Practical first steps for using AI responsibly, written for real organisations, not just big ones.
Most organisations are already using AI, often without a policy, an owner or a list of what is in use. These free tools help you close those gaps with practical steps that draw on the EU AI Act, the NIST AI Risk Management Framework and ISO/IEC 42001, written for real teams rather than lawyers.
Made for: Small and medium businesses whose staff already use AI tools, Managers asked to "sort out an AI policy", Startups building products that use AI, Compliance, risk, HR and IT leads starting an AI governance programme.
AI governance simply means deciding, in advance, how your organisation will use AI and who is responsible when it does. In most workplaces staff are already using chatbots and AI features inside everyday software, whether or not anyone approved it. The first step is to find out what is being used, for what, and with what data. A simple register does that.
Several frameworks can guide you. The NIST AI Risk Management Framework, published in the United States in January 2023, is voluntary and organises the work into four functions: Govern, Map, Measure and Manage. ISO/IEC 42001, published in December 2023, is an international standard for an AI management system, and organisations can be certified against it. Neither has to be adopted in full to borrow its good ideas.
Law is arriving too. The European Union's AI Act entered into force in August 2024 and takes a risk-based approach: some uses are prohibited, high-risk uses carry strict duties, some systems have transparency obligations and most uses face few new requirements. Its obligations apply in stages. It can matter outside the EU if your AI systems or their outputs are used there, so check whether it reaches you.
For most small organisations, good governance starts with four things: a short policy people can actually follow, a register of AI use, a habit of checking higher-risk uses before launch, and named people who are accountable. Personal data, decisions about people, and anything customer-facing deserve the closest look. Start small, review regularly and improve as you learn.
No organisation is too small to benefit from knowing what AI it uses and setting basic rules. For a small business that can be one page of policy and a simple register. The effort should match the risk.
No tool can do that on its own. These are practical starting points that reflect widely used ideas from frameworks such as the NIST AI RMF and ISO/IEC 42001. Compliance depends on your specific systems and obligations, so take qualified legal and professional advice.
Stanislaus Martins, who has two decades in marketing, digital business and technology across Africa and now focuses on AI governance. The tools are written to be practical for organisations that do not have a dedicated compliance team.
No. Policies, registers and assessments are built in your browser on your own device. Nothing you type is sent to us.
These tools offer general guidance to help you start governing AI use and are not legal, regulatory or compliance advice; laws and standards change and depend on your circumstances, so check your obligations with a qualified adviser.