An AI governance framework for UK SMEs: what to put in place before your team uses AI at work

    For a UK company of 50 to 500 people, the right AI governance framework is proportionate and risk-tiered. Build it on the five cross-sector principles from the UK government's 2023 white paper A pro-innovation approach to AI regulation (safety, security and robustness; appropriate transparency and explainability; fairness; accountability and governance; contestability and redress), and organise the work using the four functions of the NIST AI Risk Management Framework: Govern, Map, Measure and Manage. That gives you a one-page acceptable-use policy, three risk tiers that say what needs sign-off, clear data rules, and a named executive who owns it. If a client, regulator or tender later asks for certification, ISO/IEC 42001 is the route, and a framework built this way maps onto it without starting again.

    The UK has no single AI law. The white paper asked existing regulators (the ICO, FCA, CMA, Ofcom and others) to apply the five principles within their own remits, so what applies to you depends on your sector and, above all, on data protection law. For a mid-sized company the job is not to build a compliance department; it is to make a small number of sensible decisions and write them down.

    What does "proportionate" mean for a 50–500 person company?

    It means the controls match the risk. A marketing team drafting blog posts in ChatGPT needs a short policy and a data rule. A finance team feeding customer records into an automation needs a Data Protection Impact Assessment (DPIA), a named owner and a review of outputs. Same company, different tiers.

    Three tests: could you explain the whole framework to a new starter in 15 minutes? Does every rule have a named person who would notice if it were broken? Can someone try a tool on a low-risk task this week without asking? If not, people will do it anyway and you will not know.

    How do the five UK principles turn into controls we can actually run?

    The five principles are written for regulators, not for a 120-person logistics firm. The table below is how we translate them in Align workshops. Every control in the right-hand column can be run by a mid-sized company with no dedicated compliance team.

    UK AI principles and practical controls
    UK principleWhat it means in practiceControls a 50–500 person company can put in place
    Safety, security and robustness (the white paper's wording)AI outputs should not cause harm, and the tools you use should be secureApproved-tools list (business licences only, personal accounts banned for work data); SSO and MFA on every AI account; human review before any AI output goes to a customer, regulator or the public; a simple incident route ("if an AI tool does something wrong, tell X")
    Appropriate transparency and explainabilityPeople should know when AI is involved and be able to understand material decisionsDisclose AI use where it affects a customer or employee decision; keep the prompt and output for anything used in a decision record; do not use AI as the sole decider for recruitment, credit, disciplinary or pricing outcomes
    FairnessAI should not produce discriminatory or unlawful outcomesList the "people decisions" where AI is prohibited or advisory only; check outputs on a sample for bias where the subject is a person; Equality Act 2010 duties still apply to the human who signs off
    Accountability and governanceSomeone is responsible, and there is a processA named accountable executive; an AI lead who runs the register; a one-page policy everyone has read; a use-case register reviewed quarterly
    Contestability and redressPeople affected by an AI-assisted decision can challenge itTell customers and staff how to ask for a human review; log challenges; make sure a person can reverse the decision

    Most of these controls already exist in some form in your information security, HR and data protection processes; AI governance extends them rather than duplicating them. None of it requires governance software. A shared spreadsheet and a calendar reminder will do for the first year.

    How do the NIST functions fit in?

    NIST AI RMF 1.0 (January 2023) is voluntary and sector-neutral, and it is the framework most UK consultants and auditors use to structure the work. Its four functions give you the operating rhythm:

    • Govern: the policy, the roles, the culture. Done once, reviewed yearly.
    • Map: for each use case, write down what the AI does, who it affects and what could go wrong. Done when a use case is added to the register.
    • Measure: check outputs. Accuracy on a sample, time saved, error rate, complaints. Done monthly for higher tiers.
    • Manage: act on what you measured. Withdraw, restrict or expand the use case.

    NIST's Generative AI Profile (NIST AI 600-1, July 2024) lists risks specific to tools like ChatGPT and Copilot, including confabulation, data leakage through prompts and intellectual property. It is a useful, free checklist when you Map a new use case.

    Which AI uses need sign-off and which can people just try?

    This is the question that decides whether governance helps or strangles experimentation. The answer is tiers: the lower the tier, the fewer the steps, and most day-to-day use should sit in tier 1 and need nothing more than the policy.

    AI governance risk tiers
    TierTypical usesData allowedWho approvesControls
    1 – Experiment freelyDrafting internal notes, summarising public documents, rewriting your own emails, learning a tool, brainstorming, code snippets with no client dataPublic information and your own non-confidential workNobody, provided you use an approved toolRead the policy; keep a human in the loop; do not paste anything from the "never" list
    2 – Register and reviewCustomer-facing drafts (proposals, marketing copy, support replies), analysis of internal but non-personal data, meeting transcription with consent, automations that touch company systemsCompany-confidential data inside licensed business tools (for example Microsoft 365 Copilot within your tenant)Line manager, logged on the use-case register by the AI leadNamed owner; output reviewed before it leaves the company; monthly spot-check on a sample
    3 – Formal assessmentPersonal data at scale; anything affecting a decision about a person (recruitment, performance, credit, pricing, eligibility); anything regulated in your sector; customer-facing chatbots; AI in products you sellPersonal or special-category data only with a completed DPIA and lawful basisAccountable executive, with the data protection leadDPIA; vendor due diligence (where data goes, retention, training on your data); documented human review; disclosure to affected people; quarterly review
    ProhibitedThe "never" list in any tool; personal or free-tier accounts for work data; AI as sole decision-maker on a person's rights or employment; anything unlawful or against a client contractStated plainly in the policy, with a route to ask if unsure

    Most of what teams want to do sits in tiers 1 and 2. That is the point: experimentation is the default and sign-off is the exception, but the exceptions are the things that could hurt someone.

    What goes in a one-page acceptable-use policy?

    A policy nobody reads is worse than none, because it gives false comfort. Keep it to one side of A4 with these headings, two or three sentences under each.

    1. Why we use AI – one sentence on what the company wants from it, so the policy reads as permission, not prohibition.
    2. Approved tools – the named tools and accounts (for example "Microsoft 365 Copilot in the company tenant, ChatGPT Team, Claude for Work"). Anything else needs asking.
    3. What never goes into a prompt – the list from the next section, verbatim.
    4. You own the output – the person who uses an AI output is responsible for it, exactly as if they had written it. Check facts, check figures, check citations.
    5. Tell people when it matters – when AI has materially shaped something a customer, regulator or colleague will rely on, say so.
    6. People decisions – where AI is advisory only and a human decides and can explain why.
    7. When to ask first – the tier 3 list in plain words, and who to ask.
    8. If something goes wrong – who to tell, no blame for reporting.
    9. Owner and review date – the accountable executive's name and the date this will next be reviewed.

    Attach the tier table as page two if you want, but page one should stand alone.

    What should never go into an AI prompt?

    The same starting list works in most sectors. Adjust it with your data protection lead.

    • Personal data about customers, staff or the public, unless the tool is a licensed business tool inside your own environment and the use case is registered (tier 2) or assessed (tier 3).
    • Special-category data (health, ethnicity, religion, sexual orientation, trade union membership, biometrics, criminal records) unless a DPIA says so.
    • Passwords, API keys, access tokens, bank details, card numbers.
    • Unpublished financial results, M&A information, anything price-sensitive.
    • Client material covered by an NDA or a contract that restricts sub-processing.
    • Source code or documents you do not have rights to share.
    • Anything you would not want quoted in a newspaper with your company's name attached.

    When do you need a DPIA? Under UK GDPR, a DPIA is required before processing that is likely to result in a high risk to individuals. The ICO's guidance on AI and data protection says most uses of AI involving personal data will meet that bar, because AI typically involves new technology, large-scale processing or profiling. In practice: if the use case is tier 3, do a DPIA; if tier 2 involves personal data, use the ICO's DPIA screening checklist to decide. The ICO's AI and data protection risk toolkit is a sensible template for a first assessment.

    Two other ICO points. You need a lawful basis for any personal data you put through an AI tool, and "we bought a licence" is not one. And check what the vendor does with your prompts: business tiers of the main tools state that your data is not used to train their models; consumer and free tiers may differ. Read the data processing terms and record what you found.

    Who owns AI governance in a company this size?

    Not a committee. Three roles, all part-time, all named.

    The accountable executive. A director (often the COO, CFO or, in smaller firms, the MD). They sign the policy, approve tier 3 use cases and are the person the board asks. This is the accountability principle in the UK framework, the Govern function in NIST, and the first thing ISO/IEC 42001 auditors look for.

    The AI lead. The operational owner, usually from IT, operations or digital, with credibility with both leadership and users. They keep the approved-tools list and the use-case register, run the monthly spot-checks, triage questions and organise training. Half a day a week is a fair estimate for a 200-person company once things are running.

    Champions. One per team or function, chosen because they are already the person colleagues ask. They are not enforcers. They collect use cases, show what good looks like, spot tier 2 work that has quietly become tier 3, and feed back what the policy gets wrong. A 150-person company might have six to ten.

    If you have a DPO or data protection lead, they are consulted on tiers 2 and 3 but they should not be the AI lead. Governance owned by compliance alone becomes a list of no.

    How does governance fit into AI training?

    Most governance programmes fail for a boring reason: the policy is written by people who have never used the tools, and the training is delivered by people who have never read the policy. Day Seven runs governance through all four stages of its method rather than as a separate workstream.

    • Align. A leadership session in which the executive team agrees the tiers, the "never" list, the approved tools and the accountable owner. We leave with a signed one-page policy and a first use-case register.
    • Enable. Cohort workshops (around 16 people, on-site anywhere in the UK or live online) where the team builds with the approved tools on their own work. Every exercise is tiered and the "never" list is applied to examples from the room.
    • Prove. Pilots and sprints on registered use cases, with the Measure step built in. A tier 2 use case that ships with an accuracy check and a time-saved baseline is a governance artefact as well as a business result.
    • Embed. Champions take over the register, playbooks capture what worked, and the quarterly review becomes a habit.

    For how programmes are structured and priced, see the UK AI training overview and what AI training costs. The AI readiness scorecard includes a short governance section.

    How does ISO/IEC 42001 relate to all this?

    ISO/IEC 42001:2023, published in December 2023, is the international standard for an AI management system. It follows the same clause structure as ISO 27001 (context, leadership, planning, support, operation, performance evaluation, improvement), with an Annex A of AI-specific controls covering policy, roles, impact assessment, data, lifecycle and third-party AI. Organisations can be certified against it by an accredited body.

    For most 50–500 person companies it is not the starting point. It is the destination if you sell AI-enabled products, work in a regulated sector, or supply larger customers whose procurement teams are starting to ask for it. The framework on this page is aligned with 42001: the accountable executive is "leadership", the tier table and use-case register are "planning" and "operation", the monthly spot-checks are "performance evaluation", and the DPIA process covers the impact assessment control. Certifying later extends what you have rather than replacing it. See ISO/IEC 42001 training.

    FAQ

    What governance framework should we use for team AI use?

    Use the UK's five cross-sector principles as the "what" and NIST AI RMF's Govern, Map, Measure, Manage as the "how". Together they give a mid-sized company a policy, a use-case register, risk tiers and a review cycle. Add ISO/IEC 42001 only if you need certification.

    Do UK companies have to comply with any AI law?

    There is no single UK AI Act. Existing law applies: UK GDPR and the Data Protection Act 2018, the Equality Act 2010, consumer and sector rules. Regulators such as the ICO apply the five principles within their remits, so data protection is where most obligations bite.

    Does the EU AI Act affect a UK SME?

    It can, if you place AI systems on the EU market or their outputs are used there. Most UK SMEs using Copilot or ChatGPT internally are not directly caught, but check if you sell AI-enabled products or services into the EU.

    How can we prevent AI misuse while encouraging experimentation?

    Tier the risk. Make tier 1 explicitly permission-free and be precise about the short list that needs sign-off. People misuse tools when the rules are vague or when the approved route is slower than the personal account on their phone.

    Do we need a DPIA to use ChatGPT or Copilot?

    Not for tier 1 use with no personal data. If personal data goes in, use the ICO's screening checklist; if the use affects decisions about people or involves large-scale or special-category data, a DPIA is required before you start.

    Can staff use free AI tools for work?

    Not for anything beyond public information. Free and consumer tiers may use your inputs to train models and give you no contractual data processing terms. Buy business licences and put them on the approved-tools list.

    Who should own AI governance in a company of 200 people?

    A named director as accountable executive, an operational AI lead (half a day a week), and a champion in each team. Consult your data protection lead on anything involving personal data.

    How long should an AI policy be?

    One page: nine headings, two or three sentences each, with the tier table as an optional second page. If it cannot be read in five minutes it will not be read.

    Is ISO/IEC 42001 certification worth it for an SME?

    Only if a customer, regulator or market requires it, or if AI is central to what you sell. Otherwise, build a 42001-aligned framework now so certification is an extension rather than a rebuild.

    What should we do first, training or governance?

    Both, in the same week. Agree the policy and tiers in a leadership session, then teach them in the first cohort workshop. Policy without training is ignored; training without policy creates the risks the policy was meant to prevent.

    Next step

    If you want the policy, tiers and register set up in a single leadership session, followed by training that teaches them by doing, see consulting and ISO/IEC 42001 training, or

    Get a training proposal

    Tell us what your team needs. We'll get back to you within one working day.