ModelCharter
ModelCharter Team

AI Governance Checklist: 10 Steps for Small Teams

Checklist and form on a desk representing an AI governance checklist

Photo: RDNE Stock project / Pexels

Key takeaways

  • AI governance for a small team is ten concrete steps, not a department.
  • Steps 1-3 build a tool inventory; steps 4-6 vet each tool and set its approved tier; steps 7-9 write the policy and collect attestation; step 10 keeps it current.
  • Each step maps to a real obligation under the EU AI Act, GDPR, ISO 42001 or SOC 2.
  • A first pass usually takes half a day; maintaining it takes about an hour a quarter.
  • ModelCharter covers steps 4 through 9 directly, so the manual work is really just the inventory.

An AI governance checklist turns a vague worry - 'are we doing this properly?' - into ten concrete actions you can tick off without hiring anyone new. Most small and mid-sized teams stall on AI governance because it sounds like a programme, with a steering committee and a six-month rollout plan. It isn't, not at this size. This is the same checklist ModelCharter's own customers work through, usually in an afternoon, then revisit once a quarter. Each step maps to a real obligation under the EU AI Act, GDPR, ISO 42001 or SOC 2, so what you produce isn't just tidy - it's something you can hand to an auditor or a nervous customer.

Steps 1-3: find out what you actually use

Start with an inventory, not a policy. Step 1 is listing every AI tool in use, including the ones nobody bought through procurement - the browser extension someone installed to summarise emails, the free transcription app a manager swears by. Step 2 is noting what data flows into each one: names, contracts, source code, health records. Step 3 is sorting that list by sensitivity, from public to regulated: a marketing blog draft is one thing, a customer list or a support transcript with a patient's name in it is another. This is the MAP function in the NIST AI RMF, and close to the system inventory ISO 42001 expects an auditor to see. Ask every team, not just IT - most of what turns up is shadow AI, adopted quietly because the approved list moved too slowly for someone's Tuesday deadline.

Steps 4-6: vet each tool and decide

For anything touching sensitive data, check three things: does it train on your inputs, how long does it retain them, and does it offer a Data Processing Agreement or, for health data, a Business Associate Agreement. Step 5 is deciding a status per tool - approved, restricted or blocked - and naming the tier that status applies to, since a free plan and a business plan from the same vendor can have opposite answers: a marketing tool that's perfectly fine for drafting ad copy on its free tier may be entirely wrong for the same team's customer-support inbox on that same tier. Step 6 is writing those decisions into a tool register, not an email thread nobody can find in eight months. ModelCharter's AI Tool Risk Directory already holds this lookup for 60-plus popular tools, each fact sourced from the vendor's own policy, which usually turns step 4 into minutes rather than an afternoon per tool. The split between a vendor's free and paid tiers is often the deciding factor here - see consumer vs business AI tiers for why the same brand name can sit on either side of that line.

Do you need a compliance department to run this?

No. A 12-person design studio we spoke to ran the whole list between a Monday stand-up and lunch: an hour on the tool inventory, twenty minutes vetting the two tools that touched client data, and the policy generator did most of step 7. The studio's ops lead, who also handled payroll and the office lease, was the one who finished it - nobody on staff had 'compliance' in their title, and nobody needed to. The department isn't the prerequisite. Having one accountable owner who finishes the list is, and that owner can be whoever already keeps the company's other admin running.

How this maps to the formal frameworks

You don't need to read any of these documents to complete the checklist, but it helps to know where the ten steps come from. Govern, Map, Measure, Manage: those are the four functions in the NIST AI RMF, and steps 1 to 6 above are essentially Map and Measure done at small-team scale. ISO/IEC 42001, published in December 2023 as the first AI management system standard, expects a documented system inventory and a named accountable person, which is steps 3 and 9 here. SOC 2 auditors increasingly ask vendor-management questions under the AICPA's Trust Services Criteria, which step 6's tool register answers directly. None of that changes what you actually do; it just means the paperwork you're already producing has a name.

Steps 7-9: write it down and get sign-off

Step 7 is a short AI usage policy: the data rules, the approved-tools list, a human-review requirement for anything customer-facing, and a named owner. Step 8 is circulating it and collecting attestation - a timestamped record that each person read and accepted it, ideally with a one-line acknowledgement rather than a silent assumption everyone opened the email. That record is what evidences the EU AI Act's Article 4 AI-literacy duty, which has applied since 2 February 2025. Step 9 is a review cadence: annual re-attestation at minimum, plus a re-check whenever a vendor changes its terms or you add a new tool.

What happens if you skip attestation?

Nothing happens immediately, which is exactly the trap. The gap shows up later - in a SOC 2 audit that asks for evidence staff were trained on AI use, in a customer security questionnaire that asks the same thing in different words, or after an incident, when 'we told people not to do that' turns out to mean a policy sat unread in a shared drive for a year. Attestation is cheap to collect at the time and expensive to reconstruct after the fact, because by then half the people who need to sign it have left the company. Build it in at step 8, not as an afterthought you get to eventually.

Step 10: keep it current

Vendors change their terms more often than teams check them; a training-data policy that held in January can quietly change by June. A tool that was safe on a given tier six months ago may not be today. Step 10 is a standing habit, not a one-off: re-check the directory, refresh the register, and treat the whole checklist as something you maintain in roughly an hour a quarter rather than something you finish once and file away.

Where to start today

Work through the list in order and you'll be ahead of most companies your size by the end of the week. ModelCharter covers steps 4 through 9 directly - the risk directory, the policy generator, the tool register and attestation tracking in one place - so the genuinely manual part of this checklist is really just steps 1 through 3: finding out what your team already uses, and being honest about what turns up.

StepsActionMaps to
1-3Inventory tools, data flows and sensitivityNIST AI RMF (MAP); ISO 42001 system inventory
4-6Check training/retention/DPA/BAA; set an approved tier per toolISO 42001 risk treatment
7-9Write the policy; collect attestation; set a review cadenceEU AI Act Article 4 (AI literacy)
10Refresh the register as vendor terms changeSOC 2 vendor management
The 10-step checklist at a glance
The checklist isn't the finish line. It's the minimum bar auditors, customers and regulators now expect from a team of any size.
ModelCharter's compliance team

Frequently asked questions

Do we need a compliance department to do AI governance?
No. Most teams complete this checklist with one accountable owner, usually in ops, IT or HR, spending half a day on the first pass and roughly an hour a quarter after that.
How long does the checklist actually take?
For a team with a handful of AI tools in regular use, a first pass usually takes about half a day: an hour or two on the inventory, a similar amount vetting the tools that touch sensitive data, and the rest writing and circulating the policy.
What's the minimum viable AI governance for a 10-person startup?
A short AI usage policy, a list of approved tools with their tiers named, and a record that everyone has read the policy. That's steps 1, 6 and 8 done properly; everything else builds on top.
How often should we redo the checklist?
You don't redo it from scratch. Re-attest annually, and re-check any tool whenever its terms change or you add a new one to the register. Step 10 exists precisely so you never have to start over.
What if we already have a policy but no tool register?
Start at step 6. A policy without a register tends to go stale, because nobody's tracking which tools it actually covers as new ones get adopted. Add the register and the rest of the checklist gets easier to maintain.

Put this into practice

Generate a free AI usage policy for your team, then see which of your tools are safe to use.

Open the generator