Playbooks
Step-by-step playbooks for SMB operators putting AI into real workflows — the 30/60/90-day adoption sprint, the governance and risk layer that keeps it from becoming a liability, the people-side work that makes it stick, and the EU AI Act and ISO 42001 obligations in plain terms.
The AI Adoption Sprint
A practical 30/60/90-day sequence for SMB and mid-market leaders — three phases, three deliverables, three honest go/no-go moments.
Most small and mid-sized companies don't fail at AI adoption because they chose the wrong tool. They fail because nothing forced a decision.
Read articleThe most common mistake in the first month of an AI initiative is buying something.
Read articleOnce phase one produces a named workflow, an owner, and a number to hit, the temptation shifts immediately.
Read articleMost SMB AI pilots never get an explicit decision made about them. They either fade quietly as attention moves to the next priority, or they expand by default because nobody actually sa…
Read articleThe whole series
Read end to end, the sprint is one argument: adoption fails without a sequence, so fix the sequence before touching the tool. Thirty days to name one workflow, one owner, and one number; thirty to run a single protected pilot and count the hours it saves; thirty to decide scale, fix, or stop and put just enough governance around what survives. The checklists matter less than the order — each phase only works if the one before it produced something real.
AI Governance Playbook Series
Seven short playbooks that put a workable governance layer around AI — triage, vendors, data, rollout, roles, documentation, and generative content.
Start here — Playbook 1Phase 1 · Decide
Run the triage before anything goes live.
Phase 2 · Before go-live
Vendor, data, and rollout controls.
Governing AI you buy — which is most of what an SMB actually uses
Most SMB “AI governance” problems are really vendor-management problems. You're not training models — you're turning on an AI feature inside a CRM, using ChatGPT or Claude for content a…
Read playbookThe minimum viable version of data governance an SMB can actually run
“Garbage in, garbage out” applies whether you're training a model or just feeding one. The fact that data is available doesn't mean you're allowed to use it.
Read playbookGated deployment — from pilot to production to retirement
An AI system that works in testing can still behave differently once real users and real data hit it.
Read playbookPhase 3 · Run and prove it
Ownership, documentation, and everyday use.
Who does this at a company that doesn't have an AI Officer, a DPO, or an ethics committee
A full AI governance model names eight distinct roles: an AI Officer, IT, Business, Legal, a Data Protection Officer, Cybersecurity, ESG, Compliance, and Procurement.
Read playbookThe artifact that actually satisfies an auditor, a client, or your own future self
Every other playbook in this series produces a decision — a risk tier, a vendor approval, a bias check result, a go-live sign-off.
Read playbookGoverning the AI use case most SMBs actually have: content, chat, and customer-facing generation
Generative AI is where most SMBs actually meet AI risk day to day — not in a credit-scoring model, but in a marketing draft, a chatbot reply, or an AI-written customer email.
Read playbookThe whole series
The seven playbooks are one system, not a menu. Playbook 1 decides how much governance a use case needs; 2 through 4 control what you buy, what data it touches, and how it goes live; 5 through 7 assign the owners, keep the record, and govern everyday generative use. The thread running through all of them is documentation — every playbook produces a decision, and a decision only protects you once it is written down in the register.
AI Risk Management
Identify, assess, and control the risks that derail AI projects — seven risk categories, a scoring framework, per-category mitigations, and the governance cadence that keeps it running.
Start here — Part 1Phase 1 · Identify & assess
Name the categories, then score and register each risk.
The seven categories that actually derail AI projects
Most AI transformation failures are not model failures. Industry trackers commonly cite failure or stall rates in the 70–90% range — and the causes they point to sit in governance, data, and change management, not the model.
Read playbookScore it, register it, review it on a schedule
Risk identification runs at three points, not once: before kickoff as a pre-mortem, at every stage gate, and monthly through build and rollout.
Read playbookPhase 2 · Control & run
Mitigations, the governance cadence, and the templates that keep it alive.
What to do about each of the seven risk types
Mitigation is not generic. Each of the seven risk categories fails for its own reason, so each has its own controls.
Read playbookWho reviews what, how often, and when to escalate
A risk framework only works if someone is accountable for running it. Keep the structure small and the cadence fixed.
Read playbookThe four artefacts that keep the framework running
Four working templates carry the framework: the risk register, the RAID log, the pre-mortem checklist, and the stage-gate checklist.
Read playbookThe whole series
The five parts move from naming risk to controlling it. Start with the seven categories, score each risk on likelihood and impact, then apply the mitigation that fits the category rather than a generic one. Governance and cadence keep it running; the templates keep it honest. The aim is not a complete risk register — it is noticing the early warning sign while it is still cheap to fix.
Use Case Analysis
Choose the right use case before you build anything: gather six to ten real candidates, score them on value and feasibility, and rule out the four patterns that burn pilot budgets.
Start here — Part 1The Use Case Inventory
Six to ten real candidates, sourced on purpose — not the one idea that happened to walk in the door.
Read playbookThe Value × Feasibility Matrix
A use case doesn't earn a green light for being exciting. It earns one for scoring well on two axes at once.
Read playbookThe Disqualifier Checklist
Four patterns worth ruling out on sight — they've burned more pilot budgets than any wrong platform choice ever has.
Read playbookThe whole series
Three steps, in order. Gather more than one candidate so the winner actually beats something. Score them on value and feasibility rather than enthusiasm. Then rule out the four patterns that should never reach the matrix. What comes out is a use case worth building a business case for — not the idea that happened to walk in the door.
Measure Value, Risk, Costs & KPIs
Five parts on the question that decides whether any of it mattered: did the AI project pay for itself? Screen the idea, translate the metrics, do the numbers, get it approved, then measure what actually happened.
Start here — Part 1Phase 1 · Frame it
Screen the idea, then connect the metric to a business number.
The Value, Cost & Risk Canvas
Someone brings you an AI idea. A vendor pitches a solution. A team proposes an initiative.
Read playbookThe Metric-to-KPI Translator
If you cannot draw the chain from a technical metric to a business number, you don't have a business case yet. You have an interesting technical project.
Read playbookPhase 2 · Cost it and get it signed
Build the ROI figure and put it in front of the person who approves it.
The 4-Step ROI Calculator
Four steps. Every AI ROI calculation, however dressed up, reduces to this: what does the process cost today, what will it cost with AI, what's the benefit across three scenarios — never…
Read playbookThe One-Page Business Case
Four hundred to five hundred words. Two minutes to read. If a sentence doesn't help someone decide, cut it — model architecture, vendor names, API detail, and the project plan all live…
Read playbookPhase 3 · Prove it
Track the dashboard against the number you committed to.
The whole series
Five parts take an AI idea from hunch to measured result: screen it, translate the technical metric into a business number, build the ROI across three scenarios, put the conservative case into a one-page business case, then track it against a fixed dashboard. The last part is the one almost everyone skips — and it is the only one that proves the projection was real.
EU AI Regulation for SMBs
What the EU AI Act and the digital rules around it actually ask of a small or mid-sized company — by role and risk tier, not by headline.
Start here — Part 1What the 2026 changes actually mean for a company your size
The EU AI Act applies to an SMB the same way it applies to anyone: by your role in the chain and the risk tier of what you use, not by headcount.
Read playbookThe regulations that arrive alongside the AI Act — and the ones you can ignore
The AI Act rarely arrives alone. Most SMBs using AI already sit inside one or two of the EU's other digital rules — and meet them in the same vendor contract, not in five separate projects.
Read playbookThe whole series
The AI Act is the rule everyone has heard of, but it rarely stands alone. Part 1 sorts out what the Act actually asks of a company by size and role now that the Digital Omnibus has moved the deadlines and introduced the Small Mid-Cap path. Part 2 maps the rules that arrive beside it — GDPR, NIS2, the CRA, the Data Act, DORA — and, just as usefully, which ones a typical SMB can leave to the enterprises. The point in both is the same: compliance starts with one inventory and one vendor-onboarding checklist, not a project per regulation.
Change Management & Adoption Enablement Series
Six short playbooks that turn buy-in from a hope into a sequence — awareness, desire, training, coaching, and the reinforcement that keeps adoption from sliding back.
Start here — Playbook 1Phase 1 · Frame it
Name the gap before you try to close it.
Why a working pilot and an adopted pilot are two different projects
A tool that passes testing and a team that uses it daily are not the same outcome — yet most AI budgets are spent as if they were.
Read playbookBuilding the case before you build the training
People rarely resist the tool. They resist the reason for it that nobody said out loud.
Read playbookPhase 2 · Build the skill
Training and coaching, mapped to how people actually work.
Designing training that fits the job, not a generic demo
A finance controller and a sales rep need the same tool explained two different ways — that is curriculum design, not a demo.
Read playbookThe coaching layer between trained and competent
Ability is earned through repetition with feedback, not a single session — and the knowing-doing gap is where most rollouts quietly stall.
Read playbookPhase 3 · Make it stick
What keeps adoption from decaying after the launch excitement fades.
Why adoption regresses within 90 days without a deliberate hold
Old habits are the default gravity. Reinforcement is the only phase that fights it, and it is the one almost every rollout skips.
Read playbookThe four numbers that tell you if adoption actually happened
Usage, non-reversion, confidence, and observed competence — tracked on the same 30/90/180-day rhythm as the ROI checkpoints.
Read playbookThe whole series
Awareness and desire earn the right to train; training and coaching build the skill; reinforcement is what makes the first ninety days outlast the rollout’s own momentum. Without it, the sprint’s scale-or-stop decision has no adoption data to decide with.
EU AI Act & ISO 42001 Compliance Series
Five short playbooks that connect the existing governance work to the two names an SMB owner will actually be asked about: the EU AI Act and ISO 42001.
Start here — Playbook 1Phase 1 · Know where you stand
Classification and the calendar.
The EU AI Act's four tiers, mapped to what an SMB actually deploys
Most SMB AI use — a CRM's AI feature, a chatbot, an AI writing tool — sits in the limited-risk tier, which is exactly the tier already live.
Read playbookThe compliance calendar, not the whole regulation
Prohibited practices and AI-literacy duties are live, GPAI obligations are live, and transparency duties are live — the heavy high-risk deadlines are what's still ahead.
Read playbookPhase 2 · Connect it to what you already have
The crosswalk, so existing governance work counts.
Your existing governance work already covers most of the standard's clauses
Leadership, Planning, Operation and Performance Evaluation are already covered by the existing series — what is missing is a documented Support clause and a continual-improvement cadence.
Read playbookThe Article 50 duties that are live right now
Telling people they are talking to an AI, labelling generated content, and disclosing emotion-recognition use — three duties most SMBs miss by not knowing they apply.
Read playbookPhase 3 · Prove it
The record that survives an audit or a client questionnaire.
The whole series
Classify what you have built, know which obligations are already enforceable versus still ahead, map what you have already written to ISO 42001’s clauses, close the transparency gap that is live today, and keep one file that proves all of it — an extension of the governance work, not a parallel project.