Plainstart Back to the kit

Article

AI Data Governance for Small Business, a Plain Checklist

"Data governance" sounds like something with a compliance department attached. For a small business it is much simpler: knowing what information is safe to put into an AI tool, and checking each tool before you trust it with anything sensitive. You can do the whole thing on one page.

Here is the plain version.

The one question behind all of it

Before any business data goes into any AI tool, answer this: if this tool kept a copy of what I am about to enter, or used it to train itself, would that be a problem?

If yes, that data does not go in until you have checked the tool properly. If you are not sure, treat it as a yes.

Sort your data into three buckets

You do not need a formal classification scheme. Three buckets is enough:

  • Public. Already out in the world. Fine in any tool.
  • Internal. Business information that is not sensitive. Use care, prefer approved tools.
  • Confidential. Customer details, employee details, financial figures, contracts, anything under an NDA. This only goes into a tool that has passed the checks below.

Most accidents happen because someone treated Confidential data as if it were Internal. The buckets fix that.

Check any tool before Confidential data touches it

Five questions. If any answer is bad, the tool is not approved for sensitive data yet.

  1. Does it train on what you enter? Free consumer tiers often do, with no way to stop it. You want a business tier where training on your data is off.
  2. Where does the data go, and for how long? Look for a published retention policy you can live with.
  3. Who can see it? Individual logins, multi-factor authentication on, your data not visible to other customers.
  4. Does using it break any rule you are bound by? Privacy law in your country, industry rules, customer contracts.
  5. Who owns this decision in your business? Name a person. Without an owner, tools get approved by nobody and used by everybody.

When something goes wrong

Someone will paste the wrong thing in eventually. The businesses that handle it well have one habit: report it fast, fix it fast, no blame. A mistake someone hides is far more expensive than one they flag the same day.

Get the checklist and the policy free

The free Plainstart AI Usage Policy includes the core of all this: the never-enter list, the approved-tools approach, and the reporting habit.

[Download the free AI Usage Policy.] Editable, plain language, ready to adapt.

The full kit adds the complete Data Governance Checklist as a standalone tool you run once per AI tool, plus the plan to roll it all out.

General guidance, not legal advice. Check against your local privacy law.

Free download

The AI Usage Policy your team can actually follow

One page, plain language, ready to put in front of staff today. No cost, no catch.

Get the free policy