The lightweight version a small or mid-sized UK firm can actually run: the parts in the order to build them, who owns what, the documents you need and the mistakes to avoid.
For a small or mid-sized firm, an AI governance framework is a short set of rules, owners and records that shows who decides how AI is used, what it may touch and how you know it works. You don’t need an enterprise programme: a named owner, a use policy, a register and a few one-page documents cover most firms, with more controls only where the risk is higher. This is the practical version, in the order I would build it.
Why a small firm needs one at all
Your staff are probably using AI already, whether or not anyone approved it. Suppliers are switching on AI features inside software you already pay for. Without a framework, nobody knows what is in use, what data has gone where, or who would answer for a mistake. Clients and regulators can ask those questions, and “we don’t really know” is a poor answer.
The point is not paperwork. It is being able to say yes to useful tools quickly, because the rules for saying yes are already agreed.
The parts, in the order to build them
- Name an owner. One person accountable for how the firm uses AI. In a small firm this is often a director or the head of operations. They don’t need to be technical; they need the authority to say no.
- Find out what is already in use. Ask each team which AI tools they use, for what, and with what data. Check the AI features in your existing software too. This becomes the first version of your register.
- Write a short use policy. Approved tools, what must never be pasted in, who checks the output and what to do after a mistake. The free AI acceptable use policy template covers this and can be edited to suit your firm.
- Set data boundaries. For each approved tool, agree which information it may see, where it is processed and how long it is kept. Use business accounts with proper terms, never personal ones.
- Sort uses by risk. A simple low, medium and high scale is enough. Drafting an internal email is low. Anything that touches client money, advice, hiring or decisions about individuals is high.
- Agree review and approval points. Decide where a person checks the output, and which actions always need a named person to approve them. The higher the risk, the earlier and firmer the check.
- Test before go-live. For medium and high-risk uses, try the tool on real examples, including awkward ones, and write down what it got wrong. Keep that evidence.
- Form a small governance group. A few people from the business, compliance and IT who approve new uses and look at incidents. Give them clear decision rights so requests don’t stall.
- Train people. A short session on the policy and on how to check AI output does more than any document.
- Review on a schedule. Look at the register and the policy again regularly, and whenever a tool, a supplier’s terms or a regulation changes.
Who owns what
- The board or owners. Set how much risk the firm will accept and hold the AI owner to account.
- The AI owner. Keeps the register and the policy current, chairs the governance group and reports to the board.
- The process owner for each use. The manager whose team uses the tool. They own the results, the review points and the evidence.
- The data protection lead. Checks the lawful basis, the supplier’s data terms and whether a data protection impact assessment is needed.
- IT, or your IT supplier. Manages accounts, access and the settings on each tool.
- Everyone else. Follows the policy and reports mistakes quickly, without fear of blame.
The documents you need, one page each
Keep each one to a page. Long documents don’t get read, and rules nobody reads protect nobody.
- AI use policy. The rules for staff, in plain English.
- AI register. One line per tool or use: what it is, who owns it, what data it touches, its risk level and when it was last reviewed.
- Use record. For each medium or high-risk use: the purpose, the data, the review points, the test results and who approved it.
- Terms of reference for the group. Who sits on it, what it can decide on its own and what goes to the board.
- Incident log. What went wrong, what was done about it and what changed as a result.
How an AI governance framework scales with risk
The parts stay the same for every firm. What changes with the risk is how deep each one goes.
- Low risk. Drafting, summarising and research with no client or personal data. A policy, a register entry and a trained user are enough.
- Medium risk. Internal use with client or personal data, or output that customers see after a person has checked it. Add a use record, a data protection check and tests on real examples.
- High risk. Anything that affects decisions about individuals, client money, advice or regulated activity, or that acts without a person checking each output. Add formal approval by the group, firmer review points, an audit trail and regular re-testing.
Regulated firms will find more of their uses towards the top of that scale. That is also where the EU’s rules are most likely to bite: the guide to the EU AI Act for UK businesses explains when they reach a UK firm.
Where the big frameworks fit
Three names come up often. The NIST AI Risk Management Framework is a voluntary framework from NIST, the US National Institute of Standards and Technology, built around four functions: govern, map, measure and manage. ISO/IEC 42001 is the international standard for an AI management system, and firms can choose to be certified against it. In the UK, the government has taken a principles-based approach: principles such as safety, transparency, fairness and accountability, applied by the existing regulators in their own sectors rather than through a single AI law.
All three are worth knowing, and none needs adopting wholesale by a small firm. The parts above cover the same ground at a smaller scale, so you can grow into a formal standard later if clients or your regulator expect it.
Common mistakes
- Starting with a long policy. Nobody reads it, and it goes out of date. Start with one page and the register.
- Banning AI outright. People use it anyway, on personal accounts, and you lose sight of it.
- Governing tools instead of uses. The same tool can be low risk for drafting emails and high risk for summarising client files. Approve the use, not just the product.
- No named owner. If everyone is responsible, nobody updates the register.
- Approving without evidence. A good demonstration is not a test. Ask to see what went wrong.
- Treating it as a one-off. Tools, suppliers’ terms and regulations change. Put the next review in the diary.
- Making governance the brake. If every request waits months, people go around it. Clear decision rights make approval faster, not slower.
What this looks like in practice
In my experience, the firms that adopt AI fastest are the ones that agreed their boundaries first. A request that fits the register and the policy can be approved quickly, and one that doesn’t goes to the group with a clear question attached. The principles behind it, data boundaries, human oversight and evaluation, are set out on the responsible AI page.
This is practical guidance, not legal advice; check your specific obligations with a qualified adviser. If you want help putting a framework in place, see AI governance consulting, or book a free 30-minute AI consultation to talk it through.
