← Back to Playbooks

Playbook 1 — Governance Starter

Decide whether — and how much — governance a given AI use actually needs

The Core Rule: Proportional Governance

Not every AI use needs a committee. A spam filter and a hiring-screening tool are not the same risk, and treating them the same either paralyzes the business or leaves the real risk uncontrolled. The rule is simple: the higher the impact on people, the stricter the control.

Run every new AI use through the 3-question triage below before it touches customers, employees, or money.

The 3-Question Triage

1. Does it touch a sensitive decision?

Hiring, credit or pricing, performance review, access to a service, health or safety. If yes, this is at minimum “High” below.

2. Does it process personal or sensitive data?

Names, contact details, financial history, health data, behavioral tracking. If yes, GDPR applies regardless of the answer to Q1 — go to Playbook 3.

3. Does it act without a human checking the output first?

Auto-sends an email, auto-approves a transaction, auto-rejects an application. Autonomy raises the tier one level from where Q1 and Q2 put you.

Areas of Impact — Check Before You Set the Tier

Scoring how much governance a use case needs means checking it against each of these. A use case that touches several isn’t automatically high-risk; one that touches none is a strong candidate for light governance.

Risk Tiers — SMB Version

Adapted from the EU AI Act’s four-tier model, rewritten with examples an SMB actually runs into rather than banking or hospital cases.

Tier What it means SMB example
Minimal No meaningful effect on people; internal or low-stakes Spam filter, internal search, a meeting-notes summarizer
Limited Some effect, but reversible and low-stakes; usually just needs disclosure Marketing copy generation, an FAQ chatbot, background removal on product photos
High Touches a sensitive decision, processes sensitive data, or acts autonomously (per the triage above) Hiring-screening tool, a credit or pricing engine, performance-review scoring
Unacceptable Manipulative, exploitative, or social-scoring style use — not something to mitigate, something not to build Covert behavioral manipulation, untargeted biometric scraping, social scoring of employees or customers

Before You Approve Any New AI Use — Checklist

One-Page AI Use Intake Form

One page, filled in before approval. Pull the answers straight from the triage and checklist above:

Next Steps

Tier = Minimal or Limited with no personal data: log it (Playbook 6) and move on. Tier = High, or personal data is involved, or it’s bought from a vendor: continue to Playbook 2 (if vendor-supplied) and Playbook 3 (data and bias) before it goes live. Tier = Unacceptable: stop, this is not a governance problem to solve, it’s a decision not to use it.