AI governance toolkit for SMEs
Five coordinated templates to turn responsible-AI principles into a lightweight operating system for a small company.
What is included
- AI acceptable-use policy
- AI inventory and risk register
- Vendor assessment checklist
- AI literacy checklist
- Incident response procedure
Complete preview
Good governance does not begin with a large committee. It begins with knowing which tools are used, what data reaches them, who approves consequential decisions, and how incidents are handled.
1. Acceptable-use policy
Define approved and prohibited uses, data boundaries, human review, intellectual property, incident reporting, ownership, training, and review cadence. The toolkit contains the same operational policy as the standalone template, ready to customize.
2. AI inventory and risk register
For every system, record the owner, provider, purpose, affected people, users, data categories, integrations, decision impact, human reviewer, legal/security review, current controls, residual risk, next action, and review date.
Start with tools employees already use, including features embedded in office, CRM, meeting, design, development, and customer-support software.
3. Vendor assessment
Before approval, document where data is processed, retention and training defaults, subprocessors, access controls, audit logs, model changes, incident notification, deletion/export, contractual terms, security evidence, and the process for disabling the service.
4. AI literacy checklist
Training should match the person's role and include limitations, hallucinations, bias, confidential data, personal data, intellectual property, prompt injection, verification, human escalation, incident reporting, and the approved-tool register. Record completion and refresh training when the risk or tool changes.
5. Incident response
Provide one reporting channel. Triage the affected system, data and people; contain access or automation; preserve evidence; involve security, privacy, HR or legal owners; notify affected parties or authorities when required; document corrective actions; and update the risk register and training.
A lightweight operating rhythm
- Monthly: review newly discovered tools and unresolved actions.
- Quarterly: review approved tools, risk ratings, incidents, policy and training.
- Before a material launch: complete vendor, privacy, security and human-oversight checks.
- After an incident: preserve evidence, correct the control gap, and communicate the lesson.
First 30 days
- Appoint one accountable owner.
- Run a two-week tool inventory.
- Approve, restrict, or retire each tool.
- Publish the acceptable-use policy.
- Train the first high-use teams.
- Test the incident channel.
- Put the next quarterly review on the calendar.