AI Governance Checklist for Small and Mid-Size Businesses
An AI governance checklist gives your business one job: control how AI tools get used. Do it before a mistake forces the issue. The clearest structure to borrow comes from the NIST AI Risk Management Framework.
The framework breaks AI risk work into four functions: Govern, Map, Measure, and Manage. Govern sets the rules and assigns ownership. Map inventories every AI tool in use and what it touches. Measure tests whether those tools work as expected. Manage is where you act on what you found.
NIST describes Govern as cross-cutting: it shapes how the other three functions get carried out. Map, Measure, and Manage usually get applied one AI tool at a time. This checklist follows that order: Govern and Map first, then Measure and Manage in part two. For the deeper explanation, see what the NIST AI RMF is.
Quick Gut-Check: Do You Already Have Shadow AI?
Most businesses don’t have an AI-use problem. They have an AI-oversight problem. Employees adopt AI tools faster than leadership tracks them, which is exactly what “shadow AI” means.

You likely have shadow AI already if any of these are true:
- Employees paste client or company data into ChatGPT or similar tools without asking first.
- Someone on your marketing team publishes AI-written content nobody fact-checked.
- Sales or support staff run AI note-takers on calls with no data-handling review.
- No single person could list, today, every AI tool used across your company.
None of that means your business is reckless. It means governance hasn’t caught up to adoption yet. The next two sections fix that, starting with Govern.
Govern Checklist: Build the Foundation

Govern is the foundation the other three functions sit on. Weak governance undermines even a well-run Measure or Manage process. Each item below pulls from NIST’s own suggested actions, not a generic best-practice list.
| Requirement | What “Yes” Looks Like | Why It Matters |
|---|---|---|
| Written AI policy exists | Employees can point to it and explain what it allows | Without it, every AI decision is improvised |
| Ownership assigned | One named person or team owns AI risk decisions | Shared ownership becomes no ownership |
| Employee training / acceptable-use rules | Staff know what’s off-limits, like pasting client data into a public AI tool | Most shadow AI comes from unclear rules, not bad intent |
| Vendor AI tools reviewed | Any AI feature inside a purchased tool got reviewed before rollout | Vendors add AI features constantly, often without asking you |
If you can’t check all four boxes, start there before touching Map, Measure, or Manage. A policy with no owner rarely survives past its launch week.
Map Checklist: Know What AI You’re Actually Using
Map builds the context you need before testing or managing anything. NIST’s guidance is blunt about the goal: know an AI tool’s real capabilities, not the ones you assume it has. That means an honest inventory, not a guess.
Work through this checklist for every AI tool in the building, including the ones employees adopted on their own:
- [ ] Every AI tool in use is listed, official and unofficial, shadow AI included.
- [ ] For each tool, note exactly what company or customer data it touches.
- [ ] For each tool, note what could go wrong, like a wrong output, a data leak, or a bad decision made on its advice.
- [ ] For each tool, note who owns it and who gets called if something breaks.
- [ ] The list gets reviewed on a set schedule, not built once and forgotten.
A tool that touches customer data carries more risk than one that only drafts internal memos. Rank your list that way, then move the highest-risk tools to the top of your Measure work.
Measure Checklist: Test Before You Trust the Output
Measure is where you find out if an AI tool actually works. NIST’s Measure function covers testing before deployment and watching the tool after launch. A model that passed testing in week one can still drift by week twelve.
Work through this before you let any AI tool make or influence a real business decision:
- [ ] Every AI tool’s output gets checked for accuracy and bias before your team relies on it.
- [ ] Testing covers the tool’s actual job, not a generic demo scenario.
- [ ] Monitoring continues after launch, not just during rollout.
- [ ] Staff have a clear way to flag a wrong or biased AI output.
- [ ] Someone reviews those flags on a set schedule, not only when something breaks.
Skip this step and you’re trusting a tool’s output on faith. That’s the opposite of governance.
Manage Checklist: Respond, Review, Improve
Manage is where you act on what Map and Measure found. NIST frames it as picking a response for each risk: mitigate it, transfer it, avoid it, or accept it. It also covers what happens when something goes wrong.
If an AI tool leaks company data or drives a bad decision, work through these steps in order:
- Contain it. Pull the tool offline or cut its access immediately.
- Assess what data or decisions the incident actually touched.
- Notify anyone affected, following your existing incident response plan.
- Fix the root cause before turning the tool back on.
- Feed what you learned back into your AI policy.
That last step matters most. A response plan that doesn’t update your Govern policy just resets the clock until the next incident.
Two more habits belong in Manage:
- [ ] Vendor AI tools get re-reviewed on a set schedule, not just at signup.
- [ ] The whole checklist gets revisited at least once a year, or right after any AI incident.
Why “Voluntary” Still Carries Real Weight
The AI RMF is voluntary. NIST doesn’t fine a business for skipping it, and there’s no penalty structure attached to the framework itself.
That doesn’t make it optional in practice. Three places it shows up anyway:
- Contracts. More business customers now ask vendors to show an AI governance framework before signing.
- Cyber insurance. Underwriters are starting to ask about AI governance the same way they already ask about MFA and backups.
- State law. Some states point to named frameworks like the AI RMF as a legal benchmark for “did you take AI risk seriously.” Colorado’s original AI law once tied a legal safe harbor to NIST RMF compliance, though lawmakers replaced that provision with a different approach in 2026.
The pattern holds even as individual state laws change. Skipping AI governance doesn’t trigger a NIST fine. It can still cost you a contract, a lower insurance rate, or a weaker legal position if something goes wrong.
What LeadingIT Does at Each Function
Most of what NIST asks for under Measure and Manage overlaps with technical work LeadingIT already runs for managed IT clients. Access controls, monitoring, and incident response aren’t new categories, they’re existing cybersecurity work pointed at your AI tools.
| Function | What NIST Asks For | What LeadingIT Provides |
|---|---|---|
| Govern | Written policy, assigned ownership, training | Helps draft the policy and assign accountability |
| Map | Full inventory of AI tools and what they touch | Inventories AI tools across your network, often more than leadership expects |
| Measure | Test outputs, monitor after launch | Access controls, MFA, encryption, and logging around systems that feed AI tools |
| Manage | Respond, recover, feed lessons back | Vendor risk review and incident response extended to AI-related events |
Govern and Map are usually the gap. Most businesses can name their antivirus vendor. Few can name every AI tool touching company data.
See Where You Stand
Not sure which of the four functions your business is missing? Take the free 2-minute NIST AI RMF Risk-Check and get a plain-English readiness score, no sign-up required to see your result.
Take the free 2-minute NIST AI RMF Risk-Check
Related Guides
Frequently Asked Questions
It’s a working list of actions a business takes to control how AI tools get used, organized around the four functions of the NIST AI Risk Management Framework: Govern, Map, Measure, and Manage. Govern sets policy and ownership. Map inventories every AI tool in use. Measure tests whether those tools work as expected. Manage covers how you respond when something goes wrong.
No. It’s a voluntary framework published by NIST, not a law or regulation, and NIST does not certify organizations against it. Its influence comes from other instruments that reference it, including federal procurement guidance, some state laws, and vendor contracts.
No. NIST does not offer, endorse, or accredit any certification or training program for the AI RMF, and there is no NIST-issued “certified” credential for a person or a business. Any “NIST AI RMF Certified” credential you see was issued by a private training vendor, not by NIST or any government body.
Shadow AI is any AI tool employees use without leadership’s knowledge or approval, such as an unapproved chatbot or an AI note-taker nobody reviewed. Most businesses have some. It becomes a real risk when nobody knows what data those tools touch.
Contain it first by pulling the tool offline or cutting its access. Assess what data or decisions it affected, then notify anyone impacted under your existing incident response plan. Fix the root cause before turning the tool back on, and update your AI policy with what you learned.
Review it at least once a year, and immediately after any AI-related incident. Your AI tool inventory should be reviewed on a set schedule too, since new tools get adopted faster than most policies get updated.
Ready to Close the Gaps?
Building this checklist into a working program takes more than a policy document. LeadingIT’s AI governance services cover the technical side of Govern, Map, Measure, and Manage, the same access controls, monitoring, and incident response your business already needs for cybersecurity.
Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.
