Guidance for small companies

Right-size the framework for teams under 50 people: which controls are non-negotiable, which can be lightweight, and which to defer.

What to keep, what to skip

Control Small-org floor What to use
AI inventory Required A maintained sheet in Notion / Confluence / SharePoint List
Acceptable use policy Required One page, acknowledged in your HRIS (BambooHR, HiBob)
Vendor due diligence Required for any AI processing customer data Vanta / Drata questionnaires; review the vendor SOC 2 + DPA
Human oversight Required for any customer-facing or HR-impacting AI Documented reviewer + escalation path in your ticketing tool
Bias testing Required if AI affects hiring, credit, pricing Fairlearn notebook run on every model change
Board reporting Quarterly written update is enough One-page email to the leadership channel
Formal ISMS Defer until ~50 staff or first enterprise customer asks ISO/IEC 42001 lite via Vanta or Secureframe

Do this Monday

  1. Turn on Microsoft Purview or Google Workspace DLP rules that block sensitive data into ChatGPT, Claude, Gemini consumer URLs.
  2. Replace consumer AI with the team plan (ChatGPT Team, Claude for Work, Gemini Business) so prompts are excluded from training.
  3. Publish a one-page AI policy and have everyone sign it in your HRIS.

Reviewer hot-buttons

  • Even at five people, can you show who owns AI risk?
  • Is shadow AI (personal ChatGPT, Claude on phones) addressed?
  • Is the vendor list current — including embedded AI features in tools you already use?