AI Governance Framework for Small Business: The One-Page Version
A one-page AI governance framework for small businesses: who owns AI decisions, how tools get approved, what data rules apply, when humans must review output, and how often the rules get revisited. Fill-in template included.
An AI governance framework is the set of decisions that controls how your business adopts and uses AI: who has the authority to approve tools, which tools are approved, what data may enter them, which outputs require human review, and how often those rules get revisited. For a small business, all of that fits on one page. It has to, because a framework nobody reads governs nothing.
If you searched “AI governance framework,” most of what you found was written for enterprises. NIST’s AI Risk Management Framework and ISO/IEC 42001 are real, serious standards, and if you sell to large companies you may eventually be asked about them. But they assume committees, dedicated risk officers, and documentation budgets a 15-person firm does not have. Copying them at small-business scale produces a binder that gets signed once and never opened.
This post is the version I actually set up for small businesses: what governance means at your size, the one-page framework you can fill in this week, and where the acceptable use policy I published earlier fits inside it.
What is the difference between AI governance and an AI policy?
An AI policy tells your employees the rules. AI governance decides what the rules are, who gets to change them, and what happens when reality changes.
The distinction matters in practice. Plenty of businesses have downloaded a policy template, distributed it, and considered AI “handled.” Then a new tool launches, a vendor adds AI features to software the company already uses, or an employee finds a use case the policy never anticipated. Without governance, there is no defined way to answer “can we use this?” So the question gets answered by whoever wants to use the tool, which is how shadow AI happens even at companies with a signed policy on file.
Governance is the small decision layer above the policy. At enterprise scale it is a committee. At your scale it is one page and one named owner.
Does a small business actually need AI governance?
Yes, and here is the honest scope of “need.” You do not need it for compliance theater. You need it because three questions come up repeatedly once your team uses AI, and answering them ad hoc is how data exposure and tool sprawl happen:
- Can we use this new tool? New AI tools appear weekly, and existing software keeps adding AI features that change how your data is handled.
- Can AI do this task? Some tasks are fine to hand to AI with review. Some, like professional advice in regulated fields, are not.
- Something went wrong. Now what? An employee pasted client data somewhere it should not have gone, or AI output with an error reached a customer.
A governance framework is just those three answers, written down before you need them, with a name attached. If your clients are in healthcare, legal, or financial services, there is a second reason: their compliance teams increasingly ask vendors how AI use is governed. A one-page answer you can produce in five minutes is worth real money in those conversations.
The one-page AI governance framework
Here is the full framework. Copy it, fill in the brackets, and you have a working governance document. It deliberately mirrors the structure I use in paid engagements, trimmed to what a business under 50 people needs.
[COMPANY NAME] AI Governance Framework
Owner: [NAME]. This person approves tools, answers data questions, and reviews this document. Decisions they cannot make alone go to [OWNER/PARTNERS].
1. Tool approval. No AI tool may be used with company or client data until [OWNER] approves it. Approval means checking three things: where the data goes (training use, retention, storage location), whether the tier we are buying has business data controls, and whether it conflicts with any client or regulatory obligation. Approved tools are listed in our acceptable use policy, which is the employee-facing half of this framework.
2. Task rules. AI may draft, summarize, and process internal work freely. Anything client-facing requires human review before it leaves the company. AI may not produce final professional judgments (legal, financial, medical, or safety decisions). Tasks not covered here get asked about first, not assumed.
3. Data rules. Client personally identifiable information, financial records, health information, and anything under a confidentiality obligation may only enter tools approved for that data type. When unsure, do not enter it. Ask [OWNER].
4. Incidents. Suspected data exposure or a significant AI error reaching a client gets reported to [OWNER] within 24 hours. First-time honest reports are never punished. [OWNER] assesses what data was exposed, whether any client or regulatory notification applies, and what changes to prevent a repeat.
5. Review. [OWNER] reviews this framework and the approved tool list quarterly, and immediately when: a new tool is requested, an approved tool changes its data terms, a client contract adds AI requirements, or an incident occurs. Last reviewed: [DATE].
That is the whole thing. Five sections, one page, one owner.
How to put it into practice in one week
Day 1: Name the owner. In most small businesses this is the owner, a managing partner, or the office manager. The only requirements are authority to say no and availability to answer questions the same business day. A governance owner who takes a week to respond trains employees to stop asking.
Days 2 and 3: Inventory what is already in use. Ask your team directly, as amnesty rather than audit, what AI tools they already use for work. You will likely find more than you expected. Most businesses do; my AI readiness assessment guide covers this inventory step in detail. Every tool found goes through the Section 1 approval check: approve it on a proper tier, replace it, or retire it.
Day 4: Fill in the framework and the policy. The framework above is the decision layer. The acceptable use policy is the employee-facing rules layer, and the two share their tool list. Filling in both takes an afternoon.
Day 5: Tell the team. Fifteen minutes, not a seminar. The message that matters: here is who to ask, here is what is approved, asking is always safe, and honest incident reports are never punished. That last sentence does more for your actual risk posture than any other line in the framework, because hidden incidents are the expensive ones.
If you are rolling out AI at the same time, this week slots directly into Week 3 of my 30-day AI implementation plan, which is where the rules belong: after you have picked a workflow, before you train the team.
What a small business can safely skip
Value also means knowing what not to build. At under 50 people, you can skip: an AI ethics committee (one accountable person beats a committee that never meets), formal model risk documentation (you are configuring commercial tools, not training models), AI audit trails beyond what your approved tools already log, and certification against ISO/IEC 42001 (relevant only if a major client contractually requires it, and none of mine have asked a sub-50-person vendor for it yet).
The one thing you cannot skip is the named owner. Every failed governance setup I have seen failed the same way: rules existed, but no human was accountable for applying them to the next new tool.
Where the framework runs out of road
Sections 1 and 3 contain an honest limit. The framework can say “only enter client data into tools approved for it,” but at some point you need a tool that is actually approvable for sensitive data. For ordinary business data, the business tiers of mainstream AI tools are usually fine. For client PII, health records, legal matter files, or financial data, the bar is higher: you need AI running where your data stays under your control, with logging you own.
That is the part of governance I build rather than write. A secure AI work environment runs in your own Azure tenant, keeps client data inside your environment, and logs every interaction, which turns Section 3 from a restriction into a workflow your team actually likes using. If your framework keeps hitting “we cannot approve any tool for this data,” that is the fix, and I am happy to show you what it looks like running.
Frequently asked questions
What should an AI governance framework include?
Five things: a named owner with decision authority, a tool approval process, task rules defining what AI may and may not do, data rules defining what may enter which tools, and a review cadence with incident reporting. For a small business, one page covers all five.
Is NIST AI RMF or ISO 42001 relevant to small businesses?
Rarely as something to implement, occasionally as something to be aware of. NIST’s AI Risk Management Framework is voluntary guidance and ISO/IEC 42001 is a certifiable management standard, both designed for organizations with dedicated risk functions. A small business serving enterprise or regulated clients may get asked about them, and a clean one-page framework is usually a sufficient answer at sub-50-person scale.
Who should own AI governance in a small company?
Whoever can say no to a tool and answer a data question the same business day. In practice: the owner, a managing partner, or a trusted office manager. Do not assign it to a committee, and do not assign it to the most junior person who “knows computers.”
How often should the framework be reviewed?
Quarterly as a baseline, plus immediately whenever a new tool is requested, an approved tool changes its data terms, a client adds AI requirements to a contract, or an incident occurs. The scheduled review takes about 30 minutes once the framework exists.
Is an AI policy enough without a governance framework?
A policy without governance goes stale, because nobody is assigned to update the approved tool list or answer the questions the policy does not cover. The framework is small (one page, one owner) precisely so that keeping the policy alive is somebody’s actual job.
Jose Lugo is a CISSP-certified security engineer with 12 years of U.S. Army intelligence experience. He builds secure AI work environments for businesses at josecustom.ai. See his portfolio of 13 live client systems at portfolio.josecustom.ai.