Loading Your Rhythm

Ostina helps practical teams reduce repetitive admin pressure and build steady progress with clear human control.

Search Ostina
Contact Ostina
Email ai@ostina.ai
Service area United Kingdom
Follow Us
Search Ostina
Contact Ostina
Email ai@ostina.ai
Service area United Kingdom
Follow Us

AI Governance Checklist for UK SMEs

UK SME leaders reviewing a practical AI governance checklist

Ten practical controls before you automate

Spencer Hudson
Authored by
Spencer Hudson
Updated
13 August 2026
Category
Responsible AI

AI governance for a UK SME is the practical system used to decide which AI uses are allowed, who owns them, what information they can access, which decisions remain human, how results are checked and what happens when something goes wrong. A workable baseline needs ten controls: inventory, ownership, purpose, information boundaries, human decisions, transparency, supplier checks, security, incident handling and review.

The aim is not to build a large compliance department or stop staff using useful tools. It is to give people safe boundaries, clearer ownership and a reliable route to question, correct or pause a system. This checklist is operational guidance rather than legal advice. The right controls depend on the workflow, information, affected people, sector and potential impact.

Why AI governance matters for UK SMEs now

The detailed results of the UK Business Data Survey 2026 reported that 17% of businesses using AI had a formal policy, informal policy or guidance: 5% formal and 12% informal. Among the same AI-using businesses, 21% said their tools were integrated into existing systems. Separately, the Cyber Security Breaches Survey 2025–26 found that 24% of businesses using, adopting or considering AI had cyber-security practices or processes for AI risk.

These surveys use different samples and questions, so their percentages should not be combined. They do show why an SME needs more than an approved-tools list. Once AI can read an inbox, update a CRM, draft a quotation or trigger a follow-up, its information, permissions, decisions and exceptions become part of the business workflow.

Start with ownership, not software

Give the overall framework to a senior accountable person who can set boundaries and commit time. Give every individual AI use an operational owner who understands the work. In a smaller business the same person may hold both roles, but the responsibilities still need to be written down. A supplier can help implement controls; it cannot take away the organisation's responsibility for customers, staff, information or decisions.

RoleMinimum responsibilityUseful evidence
Accountable leadApproves risk appetite, higher-impact uses, resources and stop decisions.Named role, approval record and review calendar.
Workflow ownerDefines the purpose, rules, exceptions, quality checks and day-to-day escalation.Use-register entry, test record and issue log.
Information or system ownerConfirms permitted data, access, retention, connections, recovery and supplier controls.Information map, permissions review and supplier record.
Users and affected staffTest real cases, report problems and help improve the manual and AI-assisted routes.Consultation notes, training record and feedback actions.

Acas guidance on consulting employees explains that involving people in workplace changes can identify problems and improve decisions. For AI projects, the people doing the work often know the exceptions, customer sensitivities and informal workarounds that a system map misses.

Screen the risk before choosing the controls

Do not classify risk from the tool name alone. Assess the purpose, information, action and possible effect. A general writing tool used with public information is different from the same tool connected to customer records and allowed to send messages. The levels below are an Ostina planning aid, not a legal classification.

Illustrative levelTypical useControl response
Lower impactInternal brainstorming using public or non-confidential information, with no external action.Approved tool, user guidance, human review and a clear information boundary.
Moderate impactDrafting routine customer replies from approved knowledge or routing enquiries.Named owner, supplier and data checks, quality tests, approval rules, logging, fallback and escalation.
Higher impactWork affecting employment, finance, safety, rights, vulnerable people or regulated professional judgement.Specialist assessment, stronger human responsibility, documented testing and monitoring, with legal or sector advice where needed.

Treat a use as needing further review if people could be materially harmed, misled, denied an opportunity or unable to reach a responsible person. Where personal-data processing is likely to create high risk, the ICO says a data protection impact assessment should be completed before the processing begins. Make the decision case by case and obtain qualified advice when the risk or obligation is unclear.

The ten-control AI governance checklist

1. Keep an AI use inventory

Record every approved, trial and discovered AI use, including features embedded inside software the business already owns. Cover the system, purpose, users, supplier, information, connected systems, outputs, actions and current status. Speak with staff rather than relying on invoices: informal use is often where unknown data and quality risks sit. Minimum evidence: one current register with an owner and next review date for every entry.

2. Name an accountable business owner

The owner must be able to approve the purpose, resolve questions, arrange training, accept or reject residual risk and pause the use. “IT owns it” is not enough when the outcome affects sales, service, finance or employees. Minimum evidence: a named role, approval date, escalation route and deputy or continuity arrangement.

3. Define permitted and prohibited purposes

Write a narrow description of what the AI may do, for whom and using which sources. Then write explicit exclusions. “Help with admin” is too broad; “draft an acknowledgement for new website enquiries using approved service information, for sales review before sending” is testable. Minimum evidence: purpose, users, inputs, outputs, allowed actions, excluded actions and success measure.

4. Set information boundaries

Define which personal, employee, customer, commercial, confidential and special-category information may be entered, retrieved, stored or shared. Identify the source owner, lawful use, retention and deletion route. Do not assume a paid product automatically makes every input appropriate. Minimum evidence: an information map joined to the use-register entry, plus a simple “allowed, restricted, prohibited” rule for users.

5. Protect human decisions and intervention

Name the decisions a person retains, the evidence they see, the time they have and the authority to change the result. Approval must be meaningful rather than a rushed click. Pricing, contractual promises, complaints, safeguarding, employment, credit, safety and professional judgement often need stronger controls. Minimum evidence: an approval matrix with named roles, escalation thresholds and a tested manual route.

6. Be transparent with staff and customers

Explain AI use when it materially affects an interaction, decision or personal-data process. Tell people the purpose, the important information used, how a person can help and where relevant how to question an outcome. The ICO's AI transparency guidance provides fuller data-protection considerations. Minimum evidence: approved notices, channel wording and a working human-contact route.

7. Check suppliers and connected systems

Understand where information goes, who can access it, whether inputs or outputs are used for training, how long records remain, which subprocessors are involved, how incidents and changes are communicated, and how the business exits. Map every connection and permission, not just the visible interface. Minimum evidence: supplier review, contract and privacy links, connection list, change owner and exit plan.

8. Control access and security

Use named accounts, appropriate authentication, minimum necessary permissions and prompt removal when roles change. Protect prompts, knowledge, logs and connected credentials as business assets. The NCSC secure AI development guidance emphasises secure supply chains, asset tracking, controlled access and protected logs. Minimum evidence: permissions review, technical owner, recovery test and security-event route.

9. Log outcomes, corrections and incidents

Keep enough evidence to reconstruct important actions without retaining unnecessary information. Record failed handoffs, misleading outputs, unauthorised access, repeated corrections, customer complaints and unexpected behaviour. Set severity and notification rules before an incident. Minimum evidence: issue register, response owner, containment steps, communication route and post-incident action record.

10. Review, train and improve

Set a scheduled review and event triggers. Reassess when the purpose, data, model, supplier terms, connections, user group, observed behaviour or affected people change. Train staff on the approved use, information rules, checks, escalation and stop route. Minimum evidence: dated reviews, change log, current training record and an explicit continue, change, pause or retire decision.

SME colleagues recording approved AI uses and accountable owners
Human review and escalation for an AI-assisted business decision

Build a minimum AI governance pack

RecordWhat it should answerReview trigger
AI policyWhich tools, information and purposes are approved or prohibited? What must people check and report?New tool, material legal or policy change, or recurring misuse.
AI use registerWhat is in use, why, by whom, with which data, supplier, connection, owner and review date?New or changed use, connection, model, supplier or user group.
Risk and impact recordWho could be affected, what could go wrong, what controls apply and what residual risk remains?New impact, incident, complaint, scope increase or unexpected behaviour.
Supplier and system recordWhere does data go, what access exists, how are changes handled and how can the business exit?Term, subprocessor, feature, retention, integration or security change.
Test and approval recordWhich normal, unusual, sensitive and failure cases were tested, by whom, with what result?Knowledge, rule, model, workflow or acceptable-quality change.
Incident and change logWhat happened, who contained it, who was informed, what changed and was the use reapproved?Every material issue, correction trend or governance change.

Keep these records short enough to use and detailed enough to demonstrate the decision. Link them instead of duplicating information. For example, a use-register entry can point to the supplier review, impact assessment and test record. The result is a small evidence trail that grows only when the risk grows.

Use a consistent AI use-register template

FieldQuestion to answer
Use and outcomeWhat exact workflow problem is being addressed and how will a useful result be measured?
Owner and usersWho is accountable, who operates it, who reviews it and who can pause it?
InformationWhich sources and categories are allowed, restricted or prohibited, and who owns them?
Supplier and connectionsWhich product, model, subprocessors, systems, permissions and credentials are involved?
Outputs and actionsWhat can it draft, recommend, update, send or trigger, and which actions require approval?
Affected peopleWhich staff, customers or other people could benefit, be inconvenienced or be harmed?
Controls and fallbackWhat tests, review, logging, escalation, manual route and stop condition apply?
Status and datesIs it proposed, testing, live, paused or retired; when was it approved and when is review due?

Make human oversight specific

“Human in the loop” is not a control until the business defines who acts, when and with what authority. Use an approval matrix that a busy team can follow.

ActionPossible ruleEvidence
Internal draftUser checks source, accuracy, tone and confidentiality before relying on it.Guidance and sample quality review.
Routine external messageNamed reviewer approves until performance and exceptions support a documented change.Approval log, correction rate and exception review.
Price, promise or complaintEscalate to an authorised person; do not invent or commit.Escalation record and final accountable decision.
Sensitive or high-impact caseStop the AI route and use the specialist human process.Case record, specialist review and any incident action.

Prepare for failure and incident response

A useful incident plan answers six questions: how the issue is detected, who can contain or pause it, how essential work continues, which records are preserved, who must be informed and who approves restart. More capable connected systems deserve tighter limits because they can take actions across several services. The NCSC's 2026 guidance on thinking carefully before adopting more autonomous connected AI recommends clear human accountability, least privilege, monitoring, containment and planning for failure. If the business cannot understand, monitor and contain the actions, it is not ready to hand them over.

  1. Contain. Pause the workflow, revoke or reduce access and switch to the manual route.
  2. Assess. Identify affected records, people, systems, outputs and time period.
  3. Communicate. Follow contractual, legal, regulatory and customer communication routes where applicable.
  4. Correct. Fix the immediate problem, reconcile missed or duplicated work and support affected people.
  5. Learn. Record the cause, control changes, new tests, owner and reapproval decision.

Worked example: shared-inbox reply drafting

A service business wants AI to classify new shared-inbox messages and draft replies from approved knowledge. It will not send messages, agree prices or handle complaints automatically. The governance record could look like this:

ControlPractical decision
PurposeClassify routine new enquiries and prepare a draft for an employee to review.
InformationUse the message and approved service knowledge; restrict sensitive attachments and existing support cases.
Human decisionA sales administrator checks recipient, intent, facts, tone and commitments before sending.
EscalationComplaints, unusual pricing, legal language, vulnerability, urgency and uncertain classification go to named owners.
TestingTest routine, ambiguous, duplicate, malicious, sensitive and missing-information messages before live use.
MeasurementTrack time to useful draft, correction rate, incorrect routing, escalations, complaints and staff feedback.
FallbackStaff continue from the shared inbox if the AI route is paused; missed and duplicate items are reconciled.

This is a bounded assisted workflow, not a promise that every inbox is low risk. The shared-inbox AI guide covers the operational design, while the AI readiness checklist tests the wider foundations before a pilot.

Align the framework with current UK guidance

The UK government's current AI Management Essentials guidance describes a voluntary organisational self-assessment intended primarily for SMEs and startups. It covers internal processes, managing risks and communication. The government presents it as accessible baseline good practice, not product certification or a replacement for the standards that inform it.

The ICO's AI accountability guidance focuses on demonstrating compliance, assigning responsibility, assessing risk and using impact assessment where required. The ICO currently marks parts of its AI guidance as under review following legal change, so check the latest version before a material decision. NCSC guidance adds security, supply-chain, access, logging and incident considerations. Use these sources together and apply them to the actual workflow.

Frequently asked questions

Does a UK small business legally need an AI policy?

There is no single general rule that gives every business the same document requirement for every AI use. Existing data-protection, employment, equality, consumer, contractual, safety, professional and sector duties may apply. A clear policy is a practical way to communicate approved use and responsibility, but it does not replace a use-specific assessment or qualified advice.

Who should be responsible for AI governance in an SME?

A senior person should own the overall framework and risk decisions. Every AI-assisted workflow should also have an operational owner who understands its purpose, information, exceptions, checks and performance. Suppliers can support delivery, but the business retains accountability for its use and outcomes.

Should ChatGPT, Copilot and embedded AI features go in the inventory?

Yes. Include standalone tools, free trials, paid accounts and AI features inside CRM, email, finance, marketing or productivity software. Record the actual business use rather than only the product name, because one product may support several workflows with different information and risk.

Does every AI output need human approval?

Not necessarily. The control should match the impact, evidence and reliability. High-impact, unusual or externally consequential work needs stronger human checking. A lower-risk routine action may later use sampling or exception review, but only after testing, monitoring, escalation and stop rules are documented.

When does an AI project need a DPIA?

Complete a DPIA before personal-data processing that is likely to result in high risk to people. AI can be one high-risk indicator, but the answer depends on the purpose, data, scale, monitoring, decisions and effects. Document the screening decision and consult current ICO guidance or qualified advice where uncertain.

How often should an AI use be reviewed?

Set a proportionate scheduled review and review sooner when the purpose, data, supplier, model, terms, connection, user group, observed behaviour or customer impact changes. A material incident, repeated correction or complaint trend should also trigger review rather than waiting for the calendar.

Sources and further reading

The practical next step

Create a one-page inventory of every AI use your team knows about. For each one, name the purpose, owner, information, actions, human decision, current status and next review date. Then use the AI readiness checklist for small businesses to test one workflow's wider foundations. Ostina's AI governance and control services and AI readiness assessment can turn the findings into proportionate controls, a controlled pilot and an evidence-led improvement plan.

Want help applying this in your business?

Business team planning next steps