AI governance: free tools, no sign-up

Practical first steps for using AI responsibly, written for real organisations, not just big ones.

Most organisations are already using AI, often without a policy, an owner or a list of what is in use. These free tools help you close those gaps with practical steps that draw on the EU AI Act, the NIST AI Risk Management Framework and ISO/IEC 42001, written for real teams rather than lawyers.

Made for: Small and medium businesses whose staff already use AI tools, Managers asked to "sort out an AI policy", Startups building products that use AI, Compliance, risk, HR and IT leads starting an AI governance programme.

  • AI acceptable-use policy builder: Answer a few questions, get a clear AI policy your team can actually follow.
  • AI use register: List every AI tool your organisation uses, who owns it and how risky it is.
  • AI risk checker: Describe one AI use case and see where it might sit under the EU AI Act, with practical next steps.
  • AI governance readiness quiz: Twelve quick questions to see how ready your organisation is to use AI responsibly.
  • Write an AI use policy: Build a clear, plain-English policy covering approved tools, what data must never go into them, human review and who is accountable.
  • Keep a register of AI use: List every AI tool and use case in one place, with its owner, purpose, data involved and risk level. You cannot govern what you have not written down.
  • Check risk and readiness: Answer structured questions to get a first view of a use case's risk and your organisation's readiness, plus suggested next steps.

AI governance without the jargon: where to start

AI governance simply means deciding, in advance, how your organisation will use AI and who is responsible when it does. In most workplaces staff are already using chatbots and AI features inside everyday software, whether or not anyone approved it. The first step is to find out what is being used, for what, and with what data. A simple register does that.

Several frameworks can guide you. The NIST AI Risk Management Framework, published in the United States in January 2023, is voluntary and organises the work into four functions: Govern, Map, Measure and Manage. ISO/IEC 42001, published in December 2023, is an international standard for an AI management system, and organisations can be certified against it. Neither has to be adopted in full to borrow its good ideas.

Law is arriving too. The European Union's AI Act entered into force in August 2024 and takes a risk-based approach: some uses are prohibited, high-risk uses carry strict duties, some systems have transparency obligations and most uses face few new requirements. Its obligations apply in stages. It can matter outside the EU if your AI systems or their outputs are used there, so check whether it reaches you.

For most small organisations, good governance starts with four things: a short policy people can actually follow, a register of AI use, a habit of checking higher-risk uses before launch, and named people who are accountable. Personal data, decisions about people, and anything customer-facing deserve the closest look. Start small, review regularly and improve as you learn.

First steps in AI governance

  • Find out which AI tools staff are already using, and for what
  • Record each tool and use case in an AI use register with a named owner
  • Agree a short AI use policy, including what data must never be entered
  • Require a human to review AI output before it reaches customers or decides anything about people
  • Check higher-risk uses, such as hiring, lending or health, before they go live
  • Check whether laws such as the EU AI Act or local data protection rules apply to you
  • Set a date to review the policy and register, at least once a year

Questions

Is my business too small to need AI governance?

No organisation is too small to benefit from knowing what AI it uses and setting basic rules. For a small business that can be one page of policy and a simple register. The effort should match the risk.

Will these tools make me compliant with the EU AI Act or ISO/IEC 42001?

No tool can do that on its own. These are practical starting points that reflect widely used ideas from frameworks such as the NIST AI RMF and ISO/IEC 42001. Compliance depends on your specific systems and obligations, so take qualified legal and professional advice.

Who made these tools?

Stanislaus Martins, who has two decades in marketing, digital business and technology across Africa and now focuses on AI governance. The tools are written to be practical for organisations that do not have a dedicated compliance team.

Is the information I enter about my organisation stored?

No. Policies, registers and assessments are built in your browser on your own device. Nothing you type is sent to us.

These tools offer general guidance to help you start governing AI use and are not legal, regulatory or compliance advice; laws and standards change and depend on your circumstances, so check your obligations with a qualified adviser.