AI compliance for SMEs: a proportionate 90-day plan

Small and medium businesses are being asked enterprise-grade AI questions without enterprise-grade teams to answer them. This guide sets out what genuinely applies to an SME, what buyers actually want to see, and a 90-day plan that fits around the day job.

Michael McCarroll25 years in IT governance Last verified August 2026
13 min read

What actually applies to a smaller business

The AI regulation conversation is written for large providers, which leaves SMEs guessing. Strip it back and three things apply to almost every small business using AI. First, the EU AI Act's AI literacy duty on deployers, which applies horizontally and early. Second, GDPR wherever personal data enters a prompt, a training set or an output. Third, contract and procurement obligations from your own customers, which in practice arrive first and hurt fastest.

The heavy machinery of the AI Act — conformity assessments, CE marking, post-market monitoring, technical documentation files — attaches to providers of high-risk systems. If you are embedding a third-party model into an internal workflow, you are almost certainly a deployer with a much shorter list. The risk for SMEs is not over-regulation; it is spending months on the wrong tier of effort because a vendor's whitepaper implied every obligation applied to everyone.

  • Deployer duties: literacy, oversight, using systems per instructions, some transparency.
  • Provider duties: risk management, data governance, documentation, conformity, monitoring.
  • GDPR: lawful basis, minimisation, DPIA where high risk, transparency to individuals.
  • Commercial: customer questionnaires, DPAs, AI clauses in contracts.

Start with an inventory you can maintain

Every credible AI programme begins with knowing what you are running. List each AI system with a business owner, purpose, the data it touches, whether it influences decisions about people, the provider and hosting region, and whether prompts are retained or used for training. Include shadow AI — the assistant a salesperson uses to summarise calls is exactly the exposure your customers are asking about.

Keep the inventory somewhere it will be updated, and tie updates to an existing trigger such as new-supplier onboarding or expense approval for a SaaS subscription. A quarterly review of a live inventory is worth more than an exhaustive one-off audit that ages badly. In ISO-STANDARD.app the AI inventory feeds the risk register, DPIA screening and trust profile from a single record.

  • Owner, purpose and business criticality.
  • Data categories in prompts, outputs and any fine-tuning.
  • Provider, model, hosting region and contract tier.
  • Retention and training-exclusion settings.
  • Whether outputs affect decisions about people.

The four artefacts buyers ask for

Procurement teams are not looking for a legal opinion. They are looking for evidence that someone owns this. An AI acceptable-use policy states which tools are approved, what may never be entered, and where human review is mandatory. Role-based AI literacy training records show staff were told. A short risk note per system records what could go wrong and what you do about it. A public AI statement lets a buyer self-serve before the call.

Write these in plain English and keep them short. A two-page AI policy that people follow beats a twenty-page one that nobody reads, and reviewers can tell the difference within a paragraph. Version them, date them, name an owner, and set a review date — the metadata is what turns a document into evidence.

  • AI acceptable-use policy, approved and acknowledged.
  • Role-based literacy training with an attendance register.
  • One-page risk note per AI system, reviewed annually.
  • Public AI statement covering features, models, data and oversight.

A 90-day plan that fits around the day job

Days 1–30: build the inventory, name an owner, and decide your role (deployer or provider) for each system. Days 31–60: approve the AI acceptable-use policy, run Tier 1 and Tier 2 literacy training, and complete risk notes for the systems that touch personal data or influence decisions about people. Days 61–90: publish the customer-facing AI statement, wire the review dates into your calendar, and answer your three most recent buyer questionnaires against the new evidence to find the gaps.

At the end of the quarter you should be able to answer any reasonable AI question from a customer within an hour, and you will have the foundation for ISO 42001 if the business case appears. That is the correct level of ambition for a business of this size — proportionate, evidenced and maintainable, rather than an enterprise programme that stalls at week six.

  • Month 1: inventory, ownership, role determination.
  • Month 2: policy, training, risk notes.
  • Month 3: public statement, review cadence, questionnaire dry run.

When to step up to ISO 42001

Three signals mean it is time. AI becomes material to your product rather than your back office. Buyers start asking for a certification or an equivalent framework by name. Or you begin processing customer data through models in ways that carry real consequence if they go wrong. Any of those makes the management-system approach cheaper than answering each question bespoke.

The good news for SMEs is that the ISO 42001 clause structure mirrors ISO 27001, so if you already hold an ISMS the incremental work is modest: extend scope, add AI-specific risks and impact assessments, adopt the Annex A controls that apply, and run the same internal audit and management review cycle across both. Firms with an existing ISMS typically reach readiness in three to six months rather than a year.

AI governance sized for a smaller business

ISO-STANDARD.app gives SMEs the AI inventory, policy, training records, risk notes and public trust statement in one workspace — proportionate today, ISO 42001-ready when you need it.

ISO-STANDARD.app ships a ready-to-adopt ISO 42001 / AI governance workspace with the risk register, controls catalogue, policies and audit-ready exports already wired together — no spreadsheet sprawl, no consultant lock-in.

Free downloads for this topic

Prefer a conversation? Email hello@iso-standard.app — a real human responds within one business day.

Frequently asked questions

We are a 20-person business using ChatGPT. Does AI compliance apply to us?
Yes, at a proportionate level. You are a deployer, so the EU AI Act's AI literacy duty and transparency expectations apply where your outputs reach the EU, GDPR applies to any personal data in prompts, and your customers' security questionnaires will ask what tools you use and how you control them. You do not need a conformity assessment or a compliance department — you need an inventory, a policy, training records and a sensible risk note per tool.
How much does AI compliance cost a small business?
Done proportionately, the cost is mostly internal time: roughly 5–10 days of effort spread over a quarter to build the inventory, approve a policy, train staff and document the risk position. Costs rise if you are a provider of a high-risk AI system, or if you pursue ISO 42001 certification, where certification body fees are the main external expense.
Do we need ISO 42001 or is a policy enough?
If AI is incidental to how you work, a documented policy, inventory and training records are usually enough to pass procurement. If AI is a selling point of your product, or you sell into regulated buyers, ISO 42001 converts scattered good practice into an independently verified management system and answers most enterprise questions before they are asked.
What do enterprise buyers actually ask about AI?
Consistently: which AI features exist in your product, which model providers process our data, whether our data is retained or used for training, where processing happens, who reviews AI output before it reaches us, how you handle hallucinations and errors, whether staff use AI tools on our data, and what governance framework you follow. Prepare written answers once and reuse them.
Who should own AI compliance in a small company?
One named person, usually whoever already owns security or data protection, with an executive sponsor. Distributing ownership across a committee in a business of under 100 people reliably means nobody maintains the inventory. Give the owner an hour a week and a review date.
Related guides

Not sure where you stand? Score your ISMS against clauses 4–10 and Annex A in a few minutes.

Free gap analysis
Trust & security
ISO 27001 aligned
Controls mapped to Annex A
Encryption in transit & at rest
TLS 1.3 · AES-256
MFA enforced
TOTP required for all admins
GDPR & UK GDPR
DPA on request · EU/UK data
SOC 2 ready posture
Audit-grade logging
RLS-isolated tenants
Row-level data separation
← All guidesHome →