A named person or group owns AI governance.
Accountability should be clear even in a small organization.
Answer 12 practical questions. Get a readiness score and a prioritized 90-day governance plan—without sending your answers anywhere.
Accountability should be clear even in a small organization.
The policy covers permitted tools, prohibited data and employee responsibilities.
Include free tools, embedded features, pilots and vendor-supplied AI.
This helps expose unclear ownership and unintended impacts.
Examples include personal, confidential, regulated and commercially sensitive data.
AI guidance should translate labels into simple handling rules.
Review training use, subprocessors, access controls, deletion and incident terms.
Prioritize decisions affecting people, money, access, safety or legal rights.
The reviewer should have authority and enough knowledge to challenge the output.
Training includes verification, privacy, bias, copyright and incident reporting.
Use an existing incident channel where possible.
Review sooner after a serious incident, new regulation or material model update.
See where informal AI use is creating avoidable governance, privacy and security risks.
Focus on the five improvements that matter most instead of starting with a large framework.
Use the downloadable plan with leadership, IT, security, HR, legal and operational teams.