Thanks. Chris will be in touch.

Systemic Assurance

AI Governance for UK SMEs
Sized for a small team.

AI governance is the set of policies, controls and evidence that show your business uses AI safely and legally. For a UK SME that means UK GDPR, the ISO 42001 management standard, and EU AI Act duties if you touch EU users. Ignite AI builds that layer for you, sized for a small team.

The problem

Your team is already using AI. Governance starts with seeing it.

Most businesses we meet use AI daily before anyone has written a rule for it. Staff paste client emails into free chatbots to save an hour. That is shadow AI.

75%

of knowledge workers use AI at work.

80%

of AI users at small and medium-sized companies bring their own AI tools to work.

60%

of leaders worry their leadership lacks a plan and vision to implement AI.

Source: Microsoft and LinkedIn, 2024 Work Trend Index, AI at work is here. Now comes the hard part.

Shadow AI is already here

Staff use personal accounts on work data, and you cannot see where it goes.

Bans get ignored

Policies written as a list of prohibitions, by someone not doing the work, are forgotten within a month.

The fear is real

A data leak, a UK GDPR breach or an AI error in front of a client can cost you a contract and your reputation.

The standards are confusing

ISO 42001, the EU AI Act, NIST AI RMF and the UK approach overlap. None of them says where a 40-person firm should start.

How it works

Five steps from hidden AI use to rules Claude applies for you.

We write policy from what is already happening in your business, then build it into the tool your team uses.

1 Find the AIyou already use Tools, accounts anddata in use today 2 AI Manifesto Human governance:red lines, green lanes,who signs off 3 Technicalgovernance ISO 42001, UK GDPR,EU AI Act, NIST AI RMF 4 Policy builtinto Claude The enforcement layerapplies it on every task 5 Reviewed ona cadence Risk register withnamed owners New AI use found at review goes back to step 1 1 Find the AI you already use Tools, accounts and data in use 2 AI Manifesto Human governance: red lines,green lanes, who signs off 3 Technical governance ISO 42001, UK GDPR,EU AI Act, NIST AI RMF 4 Policy built into Claude The enforcement layer appliesit on every task 5 Reviewed on a cadence Risk register with named owners New AI use found at review goes back to step 1
  1. Find the AI you already use, so the policy describes your real business.
  2. Write your AI Manifesto: who is accountable and where a person stays in the loop. Signed by your leadership.
  3. Map the technical governance: controls, a risk register and evidence.
  4. Build the policy into Claude, so it applies from the first day.
  5. Review on a cadence, with named owners.

How we remove fear and risk

Rules that work before your team has learned them.

Every request your team makes passes through your policy first. Here is what that looks like.

A REQUEST "Reply to the client,update the invoiceand tidy old files." Your policy, built into Claude Drafts wait for a person before sending Finance systems are read only Archive rather than delete Anything client-facing waits for sign-off Works only in folders you approve THE RESULT A draft waiting foryour approval. Nothingsent, deleted orchanged unseen. A REQUEST "Reply to the client, update theinvoice and tidy old files." Your policy, built into Claude Drafts wait for a person to send Finance systems are read only Archive rather than delete Client-facing work waits for sign-off Works only in folders you approve THE RESULT A draft waiting for your approval.Nothing sent, deleted or changedunseen.

Policy that Claude enforces for you

This is where we differ. A policy only protects you if people follow it, and in the first months most of your team will not know it well. So we build your policy into Claude itself, as an enforcement layer that applies the rules on every task, whether or not the person asking has read them yet.

In practice Claude drafts and waits for a person before anything is sent, reads financial systems without changing them, archives rather than deletes, and holds anything a client will see for sign-off. It works only in the folders you approve. Your policy is working from the first day, while your people are still learning it.

UK government guidance, September 2026

We follow the DSIT AI Risk Management Toolkit

The Department for Science, Innovation and Technology published its AI Risk Management Toolkit on 8 September 2026. It sets out how to identify AI risks, agree your risk appetite, score likelihood and impact, and choose a treatment for each risk. Our governance systems follow this guidance, so the risk register we build with you lines up with what the UK government expects.

Download the AI Risk Management Toolkit (PDF, 36 pages) →

© Crown copyright 2026. Contains public sector information licensed under the Open Government Licence v3.0. Source: GOV.UK.

UK GDPR and ISO 42001

UK GDPR applies once AI touches personal data. Higher-risk processing needs a DPIA. ISO 42001 turns your controls into evidence an auditor can check.

People who have governed AI before

Our AI Governance Lead, Dr Joseph Ross, is a Fellow of the BCS and an AI Ethics Adviser for a UK Police Force's Ethics Committee. We are members of Anthropic's Claude Partner Network.

Which framework applies to you?

Most UK SMEs need more than one. Here is where each one fits.

UK approach United Kingdom Principles-based. Enforcedby existing regulators(ICO, FCA). Best for: domesticinnovation and agility EU AI Act EU and global exports Prescriptive law. Applies ifyou serve EU customers orprocess EU citizen data. Best for: market accessfor high-risk AI ISO 42001 International Management standard. Notlegally required, and acredibility signal in tenders. Best for: supply chaintrust and systemic risk NIST AI RMF USA and global A risk managementframework we use forred-teaming and agent safety. Best for: technicalrobustness and security UK approach United Kingdom Principles-based. Enforced by existingregulators (ICO, FCA). Best for: domestic innovation and agility EU AI Act EU and global exports Prescriptive law. Applies if you serve EUcustomers or process EU citizen data. Best for: market access for high-risk AI ISO 42001 International Management standard. Not legallyrequired, and a credibility signal in tenders. Best for: supply chain trust, systemic risk NIST AI RMF USA and global A risk management framework we usefor red-teaming and agent safety. Best for: technical robustness, security
Summarised from the framework comparison in Go deeper below, which also covers the UAE AI Office Principles.

What it costs

Two packages. Buy one, the other, or both.

From £2,950, exc VAT

See all pricing

Human governance · 14 to 21 days

AI Manifesto

Red lines and green lanes, human-in-the-loop protocols by workflow, an acceptable-use policy, an accountability map and a board-ready Manifesto document.

Framework implementation · 3 to 6 weeks

Technical Governance

AI risk audit, control mapping to the frameworks you need, EU AI Act risk classification where it applies, audit trail design and certification-ready documentation.

Sold separately. Set up before we build Claude for Teams, our governed AI operating system.

Speak to us

Start with the Blueprint.

Don't start building until you have the foundation. Download our free AI Manifesto Template, the exact governance starting point we use with our SME clients. Or talk it through with Chris.

The template includes a Risk Register Template and Policy Headers. Not sure where AI is used in your business yet? Book a SPARK Discovery.

Go deeper

More on AI governance for UK SMEs

How does UK AI governance differ from the EU?

The UK employs a principles-based, decentralised approach to AI governance, emphasising proportionality and innovation. Unlike the prescriptive EU AI Act, UK SMEs are governed by existing regulators (ICO, FCA) enforcing core principles like fairness and accountability. For business leaders, this means compliance is outcome-focused, often requiring frameworks like ISO 42001 to demonstrate "Duty of Care" under the Companies Act 2006.

What does good AI governance look like for an SME?

Six things. Get them in place and you're ahead of most companies ten times your size.

  1. An AI policy your staff will actually read. One or two pages.
  2. A data boundary. What's fine to share with AI, what never leaves the building.
  3. An approval route. Who says yes to a new tool, and how.
  4. A risk register. The handful of things that could go wrong, and who owns each.
  5. A DPIA where personal data is involved. Required under UK GDPR for higher-risk processing.
  6. Evidence. Dated records, so you can prove any of the above on request.

Read next: Is AI use covered by UK GDPR? · Do UK SMEs need ISO 42001? · Who provides AI data protection audits? · How to write an AI policy

How to choose an AI governance partner in the UK
  • Do they work at SME scale, or is it Big-4 governance built for banks?
  • Is a senior person doing the work, or a junior with a template?
  • Do they know the actual standards: ISO 42001, NIST AI RMF, CDEI assurance?
  • Do you get evidence you can reuse, or a report for a drawer?
  • Can they train your team, so the policy survives real work?

Ask those of anyone you're considering, us included. Every price is on our pricing page.

Comparing the frameworks in detail
FrameworkJurisdictionBest forIgnite strategy
ISO 42001InternationalSupply Chain Trust & Systemic RiskFull Implementation for Tier 1 Suppliers
EU AI ActEU / Global ExportsMarket Access for High-Risk AIGap Analysis & Documentation
NIST AI RMFUSA / GlobalTechnical Robustness & SecurityRed-Teaming & Agent Safety
UK Principles (CDEI)United KingdomDomestic Innovation & AgilityAligning with ICO & FCA Guidance
UAE AI Office PrinciplesUnited Arab EmiratesGCC Market Access & Public-Sector ProcurementDual-Jurisdiction Governance, UAE FZCO Delivery

Most UK SMEs need more than one framework. The Technical Governance package selects and implements the right combination for your jurisdictional exposure rather than locking you into a single standard. Most clients run more than one in parallel, so scope depends on how many frameworks and jurisdictions are in play.

The Ignite AI Manifesto: the Shield, the Heart and the Engine

Governance starts with culture. Before we touch the code, we install the "Shield," the "Heart," and the "Engine."

1. The Shield (Safety), governance and risk. If you don't have an AI strategy, you have a security breach. We apply military-grade COMSEC principles to protect IP and cut "Shadow AI" risk.

2. The Heart (Culture), education and buy-in. The barrier isn't code; it's fear. We act as Cultural Transformation Guides, moving your workforce from the "fear zone" to the "growth zone" via our 90-day CHANGE programme.

3. The Engine (System), automation and agents. We audit workflows to identify low-value admin. We replace manual drudgery with AI agents, freeing leadership to focus on strategy.

AI policy that people can actually follow

An AI policy is the written statement of what your organisation will and will not do with AI, which data may be used where, and who decides. Most fail for the same reason: they are written as prohibitions by someone who is not doing the work, so they describe a business the team does not recognise and get ignored within a month. We write policy from what is already happening, which means starting with a look at the AI use you have rather than the AI use you assume.

AI risk management and assessment

Risk management here means identifying where an AI system could produce a materially wrong outcome, deciding which of those you will accept and which you will control, and recording the reasoning. A risk register that is never revisited is documentation. One reviewed on a cadence, with named owners, is governance. Where the processing warrants it, that includes a Data Protection Impact Assessment (DPIA) rather than an assumption that one is not needed.

A DPIA is a Data Protection Impact Assessment. UK GDPR requires one before you start higher-risk processing of personal data, which a lot of AI use counts as. It's a structured way to spot and reduce the risk before it bites.

Governing AI agents

An AI agent decides its own steps toward a goal, which is precisely what makes it useful and precisely what makes it harder to govern than a chatbot. The controls that matter are different: what systems it may reach, what it may do without a human, what it must log, and how you would stop it. Most AI policies written before agents existed do not answer any of those, and were never intended to.

Governing Claude and Claude Code

Tools that read your files and act on them raise a different question from tools you paste text into. Claude works against a folder on a real machine; Claude Code operates on real repositories. The governance question is which folders, whose machines, what the retention posture of the specific tier in use actually is, and what evidence you keep. Those are answerable, and they should be answered before rollout rather than during an incident.

Process mapping as a governance input

You cannot govern a process you cannot describe. Where a workflow is about to have AI applied to it, mapping how it currently runs is frequently the step that exposes the real control gap, and it does so before any technology is introduced rather than after.

How the Claude Partner Network shapes our governance work

Ignite AI Solutions is a UK member of Anthropic's Claude Partner Network. Our governance work draws on Anthropic's own published material. Our ISO 42001 control mapping references Anthropic's deployment guidance, and our AI Manifesto templates include red lines drawn from Anthropic's Acceptable Use Policy. The result is governance built around how Claude is trained, deployed and audited, rather than a generic governance product retrofitted to AI.

We run that work from our UK company and our UAE FZCO, so clients with exposure in both jurisdictions get one governance approach. We take no commission on licences from any vendor.

Common questions

What is AI governance for UK businesses?

AI governance is the framework of policies, processes, and oversight mechanisms that ensure AI is used responsibly, securely, and in compliance with regulations. For UK businesses, this includes alignment with the UK AI regulatory framework, GDPR compliance, ISO 42001 standards, and establishing clear accountability chains for AI-driven decisions.

What is an AI Manifesto?

An AI Manifesto is a governance document that defines how your organisation will use AI. It covers: which data AI can and cannot access, who is accountable for AI decisions, human oversight requirements, acceptable use policies, risk management protocols, and compliance requirements. Ignite AI Solutions builds a bespoke AI Manifesto as a fixed-price package, set up alongside your team's Claude training.

Do UK SMEs need to comply with the EU AI Act?

If your UK business serves EU customers or processes EU citizen data, certain EU AI Act provisions apply. The UK is also developing its own AI regulatory framework. Regardless of legal requirements, implementing governance (ISO 42001 alignment, AI Manifesto, human-in-the-loop protocols) protects your business from regulatory risk, reputational damage, and operational failures.

Does my SME need an AI policy?

Yes, if staff use AI tools on work data. A short written policy covers approved tools, what data can go into them, and who signs off new use. It protects you under UK GDPR and reassures clients during due diligence.

Is AI use covered by GDPR?

Yes. If your AI processing touches personal data, UK GDPR applies, and higher-risk processing needs a DPIA. Putting customer or staff data into a public AI tool without checks is where SMEs get caught out.

Do we need ISO 42001?

You're not legally required to. It's becoming a credibility signal in tenders, and it gives you a practical checklist for running AI safely. For SMEs bidding to larger clients, it's worth the effort.

How it works

Three steps, from first conversation to a system your team runs every day.

Each step stands on the one before it, delivered by our senior team as a member of the Claude Partner Network.

  1. Step 1 · Discover

    SPARK Discovery

    One-off · 4 to 6 weeks

    We find where AI pays back first in your business, and what has to be made safe before anything gets built. You keep the findings report whatever you decide next.

  2. Step 2 · Train and govern

    Claude training and governance, side by side

    Training days · Governance pack · Run together

    Your team learns Claude on their own work while the rules are drawn around it. Shadow AI comes inside a boundary instead of being banned.

  3. Step 3 · Build and run

    Claude for Teams, your governed AI operating system

    Monthly · Run with your team

    Claude built around how your business works, then weekly sprints, cadence meetings, ongoing training and ROI measured every month. It runs inside the governance you set in step 2.

Every price is on one page: see pricing.

Chris Duffy, founder of Ignite AI Solutions

About the author

Chris Duffy Founder and Chief AI Officer, Ignite AI Solutions

Chris is the founder of Ignite AI Solutions, a Certified Chief AI Officer and one of the Top 20 AI Leaders of 2026. He is a regular expert source for Forbes on AI and cybersecurity, and a member of the UKAI Council supporting accredited pathways for upskilling. He was nominated for 3 awards at the National AI Awards 2026, including the Aiconics Award for responsible AI. A UK Special Forces veteran, he now helps UK SMEs adopt AI safely and effectively.

More about Chris · Chris in Forbes · LinkedIn · Substack

Chat on WhatsApp