AI Governance Institute
All governance templates →What does AI governance look like for a company with under 50 employees?

Implementation Kit

Startup AI Governance Checklist and Policy Templates

The lightweight set for a company under 50 people: a simple AI inventory, a one-page acceptable use policy, a three-clause vendor check, a data flow summary, and a template for answering a customer's AI governance questionnaire.

Who this is for: The founder, ops lead, or first compliance hire at a small company that needs enough governance to pass diligence and not get burned.

Download the kit (Markdown) ↓5 artifacts. Every table also copies as CSV.

1. Startup AI system inventory

Spreadsheet

The minimum viable inventory. Five columns, kept in a shared sheet.

Template

SystemPurposeVendorData processedOwner
<system><data categories><name>

Worked example

SystemPurposeVendorData processedOwner
Support assistantdraft support repliesVendor APIcustomer emails, order infoHead of Support
Code assistantdev productivityVendor IDEsource code (no prod secrets)CTO
Sales email tooloutreach draftingVendor SaaSprospect names, public company infoHead of Sales
Analytics summariesdashboard narrativesembedded in BI toolaggregated product metricsData

Acceptance criteria

  • Every AI tool in use has a row, including embedded features and free-tier use.
  • Each row names an owner.
  • The sheet is reviewed at least quarterly, even if briefly.

2. One-page acceptable use policy

Document

The whole AI policy for a small company. One page.

Template

One page. Everyone reads it at onboarding.

  • Approved tools: [list]
  • Never put in an AI tool: customer personal data, secrets or credentials, unreleased financials, anything a customer contract prohibits
  • Always: treat output as a draft and check it; do not paste large blocks of proprietary code into third-party tools
  • New tool: ask [person] before using it for work
  • Problems: tell [person] if an AI tool causes an error or exposes data; no blame for speaking up

Worked example

"Approved: [Assistant], [Code tool] (enterprise plan). Never enter customer personal data, passwords, API keys, or unreleased financials into any AI tool, including personal accounts. Treat AI output as a draft and verify it. Want a new tool? Ask [CTO] first. If an AI tool causes a mistake or leaks something, tell [CTO] right away; you will not be blamed for reporting it."

Acceptance criteria

  • It fits on one page and lists approved tools and forbidden data categories.
  • Everyone acknowledges it at onboarding.
  • It names one person as the approval and escalation point.

3. Vendor contract AI review checklist

Spreadsheet

The three clauses a small company should not sign an AI vendor without.

Template

ClauseWhat to look forPresent?Action if missing
Training-data useour data is not used to train the vendor's models, or opt-out is available and we take itY / Nrequest the enterprise/opt-out plan; get it in writing
Data handling and deletionwhere data is processed, retention period, deletion on requestY / Nask for the DPA; confirm region and retention
Liability and IPwe own outputs; some indemnity for IP claims on outputsY / Npush for output ownership at minimum; note residual risk

Worked example

ClauseVendor statusAction
Training-data useopt-out available on the Team plan, not defaultupgraded to Team; opt-out confirmed by email
Data handling / deletionDPA covers 30-day retention, EU processingacceptable
Liability / IPwe own outputs; no IP indemnityaccepted; low exposure for our use, noted in the inventory

Acceptance criteria

  • All three clauses are checked before signing any AI vendor.
  • Missing clauses have an action and, if accepted, a noted residual risk.
  • The result is recorded next to the vendor in the inventory.

4. AI data flow summary

Spreadsheet

One diagram-in-words: what personal data goes to which AI tool, and where it ends up.

Template

Data categorySourceAI tool it reachesSent howStored where / how longBasis
<category>API / SaaS / embeddedconsent / contract / legitimate interest

Worked example

Data categorySourceAI toolSent howStored / how longBasis
Customer email contentsupport inboxSupport assistant (Vendor API)API per ticketvendor: 30 days; ours: with the ticketcontract performance
Prospect name + companyCRMSales email toolSaaS syncvendor: account lifetimelegitimate interest
Source coderepoCode assistantIDE pluginvendor: 0 days (zero-retention)n/a (not personal data)

Acceptance criteria

  • Every flow of personal data into an AI tool is listed with its basis.
  • Vendor and internal retention are both recorded.
  • The summary is something you could hand to a customer's security reviewer.

5. Due diligence AI governance questionnaire response

Document

A reusable set of answers for the AI governance section of a customer or investor security questionnaire.

Template

Keep current. Reuse across deals.

  • Do you maintain an AI system inventory? yes / how often reviewed
  • Do you have an AI acceptable use policy? yes / acknowledged at onboarding
  • How is customer data protected when AI tools are used? the data flow summary in brief; opt-outs taken
  • Do you use customer data to train models? no / with the opt-outs in place
  • Human oversight of AI decisions affecting individuals? where applicable, describe it
  • Incident process for AI failures? brief description
  • Sub-processors that are AI vendors: list, with links to their compliance pages

Worked example

"We maintain an inventory of all AI tools in use, reviewed quarterly. All staff acknowledge a one-page AI acceptable use policy at onboarding. Customer data sent to AI tools is limited to what the feature requires; we use enterprise plans with training opt-outs on every AI vendor that offers one, and we do not permit customer personal data in tools without a DPA. We do not use customer data to train models. AI-assisted outputs to customers are reviewed by a person before sending. AI-related errors are handled under our incident process [link]. Our AI sub-processors are: [list with compliance-page links]."

Acceptance criteria

  • Answers are true and match the inventory, policy, and data flow summary.
  • The AI sub-processor list is current.
  • The response is version-controlled and reused rather than rewritten per deal.

Governance controls this kit produces evidence for

Completing the artifacts above gives you a head start on the evidence requirements for these controls.

MGV-002
MGV-002

The inventory and vendor checklist are a lightweight intake and approval process.

SCT-007
SCT-007

The one-page policy is the acceptable use policy for external AI tools.

PRC-001
PRC-001

The three-clause vendor check is proportionate vendor due diligence.

DGC-002
DGC-002

The data flow summary documents personal data handling across AI tools.

HOC-001
HOC-001

Even the lightweight inventory records enough to reason about each system's risk.

This kit backs one playbook. Read the full guidance for the reasoning behind each artifact.

Decide what to implement next

Assess your governance gaps, then create an action plan with owners and target dates. Build and export without an account; sign in when you want to save your plan.

Start the AI governance assessment →