Join UsCEO MastermindAI Leadership MastermindExecutive AI ProgramFractional AI Executive1:1 Coaching5-Minute Leader
BooksPower Without PermissionAI Leadership Mastermind
PodcastMeet the Team
ResourcesBlogFree AssessmentsResearch and DataCEO Coaching ReportJoin UsAdd us on Google

AI Governance Framework for Small Business: The One Page Version a CEO Can Adopt This Week

A one page AI governance framework for small business: decision rights, data rules, approved tools, human review points and a monthly review a CEO can adopt.

By Andreas Pettersson, Founder, Leaders ADAPT

At one company I worked with, employees had automated about 80 percent of their own work before anyone upstairs wrote a rule. Then the rules arrived, and the first thing they did was slow those people down.

That is the whole problem with an AI governance framework for small business as it is usually written. It exists to make the company feel safe, and it does that by making the useful thing hard. So the useful thing moves to a personal phone, where nobody governs it at all.

This page gives you the one page version instead: five parts, one line each, adoptable in a single leadership meeting. It also covers what the templates skip, what your board means by "governance" versus what your operating team needs.

Quick answer: An AI governance framework for small business covers five parts: decision rights (who may approve which AI uses), data rules (which information may enter which tools), an approved tool list with a sanctioned fast path, human review points before AI output reaches a customer or a decision, and a review cadence. Written as one page, owned by the CEO and one executive champion, reviewed monthly.

What is an AI governance framework, and what does a small company actually need?

An AI governance framework is the written set of rules that says who decides what about AI in a company, which data may enter which tools, who checks AI output before it is used, and how often the rules get reviewed.

The enterprise versions run to forty pages because they were written for companies with a legal department. A 60 person firm needs a page the managers will read, a name on each rule, and the habit of rereading it.

Here's the test for the policy you have now. Take an employee who follows it to the letter and one who ignores it. Which one gets more done this week? If the second, your policy is training people to ignore it.

Why do most AI governance frameworks fail in a 20 to 200 person company?

Let me be direct about what I see across the thirty-plus companies I have worked with on AI. Most have not had time to figure out their AI policy, so they restrict rather than enable, to be on the safe side.

Restriction feels responsible. Its unpriced consequence: the work does not stop, it moves. Lock the tools down and staff move to personal, unmonitored accounts, and what they learn about making AI work for you leaves the building the day they do.

A second failure sits above it. The WRITER and Workplace Intelligence survey of 2,400 employees and executives (April 2026) found that 75 percent of C-suite respondents called their company's AI strategy more for show than real guidance, and 29 percent of employees admitted to sabotaging it. A framework written for show produces show.

The principle I run instead is freedom under supervision. People get room to experiment, including room to waste some time on dead ends early, because punishing early experimentation kills the initiative. In exchange, leadership keeps real oversight of what is being built and where sensitive data flows. Every line below makes those two things visible without slowing the work.

The one page AI governance framework: five parts

The whole framework fits in one table; the sections after it fill in each line.

PartThe question it answersWhat the line on your page says
1. Decision rightsWho approves a new AI use, and who owns the page?CEO owns the page; one executive champion approves new uses; IT owns access and security
2. Data rulesWhich information may enter which tools?Three classes: never enters any AI tool, enters only anonymized, enters freely
3. Approved tools and the fast pathWhat may people use, and how fast can they get it?A short approved list, a same-week path to add a tool, company accounts
4. Human review pointsWhere does a named person check the output?Before anything reaches a customer, a decision or a person's record; the accountable person signs
5. Review cadenceWhen does the page change?Monthly, twenty minutes, with an incident count and a list of new uses

Part 1: Decision rights

The most common governance mistake at this size is handing the whole topic to IT. IT can tell you what is possible and what is secure. It cannot tell you which customer data you are willing to risk or which decisions must stay human. Those are business calls, which is why AI for CEOs treats that handoff as the first of the seven traps.

So the page names three roles. The CEO owns the page and the perimeter. One existing executive is the champion who approves new uses and hears about problems first. IT owns access and security.

Under a few hundred people I do not recommend a dedicated AI executive. Pair the champion with a comparatively junior technical hire who carries implementation, and save the senior role for the day AI is your market differentiator.

Workflow level decision rights, what AI drafts by default and what the owner decides alone, are covered on delegation in the age of AI.

Part 2: Data rules

Data classification at this size means three classes:

  1. Never enters an AI tool. Anything that would hurt a person or break a contract if it leaked: performance records, unreleased financials, client material under a confidentiality clause, credentials.
  2. Enters only anonymized. Client situations, deal terms, hiring notes, with names and identifiers stripped. An industry and a company size is usually all the context the model needs.
  3. Enters freely. Public material, your own marketing, drafts, process documents, meeting notes with nothing from class one.

The middle class saves most of the work. "No client information in AI" gets ignored, because client information is the work. "Strip the names first" costs ten seconds.

Part 3: Which AI tools should be approved, and what about shadow AI?

An owner in one of my groups discovered her staff had been quietly using ChatGPT to prepare their work, and her first reaction was to ask why she was paying them. Understandable, and wrong. Her people had found the tool before the company did. The right move was a secure version of the same capability, with review before use.

Shadow AI exists because the sanctioned path is slower than the unsanctioned one. The fix is not a longer banned list. It is a short approved list, company accounts so the knowledge stays in the company, and a same-week answer when someone asks for a tool. A request that takes a quarter gets answered by a personal credit card.

Part 4: Human review points

My favorite proof that everything needs a human check came from a client's own quality document. Their AI-written quality guide warned against the exact artifacts and dashes AI writing produces, and it contained every one of them. Nobody had read it before it went out.

The rule I use with the companies I advise: AI can own the sourcing, the shortlisting and the first draft of almost any workflow, and a human validation review by the accountable person stays in place until something goes out the door. Catching an error after a quote has been sent means redoing the cycle, so quality control sits before the customer-facing step, never after.

Write the review points as places: before a customer sees it, before a decision rests on it, before it touches a person's record. The accountable person signs, not whoever pressed generate. The manager's version of this rule, what to hand over and what to keep, is on AI for managers. For agents that take actions, add which they may take alone and which need a human click; agents will go outside the lines at some point, and the question is whether you can pull them back in.

Part 5: Review cadence

Aim, aim, aim produces a committee and no usage. Fire, then aim again, is the pacing that works: use the tools, review what was built and where the data went, tighten. That review is the cadence.

Monthly is my recommendation at this size. Twenty minutes, two inputs: the incident count (a class one document in a tool, an output that reached a customer unchecked) and the new uses people have started.

One incident is an occasion. Two is a pair. Three is a pattern, and the page changes.

What do boards ask for versus what the operating team needs?

A board asks for AI governance because it wants margin. Efficiency raises margins, margins multiply the valuation, so its questions are about risk to that value: liability, data exposure, whether management understands what it is doing. The board level version, with the restraint question and the directors' checklist, is on the companion page about AI governance leadership for boards.

What the board asksWhat the operating team needs
Do we have an AI policy?A page they have read, with a name next to each rule
Who is accountable for AI risk?A champion they can ask by Friday, and an answer by the following Friday
Are we exposed on customer data?The three data classes with examples from their own week
Is management on top of this?A monthly twenty minute review that changes the page
What is the AI strategy?Which wave they are in: personal productivity, then cross team efficiency, then AI in the product

That last row is the one I push hardest. Almost every leadership team I meet is talking about wave three, AI inside the product, and has not finished wave one. Write the page for the wave you are in.

How do you write an AI use policy in one page?

Copy the five parts, fill in the blanks, put a name on each:

  1. Owner and champion. The CEO owns this page. [Name], [role], approves new AI uses and is the first call for problems. IT owns accounts, access and security.
  2. Data classes. Never enters an AI tool: [your list]. Enters only after names and identifiers are removed: [your list]. Enters freely: [your list].
  3. Approved tools. [Tool, company account, who has a seat]. To request a tool, message [champion]; answer within five working days.
  4. Review points. Before it reaches a customer, decides anything or touches an employee's record, [role] reads it and signs. Agents may [list] alone and must stop for a person before [list].
  5. Review. [Champion] and [CEO] review this page on the first [weekday] of each month: incidents, new uses, changes.

That is an AI use policy template and an AI governance framework for small business at once, because at this size they are one document. Do not add a sixth part because a vendor's template had one. Do not let it grow past a page.

To check the ground under the page, the AI readiness checklist for CEOs shows which of four dimensions you are missing, and why AI rollouts stall covers the leadership failures no policy fixes.

AI governance framework for small business FAQ

What is an AI governance framework?

An AI governance framework is the set of written rules a company uses to decide who may approve AI uses, which data may enter which tools, who reviews AI output before it is acted on, and how often those rules are revisited. In a small company it is usually one page with a named owner; in a large company it grows into several documents.

What should an AI governance policy include?

Five elements cover an AI governance framework for small business: decision rights (who owns the policy and approves new uses), data rules (three classes, from never enters a tool to enters freely), an approved tool list with a fast way to add tools, human review points before output reaches a customer, a decision or an employee record, and a review cadence with an incident count. Each element carries a name.

Who should own AI governance in a small company?

The CEO owns the framework, because the core decisions are about business risk and margin rather than technology. One existing executive acts as the champion who approves new uses and hears about problems first, paired with a junior technical person for implementation. IT owns access and security. Handing the whole topic to IT usually produces restriction, not governance.

Do small businesses need AI governance?

Yes. AI governance for small business is easier than for large companies, because one leadership meeting can set the rules and culture can enforce them without software. A small business also carries the incident directly: a leaked client file or an unchecked AI output sent to a customer lands on the owner's reputation with no compliance department to absorb it.

How often should an AI governance framework be reviewed?

Monthly works for most companies under a few hundred people: a twenty minute review of the incidents since the last one and the new AI uses people have started. A single incident is watched, two of the same kind are noted, and three are treated as a pattern that changes the page. Annual reviews are too slow for tools that change quarterly.

What is the difference between an AI governance framework and an AI use policy?

An AI use policy is the set of rules employees follow: which tools, which data, which review steps. An AI governance framework is the structure around the policy: who sets the rules, who reviews them, how incidents feed back into changes. In a company of 20 to 200 people the two live on one page with one owner, and separate only when the company grows enough to need two.

The page is the easy part

Writing the page takes an hour. Keeping it honest takes twenty minutes a month. Keeping it enabling takes a CEO who can hear about a mistake without shutting the tools off that afternoon.

That is the real governance decision, and it is not on the page. It is what you do the first time an employee tells you an AI draft reached a customer with an error in it. Thank them, fix the review point, count it as one. Punish them, and the next error happens where you never see it.

Pick the executive champion this week. Fill in the five lines. Then use the tools hard for a month and let the first review show you what you got wrong. That is what the cadence is for.

When one page is not enough on its own

Some companies need the page plus someone who owns the rollout. A fractional AI executive engagement starts with four weeks of assessment and a readiness report, so the data classes and review points in your AI governance framework for small business reflect where your data actually flows. The policy framework is one deliverable, with weekly feedback to the leadership team and the training that turns the page into behavior. One more piece of the first month decides whether the framework holds or drifts, and I leave it off this page because it depends on which of the three roles is weakest in your company.

Andreas Pettersson ran AI in production before ChatGPT existed, as a tech CEO for 10 years and one of Canon's youngest CEOs. He founded Leaders ADAPT for non-technical CEOs leading in the AI era.

Leadership insights, straight to your inbox

Practical protocols from a former Canon CEO. No fluff, unsubscribe anytime.

Andreas Pettersson

Andreas Pettersson

Former Canon CEO. Founded and exited Arcules, an AI company backed by Canon and Milestone. Today he coaches CEOs and executives through Leaders ADAPT.