Practical guide
The Small Business AI Governance Checklist: 20 Things to Do Before Your Team Uses AI
A 20-point checklist covering the essential governance steps every small business should complete before allowing employees to use AI tools — policy, tools, training, and vendor review.
Key takeaways
- A small business AI governance checklist spans five areas: policy and documentation, tools and access, data and privacy, output and review, and training and incidents.
- The 20 essential steps include a written policy with a named owner, a short approved tool list, defined data input rules, reviewed vendor terms, a human review checkpoint for customer-facing output, basic staff training, and an incident log.
- Score yourself out of 20; below 14 signals meaningful gaps. Start with the policy and data sections — highest impact per hour.
- You do not need every box checked before day one, but each unchecked box is a gap in your exposure.
- The two highest-leverage first moves: write a one-page policy, and tell employees never to paste credentials or customer PII into AI tools.
AI governance sounds like a large-enterprise concern. It is not. A small business where every employee uses AI tools daily has as much exposure as a large one — often more, because there are fewer formal processes to catch errors.
This checklist covers the 20 steps that make AI use in a small business controlled, documented, and recoverable when something goes wrong. You do not need to complete every item before day one — but each unchecked box is a gap.
Policy and documentation
- [ ] Written AI usage policy exists. A document that tells employees which tools are approved, what data may not be entered, and who to contact with questions. One page is enough.
- [ ] Policy reviewed by at least one manager in a customer-facing or technical role.
- [ ] Policy distributed to all employees and acknowledged (email, onboarding form, or Slack message with a read receipt is sufficient).
- [ ] Policy has an owner and a review date. Someone is responsible for updating it annually (or when a major AI tool changes significantly).
- [ ] CHANGELOG or equivalent records when the policy was last updated and what changed.
Tools and access
- [ ] Approved tool list exists. A short list of AI tools employees may use for work, maintained somewhere employees can find it.
- [ ] Unapproved tool request process exists. Employees know how to request approval for a new tool (even if the answer is just "email [name]").
- [ ] Work AI accounts are separate from personal accounts. Employees using personal AI accounts for work tasks is a gap — work data may be subject to different retention/training settings.
- [ ] Account settings reviewed. For each approved AI tool, the data-sharing and training settings have been reviewed and configured appropriately.
Data and privacy
- [ ] Data input rules are defined. Employees know what they may and may not paste into AI tools. The rule does not have to be complex — "no credentials, no customer PII, no internal financial data" is a complete starting point.
- [ ] Vendor data-processing terms have been reviewed. For each approved AI tool that processes business or customer data, you have read the terms and know what the provider does with your data.
- [ ] No credentials in AI tools. Employees have been explicitly told that passwords, API keys, and access tokens must never be pasted into AI chat interfaces.
Output and review
- [ ] Customer-facing output is reviewed before use. Any AI-generated text sent to a customer is reviewed by a human first.
- [ ] Published content is reviewed before publication. Any AI-generated content published on your website, social media, or marketing channels is checked for accuracy and appropriateness.
- [ ] Factual claims in AI output are verified. Employees understand that AI can produce confident-sounding errors, and know to check facts against real sources.
Training and awareness
- [ ] Employees have received basic AI awareness training. Even a 15-minute briefing covering the approved tools, data rules, and output review expectation is better than nothing.
- [ ] Employees know how to escalate. There is a named person (owner, operations, IT) employees can ask when they are not sure whether a use case is safe.
- [ ] New employees receive AI policy in onboarding. The policy is part of the standard onboarding pack.
Incidents and review
- [ ] Incident log exists. When something goes wrong with an AI tool — data pasted that should not have been, a wrong output acted on — it is recorded. This does not need to be formal.
- [ ] Annual review scheduled. A recurring calendar event exists to review the tool list, data rules, and policy once a year.
How to use this checklist
Score yourself: count how many boxes are checked. Any score below 14/20 suggests meaningful gaps. Focus first on the policy and data sections — they have the highest impact per hour of effort.
Each section here has a longer treatment elsewhere on this site: how to write an AI usage policy for the documentation items, ChatGPT rules for employees for the tools-and-access tier model, 7 prompt safety tips for the data and privacy habits, and AI risk management for small businesses for deciding how tight each control needs to be.
The AI Risk Checklist on this site assesses a specific AI use case and returns a risk rating with tailored safeguards. For a full governance package — including a pre-filled version of this checklist, tool approval template, incident log, and employee guidance — see the Starter Pack.