AI Governance for a Small Organisation: Start with What Is Already in Use

Many organisations begin their AI discussion with a policy. A more useful first step is to find out where AI is already affecting work. Staff may use an assistant to draft text, summarise notes or search documents; a supplier may have added an AI feature to a system you already use. You cannot make a sensible decision about those uses until someone can describe them.

Make a small, usable inventory

List each use, its owner, the people who use it, the information it receives and the decision or output it influences. Record whether the tool is approved, being tested or awaiting review. Include agents and automated actions as well as chat tools. Ask teams about actual work, including informal experiments, rather than relying only on a list of paid subscriptions.

Keep this record proportional. A shared sheet can be enough for an initial review if it is owned and updated. The UK government’s AI Management Essentials material describes an AI system record as an inventory of documentation and resources related to AI systems; the aim here is a working record, not a claim of certification.

Choose one accountable owner per use

The owner should be able to explain why the use exists, what information enters the tool, who checks its output and when it should be stopped or changed. An IT administrator may manage access without owning the business decision. A team leader may own the workflow without knowing how the system is configured. Record both responsibilities.

Decide which risks need a treatment

For each use, note a plausible error or harm, its possible impact, and the control that would reduce it. Examples include a draft sent without review, confidential information entered into an unsuitable service, or a workflow taking action beyond its approved authority. Assign a person to test the control and a date to revisit it. Where a risk cannot be accepted, pause or narrow the use while the decision is made.

The government’s AI Risk Management Toolkit guidance includes ownership, assessment and treatment records. It is written for public-sector use, but the basic discipline of recording decisions can help other organisations too.

Keep a human review point where it matters

A person should review outputs that could affect a customer, an employee, money or access to a system. Define what the reviewer must check and what happens when the result is uncertain. Test a real sample and record what went wrong; “human in the loop” is only useful when the person has time, authority and information to intervene.

A first review can produce four things

  • A current list of AI uses and agents, including experiments.
  • Named business and technical owners.
  • A short risk register with decisions, controls and unresolved questions.
  • A date and trigger for the next review, such as a new data source or wider rollout.

This is a starting point, not an assurance verdict. Kilwhiss AI Assurance can help turn that first pass into a scoped readiness and governance plan. If the work also needs Microsoft 365 permissions review or a controlled workflow, the Group can route those parts to the relevant specialist.

← Back to Insights