An AI Governance Framework for Small Businesses
Big companies have AI committees and 80-page frameworks. A small business needs something it will actually follow. Here is a practical AI governance framework that fits on one page, plus where the big frameworks and new laws fit in.
What AI governance means for a small business
AI governance is simply deciding in advance how your business uses AI: which tools, for what, with what data, and checked by whom. Without it, AI use happens anyway, in personal accounts nobody approved, with customer data nobody meant to share.
A 7-step framework that fits on one page
- List where you use AI. Ask your team which AI tools they use and for what. Include the AI features inside tools you already pay for, like your email, CRM, or help desk.
- Name an owner. One person is responsible for the list, the policy, and questions. In a small business that's usually the owner or the operations lead.
- Approve the tools. Pick the AI tools people may use for work, ideally business accounts with admin controls and data terms you've actually read.
- Set data rules. Decide what never goes into an AI tool: customer personal data, passwords, confidential financials, health information.
- Require human review. Anything that goes to a customer, gets published, or affects a decision about a person is checked by a person first.
- Vet vendors. For AI you build or buy for customer-facing work, ask where data is stored, whether it's used for training, and how to export or delete it.
- Review twice a year. AI tools and rules change fast. Revisit the list, the policy, and anything that went wrong.
Steps 3 to 5 become your AI acceptable use policy. The free AI acceptable use policy generator writes a first draft in a few minutes.
The big frameworks, briefly
NIST AI Risk Management Framework. A free, voluntary US framework built around four functions: Govern, Map, Measure, and Manage. It's designed to scale to organizations of any size, and the seven steps above are essentially a small-business version of its Govern and Map functions.
ISO/IEC 42001. The first international standard for an AI management system, published in 2023. It's certifiable, so it mostly matters if large customers ask you to prove how you govern AI.
What the laws say, briefly
The rules are still moving, so treat this as orientation, not legal advice:
- EU AI Act: in force since 2024 and phasing in. In May 2026, EU lawmakers agreed to push the main obligations for high-risk AI uses back to December 2027 (Council of the EU). If you sell into the EU, keep an eye on it.
- Colorado: in 2026, Colorado replaced its original AI Act with a narrower law focused on transparency about automated decisions, scheduled to take effect January 1, 2027 (Skadden).
- Everywhere: existing laws already apply to AI. Privacy, consumer protection, anti-discrimination, and telemarketing rules cover what you do with AI just as much as what you do without it.
Where small businesses get into trouble
- Pasting customer data into personal AI accounts.
- Sending AI-written answers to customers without checking them.
- Letting AI make decisions about people, like hiring or credit, without review.
- Not telling customers when they're talking to an AI.
- Building on an AI vendor without reading how it uses your data.
Frequently asked questions
What is an AI governance framework?
A set of rules and responsibilities for how an organization uses AI: which tools are allowed, what data can go in, who checks the output, who is accountable, and how often it is reviewed.
Does a small business need AI governance?
If your team uses AI tools for work, yes, but it can be simple. A list of approved tools, clear data rules, and human review of anything customer-facing cover most of the risk.
What is the NIST AI Risk Management Framework?
A free, voluntary US framework for managing AI risk, organized around four functions: Govern, Map, Measure, and Manage. It is meant to be tailored to organizations of any size.
What is ISO 42001?
ISO/IEC 42001, published in 2023, is the first international standard for an AI management system. Organizations can be certified against it.
What should an AI policy include?
Approved tools, data that must never be entered, human review requirements, disclosure rules, a process for requesting new tools, an owner, and consequences for breaking the policy.
Is this legal advice?
No. It is a practical starting point. Talk to a lawyer about the rules that apply to your industry and where you do business.
Want help putting AI to work safely?
I help small businesses pick the right AI tools, set simple rules, and build the automations worth having. The first consult is free.
See AI consulting