Skip to main content
Change Management9 min read

An AI Governance Framework for a Small Business

September 10, 2026By Ajan Kanagalingam

California signed two bills on September 9 creating a state registry of AI auditors and a framework for independent organisations to verify AI systems. Nothing in it obliges a Canadian business to do anything, and the main programme is voluntary with criteria not due until 2028. What it signals is that third-party AI assurance is becoming a market, and markets like that reach small firms through customer contracts long before they arrive through law.

When you actually need this

Three conditions together. Staff are using AI on work involving customer or employee data. More than two or three people are doing it. And you would struggle to answer a client who asked which tools hold their information.

Below that, an approved-tools list and a review habit are enough, and writing a governance document instead is theatre. Above it, the trigger is nearly always external. A client sends a security questionnaire, an insurer adds an AI section to the renewal, or a tender asks how you manage AI risk. Businesses that write this after the questionnaire arrives write it badly and in a hurry.

The five components

ComponentWhat it answers
InventoryWhich AI tools are in use, on what tier, owned by whom
Data rulesWhat may go into which tool, by data class
Review ruleWhen a person must check output before it leaves
OwnerWho decides, and who decides when they are away
Review dateWhen you look at all of the above again

The inventory is the foundation, and it is dull enough that most businesses never build it. Ask the team, without blame, which AI tools they use for work. Record the tool, the tier, who owns the account, and whether the terms of that tier exclude your inputs from training. Free tiers frequently do not, which we covered in free AI tools and what they cost your business.

Data rules work best as three tiers rather than a legal taxonomy. Public information goes anywhere. Internal information goes into approved business-tier tools only. Customer, employee, financial and anything under a confidentiality clause goes into a named short list, or nowhere. Staff can apply that without training.

The review rule should key off consequence rather than volume. Anything that reaches a customer, moves money, forms part of a contract, or makes a decision about a person gets a human check before it leaves. Internal drafts and research do not. Rules based on how much AI was used are unenforceable, because nobody can measure that and everyone will guess differently.

The owner is a name, not a committee, with a deputy for when they are on holiday. Governance without a named person is a document, and documents do not make decisions on a Friday afternoon.

The review date is six months out, in the calendar, with the inventory attached. Most of what changes between reviews is the inventory, because staff adopt tools faster than policies get updated.

What to leave out

Principles nobody can apply. Commitments to fairness, transparency and human-centred AI read well in a tender and change no behaviour on a Tuesday. If a line does not tell someone what to do differently, it belongs in marketing rather than in the framework.

A risk register with impact and likelihood scores. These need maintenance you will not do, and an unmaintained register is worse than none because it looks like control. Keep a short list of the three things that would actually hurt.

Model-level controls you do not operate. Bias testing, red-teaming and evaluation regimes belong to whoever builds the model. Your governance covers how you use it, which is the part you control.

A committee. Four people who meet quarterly will not decide anything a named owner could not decide in a day.

Where the standards fit

ISO 42001 and the NIST AI Risk Management Framework are credible and built for organisations with compliance capacity. Adopt one when a customer, regulator or insurer asks, because then it is a sales asset. Adopt one speculatively and it is an expensive distraction that produces documents nobody reads.

The practical move is to make the five decisions in a shape that would map onto a standard later. An inventory, data classification, review rule, named owner and review cadence are the first things any auditor asks for, so the one-page version is a genuine head start rather than throwaway work. Businesses in regulated sectors face a different calculation, covered in AI governance in regulated industries.

The agent problem

Governance written for staff using a chat assistant does not cover software acting on its own. When an agent has an account in your systems, three more questions appear: which account it uses, what that account can reach, and what it may not complete without approval. Those are access decisions rather than policy statements, and we set them out in three boxes for an AI agent.

Add them to the framework when you deploy your first agent rather than at the next review, because agents tend to arrive between reviews and the gap is where ungoverned deployments accumulate.

Start with the inventory

Ask your team this week which AI tools they use for work, and promise in advance that nobody is in trouble. That list is 80 percent of the value and it takes an hour. Everything else is four short decisions written underneath it.

Our AI policy generator produces a usable draft in a few minutes, and whether your business needs an AI policy covers the threshold question in more detail.

Frequently Asked Questions

What is an AI governance framework?

A written set of decisions about how your organisation uses AI: which tools are approved, what data may go into them, when a person must review output, who owns the decisions, and how often you revisit all of it. Published frameworks from standards bodies are thorough and assume a risk committee, a compliance function and a dedicated owner. A business under 50 people needs the same five decisions recorded on one page.

Does a small business need AI governance?

You need it when three conditions are met: staff are using AI on work that involves customer or employee data, more than a couple of people are doing it, and you would struggle to answer a client asking which tools hold their information. Below that threshold, an approved-tools list and a review rule cover it. The trigger is usually external rather than internal, in the form of a client security questionnaire or an insurer’s renewal form.

What should an AI policy actually contain?

Five things. An inventory of the AI tools in use and who owns each. A data classification saying what may and may not be put into which tier of tool. A review rule tied to consequence rather than to volume, so that anything customer-facing, financial or contractual gets a human check. A named owner with a deputy. And a review date. Principles about being responsible and transparent read well and change no behaviour.

Do I need to follow ISO 42001 or the NIST AI framework?

Only if a customer, regulator or insurer asks for it. Both are credible and both are built for organisations with dedicated compliance capacity. For most small businesses the sensible path is to make the five decisions in a way that would map onto those frameworks later, then adopt one properly if a contract requires it. Certification is a sales asset when buyers ask for it and an expensive distraction when they do not.

Will AI audits become mandatory?

The direction of travel points that way, though nothing currently obliges a Canadian small business to be audited. California signed SB 813 and AB 1405 on September 9, 2026, creating a state registry of AI auditors and a framework for independent verification organisations, with qualification criteria due from its Government Operations Agency by 2028. Notably the SB 813 programme is voluntary. What that builds is a market for third-party AI assurance, which typically reaches smaller firms through customer contracts well before it arrives through law.

One page, written before you need it

We run the tool discovery, draft the framework your team can actually follow, and make sure it maps onto a recognised standard if a customer asks later.

Related Articles

Change Management

The CIO's Playbook: Making the Business Case for AI in Legacy ERP Systems

Feb 10, 2026Read more →
Change Management

Employee Monitoring With AI: Rules Before Tools

September 9, 2026Read more →
Data & Analytics

AI Bias in a Small Business: Where It Shows Up

August 31, 2026Read more →
AK
Ajan Kanagalingam
Founder & ChatGPT Consultant, ChatGPT.ca

Ajan leads the ChatGPT.ca team: 200+ custom GPT builds and automation projects for 50+ businesses across 20+ industries. Based in Markham, Ontario. PIPEDA-compliant solutions.

Stay ahead of AI in Canada

Weekly case studies, new tools, and ROI playbooks for Canadian SMEs. One email, zero spam.