In brief A proportionate AI governance pack for a small regulated firm is eight documents, most a page or less: an AI register, a short use policy, a named accountable owner, specific DPIAs, vendor due-diligence notes, a monitoring record, an audit-trail convention, and a two-paragraph incident playbook. Reviewed annually and after any significant new tool — no risk department or GRC budget required.
Everything above can be run by a firm with no risk department and no GRC budget — that is the point. The checklist is the whole programme: tick off what you already have, and the gaps are your to-do list. The template below gives you each document as a fill-in-the-blanks page.
The reasoning behind every item — which regulatory hook demands it, and what proportionate looks like — is in the AI governance series: the UK guide maps each control to Consumer Duty, SM&CR, UK GDPR, SYSC and record-keeping; the jurisdiction guides do the same for the EU, US, UAE & DIFC, Singapore, Hong Kong and Australia.
Two habits make the pack real rather than shelf-ware. First, the register is the gate: new tools go on it before they are used, not after — that single discipline prevents most shadow-AI problems. Second, the monitoring record is your evidence: a simple log of sampled reviews, findings and fixes is what turns “we have controls” into something you can demonstrate.
This page and the template are for informational purposes only and do not constitute regulated financial advice, legal advice, or a compliance opinion. Adapt the pack with a qualified compliance professional.
Frequently asked questions
How much AI governance does a small regulated firm actually need?
Eight working documents, most a page or less — perhaps eight to twelve pages in total, reviewed annually and after any significant new tool. Deliberately not an enterprise framework: model risk committees and algorithmic ethics boards solve problems a 12-person firm does not have. What regulators ask of a small firm is proportionate, evidenced control by named humans.
What goes in an AI register?
Every AI tool in use — including the unofficial ones — with its purpose, the data it touches, the vendor, and whether it is client-facing. Reviewed quarterly, and anything not on it is not approved. You cannot govern what you have not identified, and the register is the control every serious regulator now expects first.
Who should own AI governance in a small firm?
One named senior manager with approval authority over new AI uses — in a UK advice firm usually the SMF16 (compliance oversight) or an SMF1/SMF3 who already owns operations. The point is not a new role but making an existing one explicit, with the Statement of Responsibilities updated to reflect it.
Is the template free?
Yes — enter your name, email and phone number and the PDF downloads immediately. There's no follow-up sequence and no obligation; if you'd rather talk it through first, book a discovery call instead.