Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

AI Governance Checklist for Small and Mid-Size Businesses

August 11, 2026
hero-ai-governance-checklist-1.png

An AI governance checklist gives your business one job: control how AI tools get used. Do it before a mistake forces the issue. The clearest structure to borrow comes from the NIST AI Risk Management Framework.

The framework breaks AI risk work into four functions: Govern, Map, Measure, and Manage. Govern sets the rules and assigns ownership. Map inventories every AI tool in use and what it touches. Measure tests whether those tools work as expected. Manage is where you act on what you found.

NIST describes Govern as cross-cutting: it shapes how the other three functions get carried out. Map, Measure, and Manage usually get applied one AI tool at a time. This checklist follows that order: Govern and Map first, then Measure and Manage in part two. For the deeper explanation, see what the NIST AI RMF is.

Quick Gut-Check: Do You Already Have Shadow AI?

Most businesses don’t have an AI-use problem. They have an AI-oversight problem. Employees adopt AI tools faster than leadership tracks them, which is exactly what “shadow AI” means.

Shadow AI Warning Signs

You likely have shadow AI already if any of these are true:

  • Employees paste client or company data into ChatGPT or similar tools without asking first.
  • Someone on your marketing team publishes AI-written content nobody fact-checked.
  • Sales or support staff run AI note-takers on calls with no data-handling review.
  • No single person could list, today, every AI tool used across your company.

None of that means your business is reckless. It means governance hasn’t caught up to adoption yet. The next two sections fix that, starting with Govern.

Govern Checklist: Build the Foundation

AI Governance Checklist Basics

Govern is the foundation the other three functions sit on. Weak governance undermines even a well-run Measure or Manage process. Each item below pulls from NIST’s own suggested actions, not a generic best-practice list.

RequirementWhat “Yes” Looks LikeWhy It Matters
Written AI policy existsEmployees can point to it and explain what it allowsWithout it, every AI decision is improvised
Ownership assignedOne named person or team owns AI risk decisionsShared ownership becomes no ownership
Employee training / acceptable-use rulesStaff know what’s off-limits, like pasting client data into a public AI toolMost shadow AI comes from unclear rules, not bad intent
Vendor AI tools reviewedAny AI feature inside a purchased tool got reviewed before rolloutVendors add AI features constantly, often without asking you

If you can’t check all four boxes, start there before touching Map, Measure, or Manage. A policy with no owner rarely survives past its launch week.

Map Checklist: Know What AI You’re Actually Using

Map builds the context you need before testing or managing anything. NIST’s guidance is blunt about the goal: know an AI tool’s real capabilities, not the ones you assume it has. That means an honest inventory, not a guess.

Work through this checklist for every AI tool in the building, including the ones employees adopted on their own:

  • [ ] Every AI tool in use is listed, official and unofficial, shadow AI included.
  • [ ] For each tool, note exactly what company or customer data it touches.
  • [ ] For each tool, note what could go wrong, like a wrong output, a data leak, or a bad decision made on its advice.
  • [ ] For each tool, note who owns it and who gets called if something breaks.
  • [ ] The list gets reviewed on a set schedule, not built once and forgotten.

A tool that touches customer data carries more risk than one that only drafts internal memos. Rank your list that way, then move the highest-risk tools to the top of your Measure work.

Measure Checklist: Test Before You Trust the Output

Measure is where you find out if an AI tool actually works. NIST’s Measure function covers testing before deployment and watching the tool after launch. A model that passed testing in week one can still drift by week twelve.

Work through this before you let any AI tool make or influence a real business decision:

  • [ ] Every AI tool’s output gets checked for accuracy and bias before your team relies on it.
  • [ ] Testing covers the tool’s actual job, not a generic demo scenario.
  • [ ] Monitoring continues after launch, not just during rollout.
  • [ ] Staff have a clear way to flag a wrong or biased AI output.
  • [ ] Someone reviews those flags on a set schedule, not only when something breaks.

Skip this step and you’re trusting a tool’s output on faith. That’s the opposite of governance.

Manage Checklist: Respond, Review, Improve

Manage is where you act on what Map and Measure found. NIST frames it as picking a response for each risk: mitigate it, transfer it, avoid it, or accept it. It also covers what happens when something goes wrong.

If an AI tool leaks company data or drives a bad decision, work through these steps in order:

  1. Contain it. Pull the tool offline or cut its access immediately.
  2. Assess what data or decisions the incident actually touched.
  3. Notify anyone affected, following your existing incident response plan.
  4. Fix the root cause before turning the tool back on.
  5. Feed what you learned back into your AI policy.

That last step matters most. A response plan that doesn’t update your Govern policy just resets the clock until the next incident.

Two more habits belong in Manage:

  • [ ] Vendor AI tools get re-reviewed on a set schedule, not just at signup.
  • [ ] The whole checklist gets revisited at least once a year, or right after any AI incident.

Why “Voluntary” Still Carries Real Weight

The AI RMF is voluntary. NIST doesn’t fine a business for skipping it, and there’s no penalty structure attached to the framework itself.

That doesn’t make it optional in practice. Three places it shows up anyway:

  • Contracts. More business customers now ask vendors to show an AI governance framework before signing.
  • Cyber insurance. Underwriters are starting to ask about AI governance the same way they already ask about MFA and backups.
  • State law. Some states point to named frameworks like the AI RMF as a legal benchmark for “did you take AI risk seriously.” Colorado’s original AI law once tied a legal safe harbor to NIST RMF compliance, though lawmakers replaced that provision with a different approach in 2026.

The pattern holds even as individual state laws change. Skipping AI governance doesn’t trigger a NIST fine. It can still cost you a contract, a lower insurance rate, or a weaker legal position if something goes wrong.

What LeadingIT Does at Each Function

Most of what NIST asks for under Measure and Manage overlaps with technical work LeadingIT already runs for managed IT clients. Access controls, monitoring, and incident response aren’t new categories, they’re existing cybersecurity work pointed at your AI tools.

FunctionWhat NIST Asks ForWhat LeadingIT Provides
GovernWritten policy, assigned ownership, trainingHelps draft the policy and assign accountability
MapFull inventory of AI tools and what they touchInventories AI tools across your network, often more than leadership expects
MeasureTest outputs, monitor after launchAccess controls, MFA, encryption, and logging around systems that feed AI tools
ManageRespond, recover, feed lessons backVendor risk review and incident response extended to AI-related events

Govern and Map are usually the gap. Most businesses can name their antivirus vendor. Few can name every AI tool touching company data.

See Where You Stand

Not sure which of the four functions your business is missing? Take the free 2-minute NIST AI RMF Risk-Check and get a plain-English readiness score, no sign-up required to see your result.

Take the free 2-minute NIST AI RMF Risk-Check

Frequently Asked Questions

It’s a working list of actions a business takes to control how AI tools get used, organized around the four functions of the NIST AI Risk Management Framework: Govern, Map, Measure, and Manage. Govern sets policy and ownership. Map inventories every AI tool in use. Measure tests whether those tools work as expected. Manage covers how you respond when something goes wrong.

No. It’s a voluntary framework published by NIST, not a law or regulation, and NIST does not certify organizations against it. Its influence comes from other instruments that reference it, including federal procurement guidance, some state laws, and vendor contracts.

No. NIST does not offer, endorse, or accredit any certification or training program for the AI RMF, and there is no NIST-issued “certified” credential for a person or a business. Any “NIST AI RMF Certified” credential you see was issued by a private training vendor, not by NIST or any government body.

Shadow AI is any AI tool employees use without leadership’s knowledge or approval, such as an unapproved chatbot or an AI note-taker nobody reviewed. Most businesses have some. It becomes a real risk when nobody knows what data those tools touch.

Contain it first by pulling the tool offline or cutting its access. Assess what data or decisions it affected, then notify anyone impacted under your existing incident response plan. Fix the root cause before turning the tool back on, and update your AI policy with what you learned.

Review it at least once a year, and immediately after any AI-related incident. Your AI tool inventory should be reviewed on a set schedule too, since new tools get adopted faster than most policies get updated.

Ready to Close the Gaps?

Building this checklist into a working program takes more than a policy document. LeadingIT’s AI governance services cover the technical side of Govern, Map, Measure, and Manage, the same access controls, monitoring, and incident response your business already needs for cybersecurity.

Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.