AI Risk

Framework

AI governance for SMEs: the framework

AI governance means: you know which AI runs where, who is responsible for it, and how it is released and monitored. For an SME, six building blocks are enough. I provide the concept and templates and train your team; your company runs the solution itself.

As of: 6 October 2026

  • InventoryWhich AI tools and functions are in use, with which data, in which processes? What is not on the list cannot be steered.
  • OwnersEvery system has one person who is responsible for release, changes and incidents. Not IT as a whole, one person.
  • Risk classificationPer system from the top down: harm, hazard, failure mode, control. The classification decides how much testing is needed.
  • Release with evidenceA system only goes live when the acceptance criteria are shown. Every change to model, prompt or data triggers the checks again.
  • Data rulesWhat may go into AI tools, what may not, and where do the inputs land? This is the simplest and often most effective rule.
  • Monitoring and stopDrift and incidents are measured, every alert has an owner, and there is a way to stop the system.

What comes from me and what from your company

  • From me: the concept for the framework, templates (risk table, acceptance criteria, example test rig), training for your team and support during the build-up.
  • From your company: the inventory, the owners, the risk classification of its own systems, the releases and the operation.
  • Not included: acceptance of individual systems, certification or legal advice.

How I work

Governance and compliance

Compliance means meeting requirements, for example from law or a standard. Governance means organising steering so that responsibility, decision and evidence fit together. Compliance without governance is a document, governance without compliance may overlook requirements. Whether something is permitted is for your lawyer to decide.

Law and standards with sources

Where to begin

Begin with the inventory and the data rules. The effort is usually manageable, and both reveal typical gaps early. Then classify the system with the greatest possible harm first.

The thinking behind it: proof before claim

Answers

Does an SME need an AI policy?

An SME in which employees use AI tools should have at least a short policy with data rules and owners; a legal duty is not meant by that. It says what may be entered, who releases and who decides on incidents. One page is enough if it is lived.

Help with the introduction

What is the difference between AI governance and AI compliance?

AI compliance means meeting requirements from law, standards or contracts, AI governance means organising responsibility, decision and evidence in operation. Governance provides the evidence that compliance needs. What is legally required is for your lawyer to decide.

Who in the company is responsible for AI?

For every AI system there should be a named person who is responsible for release, changes and incidents. Overall responsibility usually lies with management. Who that is for you follows from the risk classification.

Contact

Send me the use case in two sentences. I will get back to you and say whether and how your project can be tested. Whether I can take the job depends on my workload.

admin@all-answer.com
+41 76 511 52 25