The owner decides what AI is for, how much risk and spend are acceptable, and anything customer-facing. One named AI lead approves tools and uses within those rules. Someone other than the person who set a tool up checks that it's working. In a firm of five to twenty people, that's two or three people and a one-page decision table.
Governance sounds like a big-company word, but in a small firm it just means everyone knows who can say yes, and somebody looks back regularly. The usual gap is that the person who set a tool up is the only one who ever checks it, which is how an automation built by someone who has since left can keep emailing customers for months without anyone noticing.
Decide, approve, check: three different jobs
- Decide means setting direction and limits: which problems AI should work on this year, the monthly budget, what level of risk is acceptable, and whether AI talks to customers at all. This is the owner's job because the owner carries the consequences.
- Approve means saying yes or no to specific requests within those limits: a new tool, a new use of an existing one, a new automation. This is the AI lead's job, usually an operations or office manager who understands both the work and the tools.
- Check means looking back: is each tool still used, still safe, still worth the money, still doing what it was approved for? The one rule: the person who approved or built something shouldn't be the only person checking it. It's the same logic as not signing off your own expenses.
If you haven't yet worked out who the AI lead should be, who should own AI in a small business covers the roles in more depth. This tutorial is about the decision rules those people follow.
The decision-rights table
Eight decisions cover almost everything that comes up. Fill in names, not job titles, and set the spend thresholds to suit your business; the figures below are examples.
| Decision | Who decides or approves | Must be consulted | Who checks, and when |
|---|---|---|---|
| Which problems AI works on this year | Owner | AI lead, team leads | Owner, at the annual review |
| New tool or paid plan up to $50 a month | AI lead | Whoever will use it | Owner, at the monthly check |
| New tool or plan over $50 a month, or any annual contract | Owner | AI lead | AI lead, at the 90-day review |
| Putting customer or staff personal data into any AI tool | AI lead, within the usage policy; owner for anything new | Data-protection adviser if unsure | Owner, monthly |
| Anything customers see or receive from AI | Owner | AI lead, customer-facing staff | AI lead, weekly for the first month, then monthly |
| Automations that send, pay, delete or change records | AI lead, with a human approval step on anything customer-facing or financial | Bookkeeper for anything touching money | Owner, monthly |
| Changes to the AI usage policy | Owner | AI lead, staff | AI lead, every six months |
| Switching a tool off after an incident | Anyone, immediately; restarting needs the AI lead | Owner for serious incidents | Owner, at the incident review |
That last row matters more than it looks. Anyone should be able to hit the off switch without permission; only restarting needs approval. The detail of what happens next belongs in your AI incident response plan.
The "must be consulted" column is the one people skip under time pressure. Picture an office manager at a window-fitting firm who builds an automation that reads replies to payment reminders and marks the invoice as paid whenever a customer writes "paid" or "sent it". It works well for a fortnight. Then the bookkeeper, reconciling the bank, finds three invoices marked paid with no money received: one customer had written "I haven't paid because the job isn't finished", and the AI step had picked up the word. The bookkeeper would have spotted the flaw in two minutes if asked beforehand, which is why the row says anything touching money needs her view, and why the automation now flags replies for a person instead of changing the record itself.
Three approval tiers, so the AI lead isn't a bottleneck
If every AI use needs approval, people stop asking and use personal accounts instead, which is exactly the shadow AI governance is meant to prevent. So sort uses into tiers and publish the list:
| Tier | Examples | Approval |
|---|---|---|
| Green: use freely | Drafting internal emails, summarising your own notes, rewording a job description, all in approved tools with no personal data | None; just follow the usage policy |
| Amber: AI lead approves | A new tool, a new automation, using an approved tool with customer names or job details | Short request, answered within five working days |
| Red: owner approves | Anything customers see, anything that sends money or messages automatically, sensitive personal data, annual contracts | Request plus a trial plan; owner signs off before launch |
The tiers earn their keep on the borderline requests, so publish a few worked calls alongside the table. For a physiotherapy clinic, they might be:
- "Can I use ChatGPT Business to tidy up the wording of our new cancellation policy?" Green. An approved tool, no personal data, and the owner signs off the policy anyway.
- "Can I paste a patient's treatment notes in to draft their discharge letter?" Red, not amber, because health details are sensitive personal data. The owner approves once, with conditions (business account only, name and date of birth removed, the physio reads every letter), and after that the use is recorded and becomes routine.
- "Can we connect the booking system to an automation that texts patients when a slot opens up?" Red: it messages customers automatically. It needs a trial plan and the owner's sign-off before it goes live.
Three examples like these answer more questions than a page of definitions, and they show staff that "red" means "ask first", not "no".
The request itself should be a short form, not a meeting. The AI tool approval process gives you the form and the reviewer's checklist.
What checking looks like: a 30-minute monthly review
Put a recurring 30 minutes in the diary for the AI lead and whoever checks. Keep the same agenda every month so it takes no preparation:
MONTHLY AI CHECK (30 minutes)
1. Register (5 min)
Anything added, changed or cancelled since last month?
Anyone left the business who still has access to an AI tool?
2. Spend (5 min)
AI and automation costs this month vs budget.
Any usage-based charge that jumped?
3. Quality sample (10 min)
Look at 5 real outputs: chatbot replies, AI-drafted quotes or emails,
automation runs. Anything you wouldn't have sent yourself?
4. Incidents and near misses (5 min)
Anything logged? Anything that nearly went wrong?
5. One decision (5 min)
Keep, change or stop one thing. Write it down with a name and date.
Filled in, the notes from one month's check at a nine-person architecture practice might read (illustrative):
MONTHLY AI CHECK - 2 October - AI lead + practice director
1. Register: Gemini now switched on in Workspace for all 9 staff
(was 4) - register updated. Technician who left in August still
had a Claude Team seat - removed today.
2. Spend: $214 against a $180 budget. One designer bought image-
generation credits twice ($40) on a card outside the register.
3. Quality sample: 5 AI-drafted client emails. One quoted last year's
fee scale for a measured survey; caught by the project lead, but
the prompt template still points at the old fee sheet.
4. Incidents / near misses: none logged. The fee-scale draft counts
as a near miss - logged now.
5. Decision: fee-sheet link in the prompt template replaced by the AI
lead by 6 Oct; image credits up to $20 a month allowed without
asking, anything more is amber.
Thirty minutes, and it found a leaver's seat still live, spending outside the register, and an out-of-date source feeding client emails. None of it was dramatic, which is the point: small drifts are caught while they're still small.
Beyond the monthly check, two longer reviews: each tool gets a proper 90-day keep, fix or cancel review after it's introduced, and once a year the owner revisits the direction, the budget, the policy and the vendors' current terms.
Write every approval down in one line
A check only works if there's something to check against. When the AI lead or owner approves anything amber or red, record it in a single line with four parts: what was approved, the conditions attached, who approved it, and when it will be reviewed. For example: "Otter.ai Pro for engineers' voice notes; no customer phone numbers or door codes in recordings; approved by office manager, 14 July; review 14 October."
The conditions are the part people skip, and they're what the monthly check tests. If the approval said "drafts checked before sending", the quality sample should find evidence that drafts are being checked. If it said "no personal data", someone should glance at what's actually going in. An approval with no conditions and no review date is a permanent yes that nobody meant to give.
To test whether the system is working, pick one approval and trace it end to end. Take the Otter.ai line above. At the October review, the office manager opens the approval, reads the condition (no customer phone numbers or door codes), then searches the last month's transcripts for "code" and for runs of digits. In an illustrative run, one of 40 transcripts has an engineer reading out a key-safe number. That isn't a disaster, but it shows the condition existed on paper only. The fixes took ten minutes: delete that transcript, remind the engineers at the Monday meeting to say "code as usual" instead, and add the transcript search to the monthly quality sample. If you can't trace an approval like this, from the line in the register to evidence that its conditions hold, that part of your governance is decoration.
The AI register: one page that holds it together
You can't check what you haven't listed. The register is a single table, kept by the AI lead, with one row per tool or automation:
| Tool and plan | Used for | Data it touches | Customer-facing? | Owner | Approved by, date | Cost a month | Last reviewed |
|---|---|---|---|---|---|---|---|
| ChatGPT Business, 3 seats | Drafting quotes and replies | Customer names, job details | No (drafts checked) | Office manager | Owner, March | $75 | September |
| Zapier Professional | Job-completed follow-up emails | Customer emails | Yes | Office manager | Owner, May | $29.99 | September |
| Otter.ai Pro, 1 seat | Engineers' job reports from voice notes | Addresses, job details | No | Senior engineer | Office manager, July | $16.99 | August |
The costs shown are examples on monthly billing: ChatGPT Business Standard is $25 per seat a month billed monthly, Zapier Professional starts at $29.99 a month billed monthly, and Otter.ai Pro is $16.99 a month billed monthly. Your own rows should use what you actually pay.
Sizing it to your headcount
| Size | Decide | Approve | Check |
|---|---|---|---|
| Solo or 2 to 4 people | Owner | Owner, using a written checklist so decisions are consistent | Owner, quarterly, plus a yearly look from your accountant or a trusted peer |
| 5 to 15 | Owner | One AI lead | Owner monthly; AI lead reviews anything the owner approved |
| 16 to 50 | Owner or leadership team | AI lead, with team leads approving green-tier tools for their teams | A second person (finance or operations) monthly; owner quarterly |
Sole traders can't separate the roles, so the written checklist does the work of a second person: it stops you approving on enthusiasm alone.
Five questions are enough for that checklist. A freelance bookkeeper tempted by an AI tool that connects to clients' bank feeds and suggests categories might answer them like this:
1. What problem does it solve? About 6 hours a month of categorising
2. What data does it touch? Every client's bank transactions
3. Where does that data go? Vendor's servers; training use not
stated on the pricing page
4. What if it's wrong? Wrong categories flow into clients'
accounts unless I check every one
5. Can I stop it cleanly? Unknown: no export route documented
Two "unknowns" on a tool that touches every client's money is a clear "not yet". The decision goes into her register as "on hold until the vendor's data processing terms confirm no training use and a full export", with a date to look again. That's exactly what a second person would have said, and the checklist said it without one.
Worked example: a twelve-person plumbing firm
An illustration. Say a plumbing and heating firm has the owner, an office manager, a bookkeeper two days a week and nine engineers. The owner decides; the office manager is AI lead; the owner checks monthly what the office manager approved, and the office manager reviews anything the owner approves.
- An engineer asks to use an AI transcription app to turn voice notes into job reports. Amber tier: the office manager approves within a week, on condition that customer phone numbers and door codes stay out of the recordings, and adds it to the register.
- The owner wants a website chatbot to answer out-of-hours enquiries. Red tier: the owner decides, but only after the office manager runs it for two weeks in shadow mode, where it drafts answers nobody sees but staff, and the owner reviews 30 of them.
- At the September monthly check, the quality sample turns up a Zapier automation sending review requests that nobody remembers approving. It was set up by an engineer who has since left. It goes on the register with a named owner, and their old account is removed.
Total time: about 30 minutes a month for the check, and perhaps an hour a month of approvals. That's the whole cost of governance at this size.
Where outside rules come in
Most small firms need no formal framework, but three outside factors are worth building in:
- If you sell to customers in the EU, Article 4 of the EU AI Act has required AI literacy measures since 2 February 2025. Since the Digital Omnibus on AI came into force on 27 July 2026, the duty is to take reasonable steps to build staff AI literacy; you no longer have to guarantee that everyone reaches a particular standard. Giving the AI lead responsibility for that training fits naturally here. Transparency duties for chatbots also remain.
- Data protection: the decision table should name who answers "can this data go into this tool?", and when that person asks your data-protection adviser.
- ISO/IEC 42001, the AI management systems standard published in December 2023, is what larger organisations certify against. A small firm doesn't need certification, but its core ideas (assigned roles, a register, regular review) are what this tutorial scales down.
Signs your governance is too heavy, or too light
Too heavy: requests wait more than two weeks; staff say "it's easier to just use my own account"; the monthly check keeps getting cancelled because it takes too long. Loosen the green tier and raise the AI lead's spending limit.
Here's how "too heavy" tends to show up. Imagine a six-person marketing agency whose owner, after a scare, ruled that every AI use needed her personal approval. Six weeks later, eleven requests were sitting unanswered in her inbox, the oldest a month old. The first monthly check that actually happened found two designers generating images on personal accounts, with client logos uploaded to both. The rule meant to reduce risk had moved the risky work somewhere nobody could see it. The fix was a published green list (drafting, rewording, summarising internal notes in the business account), approval for the rest by the account director within five days, and the owner kept only the red tier.
Too light: nobody can list every AI tool in use; an AI bill surprises you; something customer-facing changed without the owner knowing; a leaver still has access to an AI account three months on. Fill in the register first, then restart the monthly check.
Questions about running AI governance in a small team
Do we need an AI committee?
Not below about 50 people. A committee in a small firm usually means decisions wait for a meeting that keeps getting moved. Named individuals with clear limits work better: the owner decides, the AI lead approves within agreed thresholds, and someone else checks monthly. If a decision is big enough to need several views, the owner can ask for them without a standing committee.
Can our IT support company be the AI lead?
They can handle the technical side: setting up accounts, connecting tools, removing access when people leave. But the AI lead also judges whether a use makes business sense and fits your rules, which needs someone inside the business. A good split is an internal AI lead who approves, with the IT provider consulted on security and doing the account changes.
How is AI governance different from an AI usage policy?
The policy tells staff what they may and may not do with AI. Governance decides who writes and changes that policy, who approves the exceptions, and who checks it's being followed. You need both, but governance comes first: a policy without an owner goes out of date within months and nobody notices.
Further reads
- How to Write an AI Usage Policy for Your Small Business — The staff-facing rules this structure keeps current.
- A Simple AI Risk Register for Small Businesses (With Template) — The risk list your monthly check should review.
- How to Set Up Human Review for AI Work Without Slowing Down — Day-to-day checking of AI output, below governance level.
- Automation Audit: Find the Zaps and Scenarios Nobody Owns — Find automations nobody approved or owns.
- How to Choose and Support an AI Champion in a Small Team — Picking the person who'll act as AI lead.
- AI Compliance Checklist for Small Businesses: What Applies to You — Which outside rules apply to your AI use.
- What an AI Consultant Can't Do for You, and What You Must Own — Seven responsibilities that stay with the business when you hire AI help, an ownership card for every automation, and promises no consultant should make.
- How to Scale AI From One Workflow to the Whole Business — How to copy your first working AI workflow across the business: a readiness gate, a playbook template, adjacency rules and a pet shop's nine months.
- AI Ethics for Small Businesses: A Practical Checklist — Twenty-five questions in six groups, each with why it matters and how to check, plus red lines and a nursery example run end to end.
- AI Literacy Requirements: What Your Staff Need to Know — A role-by-role checklist of what staff should know about AI, what Article 4 of the EU AI Act asks since the 2026 changes, and how to record it.
- AI Adoption Stages: Where Is Your Business Now, and What's Next? — Place your business on a five-stage AI adoption scale with a ten-question check, then see the one move that gets you to the next stage.
- Does a Five-Person Business Really Need an AI Policy? — Why a five-person business needs a one-page AI policy rather than a handbook: six triggers, a complete template, and when one page stops being enough.
- AI Governance Checklist for Small Financial Advice Firms — Eight groups of checks, each with the evidence to keep, so a small advice firm can show how AI is approved, supervised and recorded.
- How Property Managers Use AI to Screen Tenant Applications Fairly — Written criteria, one summary format for every applicant, human decisions with recorded reasons, and a monthly check that your rules aren't quietly unfair.
- Charity AI Risks: Data Protection, Deepfakes, and Donor Trust — Three risk areas for charities using AI, with real cases, the controls that work for a small team, and a filled-in one-page risk register.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: EU AI Act Article 4 as amended by the Digital Omnibus on AI; ISO/IEC 42001 (AI management systems, published December 2023). Business examples are illustrative.