Skip to content

An AI governance framework for a smaller business

AI governance sounds like something for large companies with compliance teams. For a smaller business it comes down to a few things written down: who decides, what the rules are, which tools you use and who checks the results.

Last checked 05/10/2026

What is AI governance?

AI governance is how a business decides which AI tools it uses, for what and under which rules, and how it checks they're working as intended. For a smaller business, that means a named owner, a short policy, a list of where AI is used, a check before each new use and a regular review.

Why does AI governance matter for a smaller business?

AI tools are easy to start using and hard to keep track of. Without anyone in charge, staff pick their own tools and accounts, personal data goes where it shouldn't, and nobody can say what AI is doing in the business when a client, an insurer or the ICO, the UK's data protection regulator, asks.

What does the UK government expect?

The UK government chose not to create a new AI regulator. Its 2023 white paper set five principles for existing regulators to apply: safety, security and robustness; transparency and explainability; fairness; accountability and governance; and contestability and redress. Data protection law applies whenever AI uses personal data.

The ICO says people's data protection rights apply wherever personal data is used in an AI system, from the data that goes in to the outputs that come back.

A simple AI governance framework

A workable framework for a smaller business has six parts: one owner, a short AI policy, a register of where AI is used, a check before each new use, a named person checking outputs, and a review every six months. The table shows what each part involves and which free template covers it.

PartWhat it meansTemplate
An ownerOne person accountable for how the business uses AI, with time to do it.
An AI policyWhich tools staff can use, what never goes in and who checks the work.AI policy template
A register of AI usesA list of each tool, the job it does, who owns it and when it was approved.
A check before each new useWhat goes in, where it goes and which route to test, with a data protection impact assessment (DPIA) where personal data is involved.DPIA template
A person checking outputsA named reviewer for each use, so AI work is checked before it's relied on.
A regular reviewThe register and policy reviewed every six months, or when tools change.AI risk assessment

How do you put AI governance in place?

Start with what's already happening: ask who uses AI and for what, and write it into a simple register. Name an owner, agree the policy, and run a check before anything new goes live. Then review the register and the policy every six months, or sooner if your tools change.

What should an AI register include?

For each use, record the tool and supplier, the job it does, who uses it, what information goes in, who checks the output, whether a DPIA or risk assessment was done, who approved it and when, and the next review date. A spreadsheet is enough to start with.

  • The tool and the supplier
  • The job it does, and who uses it
  • What information goes in
  • Who checks the output
  • Whether a DPIA or risk assessment was done
  • Who approved it, and when
  • The next review date

Start the register with one job.

The free check turns one AI idea into a one-page brief you can file in your register: the route to test first, the data rules and whether you need a DPIA. It's free, and any work after it is agreed separately.