Key takeaways
- AI governance isn't an enterprise-only concept — it scales down to one owner, one register, and one review date.
- Pick a single person to own AI decisions. Shared ownership across a small team tends to mean no ownership.
- A simple approval flow — request, quick check, decision — beats no process and beats a slow one equally.
- A tool register (what's in use, who owns it, what data it touches) is the single most useful governance artifact for a small business.
- Review the whole system on a fixed schedule — quarterly is plenty for most small teams.
"Governance" sounds like something that requires a compliance department, a legal budget, and a stack of policy binders. For a small business, it's none of that. It's one person who owns the decisions, a short process for approving a new tool, a simple list of what's actually in use, and a date on the calendar to check it all again. That's the entire starter kit, and it takes an afternoon to set up.
What "AI governance" actually means at small-business size
Strip away the enterprise language and governance is just three questions, answered consistently: who decides which AI tools we use, what do we know about the tools already in use, and how often do we check that both answers are still accurate. Most small businesses have answered none of these — not because the questions are hard, but because nobody's been assigned to ask them.
The cost of skipping this isn't abstract. Nearly half of small and midsize businesses — 49% — name data security and compliance as their top barrier to using AI at all, according to Upwork's 2026 State of AI in SMBs research. That hesitation is rational when there's no process behind it. Governance is what turns "we're nervous about AI" into "we know what's running and we've looked at it."
Who should own AI decisions
One person. Not a committee, not "the leadership team," not "whoever's using it." A named owner — often the business owner in a very small company, or an office manager, operations lead, or IT-adjacent role once the team grows past a handful of people. The job isn't technical. It's administrative: keep the tool register current, run the approval conversation when someone requests a new tool, and put the review on the calendar.
For a team under 15 people, this is realistically one hour a month. It's a responsibility added to an existing role, not a new job description.
A three-step approval flow
The point of an approval flow is to make "ask before you use something new" a real, followable step instead of a vague expectation. Three steps is enough for almost every small business — more than that and people start skipping the process entirely.
| Step | What happens |
|---|---|
| 1. Request | Employee tells the AI owner what tool they want to use and why, in a sentence or two — email or a shared form both work. |
| 2. Quick check | The owner runs through a short evaluation: what data would the tool touch, does it train on input, does it offer admin controls. See our approved AI tools checklist for the full list of questions. |
| 3. Decision | Approve, approve with limits (e.g., no customer data), or decline — and add the outcome to the tool register either way. |
Turnaround matters as much as thoroughness here. If a request sits for two weeks, the employee will likely use the tool anyway and just not mention it — which is exactly the "shadow AI" problem governance is meant to prevent. A same-week answer, even a cautious one, keeps people inside the process instead of around it.
The tool register — your single source of truth
This is the one document that makes everything else in this guide real. Without it, "we have a governance process" is just a claim nobody can verify. With it, you can answer "what AI tools touch our customer data" in thirty seconds instead of asking around the office.
A basic spreadsheet is enough. The value isn't in the tool that holds it — it's in the discipline of adding a row every time a new AI tool enters the business, and updating the "last reviewed" column on the schedule below.
Setting a review cadence
Governance fails quietly when nobody revisits it. A quarterly review is enough for most small businesses: the AI owner spends thirty minutes checking the tool register against what's actually being used, closing out anything abandoned, and confirming nothing new slipped in unapproved. Twice a year is the outer limit — AI tools and their data practices change fast enough that a full year between reviews leaves too much room for drift.
Seventy percent of small business owners say they need more training to use AI effectively, according to a Thryv survey reported by Carrier Management. A governance process without a training component leaves that gap open — pair this starter kit with our employee AI training guide.
How this scales as the team grows
The starter kit above is sized for a company under roughly 15 people. As a business grows past that point, the same four pieces — owner, approval flow, register, review cadence — still work, but each one usually needs a small adjustment rather than a full rebuild.
| Team size | What typically changes |
|---|---|
| Under 15 | One owner, informal register, quarterly review — the starter kit as written. |
| 15–50 | The owner role often gets a backup person, and department leads start flagging their own tool requests rather than routing everything through one inbox. |
| 50+ | Governance usually becomes a shared responsibility between IT/operations and department heads, with the register split by department but still reviewed centrally. |
What shouldn't change, regardless of size, is the core discipline: one place where every AI tool in use is recorded, one clear path for getting a new one approved, and a fixed date to check both. Businesses that build more process than that before they need it tend to see the extra structure abandoned within a quarter, because nobody has time to maintain a system built for a company twice their size.
Governance alone isn't enough
A tool register and an approval flow tell you what's allowed and what's in use — they don't teach anyone how to use AI well. Those are two different problems, and small businesses often solve the governance half while leaving the skills half untouched. That gap matters: seventy percent of small business owners report needing more training to use AI effectively, according to a Thryv survey reported by Carrier Management, which suggests most companies are further behind on capability than on control.
Treat governance as the guardrails and training as the actual driving lessons. A well-governed company where nobody knows how to get good results from an approved tool hasn't solved much — it's just added paperwork around underused software. Pair the governance work in this guide with a short, role-specific training plan so the approved tools actually get used well, not just safely.
What the first 30 days actually look like
Building this from nothing can feel like a bigger project than it is. In practice, most small businesses can go from no governance at all to a working starter kit inside a month, without a dedicated project or outside help.
| Week | What happens |
|---|---|
| 1 | Name the owner. Start the tool register with whatever tools you already know are in use. |
| 2 | Ask the team directly what else they're using — this usually adds several rows to the register. |
| 3 | Run the four-question checklist against each tool already in the register, starting with the ones touching the most sensitive data. |
| 4 | Set the first quarterly review date, and share the register and approval process with the team. |
By the end of the month, you have a real answer to "what AI tools are we using and did anyone check them" — which is more than most small businesses can say today, and it took roughly the effort of one part-time project, not a major initiative.
Common mistakes
- Making the owner a committee. Shared responsibility for the tool register and approvals almost always means nobody actually maintains either.
- Building an approval process too slow to use. If requests take weeks, employees will bypass it and you'll be back to shadow AI.
- Skipping the register because "we don't have that many tools." Small teams still accumulate tools fast — a register started early stays much easier to maintain than one built from memory a year later.
- Treating governance as a one-time project. Without a fixed review date, even a good system goes stale within a couple of quarters.
- Copying an enterprise framework wholesale. Multi-page risk matrices and formal committees are overkill for a ten-person business and tend to get abandoned within a month.
Once the owner, the approval flow, and the register are in place, the next step is usually a written policy that reflects them — see our guides on the AI acceptable use policy and the NIST AI RMF explained for small business for how this starter kit maps to a more formal framework as you grow.
◆ Small Business AI Kickstart
Get AI ready today.
Before it's too late.
yforest AI Labs comes to your company, trains your team, and ships your first tools.
FAQ
Isn't AI governance just for large enterprises with compliance teams?
No — governance scales down. A five-person company doesn't need a committee, but it does need one person who owns the approved-tools list, a simple way to request a new tool, and a record of what's in use. That's governance at small-business size.
Who should own AI governance at a small company?
One person, not a committee. It's often the owner, an office manager, or whoever already owns IT and software decisions. The role can be one line in someone's existing job, not a new hire.
How is this different from just writing an AI acceptable use policy?
The policy sets the rules. Governance is the ongoing process that keeps the rules current — who approves a new tool, who tracks what's in use, and how often the whole thing gets reviewed. You need both.
What's the minimum viable version of this for a very small team?
One owner, one tool register with five or six columns, and a review every quarter. That alone puts most small businesses ahead of where they are today.
How does this connect to frameworks like NIST's AI RMF?
The starter kit here is a small-business-sized version of the same idea NIST's framework describes at enterprise scale: know what AI you're using, assess the risk, and manage it on a schedule. See our plain-English NIST AI RMF guide for the full mapping.
Sources
This guide is general information, not legal advice. Have a qualified attorney review any policy before you adopt it.