Most small businesses do not need an AI governance department.

They do need to know which AI tools people are using, what those tools can reach, what information is going into them, and who checks the output before it affects a customer, employee or business decision.

This is a 20-minute first-pass check, not a full security audit. The aim is to spot obvious gaps quickly, write down what needs fixing, and leave with a clearer picture than you had 20 minutes ago.

Set a timer. Give each check roughly a minute. If something needs a deeper investigation, mark it and move on.

Some checks are genuinely one-minute checks. Others, especially first-time admin-console or provider-setting reviews, may take a few extra minutes to locate. The point is a fast audit, not racing the clock.

Tools and accounts

1. List the AI tools people are actually using

Do not start with the tools the business officially bought.

Start with reality.

Write down the AI assistants, meeting tools, browser extensions, design tools, coding assistants and other AI services people are actually using for work.

The NCSC describes unapproved workplace AI as shadow AI and warns that organisations cannot manage risks they cannot see.

If your list is blank, ask the team. You may be surprised.

2. Put an owner next to every tool

Every AI service on the list should have a person who can answer:

  • why the business uses it
  • who has access
  • what information goes into it
  • whether it is still needed

This does not need to be a security specialist. In a small business it might simply be a director, operations lead or technical person.

No owner usually means no review.

3. Check whether people are using personal or business accounts

A familiar logo does not mean every account is governed the same way.

Check whether work is happening in:

  • personal AI accounts
  • company-managed accounts
  • shared logins
  • business or enterprise workspaces

The account type can affect administrative controls, retention, data-use settings and who can manage access.

If staff are doing company work in personal accounts, mark that for review.

4. Remove one AI tool nobody needs anymore

Look at the list and ask one simple question:

Are we still using this?

Old tools create forgotten accounts, stored conversations and lingering integrations.

If an experiment ended months ago, close it properly rather than leaving it connected forever.

5. Check AI browser extensions

AI browser extensions can have a very different permission model from a normal web app.

Open the extension list on managed browsers and look for AI tools that can read or change pages, access browsing data or operate across many websites.

If an extension has broad access and nobody can explain why it needs it, review or remove it.

Our guide to an employee connecting an AI tool to work explains why extensions and OAuth-connected apps need slightly different checks.

Access and permissions

6. Turn on MFA for important AI accounts

If an AI account contains company conversations, uploaded documents or connected business systems, protect it like another important online account.

Check that multi-factor authentication is enabled where the service supports it, particularly for administrators and workspace owners.

The NCSC's current small-organisation guidance treats stronger account protection as a basic cyber-security measure, not an enterprise-only extra.

7. Review what each AI tool is connected to

Look for connections to:

  • Google Drive or OneDrive
  • Gmail or Outlook
  • calendars
  • Slack or Teams
  • GitHub
  • CRM systems
  • design tools
  • databases or internal apps

A chatbot with no integrations is a different risk from an AI service that can search years of email and documents.

Write down the connections rather than relying on memory.

8. Reduce one permission that is broader than necessary

If an AI tool only needs a small part of a system, see whether you can give it less.

That might mean:

  • one folder rather than the whole Drive
  • read access rather than edit access
  • a dedicated mailbox rather than the main inbox
  • a normal user rather than an administrator

The principle is simple: the AI should have the access the job needs, not everything the person who connected it can access.

That is the same least-privilege idea covered in our guide to AI agents with too much power.

9. Check whether the AI can send, publish, delete or pay

Reading information is one level of access.

Taking an action is another.

Identify any AI workflow that can:

  • send email or messages
  • publish content
  • delete records
  • change permissions
  • issue refunds or payments
  • update customer data

For consequential actions, decide whether a person should approve the step first.

Do not wait for an incident to discover that an "assistant" had permission to act on its own.

10. Revoke a connection that should no longer exist

Disconnecting a tool is not always the same as logging out of it.

Check your Google, Microsoft or other identity controls for old third-party app authorisations and revoke anything that should no longer have access.

This is especially useful after trials, staff changes and abandoned experiments. Make revoking old AI and third-party access part of normal offboarding when someone leaves, changes role, or a project ends.

Data and sharing

11. Write down what must never be pasted into a general AI chat

Make the rule obvious.

A sensible starting list includes:

  • passwords
  • API keys
  • recovery codes
  • payment credentials
  • private encryption keys
  • confidential information you are not authorised to disclose

People make better decisions when the boundary is written down rather than assumed.

Never paste by default: passwords, API keys, recovery codes, private keys, full payment credentials, or sensitive personal information you are not authorised to share.

For a broader decision framework, see Can I paste this into AI?.

12. Check one real workflow for personal or client data

Pick an AI task people already do, such as summarising meeting notes or reviewing documents.

Ask:

  • does this include personal data?
  • does it include client-confidential material?
  • are we actually allowed to send that information to this service?
  • are we sharing more than the task needs?

The ICO's AI guidance stresses that existing data-protection responsibilities still apply when AI processes personal data.

"AI" is not an exemption from normal obligations.

13. Check the provider's data controls for the exact account you use

Do not rely on a blog post from two years ago or assumptions based on the brand.

Open the current settings or documentation for the actual account and check:

  • whether content may be used to improve models
  • what retention controls exist
  • what administrators can control
  • whether connected-app data is treated differently
  • whether business and consumer accounts have different terms

For individual or consumer accounts, look for the user's own data-use and model-improvement controls. For managed business or workspace accounts, confirm the organisation-level settings and the provider commitments that apply to that specific plan. These differences are provider- and plan-specific, so do not assume the same brand behaves identically across every account type.

Our guide to what happens to your data after you send it to AI explains why "not used for training" is only one part of the picture.

14. Look for shared chats, links and public workspaces

AI tools increasingly make it easy to share a conversation, agent, project or generated result with a link.

Check whether your team has created shared links or public resources that are no longer needed.

A harmless-looking shared chat can still contain internal context, pasted data or attachments.

Remove anything that should not still be accessible.

15. Reduce the information in one regular prompt

Choose a task people repeat and ask:

Does the AI really need all of this information?

Remove names, entire documents, full customer records or background detail if the job can be completed with less.

Data minimisation is useful even when the AI provider itself is approved.

Less unnecessary data means less unnecessary exposure.

Outputs, incidents and team habits

16. Pick one type of output that always needs human review

Not every AI output deserves the same level of checking.

Choose the outputs where a mistake would matter most, for example:

  • customer-facing advice
  • financial figures
  • legal or contractual wording
  • hiring decisions
  • health or safety information
  • code going into production

Make it explicit that a person reviews those outputs before they are used.

NIST's Generative AI Profile identifies confabulation - confidently presented false or erroneous content - as a distinct generative-AI risk.

17. Check a recent AI answer against its source

Open one recent piece of AI-assisted work that contains facts, figures or citations.

Verify a few claims against the original source.

This takes a minute and tells you something useful about how much trust people are currently placing in generated output.

AI can sound certain when it is wrong. Fluency is not verification.

18. Check what happens when AI reads outside content

If an AI tool reads email, documents, websites or uploaded files, remember that the content may contain instructions written by somebody else.

That matters because of prompt injection: external content can try to influence what an AI system does.

You do not need to become a prompt-injection researcher in minute 18.

Just check that an AI reading untrusted content does not also have unnecessary permission to send, delete, publish or change important things.

Our prompt injection guide explains the problem in plain English.

19. Give staff somewhere to report an AI mistake

People should know what to do if they:

  • paste something sensitive by accident
  • connect the wrong account
  • get a suspicious AI-generated result
  • notice an unapproved tool
  • discover an AI action they did not expect

The reporting route can be as simple as "tell Sarah in Teams" or "email support@company.com".

The important thing is that mistakes surface quickly rather than being hidden because somebody fears getting into trouble.

20. Write one sentence that describes your AI rule

Finish the exercise by writing a rule the team can actually remember.

For example:

Use approved AI tools for work, do not paste secrets or unapproved confidential data into them, and ask before connecting AI to company systems.

It will not cover every edge case.

It does not need to.

A short rule people understand is more useful than a policy nobody reads.

What to do when the timer stops

You will probably have a few checks you could not finish in one minute.

That is expected.

Put them into three buckets:

  • Fix now - easy changes such as enabling MFA or removing an old shared link.
  • Investigate - things where you need to check permissions, provider terms or what data has already been used.
  • Accept for now - risks you understand and are comfortable with at the moment.

NIST's AI Risk Management Framework is deliberately risk-based rather than a single universal checklist. The right controls depend on the AI use, context and potential impact.

For a small company, the win is not producing perfect governance in 20 minutes.

It is going from "we think we're probably fine" to "we know what we're using, what it can access, and what needs attention next."

Do the exercise again when you adopt a significant new AI tool, after an incident or major account change, and periodically as your use of AI grows.