AI Governance
AI Governance for SMEs: It Doesn't Need to Be a Bureaucratic Nightmare
AI governance can sound like something designed for banks, governments and enormous technology companies. For most SMEs, it should be much simpler: know where AI is being used, understand what could go wrong, give people sensible boundaries and make the safe way the easy way.
What running a SaaS company taught me about moving fast, managing AI risk and keeping governance proportionate
If you’d asked me about AI governance a few years ago, I probably wouldn’t have had much of an answer.
I spent more than a decade building and running a SaaS company. Like most startups, we shipped things, experimented, changed direction, tried new technology and worried about solving customer problems.
We considered GDPR because we had to. But AI governance? AI risk management? Management systems?
Not really.
At one stage, we were even working on our own AI model to review content submitted to our platform and decide whether it met the criteria for promotion. We got reasonably far with it. Then generative AI advanced so quickly that the problem changed underneath us. Rather than continuing to build the capability ourselves, we could give an existing AI system our rules and ask it to perform much of the review.
That was quicker, cheaper and considerably easier.
And that is exactly how many small businesses are adopting AI today.
Nobody holds a board meeting called “Beginning our AI transformation programme.”
Someone discovers that ChatGPT saves them half an hour. Someone else installs an AI meeting assistant. Marketing starts using Canva’s AI features. Sales switches on an AI function inside the CRM. A developer starts using an AI coding assistant.
Then suddenly the company is using AI in ten different places.
Nobody has actually stopped to count them.
“Governance” is an unnecessarily frightening word
Tell the founder of a 20-person company that they need AI governance and I suspect they imagine committees, lawyers, hundreds of pages of documentation and expensive consultants telling everyone what they’re no longer allowed to do.
That isn’t what good governance should look like.
At its simplest, governance means answering some fairly ordinary questions:
- What are we using?
- What are we using it for?
- What information are we giving it?
- Who could be affected if it goes wrong?
- Who is responsible for deciding what is acceptable?
- How do we know it is still working as intended?
These are management questions, not AI engineering questions.
This is also one of the things I found most useful when I began studying management systems properly.
ISO/IEC 42001, the international standard for AI management systems, isn’t limited to companies building AI models. Its scope includes organisations that use products or services incorporating AI systems, as well as those that provide them.
But that doesn’t mean every 20-person business needs an ISO/IEC 42001 certification project.
Far from it.
The standard itself recognises that the amount of documented information needed will differ between organisations depending on factors including their size, activities, process complexity and the competence of their people.
That principle matters.
Governance should fit the organisation. The organisation shouldn’t be bent out of shape to fit the governance.
A marketing agency and an AI SaaS company are not the same thing
Imagine two businesses.
Both employ 20 people.
The first is a marketing agency. Its team uses third-party products such as ChatGPT, Claude, Canva and AI features built into its CRM.
The second is a SaaS company embedding AI functionality directly into the product it sells to customers.
They’re the same size, but their AI risk profiles can be completely different.
The SaaS company may have to consider things such as system development, testing, data provenance, model performance, supplier dependencies, monitoring, customer requirements and potentially significant regulatory obligations.
The marketing agency may primarily need to think about confidentiality, personal data, client contracts, intellectual property, unreliable outputs and employees signing up to unapproved services.
The answer isn’t therefore:
Small company = lightweight governance.
It’s:
Lower-risk use = lighter governance. Higher-risk use = stronger governance.
Context comes first.
That’s consistent with the approach taken by ISO/IEC 42001. Its risk requirements consider the AI system’s application context, intended use and the organisation’s wider internal and external context. Risk assessment can also consider potential consequences for the organisation, individuals and society where relevant.
It’s one of the biggest things I’ve taken from studying AI risk management:
You can’t sensibly talk about risk without first understanding what you’re trying to achieve and who could be affected.
The first problem is often not dangerous AI. It’s invisible AI.
This is where I’d start with most SMEs.
Before writing an AI policy, find out what people are actually using.
Because the founder’s answer and the employees’ answer may be very different.
Ask the team:
What AI tools, features or browser extensions have you used for work during the last month? What do you use them for?
Make it explicitly non-judgemental.
You’re not trying to catch anyone.
You’re trying to discover reality.
The idea of identifying relevant AI resources is also reflected in ISO/IEC 42001. Its controls address relevant resources associated with AI systems, including tooling, data, computing resources and people. Understanding those resources helps an organisation understand its risks and potential impacts.
You might discover:
- ChatGPT
- Claude
- Microsoft Copilot
- Canva
- Grammarly
- an AI meeting recorder
- CRM automation
- AI browser extensions
- coding assistants
- image generators
- specialist tools you’ve never heard of
That simple exercise is already governance.
You can’t manage what you don’t know exists.
Make the safe route the easiest route
This is where small-company governance often goes wrong.
Management writes:
Employees must not use unauthorised AI systems.
Excellent.
Then employees discover that the authorised process requires three approvals, a form and a tool that’s worse than the one they’re already using.
Guess what happens next.
They use the other one.
Good governance needs to take human behaviour seriously.
If your team relies heavily on a particular AI service, investigate whether the appropriate commercial workspace gives you better organisational controls and data terms, and make that the easiest environment for employees to use.
For example, OpenAI currently states that data from its business offerings is not used to train its models by default. Anthropic similarly states that inputs and outputs from its commercial products are not used for model training by default.
That doesn’t make either product automatically appropriate for every type of confidential or personal information. Data retention, integrations, permissions, contractual requirements and the nature of the information still matter.
But it illustrates the broader principle:
Don’t merely tell people to behave safely. Design the working environment so that safe behaviour is convenient.
ISO/IEC 42001 takes a similarly contextual approach to responsible use. Its guidance considers areas such as approvals, sourcing requirements, applicable legal requirements, third-party solutions and meaningful human oversight rather than assuming one control will work everywhere.
Make it about client trust, not compliance theatre
If you’re running a creative agency, most employees are unlikely to leap out of bed excited about a management-system clause.
They may care considerably more about this:
Our client has trusted us with information they haven’t released publicly. We need to be careful about where that information goes.
That’s a very different conversation.
The same rule now has a purpose.
Your client agreements may restrict the way confidential information, personal data or third-party systems can be used.
UK data protection law also remains relevant when personal data is processed through AI systems. The Information Commissioner’s Office provides specific guidance on applying data protection principles and risk management to AI.
Governance becomes:
Protect the trust that allows us to do business.
That’s considerably easier to understand than:
Comply with the AI policy because management says so.
Policies aren’t enough
One of the things standards thinking has changed for me is my view of documentation.
Previously, I’d have associated standards with paperwork.
Now I increasingly see documentation as memory for an organisation.
Who decided this?
Why?
What are we supposed to do?
What happened last time?
Has anything changed?
In a tiny startup, a surprising amount of this can live inside people’s heads.
We experienced that ourselves. We didn’t call what we were doing Plan-Do-Check-Act, but we did plenty of it naturally. We tried something, looked at what happened, changed it and tried again.
That’s one of the great strengths of a startup.
It’s also one of its vulnerabilities.
As the organisation grows, the shared memory becomes less reliable.
The objective shouldn’t be to document everything.
It should be to document enough that people can reliably understand what needs doing, by whom and why.
ISO/IEC 42001 requires certain documented information, but also leaves organisations to determine what additional documentation they need for the management system to be effective. The extent of that documentation can vary according to the organisation and its context.
That’s very different from:
Produce as much paperwork as possible.
Human oversight still matters
There’s one rule I particularly like for a small creative organisation:
AI can brainstorm, draft and refine, but it doesn’t get to hit Send or Publish.
That isn’t a universal legal rule, and it wouldn’t be appropriate for every AI use case.
It’s a practical operating rule.
If AI helps draft a campaign, write code, produce an image or summarise a client document, somebody appropriately competent remains accountable for deciding whether the output is good enough to leave the building.
That matters because AI systems can produce convincing but incorrect outputs.
Human oversight is also a recurring theme within ISO/IEC 42001’s responsible-use guidance. This includes human review, the authority to override AI decisions, monitoring output performance and determining whether automated decision-making is appropriate for the intended use.
For organisations within the scope of the EU AI Act, AI literacy is also now an important consideration.
The European Commission’s current guidance explicitly gives examples involving employees using tools such as ChatGPT for tasks including advertising copy or translation, where staff should understand relevant risks such as hallucination.
Again, that doesn’t mean everyone needs a three-day compliance course.
Sometimes good AI literacy might begin with 15 minutes showing people what the tools are good at, what they’re bad at and what information they shouldn’t casually put into them.
What I’d do in the first week
If I walked into a 20-person SME on Monday morning and discovered AI was already being widely used but nobody had formally thought about governance, I wouldn’t begin by writing a 40-page policy.
I’d do three things.
1. Find the hidden AI
Ask the team what AI tools and AI-enabled features they’re actually using and for what purpose.
Record the answers.
You now have the beginnings of an AI inventory.
2. Decide what you’re comfortable with
Look at the important tools.
Consider the information being put into them, the vendor’s terms, privacy and security arrangements, the client’s requirements and the consequences if something goes wrong.
Decide which tools and uses are approved.
Where practical, provide appropriate company-managed services rather than leaving everyone to improvise with personal accounts.
ISO/IEC 42001’s controls also address supplier relationships, including the need to consider whether supplier products and services align with an organisation’s approach to responsible AI use.
3. Draw a line around human responsibility
Decide which AI outputs need human review, what that review actually means and who is responsible.
For a marketing agency, my starting principle would be simple:
AI can assist. A competent human remains responsible for what reaches the client or public.
Then improve from there.
Do you need ISO/IEC 42001 certification?
For many small businesses simply using ordinary third-party AI tools, I wouldn’t make certification the starting objective.
The commercial case may not exist.
The level of risk may not justify it.
And there may be much simpler things you should fix first.
A SaaS business building AI into a customer-facing product is a different conversation.
So is a business selling into enterprise procurement, operating in a regulated environment or using AI in contexts where decisions can materially affect people.
Interestingly, ISO/IEC 42001 itself reinforces the idea of selecting controls according to need rather than applying every possible control indiscriminately. Annex A provides a reference set of controls, but not every control necessarily needs to be used, and organisations implementing the standard can also design controls appropriate to their own circumstances.
The standard can therefore be useful even before certification enters the conversation.
What I’ve found particularly valuable in studying it isn’t a pile of documents.
It’s the questions it forces you to ask.
Who is responsible?
What are we trying to achieve?
What could prevent that?
Who could be affected?
What information are we relying on?
What happens if a supplier changes something?
How will we know if the system stops performing as expected?
And what will we do about it?
Those are good management questions whether you employ 20 people or 20,000.
Governance shouldn’t slow AI adoption down
This is probably the biggest change in how I now think about the subject.
Governance isn’t supposed to stop people using AI.
Done well, it should do the opposite.
It should allow people to experiment more confidently because somebody has established where the boundaries are.
Your employees know which tools are approved.
They understand what information is sensitive.
They know when human review is required.
Somebody owns the decision-making.
And when circumstances change, you look again.
That’s governance.
No enormous committee required.
No certification badge required.
No bureaucracy for bureaucracy’s sake.
Just enough structure to make sure that while your company is moving quickly, somebody is still steering it.
About Matthew
Matthew Spurr is a former SaaS founder and a BSI certified AI Management Systems Practitioner, now developing his professional specialism in AI management, governance and responsible adoption. He continues to explore AI governance, AI risk management, information security and quality management, including the ISO/IEC 42001 family of standards.
