Guidance for small companies
Right-size the framework for teams under 50 people: which controls are non-negotiable, which can be lightweight, and which to defer.
What to keep, what to skip
| Control | Small-org floor | What to use |
|---|---|---|
| AI inventory | Required | A maintained sheet in Notion / Confluence / SharePoint List |
| Acceptable use policy | Required | One page, acknowledged in your HRIS (BambooHR, HiBob) |
| Vendor due diligence | Required for any AI processing customer data | Vanta / Drata questionnaires; review the vendor SOC 2 + DPA |
| Human oversight | Required for any customer-facing or HR-impacting AI | Documented reviewer + escalation path in your ticketing tool |
| Bias testing | Required if AI affects hiring, credit, pricing | Fairlearn notebook run on every model change |
| Board reporting | Quarterly written update is enough | One-page email to the leadership channel |
| Formal ISMS | Defer until ~50 staff or first enterprise customer asks | ISO/IEC 42001 lite via Vanta or Secureframe |
Do this Monday
- Turn on Microsoft Purview or Google Workspace DLP rules that block sensitive data into ChatGPT, Claude, Gemini consumer URLs.
- Replace consumer AI with the team plan (ChatGPT Team, Claude for Work, Gemini Business) so prompts are excluded from training.
- Publish a one-page AI policy and have everyone sign it in your HRIS.
Reviewer hot-buttons
- Even at five people, can you show who owns AI risk?
- Is shadow AI (personal ChatGPT, Claude on phones) addressed?
- Is the vendor list current — including embedded AI features in tools you already use?