AI governance for UK SMEs

Practical AI governance for smaller organisations

Whether AI use has moved ahead of your controls, or you want the right controls in place before adopting more, we help you put practical, proportionate governance in place.

You may need this if…

  • Staff are using personal ChatGPT, Claude or other AI accounts for work.
  • Customer, candidate or other sensitive information may be entered into AI tools.
  • AI is influencing customer, candidate or other material business decisions.
  • AI features are being switched on inside existing business software without a clear approval process.
  • Management cannot confidently list which AI tools and use cases are currently in use.
Start here

AI Control Snapshot

Answer 8 questions in around 3 minutes for a quick first check of your current or planned AI use. It helps management see whether there may be material control gaps worth addressing — whether AI is already in use or you want sensible controls in place before adopting more.

No contact details are required to receive your result. Results are immediate.

This result is a practical control-gap indicator, not a certification, legal assessment, technical security assessment or regulatory approval.

AI Governance Baseline

£495

Turn Snapshot findings into a practical governance baseline: document AI use, prioritise material risks and proportionate controls, and set clear rules and next steps.

At the end, management should know what AI is being used, where the material risks are, who owns them and what needs to happen next.

Includes a short questionnaire, a 30-minute management discussion and a 30-minute handover. Normally delivered within 5 working days of receiving the required information.

What’s included

  • AI use and tool register
  • Review of up to 5 current AI use cases
  • Practical risk categorisation
  • Short AI acceptable-use policy
  • One-page staff guidance
  • Action and risk register
  • Concise management summary and handover

Excludes legal advice, certification, regulatory approval, technical security testing, ISO 42001 readiness, unlimited consulting and control implementation. No compliance guarantee.

How it works

01

Understand current AI use

02

Identify material gaps and risks

03

Prioritise proportionate controls

Practical, evidence-based governance

The approach is informed by current UK AI and data-protection guidance, ICO expectations, NIST AI risk-management principles and ISO/IEC 42001 concepts where proportionate. The focus is on practical controls for smaller organisations rather than unnecessary complexity.

We normally assess processes and use cases rather than asking for sensitive client, customer or employee data.

About Baseline Governance

Baseline Governance provides practical AI governance support for smaller organisations, helping management understand how AI is being used, where material risks exist and which controls are proportionate.

Our work is led by professionals with senior experience delivering complex technology, data and AI programmes, including within large and regulated organisations. We focus on practical, proportionate governance that smaller organisations can put into use quickly.

Baseline Governance is a trading name of Berrymoon Ltd, registered in England and Wales.

Company number: 07984930. Registered office: 4th Floor, 4 Tabernacle Street, London, United Kingdom, EC2A 4LU.