Skip to main content
Governance

AI governance for SMEs without a legal department

Glen Jones6 min read

Governance sounds like enterprise overhead. In practice it is four documents and one named owner — and it is what keeps an AI pilot from becoming an incident.

Every small business owner hears "AI governance" and pictures a policy binder nobody reads. The useful version is far smaller: know what you use, know what data it touches, know who signs off, and know what happens when it is wrong.

The four documents that cover most of it

  • An AI tool register — what is in use, by whom, and what data it can reach.
  • An acceptable-use policy — one page, plain English, covering what must never be shared.
  • A human oversight rule — which decisions require a person to approve before anything reaches a customer.
  • An incident note — what to do when an output is wrong, biased or leaks something.
Governance is not a brake. It is the thing that lets you say yes to a use case quickly, because you already know the boundaries.

The GDPR questions that come up first

  • What is your lawful basis for processing this data through an AI tool?
  • Does the provider train on your inputs, and can that be turned off?
  • Where is the data processed, and who are the sub-processors?
  • How long is it retained, and can you request deletion?

The answers are usually in the provider's data-processing addendum. Reading it once per tool is a far cheaper hour than explaining a breach later.

Review cadence

Quarterly is enough for most SMEs. Check the register is current, confirm nobody has adopted something new off the books, and re-test one incident scenario. Thirty minutes, four times a year.

Score your own AI readiness

Answer thirty questions in about ten minutes and get a maturity score, benchmark and prioritised roadmap across all six dimensions.

Get your free score

Related reading