What should a good AI governance policy include for a UK SME?

22 July 2026

What should a good AI governance policy include for a UK SME?

For most UK SMEs, a good AI governance policy is a practical 6 to 12 page operating document, not a legal essay. It should say which AI tools are allowed, what data can and cannot be used, who approves high-risk use cases, when a DPIA is needed, how outputs are checked, what suppliers must prove, how incidents are handled, and who owns the policy. A focused first version usually costs £1,500 to £6,000 externally, or 2 to 5 internal working days if you already have strong data protection and cyber security processes.

The short answer: include rules people can actually follow

A good AI governance policy for a UK SME should include twelve things: purpose, scope, approved tools, banned uses, data classification, data protection rules, DPIA triggers, human review, supplier checks, cyber security controls, audit logs, incident response, ownership, training, and review dates. If any of those are missing, the policy will probably fail in the real world.

The policy does not need to look like an enterprise bank document. Most SMEs need something between 6 and 12 pages, plus a one-page staff summary. The detailed version protects the business. The one-page version gets used.

The biggest mistake is writing principles without decisions. "Use AI responsibly" is not governance. "Do not enter customer personal data into consumer AI tools. Use Microsoft Copilot only with company login. CRM-connected AI requires director approval and a DPIA screen" is governance.

There is a cost to doing this properly. A light policy for low-risk office use may cost £500 to £1,500 externally. A proper SME policy covering customer data, Microsoft 365 or Google Workspace, CRM, support and finance workflows is usually £1,500 to £6,000. Regulated, sensitive or multi-site work can run from £7,500 to £25,000 if it includes a full DPIA, legal review, supplier review and security assessment.

What does UK guidance say your policy needs to cover?

UK guidance points in the same direction: AI risk depends on context, data, control and accountability. The GOV.UK AI regulation white paper sets out five cross-sector principles: safety, security and robustness, appropriate transparency and explainability, fairness, accountability and governance, and contestability and redress. For an SME, those principles translate into practical policy clauses.

The ICO guidance on AI and data protection covers accountability, transparency, lawfulness, accuracy, fairness, security, data minimisation and individual rights. If your AI use involves personal data, your policy should show who has considered those issues and what staff must do differently.

The NCSC guidelines for secure AI system development are aimed at providers of AI systems, including systems built on external APIs. They split secure AI work across secure design, secure development, secure deployment, and secure operation and maintenance. Even if you are buying rather than building, those headings are a useful sanity check for supplier questions and internal controls.

GOV.UK cyber data also makes this a real business issue, not a theoretical compliance exercise. The Cyber Security Breaches Survey 2025 found that 43% of UK businesses reported a cyber security breach or attack in the previous 12 months. It also found that only 14% of businesses reviewed risks from immediate suppliers and only 7% looked at wider supply chain risks. AI governance has to include suppliers because most AI systems depend on external vendors, APIs, hosting, model providers, plugins or automation platforms.

What should the approved tools section include?

The approved tools section should name the tools staff may use and the conditions attached to each one. Do not write "approved AI tools" and leave people guessing. Name them: ChatGPT Team or Enterprise, Microsoft Copilot, Gemini for Workspace, Claude Team, Perplexity Enterprise, HubSpot AI, Salesforce Einstein, Zendesk AI, Notion AI, Make, Zapier, n8n, or your own internal assistant.

For each tool, record the plan type, owner, permitted users, permitted data, banned data, whether prompts are used for model training, retention settings, admin controls, logging, and who approved it. Consumer accounts should usually be banned for customer data, employee data, finance data, legal material and confidential business information.

This is where SMEs need to be blunt. If staff are using free personal AI accounts for work, the policy should say whether that is banned, tolerated for public information only, or being replaced with company-managed tools. Ambiguity creates shadow AI.

Include a process for requesting new tools. A simple form is enough: tool name, business reason, data involved, users, expected output, supplier terms, security notes, cost, and proposed owner. Low-risk tools can be approved by the operations lead. High-risk tools should need senior approval, IT or security input, and a DPIA screen.

What data rules should be in the policy?

Data rules are the heart of AI governance. They should tell staff what can be entered into AI tools, what cannot be entered, and what needs approval first. Use plain categories: public, internal, confidential, personal data, special category data, employee data, customer data, financial data, contracts, source code, credentials, legal advice, complaints and regulated advice.

A practical SME policy might use this table:

Data typeDefault ruleApproval needed
Public informationAllowed in approved toolsNo
Internal non-sensitive documentsAllowed in managed business toolsSometimes
Customer personal dataRestrictedYes, with DPIA screen
Special category dataNormally banned unless explicitly approvedYes, senior and data protection approval
Passwords, API keys, secretsBannedNo routine approval
Contracts and legal documentsRestrictedYes, owner approval
Financial, HR or payroll dataRestrictedYes, senior approval

The policy should also cover outputs. If AI drafts a customer email, sales recommendation, support answer, job advert, contract summary, complaint response or financial analysis, who checks it before use? Human review is not a vague comfort phrase. It needs named roles and clear thresholds.

If your concern is specifically connecting AI to live business systems, read our guide to security and privacy risks when connecting AI to business data. The policy is where those risks become operational limits.

When should a DPIA or risk assessment be triggered?

Your policy should not say "do a DPIA where required" and stop there. Most staff do not know when that is. Give them triggers.

For a UK SME, require at least a DPIA screen when AI uses personal data, connects to CRM, support, HR, finance, email or document stores, profiles people, ranks customers, drafts regulated advice, influences hiring, handles complaints, analyses call recordings, processes special category data, or makes recommendations that could materially affect a person.

A full DPIA may be needed where processing is high risk. The ICO expects organisations to consider risk, safeguards and individual rights. Your policy should say who completes the DPIA screen, who decides whether a full DPIA is needed, where the record is stored, and whether legal, DPO, security or senior management review is required.

For non-personal but commercially sensitive work, use an AI risk assessment instead. That should cover confidentiality, commercial harm, inaccurate outputs, supplier lock-in, intellectual property, availability, cyber exposure and operational dependency.

The key point is speed. A DPIA screen should take 20 to 45 minutes, not three months. If the screen finds high risk, slow down. If it finds low risk, record the decision and move.

What supplier and security clauses should be included?

Most SMEs will not host every AI system themselves. Your policy must tell people what to check before using an AI supplier. Minimum checks include data location, sub-processors, training use, retention, deletion rights, access control, encryption, audit logs, security certifications, breach notification, support route, export options, pricing model, and what happens if the supplier changes the product.

NCSC guidance is useful here because it treats AI systems as live systems that need secure design, deployment, operation and maintenance. Your policy should require logging, monitoring, version control, access review and an off-switch for AI used in important workflows.

For customer-facing or operational AI, include these security rules: no shared admin accounts, multi-factor authentication for admins, least privilege access, separation between test and production, no real customer data in unmanaged prototypes, prompt and response logging where proportionate, regular permission reviews, and incident escalation within 24 hours.

The supplier section should also say when procurement can be lightweight. If a staff member wants a £20 per month design assistant for public marketing images, do not run a six-week review. If the tool reads customer emails or updates a CRM, do the review properly.

Who should own AI governance in an SME?

Ownership should sit with the business, not the vendor and not the most enthusiastic AI user. In a small company, the accountable owner is usually the managing director, operations director, finance director, or head of the department using AI. They should be supported by whoever handles IT, data protection, security, HR and supplier contracts.

The policy should name four roles. The accountable owner approves the policy and accepts risk. The tool owner manages a specific AI tool or workflow. The data owner decides whether a data source can be used. The user is responsible for following the rules and checking outputs.

For a 10 person business, those roles may be the same two people. That is fine. For a 100 person business, they should be separated. The policy should also state who can pause or disable an AI workflow if it behaves badly, exposes data, produces harmful output or becomes too expensive.

Review frequency matters. Update the policy every 6 months, or sooner if a new AI tool is introduced, a supplier changes terms, a data incident occurs, a regulated workflow is added, or staff start using AI in a materially different way.

What should this cost and how long should it take?

A first AI governance policy should not become a transformation programme by stealth. If your business already has decent GDPR records, cyber controls and supplier processes, a focused policy can be drafted in 2 to 5 working days. If your data and access controls are messy, allow 2 to 4 weeks because the policy will expose gaps.

Policy levelBest fitTypical costTimeframe
One-page acceptable useLow-risk drafting and public research£0 to £7501 day
Practical SME AI policyManaged tools, internal data, staff guidance£1,500 to £4,0001 to 2 weeks
Customer data governance packCRM, support, finance or document integrations£3,000 to £8,0002 to 4 weeks
Regulated or sensitive AI governanceHR, health, finance, legal, vulnerable customers£7,500 to £25,000+4 to 10 weeks

GOV.UK research on AI activity in UK businesses is a useful reality check. It found that around 15% of UK businesses had adopted at least one AI technology, and that businesses adopting AI spent £16.7 billion on AI technologies in 2020 but £46.0 billion on labour associated with development, operation or maintenance. The average small business spend was £9,500 on AI technology and £24,400 on related labour. Governance is part of that labour cost. It is the work that makes AI usable without creating unmanaged risk.

When this does NOT apply

This does not apply in full when the AI use is genuinely low risk. If a director uses AI to brainstorm blog topics from public information, a full governance pack is overkill. If a designer uses an approved image tool with no customer data and no confidential files, keep the controls light. If a developer uses AI against dummy data in a sandbox, focus on code review, secrets control and licensing rather than a broad business policy.

It also does not solve bad data management. If your CRM permissions are wrong, document folders are open to everyone, old exports sit in shared drives, and nobody owns supplier contracts, an AI policy will not magically fix that. Start with data access, records of processing, supplier contracts and cyber basics.

Finally, do not use governance as an excuse to avoid decisions. Some businesses turn AI policy into theatre: committees, values statements, approval meetings and no actual controls. That is worse than a short policy that clearly says what staff can and cannot do.

The goal is not to stop AI. The goal is to make AI boringly controlled: approved tools, known data, named owners, checked outputs, logged decisions and a route for fixing problems.

What should you do next?

Start with an AI use inventory. List every AI tool currently used by staff, including personal accounts. Then list the data each tool may see: public, internal, customer, employee, financial, legal, technical or sensitive. Next, mark each use case as low, medium or high risk.

From there, write the minimum policy that can make decisions. Include the approved tools list, banned data, approval triggers, DPIA screen, supplier checks, output review, logs, incident route and policy owner. Do not wait for perfection. The first version should control the obvious risks within days.

If you want a wider starting point, read whether you need an AI policy before staff use ChatGPT, Copilot or Gemini at work. If you are already connecting AI to customer systems, governance needs to move from guidance to operating control.

If you want help deciding what level of AI governance your SME actually needs, book a free call. No pitch, no pressure. Just a direct conversation about your tools, data, risks and the lightest policy that would still protect the business.

Is This Right For You?

This is right for you if staff use ChatGPT, Microsoft Copilot, Gemini, Claude, HubSpot AI, Salesforce Einstein, Zendesk AI, automation tools, or custom AI systems for real business work. It is especially relevant if AI touches customer data, employee data, contracts, finance, regulated advice, sales decisions, complaints, HR, support tickets, intellectual property, or confidential documents.

It is not right for you if you are trying to create a 50 page policy before anyone has tested a low-risk AI use case. For public research, generic drafting, meeting preparation, or internal brainstorming with no personal or confidential data, start with a one-page acceptable-use rule and a named owner. Add the full policy when the AI starts touching sensitive data, live workflows, customer communications, or business decisions.

The honest test is this: if a member of staff asked whether they can paste a customer email, payroll file, supplier contract, or sales call transcript into an AI tool, could your policy give a clear answer in under 30 seconds?

Frequently Asked Questions

Does a UK SME legally need an AI governance policy?

Not always by that exact name. But if AI uses personal data, customer data, employee data or regulated workflows, UK GDPR, cyber security duties, contracts and sector rules create accountability requirements. A governance policy is the practical way to show how those requirements are handled.

How long should an AI governance policy be?

For most SMEs, 6 to 12 pages plus a one-page staff summary. If staff cannot understand it, it will not work. If it does not cover data, tools, approvals, incidents and ownership, it is too thin.

Who should write the AI governance policy?

The business owner should lead it with input from IT, data protection, security, HR, legal or compliance, and the teams using AI. Do not let a vendor write the policy alone. The business using AI owns the risk.

What is the most important section of the policy?

The data rules. Staff need to know what they can put into AI tools, what is banned, and what needs approval. Most AI risk starts with the wrong data going into the wrong tool.

Should the policy cover ChatGPT, Copilot, Gemini and Claude?

Yes. It should name each approved tool and the conditions attached to it. The rules may differ by plan type. A managed business account is not the same as a free personal account.

When do we need a DPIA for AI?

Run at least a DPIA screen when AI uses personal data, connects to customer or employee systems, profiles people, supports decisions that affect individuals, or processes sensitive data. A full DPIA may be needed where the processing is high risk.

How often should an AI governance policy be reviewed?

Every 6 months, or sooner if you add a new AI tool, connect AI to a new data source, change supplier terms, handle an incident, or move from low-risk drafting into operational workflows.

Can we use a template?

Yes, but only as a starting point. A template is useful for structure, but the real value is in your approved tools, data categories, approval triggers, owners, suppliers and incident process. Generic AI policy templates often fail because they do not make real decisions.