AI Governance Checklist for Small Businesses
IT Club provides practical technology guidance, not legal advice. Laws, contractual obligations and regulatory requirements vary according to the organisation, sector, data, location and use case. Obtain appropriate legal, data-protection, employment or regulatory advice where required.
This checklist condenses the whole AI Governance hub into one working document. Use it when adopting a new tool, reviewing an existing one, or running the periodic review. Every question links back to a fuller guide in this hub — and the whole checklist is available as a downloadable PDF.
Purpose
- Is the use case defined?
- Is AI genuinely needed?
- Is an accountable owner assigned?
Information
- Has the data been classified?
- Is personal data involved?
- Is confidential information involved?
- Can placeholders or anonymous data be used?
Platform
- Is the tool approved?
- Have supplier terms been reviewed?
- Are data locations and subprocessors understood?
- Are training and retention settings understood?
People
- Are users trained?
- Are access rights appropriate?
- Are freelancers included?
Control
- Is human review defined?
- Are high-risk decisions excluded or escalated?
- Are outputs and sources checked?
Customers
- Is disclosure required?
- Do contracts and privacy information reflect the actual use?
- Could customer expectations be misleading?
Review
- Are incidents recorded?
- Is performance measured?
- Is the tool reviewed periodically?
This checklist supports internal governance. It is not legal advice or a substitute for professional review.
When something goes wrong
No control system prevents every incident — sensitive data pasted into the wrong tool, incorrect content sent to a customer, an invented source published, an unauthorised tool discovered. What distinguishes well-governed businesses is the response. Keep the downloadable AI Incident Record alongside this checklist, and follow a consistent sequence:
- 1Stop further use.
- 2Preserve proportionate evidence.
- 3Contain the exposure.
- 4Notify the responsible internal person.
- 5Assess affected information and people.
- 6Contact the supplier where needed.
- 7Obtain legal, data-protection, employment or insurance advice where appropriate.
- 8Correct customer-facing information.
- 9Record decisions.
- 10Review the control failure.
Whether a personal-data incident must be reported to the ICO or affected individuals depends on the specific circumstances and risk. Assess each case on its facts and take advice where the answer is not clear — this guide does not make breach-reporting decisions for you.
Plain-English Takeaway
Print the checklist, name an owner, and run it: at adoption for every new tool, and at each periodic review for the tools you already have. Governance that lives in a working document gets done; governance that lives in a policy folder does not.
Downloadable checklist
AI Governance Checklist for Small Businesses
The full checklist as a printable A4 PDF with tick boxes — purpose, information, platform, people, control, customers and review.
Download PDFSources and further reading
External guidance changes. Check the source itself for the current position before acting on it.