top of page

AI Governance for small or medium sized companies: where to start?

  • Aug 17
  • 7 min read

By Laura Pappi, CEO of Veritas Fox. PECB-certified ISO/IEC 42001 Lead Implementer, twelve years in operations across startups and enterprise. Last reviewed: 11 August 2026.


"AI governance" is one of those phrases that sounds like it was invented to sell you something you don't need. It makes me think of boring things, like binders full of paperwork and forms with lots of boxes. If that's the picture in your head, I understand why you've been ignoring it.




So let me write this the way I'd explain it to you, because right now I'm living it.


We're a small firm, and we're building our own AI management system to ISO/IEC 42001 as I write this (not because a regulator made us, but because we advise other people on it and it would be a bit rich not to run it ourselves.)


Here's how we are thinking about our compliance, stripped down. For a small business, AI governance can come down to thinking about just four questions:


  1. What AI do we use?

  2. Who's responsible for it?

  3. What rules apply to us?

  4. How do we stop it going wrong?


Answer those honestly and you are on your way. Everything else you'll read about (the frameworks, the standards, and yes the audits) is a more detailed way of answering the same four questions and being able to show your working.


First, the one-line definition


You can use the four questions to define AI governance. It is knowing what AI your business uses, who owns it, what rules apply, and how you keep the risks in check.

Notice what that doesn't say. It doesn't say you have to build AI tools or technologies. Most SMEs never will. You use it, and it's already everywhere: inside your CRM, your marketing tools, your support chatbot, your accounting software, and whatever your team quietly started doing with ChatGPT last spring. Governance is about that everyday use.


Question 1: What AI do you use?


Let’s think about how to answer the questions. The first, makes us think about how our organisation has introduced artificial tools and where they are operating. This isn’t necessarily as easy as it sounds. Vendors may have switched AI features on by default and rebranded them as "smart" or "assistant", so a lot of the AI in your business might have arrived without anyone deciding to buy it.

The best way to get a grip on it is to build a simple inventory (some people call it a register). List out every AI tool or feature you use, what it does, what data it touches, and who's using it.

In my experience, most businesses have never done this, yet this is the exact place every framework and every regulator tells you to begin. If you take one thing from this article, make it this: build the list.


Question 2: Who owns it?


Once we’ve documented what AI we are using we then come on to the question of ownership. And, when we say ownership it isn't about who bought the licence. It's about what happens when a tool gets something wrong: an AI shortlist that quietly discriminates, a made-up figure in a client report, customer data sent somewhere it shouldn't go. Whose responsibility is that, and who was supposed to be watching?

In a lot of small businesses the honest answer is "nobody," and that's the gap governance closes. You don't need a Chief AI Officer. At a minimum there needs to be a name against each tool that matters, usually whoever runs the part of the business that depends on it. Marketing owns the marketing AI, ops owns the ops AI etc. It's about someone holding accountability and oversight for it, not about growing headcount.


Question 3: What rules apply to you?


This is where the paperwork comes in. But don’t glaze over: here's what's true as of August 2026.


  • The EU AI Act

The EU AI Act (Regulation (EU) 2024/1689) is the first big binding law on AI, and the name is a bit misleading. It can reach you even from outside the EU, as it applies where you put AI systems on the EU market, or where your AI's outputs are used there. What does that mean? Well think of it like this; if your system is ever being used by a person based in the European Union, or if your AI generated content is reaching them, it applies.

An important consideration is also that it's risk-based: your obligations differ depending on how risky the Act views that your use is (not how big your company is.)

Two points really matter for a small or medium sized business:


  1. Most of what AI can do is considered low-risk in the Act. An AI writing tool, a chatbot, a "smart" analytics feature, these usually sit in the low or limited-risk tiers of risk. In these cases your main responsibility is to be upfront: telling people when they're dealing with a bot or AI-generated content.

  2. The Act is already live in some important respects. Since February 2025 a handful of "unacceptable" uses of AI have been banned outright, and there's an AI literacy duty in force too: if your business provides or uses AI, you're expected to make sure the relevant staff actually understand the tools they work with.


The heaviest requirements in the Act are reserved for the systems it sees as high-risk. This includes AI used in things like hiring, credit scoring, or access to essential services. If that's you, it's a much bigger conversation.


But the timeline recently shifted: the EU's Digital Omnibus (Regulation (EU) 2026/1744, in force since 27 July 2026) pushed the main high-risk deadline for standalone systems from August 2026 out to 2 December 2027, and to 2 August 2028 for AI built into products that are already regulated. So there's more breathing room to consider high risk uses than there was a couple of months ago. The fines for breaching the EU AI Act are still serious though: up to €35 million or 7% of global turnover for the worst breaches.


The short version: first work out whether any of your AI counts as high-risk. If it does, you've got real work ahead.


  • ISO/IEC 42001

If the EU AI Act is about what you're legally required to do, ISO/IEC 42001:2023 is about how to run AI responsibly and be able to prove it. Published in December 2023, it's the world's first certifiable AI management system standard.

If you've ever dealt with ISO 27001 for information security or ISO 9001 for quality, it'll feel familiar. It has the same shape, same "plan it, do it, check it, improve it" rhythm, pointed at AI. It asks you to know your AI systems, weigh their impact, manage the risks across their whole life, and keep an eye on the third-party AI you depend on.

Why would a small business bother with something voluntary? Mostly one reason: procurement. Bigger customers are starting to ask suppliers to prove they handle AI responsibly, and "trust us, we're careful" doesn't cut it any more. A credible answer to that question can be the difference between winning a contract and watching it walk.

One boundary worth being clear about, because it's often blurred: implementing a management system and certifying it are two different jobs, kept deliberately separate. I can help you build and run an AIMS and get you ready for the audit. The certificate itself has to come from an independent, accredited certification body: not from me, and not from anyone who built your system.


Question 4: How do you keep it under control?


Once you know what you've got, who owns it, and what applies, controlling the risk is mostly common sense done consistently. For an SME that's usually three things:

A short AI use policy, so staff know what they can and can't put into these tools. (Client data? Confidential numbers? No.)

A human eye on anything that matters, so no AI-generated decision about a person or a customer goes out unchecked.

A light paper trail, so if something does go wrong you can show what happened and what you did about it.

That's proportionate governance for a small business. Put the effort where AI touches people, money, or personal data, and go easy on the tool that tidies your calendar.

"I'm just a small business using ChatGPT. Does any of this really apply to me?"

The real risk for a business your size is the gap between "we use AI all over the place" and "nobody's actually looking at it." Closing that gap cheaply, before a client questionnaire or an awkward incident forces you to, is basically the whole game.



Short version - where to start (give it an afternoon)

  1. List your AI. Every tool and feature, what it does, what data it touches. That's your inventory.

  2. Put a name against each one that matters.

  3. Flag anything that seems high-risk (for example, involving hiring, credit, anything heavy on personal data) for a proper look.

  4. Write a one-page policy telling staff what's allowed.

  5. Communicate the one pager clearly to your staff


FAQs

What is AI governance in plain English? Knowing what AI your business uses, who's responsible for it, what rules apply, and how you stop it causing harm and being able to show you're on top of it.


Does the EU AI Act apply to a UK or non-EU business? It can. It reaches businesses outside the EU where they put AI systems on the EU market, or where the AI's outputs are used in the EU, wherever the company is based.


Do I need ISO 42001 certification? No, it's voluntary. It's worth considering once customers start asking you to prove you manage AI responsibly, which tends to happen in enterprise procurement.


What's the very first thing I should do? Build an AI inventory: a simple list of every AI tool and feature you use, what it does, and what data it touches. Everything else builds on it.





Further reading (primary sources)

EU AI Act, official text (Regulation (EU) 2024/1689): https://eur-lex.europa.eu/eli/reg/2024/1689/oj

ISO/IEC 42001:2023 (official standard page): https://www.iso.org/standard/42001

This article is general information, not legal advice.

Comments


bottom of page