An AI governance framework is the set of owners, rules and checks a company uses to decide which AI tools and uses are allowed, who answers for each one, and how problems get caught. For a small or mid-size company it fits on one page with six parts: an owner, an inventory, risk tiers, a policy, controls and a review cycle. Below is that page as a template you can copy, a simple way to score risk, and a 90-day plan to get it running.
On this page
- What an AI governance framework is
- The six parts
- NIST AI RMF, EU AI Act or ISO 42001?
- How to score risk (worked example)
- The one-page template
- Who owns what
- The 90-day rollout plan
- Questions people ask
What is an AI governance framework?
It is how you answer four questions before something goes wrong. Which AI tools are we using? What are they allowed to touch? Who signs off on the risky uses? How would we find out if one went bad?
A policy is one part of it. The policy tells staff what they can and cannot do. The framework is the machinery around the policy: the person who owns it, the list of tools, the rules for sorting uses by risk, and the dates when someone checks. Companies that only have a policy tend to find out about new AI tools after the invoice arrives.
Most of the pages that rank for this term are written for enterprises with an ethics board and a model risk team. If you have 20 to 500 people, you need the same logic with far less paperwork. That is what this guide covers.
The six parts of an AI governance framework
1. An owner
One named person answers for AI use across the company. In a small firm that is often the COO, the head of operations or whoever runs IT. For high-risk uses, add a small sign-off group: the owner plus someone from legal or HR and the manager of the team that wants the tool. Three people is enough.
2. An inventory of AI tools and uses
A spreadsheet with one row per use, not per tool. ChatGPT for drafting marketing copy and ChatGPT for summarizing customer complaints are two rows, because the data and the risk differ. Record the tool, the team, what it is used for, what data goes in, who owns it and its risk tier.
3. Risk tiers
Three tiers are plenty: low, medium and high. The tier decides how much checking a use needs. The scoring method is further down.
4. A policy staff can read
One page that says which tools are approved, what data never goes into them, when a person must check the output and where to ask. Our generative AI policy template lays out the sections, and the free AI policy template gives you a full draft to edit.
5. Controls for each tier
What has to be true before a use goes live: approval, human review, logging, a check of the vendor's data terms. Low-risk uses need almost nothing. High-risk uses need all of it.
6. A review cycle
Check the inventory every quarter and the whole framework once a year, or sooner if the law or your tools change. Put the dates in a calendar now, or they will not happen.
NIST AI RMF, EU AI Act or ISO 42001: which do you need?
You will see three names come up again and again. They do different jobs, and you do not need to adopt all three to run a sound framework.
| Name | What it is | Binding? | When it matters to you |
|---|---|---|---|
| NIST AI Risk Management Framework | US guidance built around four functions: Govern, Map, Measure, Manage. Has a separate profile for generative AI. | No, voluntary | A good structure to borrow. US customers and investors often recognise it. |
| EU AI Act | EU law that sorts AI uses by risk, from banned to minimal. | Yes, if you sell into or operate in the EU | Whenever your AI use touches people in the EU, especially hiring, credit or education. |
| ISO/IEC 42001 | An international standard for running an AI management system. | No, voluntary | When large customers ask you to show a formal system in their security reviews. |
A few facts worth knowing. NIST released the AI RMF 1.0 in January 2023 for voluntary use, and says it is now being revised (NIST). Under the EU AI Act, banned practices and the AI literacy duty have applied since 2 February 2025. Rules for high-risk uses in sensitive areas such as recruitment now start on 2 December 2027, after the "AI Omnibus" agreement pushed the date back (European Commission). ISO/IEC 42001, published in 2023, sets requirements for setting up and improving an AI management system (ISO).
A practical line for a small company: use the NIST functions as your checklist, use the EU AI Act's risk categories to spot the uses that need the most care, and leave ISO 42001 until a customer asks for it. This is not legal advice. If you use AI in hiring or credit decisions in the EU, get a lawyer to look at your setup.
How to score risk: a worked example
Enterprise frameworks tend to leave risk scoring vague. Here is a method a manager can apply in two minutes. Score each use on three questions, from 0 to 2, then add them up.
| Question | 0 | 1 | 2 |
|---|---|---|---|
| What data goes in? | Public or none | Internal business data | Personal, customer or confidential client data |
| Who does the output affect? | Only the person using it | Customers or the public see it | It feeds a decision about a person (hiring, pay, credit, access) |
| How much does it act alone? | A person reads every output | A person spot-checks | It acts without a person checking (sends, books, pays, deletes) |
A total of 0 to 1 is low risk. 2 to 3 is medium. 4 to 6 is high. These examples use made-up but typical uses:
- Drafting a blog post from public research: data 0 + affects 1 + autonomy 0 = 1, low.
- Summarizing internal meeting notes: data 1 + affects 0 + autonomy 0 = 1, low.
- Drafting replies to customer complaints that an agent edits: data 2 + affects 1 + autonomy 0 = 3, medium.
- Sorting job applications before a recruiter sees them: data 2 + affects 2 + autonomy 1 = 5, high.
- An AI agent that sends follow-up emails to leads on its own: data 2 + affects 1 + autonomy 2 = 5, high.
That last line is where an agentic AI governance framework differs from one written for chatbots. The moment a tool can act without someone reading its output first, autonomy scores 2 and the use jumps a tier. Agents need a named owner, a spending or sending limit, and a log you can read.
Now match controls to tiers:
| Tier | Before it goes live | While it runs |
|---|---|---|
| Low | Approved tool, on the inventory | Normal policy applies |
| Medium | Owner approves; vendor data terms checked | A person checks output before it leaves the company |
| High | Sign-off group approves; test on real examples; write down what could go wrong | Human review of every decision about a person; logs kept; quarterly check of results |
The one-page AI governance framework template
Copy this into a document, fill in the brackets and you have a working framework.
AI GOVERNANCE FRAMEWORK: [Company name]
Version [1.0], approved [date] by [name, role]
1. OWNER
AI owner: [name, role]
High-risk sign-off group: [AI owner] + [legal/HR name] + [manager of the requesting team]
Questions go to: [channel or inbox], answered within [2] working days
2. INVENTORY
Kept at: [link to spreadsheet]
One row per use: tool | team | purpose | data that goes in | owner | tier | date approved
Anyone starting a new AI use adds a row before they start.
3. RISK TIERS
Score each use 0-2 on data, who it affects, and autonomy.
0-1 low | 2-3 medium | 4-6 high
4. POLICY
Staff policy: [link]. Approved tools: [list].
Never put into any AI tool: [customer personal data outside approved tools, passwords,
client confidential material, ...]
5. CONTROLS
Low: approved tool + inventory row
Medium: owner approval, vendor terms checked, human check before anything leaves the company
High: sign-off group approval, test run, human review of every decision about a person,
logs kept for [12] months
6. REVIEW
Inventory reviewed: every quarter ([dates])
Framework reviewed: every [12] months, or when law or tools change
Incidents: report to [channel] within [24] hours. No blame for reporting.
Keep the staff-facing policy separate from this page. Staff need the short rules. The framework is for the people who run it. Our AI acceptable use policy examples show strong and weak wording for the clauses that go in section 4.
Who owns what in a small company
Enterprise guides list ethics boards and model risk officers. Most companies under 500 people have none of those. This split works with the roles you already have.
| Task | AI owner | Team manager | Legal or HR | IT |
|---|---|---|---|---|
| Keep the inventory current | Owns | Adds rows | Flags new tools on company cards | |
| Score and approve medium-risk uses | Approves | Scores | ||
| Approve high-risk uses | Approves | Proposes | Approves | Checks vendor security |
| Write and update the policy | Owns | Gives feedback | Reviews | Reviews |
| Handle incidents | Owns | Reports | Advises | Contains |
The 90-day rollout plan
The top-ranking guides we read skip the timeline, so here is one. It assumes the AI owner spends a few hours a week on this.
- Days 1 to 15: Name the owner and the sign-off group. Send a short survey asking every team which AI tools they use and for what. Check company card statements for AI subscriptions.
- Days 16 to 30: Build the inventory from the survey. Score every use. Anything that scores high gets reviewed first, and paused if nobody can say what data goes in.
- Days 31 to 60: Write the one-page staff policy. Pick the approved tools, preferring business plans that let you control data use. Get the sign-off group to approve the high-risk uses or change them.
- Days 61 to 75: Launch the policy and run short team sessions with real examples. Our guide to rolling out a company AI policy has the launch email and training format.
- Days 76 to 90: Run the first review. Which questions came up most? Which tools did people ask for? Update the inventory, set the next quarterly date and close out.
If you want a quick read on where your company stands before you start, the free AI readiness assessment takes a couple of minutes.
AI data governance: the part people skip
Most AI incidents at small companies are data incidents. Someone pastes a client file into a personal account, or a free tool keeps prompts to train its models. Three rules cover most of it. Use business accounts where you control whether your data trains the vendor's models. Keep a written list of data that never goes into any AI tool. And make the approved tool easy to use, so people do not reach for their personal one.
Want the rules inside the tools, not just on paper?
AI Setup for Your Company turns your policy into instructions your assistants follow, with helpers for the tasks your teams do every week.
Questions people ask
What are the main components of an AI governance framework?
Six parts cover it for most companies: a named owner, an inventory of AI tools and uses, risk tiers, a staff policy, controls matched to each tier, and a regular review. Large enterprises add ethics boards and model testing teams, but the same six parts sit underneath. If one is missing, that is usually where problems show up first.
What is the difference between AI governance and an AI policy?
An AI policy tells staff what they can and cannot do with AI tools. AI governance is the wider system around it: who owns AI use, which tools are in use, how risky each use is, who approves it and when it gets reviewed. The policy is one part of the framework. A company can have a policy and still have no governance.
Does a small business need an AI governance framework?
If staff use AI tools with customer or company data, yes, though it can be small. A one-page framework with an owner, an inventory and three risk tiers takes a few weeks to set up. It is much cheaper than dealing with a data leak or a biased hiring decision after the fact. Scale the paperwork to your size.
Which AI governance framework should I follow: NIST or the EU AI Act?
They do different jobs. The NIST AI RMF is voluntary guidance that gives you a structure: Govern, Map, Measure, Manage. The EU AI Act is law, and applies if your AI use touches people in the EU. Many companies use NIST as their working checklist and check EU AI Act risk categories to find the uses that need extra care.
How often should an AI governance framework be reviewed?
Review the inventory of AI uses every quarter, because new tools appear fast. Review the whole framework at least once a year. Also review it when something changes: a new law takes effect, you adopt an AI agent that can act on its own, or there is an incident. Put the review dates in a shared calendar when you approve the framework.
Leave a comment: