AI Governance for Small Businesses: A Practical 5-Pillar Framework
By Zachariah Crabill, JD · FAIIR, LLC · Updated
The short answer
AI governance for a small business means writing down which AI tools are used, for what, with what data, by whom, and what happens when something goes wrong. The FAIIR five-pillar framework turns that into a 30-day plan: name an AI officer, build a use-case register, set data rules, adopt an acceptable use policy, train staff, and define AI incidents before Colorado's 2027 AI laws take effect.
Key takeaways
- A small business can stand up minimum viable AI governance in about 30 days with a handful of short documents and one spreadsheet.
- The first artifacts to build are an AI officer designation (FAIIR A1), a use-case register (F1), and written out-of-scope boundaries (F2).
- Data rules (I1–I3), an acceptable use policy (U1), and training (U2) address the most common small-business failure: staff pasting customer data into AI tools.
- A risk register (R1), an incident definition (R2), and a short playbook (R3) mean the business knows what to do when an AI tool gets something wrong.
- Colorado's ADMT Act and the Chatbot Safety Act's operator duties apply from January 1, 2027, and neither has a small-business exemption; whether either applies to a specific business is a question for counsel.
What is AI governance for a small business?
AI governance for a small business is a short set of written rules and records that answer five questions: what AI you use, who owns it, what data goes into it, what people are told, and what you do when it fails. It is not a compliance department. For most businesses under 100 people, it is a spreadsheet, a two-page policy, a training session, and a one-page incident plan.
This guide uses the FAIIR framework, a five-pillar standard with 41 pass/fail controls: Fitness for Purpose, Accountability, Integrity of Data, Informed Use, and Risk Management. You do not need all 41 on day one. The plan below covers the eleven controls that do the most work first. For background on the standard itself, see What Is FAIIR Certification?.
Why does a small business need AI governance without a compliance team?
A small business needs AI governance because the risks of AI use do not scale down with headcount, and the people asking about it (clients, insurers, and regulators) expect written answers. Four pressures show up first.
- Liability you may not know you carry. If an employee pastes a client's financial records into a free AI tool, or a chatbot tells a customer something false, the business owns the result. Governance is how you find those exposures before someone else does.
- Client trust. Clients increasingly want to know whether their information goes into AI tools and whether a human checks AI output. A use-case register and data rules let you answer in one email instead of improvising.
- Insurance and vendor questionnaires. If an insurer, enterprise customer, or partner asks how you use AI, a written register, policy, and incident plan turn a vague answer into a documented one. FAIIR control A5 asks you to check your own liability coverage for AI-related claims, even if you add nothing.
- Colorado's 2027 laws. Colorado's ADMT Act (SB 26-189) and Chatbot Safety Act (HB 26-1263) both put their main duties in force January 1, 2027. Neither has a small-business exemption.
Which Colorado laws might apply to a small business?
The ADMT Act applies to deployers that use technology processing personal data whose output materially influences a consequential decision in education, employment, Colorado residential real estate, financial or lending services, insurance, health-care services, or essential government services. The statute requires those deployers to give a pre-use notice, disclose adverse outcomes within 30 days, provide data access and correction, offer meaningful human review to the extent commercially reasonable, and keep records for three years. Tools used solely to summarize, organize, translate, draft, route, or present information for human review of administrative processing are excluded from the definition.
The Chatbot Safety Act applies to operators of consumer-facing conversational AI services, with no size threshold, subject to exclusions such as B2B tools, internal tools, and certain customer-support bots. Its duties include AI disclosure, age estimation, minor protections, self-harm response protocols, and a ban on presenting chatbot output as coming from a licensed professional. Whether either law reaches your business depends on facts; talk to counsel about your situation. The Colorado ADMT Act compliance checklist walks through the statute in detail.
How do you set up AI governance in the first 30 days?
Set up AI governance in four weeks: name an owner and inventory your tools in week one, set data rules in week two, publish a policy and train staff in week three, and plan for failures in week four. Each step below names the FAIIR control it satisfies.
Week 1, step 1: Name an AI officer (A1)
Designate one person, by role and by name, as responsible for AI governance. In a 10-person business this is usually the owner or office manager. Write it down in one paragraph: "The Operations Manager (currently Jane Doe) is the AI Officer and approves new AI tools, maintains the use-case register, and owns AI incidents." That single sentence also covers much of A7 (Incident Response Owner).
Week 1, step 2: Build a use-case register (F1)
Create a spreadsheet with one row per AI tool and these columns: tool name, vendor, plan tier (free, paid, enterprise), who uses it, approved tasks, and owner. To find every tool:
- Ask every employee, in writing, which AI tools they have used for work in the last 90 days, including free and personal accounts.
- Check card statements and expense reports for AI subscriptions.
- List AI features built into software you already pay for: email, CRM, accounting, document, and meeting tools often have them switched on by default.
- Note any chatbot or AI feature on your website or in customer communications.
Week 1, step 3: Write out-of-scope boundaries (F2)
Add a "Not approved for" column to the register. Be specific: "Not for employment decisions," "Not for final pricing or credit decisions," "Not for medical, legal, or tax conclusions sent to customers," "Not for anything a customer will see without human review." Boundaries matter most for tools that could touch the consequential-decision areas listed above.
Week 2: Set data rules (I1, I2, I3)
- I1 — Data classification map. Sort the data your business handles into four classes: Public, Internal, Confidential, and Regulated (for example, health, financial account, or government ID data). One page is enough.
- I2 — AI-permitted data rules. Add a column to the register stating which classes each tool may receive. A free chatbot might be approved for Public and Internal only; an enterprise tool under a data processing agreement might be approved for Confidential.
- I3 — No-PII default. Adopt the rule that no personally identifiable information goes into any third-party AI tool unless a data processing agreement covers it. Put that sentence at the top of your policy.
Week 3, step 1: Adopt an AI acceptable use policy (U1)
Write a two-page policy that points to the register rather than repeating it. Cover: only approved tools may be used; only permitted data classes may go in; AI output that reaches a customer or affects a decision gets human review; how to request a new tool; and how to report a problem. Distribute it to every employee and collect a written acknowledgment, since an unsigned policy does not pass U1.
Week 3, step 2: Train employees (U2)
Run one 30-to-60-minute session, live or recorded, for everyone who uses AI tools. Walk through the policy, show two or three real examples of what not to paste, explain how to spot a wrong or invented answer, and show how to report an incident. Keep an attendance record with dates. U2 requires an annual refresh, so put next year's date on the calendar now.
Week 4: Plan for failures (R1, R2, R3)
- R1 — Risk register. For each tool in the use-case register, list the one or two things most likely to go wrong, rate likelihood and severity (low, medium, high), and write the mitigation. Example: "Chatbot gives wrong return policy — medium/medium — chatbot limited to FAQ content, weekly spot check." Schedule a quarterly review.
- R2 — Incident definition. Write down what counts as an AI incident. Not every wrong answer qualifies. A workable definition: confidential or regulated data entered into an unapproved tool; AI output sent to a customer that was materially wrong; an AI-influenced decision about a person made without the required human review; or a vendor security event involving your data.
- R3 — Incident response playbook. On one or two pages: who is called first (the AI officer), what is logged (date, tool, data involved, who saw the output), who is notified internally, when customers are told, and when to call counsel or your insurer.
What is minimum viable AI governance?
Minimum viable AI governance is eight short artifacts that together cover all five FAIIR pillars at a starting level. Time estimates below are typical for a small business with a handful of AI tools; yours may vary.
| Artifact | What it contains | Time to create (estimate) | FAIIR control |
|---|---|---|---|
| AI officer designation | Named role and person, responsibilities, incident ownership | 15 minutes | A1 (and A7) |
| Use-case register | One row per AI tool: vendor, tier, users, approved tasks, owner | 2–4 hours | F1 |
| Out-of-scope boundaries | "Not approved for" rules per tool | 1 hour | F2 |
| Data classification and AI data rules | Four data classes; permitted classes per tool; no-PII default | 2–3 hours | I1, I2, I3 |
| AI acceptable use policy | Approved tools, data rules, human review, reporting; signed acknowledgments | 3–4 hours plus sign-off | U1 |
| Training record | Session date, materials, attendee list | 1 hour to prepare, 1 hour to deliver | U2 |
| Risk register | Risks per tool, likelihood, severity, mitigation, review date | 2 hours | R1 |
| Incident definition and playbook | What counts as an incident; who is called, what is logged, who is told | 2–3 hours | R2, R3 |
What are the most common AI governance mistakes small businesses make?
The most common mistake is writing a policy without an inventory, which produces rules that do not match the tools people actually use. Others follow close behind.
- Banning AI outright. A blanket ban usually drives use onto personal accounts where you have no visibility. An approved list with data rules is easier to enforce.
- Missing embedded AI. AI features inside existing software count. If the register lists only standalone chatbots, it is incomplete.
- No signatures, no dates. A policy nobody acknowledged and a training nobody logged leave no evidence that either happened.
- Ignoring free-tier settings. Many consumer AI plans have training and retention settings that differ from business plans. FAIIR I4 and I5 ask you to check them per tool.
- Assuming size is an exemption. Colorado's ADMT Act has no small-business exemption, and the Chatbot Safety Act has no size threshold. Coverage turns on what the tool does, not how many employees you have.
- Treating governance as legal compliance. A register and policy show reasonable care; they do not by themselves satisfy any statute, and no certification is recognized under Colorado law.
- Set and forget. Tools change monthly. Review the register quarterly with the risk register, and log material changes (R9).
Buying new AI tools is where many of these gaps start. The AI vendor due diligence questions post covers what to ask before a tool goes into the register.
Where FAIIR fits
The eleven controls above are the starting core of the FAIIR framework; the remaining controls add accuracy thresholds, vendor contract review, customer disclosure, monitoring, and audit-log retention. FAIIR is a private governance standard published by FAIIR, LLC, which is not a law firm, and Colorado law does not recognize any AI certification. For questions about how a specific law applies to your business, talk to your own counsel.
Frequently asked questions
What is the first step in AI governance for a small business?
The first step is naming one person responsible for AI governance and building a use-case register that lists every AI tool in use and what it is approved for. In the FAIIR framework these are controls A1 and F1. Everything else, including data rules and policy, builds on that inventory.
Does a small business need an AI acceptable use policy?
An AI acceptable use policy is the simplest way to tell employees which tools and data are allowed and to show later that you did. FAIIR control U1 requires the policy to be written, distributed to all employees, and acknowledged in writing. Two pages that point to your use-case register is usually enough.
How long does it take to set up basic AI governance?
Most small businesses can build a minimum viable set of AI governance documents in about 30 days, working a few hours a week. The core artifacts are an AI officer designation, use-case register, data rules, acceptable use policy, training record, risk register, and incident playbook.
Is there a small-business exemption from Colorado's ADMT Act?
No. Colorado's ADMT Act (SB 26-189), effective January 1, 2027, has no small-business exemption; coverage depends on whether a tool's output materially influences a consequential decision in one of seven listed domains. The Chatbot Safety Act (HB 26-1263) also has no size threshold. Talk to counsel about whether either applies to your business.
What counts as an AI incident?
Each business defines its own AI incidents in writing, which is what FAIIR control R2 requires. A practical definition includes regulated or confidential data entered into an unapproved tool, materially wrong AI output sent to a customer, and an AI-influenced decision about a person made without required human review. Routine wrong answers caught before use usually do not qualify.
Sources
This article is general information from FAIIR, LLC, which is not a law firm, and is not legal advice. Colorado law does not require or recognize any third-party AI certification, and FAIIR certification is not a government approval or a guarantee of compliance. For advice about your situation, consult a licensed attorney.