AI Governance for SMEs

AI governance, from a blank page.

Your business is using AI. Customers, regulators, auditors, and your own board are about to start asking how you govern it. Built-from-scratch AI governance programmes for SMEs across the UK and Europe, led by an IAPP-certified AI Governance Professional.

Book an introductory call What this looks like in practice

Why this matters now

AI quietly entered your business. The questions are about to arrive.

AI adoption in most SMEs hasn't been planned — it's happened. Marketing started using ChatGPT to draft copy. Engineering wired an LLM into the codebase. Finance is feeding customer data into a tool no one formally approved. Every team has its own pattern of use, and no one has a complete picture of what's running, on whose data, with what oversight.

That ambiguity is fine until something arrives that demands clarity. Increasingly, those things are arriving. Below are the most common moments that bring SMEs to me.

  • An enterprise customer's security questionnaire A new section on AI use, training data, model providers, and human-in-the-loop controls. The contract depends on the answer being credible.
  • The board reads about the EU AI Act The CEO or chair forwards an article and asks a version of "are we ready?" — knowing they need a defensible answer rather than a defensive one.
  • An auditor adds AI to the scope ISO 27001 surveillance audits, SOC 2 examinations, and FCA-driven reviews are increasingly asking pointed questions about AI risk, oversight, and controls.
  • An incident, a near-miss, or a regulator's letter A model produces something embarrassing or non-compliant. A staff member pastes confidential data into a public LLM. The ICO writes to ask about a complaint. The absence of a programme becomes obvious.
  • Cyber insurance renewal Insurers are adding AI risk management to their underwriting questionnaires. Without a programme, premiums rise, exclusions widen, or cover narrows.
  • You sell into the EU, or process EU users' data The EU AI Act applies extraterritorially. UK-based businesses serving EU customers are within scope, regardless of UK government policy.

What AI governance involves

Eight things every AI governance programme needs.

AI governance is not a single document or a single tool. It's a programme — comparable in shape to an information security programme — built from a small number of distinct components, each of which has to work together. When SMEs come to me with no programme in place, this is the structure we build out.

01

AI inventory

You can't govern what you can't see. The first step is a complete picture of every AI system in use — built in-house, embedded inside SaaS tools, used informally by staff. Without this, every later step is guesswork.

02

Risk classification

Each system in the inventory is classified by risk — using EU AI Act tiers, NIST AI RMF categories, or a tailored framework. Risk drives controls; controls drive cost and friction. Getting this right keeps the programme proportionate.

03

Policies that fit your business

Acceptable use, development standards, vendor assessment, data handling, and incident response. Not generic templates — policies your people will actually follow because they're written for the way your business operates.

04

Controls along the lifecycle

Practical safeguards at procurement, development, deployment, ongoing operation, and decommissioning. Aligned with the existing security and data protection controls you already have, rather than a parallel structure.

05

Roles and accountability

Who owns AI risk. Who decides whether a new AI use case proceeds. Who reports to the board. An AI council or steering group, with clear decision rights and escalation paths.

06

Training that lands

Role-specific awareness for staff, deeper training for engineers and data teams, and board-level briefings for those accountable for the programme. Tailored to the actual AI use you've discovered.

07

Monitoring and review

AI use evolves continuously. Inventory drifts, new tools appear, models update, regulations move. The programme needs a regular review cadence and the means to keep up without consuming the business.

08

Reporting and assurance

Clear, defensible reporting for the board, customers, auditors, and regulators. The kind that shortens the next questionnaire, builds trust, and demonstrates that governance is real rather than performative.

The frameworks to know about

Four frameworks shape the territory.

Few SMEs need to implement all of these. But anyone working on AI governance should understand the landscape they sit within, because the right combination depends on where your customers are, which regulators apply to you, and where you're trying to compete.

EU AI Act

The world's first comprehensive AI law, in force since 2024 with phased application running into 2027. It takes a risk-based approach — unacceptable, high, limited, and minimal-risk categories — and imposes obligations that scale accordingly. UK businesses are within scope if they place AI systems on the EU market, deploy them in the EU, or serve EU users. The Act is the single most consequential AI regulation for any UK SME with EU exposure.

ISO/IEC 42001

The first international management system standard for AI, published in December 2023. It is structurally similar to ISO 27001 — auditable, certifiable, designed to be integrated with existing management systems — and provides a defensible, market-recognised way to demonstrate that an organisation governs AI systematically. For SMEs already certified to ISO 27001, ISO 42001 is the natural next step and the structures translate well.

NIST AI Risk Management Framework

A voluntary US framework, published in early 2023 and widely adopted internationally as a lighter-weight alternative to formal certification. It is well-suited to SMEs that want a practical, principles-led approach without the overhead of an ISO management system. Often used as an interim destination on the way to ISO 42001.

UK regulatory context

The UK has taken a sectoral, regulator-led approach rather than legislating a single AI law. The ICO governs data and automated decision-making. The FCA expects regulated firms to manage AI risk under existing operational resilience and conduct rules. The MHRA, Ofcom and others regulate within their remits. UK SMEs need to understand which regulators apply to their business and what each one expects — there is no single rulebook.

How I help

Concrete deliverables, not slide decks.

Every engagement is shaped around what your business actually needs. Some clients want a full programme stood up end to end; others want help with a specific deliverable; others want fractional oversight while their team does the work. The components below are the pieces I most often deliver.

  • AI discovery and inventory exercise
  • AI risk classification methodology
  • AI policy framework (acceptable use, development, vendor)
  • Vendor and tooling assessment process
  • EU AI Act gap analysis and readiness plan
  • ISO 42001 readiness assessment and implementation
  • NIST AI RMF alignment
  • AI governance council design and terms of reference
  • Role-based training and awareness programmes
  • Board reporting and governance papers
  • Customer due-diligence response support
  • Integration with existing ISO 27001 and SOC 2 programmes

Why me

The CISO who can also stand up your AI governance.

AI governance sits at the intersection of cybersecurity, data protection, risk management, and emerging regulation. Very few practitioners cover all of those credibly. Most consultancies offer one specialism — privacy lawyers who don't understand the technical risk, data scientists who don't understand the regulatory machinery, generalist consultants who haven't built either type of programme from scratch.

I'm one of a small number of UK practitioners certified by the International Association of Privacy Professionals as an AI Governance Professional (AIGP), alongside CISSP, CCSP, CISM, and GDPR DPO certifications. That combination matters: AI governance has to be built on top of — and integrated with — the security and data protection programmes that already exist in your business. I've spent fifteen-plus years building those programmes, most recently as Head of Information Security at IFX Payments and before that as CISO at Allica Bank.

For SMEs that need AI governance built from scratch, that combination is rare and useful: the regulatory understanding to know what good looks like, the security and risk experience to integrate it without creating parallel bureaucracy, and the practical bias of someone who's actually delivered governance programmes that hold up to audit.

AI governance also rarely sits cleanly within one jurisdiction. The EU AI Act applies extraterritorially. Multinationals need a consistent approach across UK, EU, and global operations. Customer due-diligence questions cut across whichever regulatory context applies to the questioner, not just to you. I work primarily with clients across the UK and Europe, and selectively with international firms where AI governance crosses borders and that combined regulatory fluency is the work.

How engagements work

Three ways to start.

Discovery and baseline assessment

A short, fixed-scope engagement — typically two to five days — to give you a clear picture of where you are. AI inventory, risk-classification snapshot, regulatory exposure analysis, and a prioritised roadmap. Useful when you know AI governance is on the horizon but don't yet know what you're committing to.

Programme delivery

End-to-end build of an AI governance programme over three to six months: inventory, policies, controls, governance structure, training, and documentation. Sized to your business, integrated with your existing security and data protection work, and handed over with the people and processes to keep it running.

Fractional oversight

Ongoing AI governance leadership at a few days a month — for businesses that have stood up the basics but need senior accountability for risk decisions, board reporting, and continuous review. Often combined with broader Fractional CISO engagements where security and AI governance share the same advisor.

Day rate is £750–£1,250 depending on scope and engagement model. Most engagements operate outside IR35.

Get in touch

Start with a thirty-minute call.

The best place to begin is a conversation. No pitch, no obligation — just an honest discussion about where your business is on AI, what's driving the question, and whether I'm the right person to help.

Two ways to reach me

Email pete@guardiansmith.com with a couple of lines on what you're working on, or connect via LinkedIn. I aim to reply within one working day.

Email me