Skip to main content
    NixInfinity-AI
    AI Governance

    AI Governance for SMEs: A Practical Framework, Not Corporate Theatre

    Published 23 July 2026

    Why most SME AI policies fail

    They are either copied from a Fortune 500 template (unworkable) or written as "be sensible" (unenforceable). The middle path: short documents, clear decisions, a named owner, and a register that is actually maintained.

    The five components

    1. Approved tools list

    A single page listing the AI tools staff may use, the data classifications allowed in each, and the licence type held. Example: Microsoft 365 Copilot (all internal data), ChatGPT Enterprise (no client-confidential), public ChatGPT (no business data at all).

    2. Acceptable use policy

    • What data may go in (and what may not – client confidential, personal data, IP)
    • Disclosure when AI is used in customer-facing output
    • Fact-checking and human review expectations
    • Copyright and IP ownership of generated output
    • Reporting suspected misuse

    3. Risk tiers per use case

    A three-tier model is enough for most SMEs:

    • Low: Internal drafting, code suggestions, summarisation of public content
    • Medium: Customer-facing content, support chat, internal decisions about staff or money under a threshold
    • High: Decisions affecting customer eligibility, pricing, hiring, fraud, safeguarding, or anything regulated

    4. AI impact assessment (light)

    A one-page assessment triggered for medium and required for high. Captures purpose, data, model, vendor, human review point, fairness considerations, IP exposure and a sign-off. For high-risk use, conduct alongside a DPIA.

    5. Vendor checks

    • Where is data processed and stored?
    • Is our data used to train models? Can we opt out?
    • What is the breach-notification SLA?
    • Does the vendor hold CE/CE+, ISO 27001 or SOC 2?
    • What is the model version and change-management policy?

    Who owns what

    • Board: Risk appetite, annual review
    • AI owner (often COO or CTO): Policy, register, approvals
    • Tool owners: Configuration, access control, monitoring
    • Users: Adherence and reporting

    The minimum operating cadence

    • Monthly: review approved tools list, check shadow-AI logs (M365 audit, SaaS DLP)
    • Quarterly: review high-risk use cases and incidents
    • Annually: refresh policy, retrain staff, review vendor changes

    Integrating with cyber

    AI governance does not replace cyber baseline – it sits on it. MFA, account separation, patching and Cyber Essentials underpin everything. See our NCSC AI guidance and CE scope piece for the technical overlap.

    Common SME pitfalls

    • Banning AI outright – staff move it underground
    • Approving every tool a department asks for – sprawl and shadow-sm IT
    • Policy with no register – no way to evidence what is approved
    • No defined human review point on high-risk use
    • No IP clause in vendor contract about model training on inputs

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions