one senior person who answers for AI use across the company. Operations leadership is a natural home for the role. It should not default to whoever knows the tools best.
Ask every team which AI tools they use and for what. Include free and personal accounts used for work. You can't govern what you haven't listed. Pair the list with an AI readiness assessment to see where use should go next.
Sort your data into simple classes, such as public, internal and confidential. State which classes may go into which tools. Name data that stays out of AI tools unless approved, such as confidential client material and personal information.
Give people a single route to request a new tool. Check where the data goes, who can see it and what the contract says about reuse of inputs. The checks further down help. Record the decision.
Decide which outputs need review before use. Anything customer-facing, financial or affecting a person's job is a sensible starting set. Record who reviewed it.
Walk staff through the rules in plain language, with examples of acceptable and unacceptable use. Invite people to report tools they already use, without blame.
Decide what people do when something goes wrong and who they tell. Review the rules on a regular schedule, because tools and use both change.
A short policy turns the steps above into rules people can follow. Adapt each starting rule to your company, your clients and your contracts.
| Policy section | Question it answers | Starting rule to adapt |
|---|---|---|
| Purpose and scope | Who and what does this cover? | Applies to all staff, contractors and every AI tool used for company work. |
| Approved tools | Which tools may people use? | Use only tools on the approved list. Request others through the approval path. |
| Data rules | What may go into a tool? | Confidential and personal data stay out unless the tool is approved for that class. |
| Human review | Who checks the output? | A named person reviews customer-facing and financial output before use. |
| Disclosure | When do we say AI was used? | Tell clients and staff when AI shaped the work, if your contracts or values call for it. |
| Accountability | Who answers for AI use? | The named owner reports to the leadership team. |
| Incidents | What if something goes wrong? | Report it to the owner straight away. |
| Review | How does the policy stay current? | The owner reviews the policy on a set schedule and after any incident. |
An approval path works when the reviewer knows what to look for. These questions apply to any AI tool, whoever supplies it.
Find out where inputs are stored and processed. Check whether that fits your contracts and the data rules you set.
Ask whether the supplier keeps your inputs and whether it can use them to improve its own models. Ask how you can have them deleted.
Check how accounts are created and removed, and whether you can see who uses the tool. Shared logins make later review hard.
Ask what logs the tool keeps. Records of who used it and when help you investigate an incident.
Read the terms on data use, liability and confidentiality. Have a qualified professional review terms for sensitive use.
Check that you can export your data and stop using the tool without losing work you depend on.
The NIST AI Risk Management Framework is a framework to better manage AI risks to individuals, organizations and society. It has four core functions: Govern, Map, Measure and Manage. Version 1.0 was released on January 26, 2023.
This article does not summarize the framework, and the starter structure above is not a version of it. If your company handles sensitive data or serves regulated clients, read the framework itself and take professional advice.
A senior operational leader is often a sensible owner of AI governance in a growing company. That leader needs authority to approve or refuse tools, and time to keep the tool list current.
The owner keeps the tool list, decides on approvals, answers staff questions and reports to the leadership team. The role can take less time when the rules are clear. It can grow heavy when nothing is written down.
The founder can set the stance. Routing every approval through the founder can recreate the founder bottleneck.
Technology and AI decisions sit inside my Fractional COO engagement. My Fractional COO + AI Transformation engagement adds AI governance, alongside AI opportunity assessment, vendor selection and implementation oversight.
If your company needs rules like these, you can start a conversation about your own setup.
AI governance can fail in several familiar ways. Some come from rules that are hard to follow. Watch for these:
AI governance is the set of rules, roles and checks that control how a company chooses and uses AI tools. In a small company the core questions are simple. Who approves tools, what data may go in, how outputs are checked and who is accountable?
A small company should consider an AI policy once staff use AI tools on company or client work. A one-page policy can be enough to start. It gives people clear rules and gives the company a record of what was agreed.
An AI policy can cover scope, approved tools, data rules, human review, disclosure, accountability, incidents and periodic review. The table above gives a starting rule for each section. Adapt them to your industry and contracts.
AI governance in a growing company should have one named owner, usually a senior operational leader. The owner needs authority to approve or refuse tools. The founder sets the stance but should not approve every request.
A small company can find a blanket ban on AI tools hard to enforce. People may keep using tools out of sight, and the company can lose track of what is in use. Clear rules and an approved list are one alternative.
The NIST AI Risk Management Framework is a framework to better manage AI risks to individuals, organizations and society. Its four core functions are Govern, Map, Measure and Manage. Version 1.0 was released on January 26, 2023.
I work with a small number of founder-led companies. If AI use in your company needs structure, let's talk.
Book a conversation