Back to resources
Toolkit

AI governance toolkit for SMEs

Five coordinated templates to turn responsible-AI principles into a lightweight operating system for a small company.

What is included

  • AI acceptable-use policy
  • AI inventory and risk register
  • Vendor assessment checklist
  • AI literacy checklist
  • Incident response procedure

Complete preview

Good governance does not begin with a large committee. It begins with knowing which tools are used, what data reaches them, who approves consequential decisions, and how incidents are handled.

1. Acceptable-use policy

Define approved and prohibited uses, data boundaries, human review, intellectual property, incident reporting, ownership, training, and review cadence. The toolkit contains the same operational policy as the standalone template, ready to customize.

2. AI inventory and risk register

For every system, record the owner, provider, purpose, affected people, users, data categories, integrations, decision impact, human reviewer, legal/security review, current controls, residual risk, next action, and review date.

Start with tools employees already use, including features embedded in office, CRM, meeting, design, development, and customer-support software.

3. Vendor assessment

Before approval, document where data is processed, retention and training defaults, subprocessors, access controls, audit logs, model changes, incident notification, deletion/export, contractual terms, security evidence, and the process for disabling the service.

4. AI literacy checklist

Training should match the person's role and include limitations, hallucinations, bias, confidential data, personal data, intellectual property, prompt injection, verification, human escalation, incident reporting, and the approved-tool register. Record completion and refresh training when the risk or tool changes.

5. Incident response

Provide one reporting channel. Triage the affected system, data and people; contain access or automation; preserve evidence; involve security, privacy, HR or legal owners; notify affected parties or authorities when required; document corrective actions; and update the risk register and training.

A lightweight operating rhythm

  • Monthly: review newly discovered tools and unresolved actions.
  • Quarterly: review approved tools, risk ratings, incidents, policy and training.
  • Before a material launch: complete vendor, privacy, security and human-oversight checks.
  • After an incident: preserve evidence, correct the control gap, and communicate the lesson.

First 30 days

  1. Appoint one accountable owner.
  2. Run a two-week tool inventory.
  3. Approve, restrict, or retire each tool.
  4. Publish the acceptable-use policy.
  5. Train the first high-use teams.
  6. Test the incident channel.
  7. Put the next quarterly review on the calendar.

This toolkit supports internal organization and does not replace legal, cybersecurity, employment, or data-protection advice.

Sources

Reviewed:

Reviewed by: Javier Chulvi Bernad

Want to apply these controls to your internal knowledge?

Request demo