Playbook 1 — Governance Starter
Decide whether — and how much — governance a given AI use actually needs
The Core Rule: Proportional Governance
Not every AI use needs a committee. A spam filter and a hiring-screening tool are not the same risk, and treating them the same either paralyzes the business or leaves the real risk uncontrolled. The rule is simple: the higher the impact on people, the stricter the control.
Run every new AI use through the 3-question triage below before it touches customers, employees, or money.
The 3-Question Triage
1. Does it touch a sensitive decision?
Hiring, credit or pricing, performance review, access to a service, health or safety. If yes, this is at minimum “High” below.
2. Does it process personal or sensitive data?
Names, contact details, financial history, health data, behavioral tracking. If yes, GDPR applies regardless of the answer to Q1 — go to Playbook 3.
3. Does it act without a human checking the output first?
Auto-sends an email, auto-approves a transaction, auto-rejects an application. Autonomy raises the tier one level from where Q1 and Q2 put you.
Areas of Impact — Check Before You Set the Tier
Scoring how much governance a use case needs means checking it against each of these. A use case that touches several isn’t automatically high-risk; one that touches none is a strong candidate for light governance.
- Fairness — does it treat comparable people or cases comparably?
- Accountability — is it clear who owns a bad outcome?
- Transparency & explainability — can you say why it did what it did?
- Security & privacy — what data does it touch, and how is it protected?
- Safety & health — could a wrong output cause physical or financial harm?
- Financial consequences — for the business, or for the people affected.
- Accessibility — can everyone who needs to use it, actually use it?
- Human rights — an overused phrase at SMB scale, but worth a beat for anything touching hiring, credit, or access to a service.
Risk Tiers — SMB Version
Adapted from the EU AI Act’s four-tier model, rewritten with examples an SMB actually runs into rather than banking or hospital cases.
| Tier | What it means | SMB example |
|---|---|---|
| Minimal | No meaningful effect on people; internal or low-stakes | Spam filter, internal search, a meeting-notes summarizer |
| Limited | Some effect, but reversible and low-stakes; usually just needs disclosure | Marketing copy generation, an FAQ chatbot, background removal on product photos |
| High | Touches a sensitive decision, processes sensitive data, or acts autonomously (per the triage above) | Hiring-screening tool, a credit or pricing engine, performance-review scoring |
| Unacceptable | Manipulative, exploitative, or social-scoring style use — not something to mitigate, something not to build | Covert behavioral manipulation, untargeted biometric scraping, social scoring of employees or customers |
Before You Approve Any New AI Use — Checklist
- I’ve run the 3-question triage and assigned a risk tier.
- If High or Unacceptable, no one has started using it in production yet.
- I know whether we’re building this or buying it from a vendor (changes which playbook applies next).
- I’ve named one person who owns this AI use going forward — not “the team.”
- It’s logged in the AI system inventory (Playbook 6) — even if the answer to everything above is “low risk.”
One-Page AI Use Intake Form
One page, filled in before approval. Pull the answers straight from the triage and checklist above:
- AI use name / one-line description
- Requested by / date
- Business owner (a named person — not “the team”)
- Built in-house or bought from a vendor
- Triage answers: sensitive decision? personal data? autonomous action?
- Resulting risk tier
- Data types involved
- Next playbook(s) to complete before go-live
- Approval: name + date
Next Steps
Tier = Minimal or Limited with no personal data: log it (Playbook 6) and move on. Tier = High, or personal data is involved, or it’s bought from a vendor: continue to Playbook 2 (if vendor-supplied) and Playbook 3 (data and bias) before it goes live. Tier = Unacceptable: stop, this is not a governance problem to solve, it’s a decision not to use it.