AI Governance & Regulation: EU AI Act, NIST AI RMF and ISO/IEC 42001Capstone: an AI governance pack for an SME · Lesson 17 of 17

Capstone: build an AI governance pack for an SME

Article · 25 min · 8 min lecture

Video lecture

Capstone: build an AI governance pack for an SME

13 chapters · about 8 min · full transcript

Coming soon

Chapter 1 of 13

Capstone: SME governance pack

  • Answer enterprise questionnaires
  • Meet applicable AI Act duties
  • Proportionate and readable
  • Case: Crescent Digital

The narrated lecture is in production

Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.

Chapters

The brief

You will assemble a complete AI governance pack for a small or medium-sized business. Use your own organization, a client, or the case below. The pack should be proportionate: enough to satisfy a demanding enterprise client's AI questionnaire and to meet the EU AI Act duties that apply, without creating a bureaucracy the business will ignore.

Case (if you need one): "Crescent Digital", a 30-person marketing agency with offices in Lahore and Dubai, serving e-commerce and healthcare-adjacent clients in Pakistan, the UAE, Saudi Arabia, the UK and Germany. AI uses:

  1. Generative text and image tools for content production.
  2. A client-branded website chatbot for a dental clinic group (UAE and UK patients).
  3. AI voice-overs, including a cloned voice of one client's founder.
  4. Meeting transcription for client calls.
  5. A lead-scoring add-on in the agency's own CRM.
  6. A pilot of an AI tool that pre-screens job applicants for the agency's own hiring.

The pack contents

#ArtifactBuilt inTarget length
1AI policy (signed)Lesson 5.11 to 2 pages
2Acceptable use (traffic lights) + approved tools listLesson 5.11 page + table
3RACI for AI decisionsLesson 5.1Table
4AI inventory with classification and risk scoresLessons 1.2, 5.2One entry per use case
5Jurisdiction registerLessons 4.1, 4.2Table
6Impact assessment(s) for items above thresholdLesson 5.23 to 6 pages each
7Vendor due diligence recordsLesson 5.3Questionnaire per standard/enhanced tool
8Transparency and disclosure SOP + synthetic asset registerLessons 2.4, 6.11 to 2 pages + register
9Data protection addendum (lawful bases, retention, transfers)Lesson 6.2Table
10AI literacy planLesson 2.1YAML/1 page
11Incident response runbookThis lesson1 page
12Compliance calendar and review cycleLesson 2.5CSV
13Framework mapping (NIST functions / ISO 42001 clauses)Lessons 3.1, 3.2Table

Step-by-step build (suggested 6 to 8 hours)

Step 1: Inventory and classify (90 minutes). List each use case. For Crescent Digital: the dental chatbot carries Article 50(1) chatbot duties for UK/EU exposure and data protection duties (health-adjacent data could appear in chats); the founder voice clone is a deepfake under Article 50(4) wherever EU audiences see it and needs written consent; the hiring pre-screen is an Annex III high-risk use (deployer duties from 2 December 2027, and GDPR/UK GDPR automated decision rules now); the lead scoring is low-to-moderate risk profiling.

Step 2: Decide what is out of bounds (30 minutes). Run the Article 5 screen. Confirm no emotion recognition in hiring interviews, no inference of sensitive traits. Decide whether the hiring pilot proceeds at all; a small agency might reasonably decide the governance cost outweighs the benefit and stop the pilot. That is a legitimate governance outcome.

Step 3: Policy, acceptable use, RACI (60 minutes). Draft with AI, edit to reality, get leadership sign-off.

Step 4: Impact assessments (90 minutes). Complete combined assessments for the dental chatbot and, if continued, the hiring tool. Include DPIA modules.

Step 5: Vendor due diligence (60 minutes). Standard questionnaires for chatbot platform, transcription, voice tool, and hiring tool vendor.

Step 6: Transparency, data protection, literacy (60 minutes). Disclosure SOP with approved wording in English and Arabic; synthetic asset register; lawful bases and retention table; literacy plan.

Step 7: Incident runbook and calendar (45 minutes).

Incident response runbook template

AI INCIDENT RUNBOOK v1.0 (owner: AI lead; backup: COO)
What counts: harmful, false or offensive AI output reaching a client or the public; personal or
confidential data exposed via an AI tool; AI system acting outside its permissions; disclosure missing
on a chatbot or deepfake; complaint alleging AI bias or deception; vendor security incident.

1. CONTAIN (within 1 hour): disable feature flag / pause automation / revoke tokens. Preserve logs.
2. ASSESS (within 4 hours): what happened, who is affected, what data, which jurisdictions.
3. NOTIFY: client account lead immediately; DPO/privacy lead if personal data involved (GDPR
   breach notification to authority within 72 hours where required; check UAE/KSA timelines);
   vendor; serious incidents involving high-risk systems per AI Act rules when applicable.
4. FIX: root cause (prompt, data, permissions, vendor change); add a regression test.
5. LEARN (within 10 working days): short post-incident review; update inventory, SoA, training.
Contacts: AI lead / Privacy lead / Security / Client comms / Legal counsel.

Framework mapping table (excerpt)

Pack artifactNIST AI RMFISO/IEC 42001EU AI Act
AI policy, RACI, literacy planGovernClauses 5, 7; Annex A policies and organizationArt. 4
Inventory, classification, jurisdiction registerMapClause 4, 6; Annex A resourcesArt. 5, 6, 50 classification
Impact assessments, testsMap, MeasureClause 6, 8; Annex A impact assessmentArt. 26, 27 (if applicable)
Vendor recordsGovern, ManageAnnex A third-party relationshipsArt. 26 (instructions), Art. 53 information
Disclosure SOP, asset registerManageAnnex A information for interested partiesArt. 50
Incident runbook, calendarManageClauses 9, 10Art. 26 monitoring, Art. 73 incidents

Quality checklist before you submit

  • Every inventory entry has an owner, a classification with reasoning and a review date.
  • Any Annex III use has a deployer-duty plan dated before 2 December 2027, or a documented decision to stop.
  • Every chatbot and voice agent has tested disclosure wording.
  • Every real-person likeness has a consent record.
  • Every standard/enhanced vendor has a questionnaire and DPA where relevant.
  • The pack states clearly that it is not legal advice and lists items to confirm with counsel.
  • Total length is something leadership will actually read: aim for under 30 pages plus registers.

How to present it

Prepare a 10-minute briefing for leadership: the inventory heat map, the three biggest risks and their mitigations, the decisions needed (for example "continue or stop the hiring pilot"), and the calendar. Governance succeeds when leaders make informed decisions, not when documents exist.

Key takeaways

  • A proportionate SME governance pack has about 13 artifacts, most built from earlier lessons, and should stay short enough to be read.
  • Classification drives effort: chatbots and deepfakes need disclosure, Annex III uses need deployer plans before 2 December 2027, or a decision to stop.
  • An incident runbook defines AI incidents and sets contain, assess, notify, fix and learn steps with timelines.
  • Governance succeeds when leaders make informed decisions; present the heat map, top risks and decisions needed.

Check your understanding

Quick questions to lock in the lesson. They don’t count towards your certificate.

  1. In the Crescent Digital case, which use carries the heaviest AI Act obligations?
  2. A small agency decides to stop its AI hiring pilot after assessing governance costs. How should this be viewed?
  3. Within what time frame does GDPR generally require notifying the supervisory authority of a reportable personal data breach?

Put it into practice

Assemble the 13-artifact governance pack for your organization or the Crescent Digital case, run the quality checklist, and deliver a 10-minute leadership briefing with decisions needed.

Enrol for free to save your progress

Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.