AI governance for a small business, on one page
AI governance, risk & compliance

AI governance for a small business, on one page

Ben Richards

There is now an international standard for managing AI inside an organisation. Your business almost certainly does not need to certify against it. But the questions it forces an organisation to answer are the right questions, and stripped of the certification machinery, a small business can answer them on a single page.

The starting point is not a policy. It is a list, because you cannot supervise something nobody has written down.

Most businesses have more AI in them than the owner realises

This is the part that catches people. Nobody was reckless. The tools simply arrived one at a time. Someone switched on the meeting summaries. Someone else started drafting quotes with a chatbot. The accounting software added a feature nobody asked for and enabled it by default. A staff member found something useful and started using it on their own account.

Each decision was sensible in isolation. What is missing is anyone holding the whole picture, because the picture was never drawn.

Try it now, before reading on. List every AI tool operating in your business from memory. Most owners get to three, then remember two more an hour later. That gap is the actual governance problem, and it is not solved by writing a policy.

What is ISO 42001, and do I need it?

ISO/IEC 42001 was published in December 2023 and is the first international standard for AI management systems. It sits in the same family as the information security standard some of your larger clients have probably asked you about, and it uses the same underlying management-system structure, so anyone who has been through that process will recognise the shape of it.

Broadly, it asks an organisation to be able to answer for: leadership and accountability, an AI policy and objectives, risk management for AI systems, data governance across the system lifecycle, transparency about how AI is being used, ongoing monitoring and performance evaluation, and continual improvement. Certification is voluntary and is done by independent certification bodies, not by ISO itself.

Do you need it? Almost certainly not. It is built for organisations considerably larger than yours, and pursuing certification is a serious undertaking with real cost.

Here is the useful part anyway. Somebody has already done the hard thinking about what a complete answer looks like. You can borrow the shape of the answer without buying the process.

The one-page version

Take the standard's questions and shrink them to what a business of five or fifty can actually maintain. One page, three columns.

Column one: every AI tool the business uses. Include the ones bundled inside software you already pay for, and the ones individual staff have started using on their own accounts. Those two categories are where the surprises live.

Column two: who is accountable for each. Not who uses it. Who is answerable if it goes wrong. In a small business this will often be the same one or two names repeatedly, and that is fine. What matters is that no row is blank.

Column three: what you would do if it produced something wrong that reached a customer. One sentence. If you cannot write that sentence for a given row, you have found the row that needs attention this month.

That is it. It takes about an hour, and it is a better use of that hour than any framework built for an organisation a hundred times your size. Once the list exists, most rows answer their own accountability question. The two or three that do not are exactly the ones worth spending real time on, and now you know which they are instead of worrying about all of them equally.

Why the list beats the policy

Policies fail in small businesses for a boring reason: nobody reads them, and there is no compliance function to notice.

A list works because it is short enough to stay current and specific enough to act on. It also surfaces the thing a policy never does, which is the tool nobody knew about.

The framing we use with clients is simple. One page you maintain beats a policy nobody reads. If governance costs you more than an hour a quarter at this size, it will quietly stop happening, and governance that stops happening is worse than none because it creates the impression of control.

This connects to two things we have written about before. The first is that safety in AI comes from bounding what a tool can touch rather than trusting it to behave, which we covered in guardrails, not trust. The second is the practical checklist for letting an AI agent act on your behalf, in using AI agents safely.

There is also a fourth column some businesses should add, which is where the setup itself lives and whether it would survive a lost laptop. We made that case in backing up your AI setup. If you want this done properly rather than done once, it usually sits inside a roadmap or retainer engagement. Our services page covers how that works.

Ready to find out where you stand?

If you want a straight look at what AI is already running in your business and who is accountable for it, our free AI Readiness Check covers exactly that. No cost, no pitch.

Frequently asked questions

Do I need an AI policy at all?

Eventually, and it can be short. But not first. A policy written before you know what is actually running in the business governs an imaginary version of it.

Should I get ISO 42001 certified?

Only if a client or a tender requires it, or you are large enough that formal certification unlocks work you cannot otherwise win. For most small businesses the cost is not justified, and the underlying questions are available for free.

What if staff are using AI tools on personal accounts?

Put them on the list rather than banning them. A ban moves the usage out of sight without stopping it, and you lose the visibility that makes the list worth having.

How often should the list be reviewed?

Once a quarter is enough for most businesses, plus whenever you add a new system. If it needs more than that, it has grown into something bigger than a one-page list, which is itself useful to know.

What is the biggest risk for a business our size?

Usually not a dramatic failure. It is confidently wrong output reaching a customer without anyone checking it, because nobody was clearly accountable for checking. That is exactly what column two and column three are for.

Ready to find out where you stand?

Take the free five-minute AI Readiness Check. There is no pitch at the end of it.

Take the AI Readiness Check
Ben Richards
Ben Richards
Co-founder, Handiwork
Co-founder of Handiwork, Brisbane's practical AI consultancy for small and medium businesses.
Connect on LinkedIn →

Sources

  • ISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system. International Organization for Standardization, published 18 December 2023, https://www.iso.org/standard/42001
  • ISO 42001 explained: what it is and why it matters. International Organization for Standardization, https://www.iso.org/home/insights-news/resources/iso-42001-explained-what-it-is.html
August 17, 2026
August 17, 2026
Brisbane-based AI advisory & implementation© 2026 Handiwork Consulting Pty Ltd