Systemic Assurance
AI Governance for UK SMEs
Sized for a small team.
AI governance is the set of policies, controls and evidence that show your business uses AI safely and legally. For a UK SME that means UK GDPR, the ISO 42001 management standard, and EU AI Act duties if you touch EU users. Ignite AI builds that layer for you, sized for a small team.
The problem
Your team is already using AI. Governance starts with seeing it.
Most businesses we meet use AI daily before anyone has written a rule for it. Staff paste client emails into free chatbots to save an hour. That is shadow AI.
75%
of knowledge workers use AI at work.
80%
of AI users at small and medium-sized companies bring their own AI tools to work.
60%
of leaders worry their leadership lacks a plan and vision to implement AI.
Source: Microsoft and LinkedIn, 2024 Work Trend Index, AI at work is here. Now comes the hard part.
Shadow AI is already here
Staff use personal accounts on work data, and you cannot see where it goes.
Bans get ignored
Policies written as a list of prohibitions, by someone not doing the work, are forgotten within a month.
The fear is real
A data leak, a UK GDPR breach or an AI error in front of a client can cost you a contract and your reputation.
The standards are confusing
ISO 42001, the EU AI Act, NIST AI RMF and the UK approach overlap. None of them says where a 40-person firm should start.
How it works
Five steps from hidden AI use to rules Claude applies for you.
We write policy from what is already happening in your business, then build it into the tool your team uses.
- Find the AI you already use, so the policy describes your real business.
- Write your AI Manifesto: who is accountable and where a person stays in the loop. Signed by your leadership.
- Map the technical governance: controls, a risk register and evidence.
- Build the policy into Claude, so it applies from the first day.
- Review on a cadence, with named owners.
How we remove fear and risk
Rules that work before your team has learned them.
Every request your team makes passes through your policy first. Here is what that looks like.
Policy that Claude enforces for you
This is where we differ. A policy only protects you if people follow it, and in the first months most of your team will not know it well. So we build your policy into Claude itself, as an enforcement layer that applies the rules on every task, whether or not the person asking has read them yet.
In practice Claude drafts and waits for a person before anything is sent, reads financial systems without changing them, archives rather than deletes, and holds anything a client will see for sign-off. It works only in the folders you approve. Your policy is working from the first day, while your people are still learning it.
UK government guidance, September 2026
We follow the DSIT AI Risk Management Toolkit
The Department for Science, Innovation and Technology published its AI Risk Management Toolkit on 8 September 2026. It sets out how to identify AI risks, agree your risk appetite, score likelihood and impact, and choose a treatment for each risk. Our governance systems follow this guidance, so the risk register we build with you lines up with what the UK government expects.
Download the AI Risk Management Toolkit (PDF, 36 pages) →
© Crown copyright 2026. Contains public sector information licensed under the Open Government Licence v3.0. Source: GOV.UK.
UK GDPR and ISO 42001
UK GDPR applies once AI touches personal data. Higher-risk processing needs a DPIA. ISO 42001 turns your controls into evidence an auditor can check.
People who have governed AI before
Our AI Governance Lead, Dr Joseph Ross, is a Fellow of the BCS and an AI Ethics Adviser for a UK Police Force's Ethics Committee. We are members of Anthropic's Claude Partner Network.
Which framework applies to you?
Most UK SMEs need more than one. Here is where each one fits.
What it costs
Two packages. Buy one, the other, or both.
From £2,950, exc VAT
Human governance · 14 to 21 days
AI Manifesto
Red lines and green lanes, human-in-the-loop protocols by workflow, an acceptable-use policy, an accountability map and a board-ready Manifesto document.
Framework implementation · 3 to 6 weeks
Technical Governance
AI risk audit, control mapping to the frameworks you need, EU AI Act risk classification where it applies, audit trail design and certification-ready documentation.
Sold separately. Set up before we build Claude for Teams, our governed AI operating system.
Speak to us
Start with the Blueprint.
Don't start building until you have the foundation. Download our free AI Manifesto Template, the exact governance starting point we use with our SME clients. Or talk it through with Chris.
The template includes a Risk Register Template and Policy Headers. Not sure where AI is used in your business yet? Book a SPARK Discovery.
Go deeper
More on AI governance for UK SMEs
How does UK AI governance differ from the EU?
The UK employs a principles-based, decentralised approach to AI governance, emphasising proportionality and innovation. Unlike the prescriptive EU AI Act, UK SMEs are governed by existing regulators (ICO, FCA) enforcing core principles like fairness and accountability. For business leaders, this means compliance is outcome-focused, often requiring frameworks like ISO 42001 to demonstrate "Duty of Care" under the Companies Act 2006.
What does good AI governance look like for an SME?
Six things. Get them in place and you're ahead of most companies ten times your size.
- An AI policy your staff will actually read. One or two pages.
- A data boundary. What's fine to share with AI, what never leaves the building.
- An approval route. Who says yes to a new tool, and how.
- A risk register. The handful of things that could go wrong, and who owns each.
- A DPIA where personal data is involved. Required under UK GDPR for higher-risk processing.
- Evidence. Dated records, so you can prove any of the above on request.
Read next: Is AI use covered by UK GDPR? · Do UK SMEs need ISO 42001? · Who provides AI data protection audits? · How to write an AI policy
How to choose an AI governance partner in the UK
- Do they work at SME scale, or is it Big-4 governance built for banks?
- Is a senior person doing the work, or a junior with a template?
- Do they know the actual standards: ISO 42001, NIST AI RMF, CDEI assurance?
- Do you get evidence you can reuse, or a report for a drawer?
- Can they train your team, so the policy survives real work?
Ask those of anyone you're considering, us included. Every price is on our pricing page.
Comparing the frameworks in detail
| Framework | Jurisdiction | Best for | Ignite strategy |
|---|---|---|---|
| ISO 42001 | International | Supply Chain Trust & Systemic Risk | Full Implementation for Tier 1 Suppliers |
| EU AI Act | EU / Global Exports | Market Access for High-Risk AI | Gap Analysis & Documentation |
| NIST AI RMF | USA / Global | Technical Robustness & Security | Red-Teaming & Agent Safety |
| UK Principles (CDEI) | United Kingdom | Domestic Innovation & Agility | Aligning with ICO & FCA Guidance |
| UAE AI Office Principles | United Arab Emirates | GCC Market Access & Public-Sector Procurement | Dual-Jurisdiction Governance, UAE FZCO Delivery |
Most UK SMEs need more than one framework. The Technical Governance package selects and implements the right combination for your jurisdictional exposure rather than locking you into a single standard. Most clients run more than one in parallel, so scope depends on how many frameworks and jurisdictions are in play.
The Ignite AI Manifesto: the Shield, the Heart and the Engine
Governance starts with culture. Before we touch the code, we install the "Shield," the "Heart," and the "Engine."
1. The Shield (Safety), governance and risk. If you don't have an AI strategy, you have a security breach. We apply military-grade COMSEC principles to protect IP and cut "Shadow AI" risk.
2. The Heart (Culture), education and buy-in. The barrier isn't code; it's fear. We act as Cultural Transformation Guides, moving your workforce from the "fear zone" to the "growth zone" via our 90-day CHANGE programme.
3. The Engine (System), automation and agents. We audit workflows to identify low-value admin. We replace manual drudgery with AI agents, freeing leadership to focus on strategy.
AI policy that people can actually follow
An AI policy is the written statement of what your organisation will and will not do with AI, which data may be used where, and who decides. Most fail for the same reason: they are written as prohibitions by someone who is not doing the work, so they describe a business the team does not recognise and get ignored within a month. We write policy from what is already happening, which means starting with a look at the AI use you have rather than the AI use you assume.
AI risk management and assessment
Risk management here means identifying where an AI system could produce a materially wrong outcome, deciding which of those you will accept and which you will control, and recording the reasoning. A risk register that is never revisited is documentation. One reviewed on a cadence, with named owners, is governance. Where the processing warrants it, that includes a Data Protection Impact Assessment (DPIA) rather than an assumption that one is not needed.
A DPIA is a Data Protection Impact Assessment. UK GDPR requires one before you start higher-risk processing of personal data, which a lot of AI use counts as. It's a structured way to spot and reduce the risk before it bites.
Governing AI agents
An AI agent decides its own steps toward a goal, which is precisely what makes it useful and precisely what makes it harder to govern than a chatbot. The controls that matter are different: what systems it may reach, what it may do without a human, what it must log, and how you would stop it. Most AI policies written before agents existed do not answer any of those, and were never intended to.
Governing Claude and Claude Code
Tools that read your files and act on them raise a different question from tools you paste text into. Claude works against a folder on a real machine; Claude Code operates on real repositories. The governance question is which folders, whose machines, what the retention posture of the specific tier in use actually is, and what evidence you keep. Those are answerable, and they should be answered before rollout rather than during an incident.
Process mapping as a governance input
You cannot govern a process you cannot describe. Where a workflow is about to have AI applied to it, mapping how it currently runs is frequently the step that exposes the real control gap, and it does so before any technology is introduced rather than after.
How the Claude Partner Network shapes our governance work
Ignite AI Solutions is a UK member of Anthropic's Claude Partner Network. Our governance work draws on Anthropic's own published material. Our ISO 42001 control mapping references Anthropic's deployment guidance, and our AI Manifesto templates include red lines drawn from Anthropic's Acceptable Use Policy. The result is governance built around how Claude is trained, deployed and audited, rather than a generic governance product retrofitted to AI.
We run that work from our UK company and our UAE FZCO, so clients with exposure in both jurisdictions get one governance approach. We take no commission on licences from any vendor.