---
title: "Capstone: build an AI governance pack for an SME"
description: "The brief You will assemble a complete AI governance pack for a small or medium-sized business. Use your own organization, a client, or the case below…"
url: https://optimizeall.com/learn/ai-governance-eu-ai-act/capstone-build-an-sme-governance-pack
updated: 2026-10-05
---

AI Governance & Regulation: EU AI Act, NIST AI RMF and ISO/IEC 42001 · Capstone: an AI governance pack for an SME · lesson 17 of 17 · 25 min

# Capstone: build an AI governance pack for an SME

## The brief

You will assemble a complete AI governance pack for a small or medium-sized business. Use your own organization, a client, or the case below. The pack should be proportionate: enough to satisfy a demanding enterprise client's AI questionnaire and to meet the EU AI Act duties that apply, without creating a bureaucracy the business will ignore.

**Case (if you need one): "Crescent Digital"**, a 30-person marketing agency with offices in Lahore and Dubai, serving e-commerce and healthcare-adjacent clients in Pakistan, the UAE, Saudi Arabia, the UK and Germany. AI uses:

1. Generative text and image tools for content production.
2. A client-branded website chatbot for a dental clinic group (UAE and UK patients).
3. AI voice-overs, including a cloned voice of one client's founder.
4. Meeting transcription for client calls.
5. A lead-scoring add-on in the agency's own CRM.
6. A pilot of an AI tool that pre-screens job applicants for the agency's own hiring.

## The pack contents

| # | Artifact | Built in | Target length |
|---|---|---|---|
| 1 | AI policy (signed) | Lesson 5.1 | 1 to 2 pages |
| 2 | Acceptable use (traffic lights) + approved tools list | Lesson 5.1 | 1 page + table |
| 3 | RACI for AI decisions | Lesson 5.1 | Table |
| 4 | AI inventory with classification and risk scores | Lessons 1.2, 5.2 | One entry per use case |
| 5 | Jurisdiction register | Lessons 4.1, 4.2 | Table |
| 6 | Impact assessment(s) for items above threshold | Lesson 5.2 | 3 to 6 pages each |
| 7 | Vendor due diligence records | Lesson 5.3 | Questionnaire per standard/enhanced tool |
| 8 | Transparency and disclosure SOP + synthetic asset register | Lessons 2.4, 6.1 | 1 to 2 pages + register |
| 9 | Data protection addendum (lawful bases, retention, transfers) | Lesson 6.2 | Table |
| 10 | AI literacy plan | Lesson 2.1 | YAML/1 page |
| 11 | Incident response runbook | This lesson | 1 page |
| 12 | Compliance calendar and review cycle | Lesson 2.5 | CSV |
| 13 | Framework mapping (NIST functions / ISO 42001 clauses) | Lessons 3.1, 3.2 | Table |

## Step-by-step build (suggested 6 to 8 hours)

**Step 1: Inventory and classify (90 minutes).** List each use case. For Crescent Digital: the dental chatbot carries Article 50(1) chatbot duties for UK/EU exposure and data protection duties (health-adjacent data could appear in chats); the founder voice clone is a deepfake under Article 50(4) wherever EU audiences see it and needs written consent; the hiring pre-screen is an Annex III high-risk use (deployer duties from 2 December 2027, and GDPR/UK GDPR automated decision rules now); the lead scoring is low-to-moderate risk profiling.

**Step 2: Decide what is out of bounds (30 minutes).** Run the Article 5 screen. Confirm no emotion recognition in hiring interviews, no inference of sensitive traits. Decide whether the hiring pilot proceeds at all; a small agency might reasonably decide the governance cost outweighs the benefit and stop the pilot. That is a legitimate governance outcome.

**Step 3: Policy, acceptable use, RACI (60 minutes).** Draft with AI, edit to reality, get leadership sign-off.

**Step 4: Impact assessments (90 minutes).** Complete combined assessments for the dental chatbot and, if continued, the hiring tool. Include DPIA modules.

**Step 5: Vendor due diligence (60 minutes).** Standard questionnaires for chatbot platform, transcription, voice tool, and hiring tool vendor.

**Step 6: Transparency, data protection, literacy (60 minutes).** Disclosure SOP with approved wording in English and Arabic; synthetic asset register; lawful bases and retention table; literacy plan.

**Step 7: Incident runbook and calendar (45 minutes).**

## Incident response runbook template

```text
AI INCIDENT RUNBOOK v1.0 (owner: AI lead; backup: COO)
What counts: harmful, false or offensive AI output reaching a client or the public; personal or
confidential data exposed via an AI tool; AI system acting outside its permissions; disclosure missing
on a chatbot or deepfake; complaint alleging AI bias or deception; vendor security incident.

1. CONTAIN (within 1 hour): disable feature flag / pause automation / revoke tokens. Preserve logs.
2. ASSESS (within 4 hours): what happened, who is affected, what data, which jurisdictions.
3. NOTIFY: client account lead immediately; DPO/privacy lead if personal data involved (GDPR
   breach notification to authority within 72 hours where required; check UAE/KSA timelines);
   vendor; serious incidents involving high-risk systems per AI Act rules when applicable.
4. FIX: root cause (prompt, data, permissions, vendor change); add a regression test.
5. LEARN (within 10 working days): short post-incident review; update inventory, SoA, training.
Contacts: AI lead / Privacy lead / Security / Client comms / Legal counsel.
```

## Framework mapping table (excerpt)

| Pack artifact | NIST AI RMF | ISO/IEC 42001 | EU AI Act |
|---|---|---|---|
| AI policy, RACI, literacy plan | Govern | Clauses 5, 7; Annex A policies and organization | Art. 4 |
| Inventory, classification, jurisdiction register | Map | Clause 4, 6; Annex A resources | Art. 5, 6, 50 classification |
| Impact assessments, tests | Map, Measure | Clause 6, 8; Annex A impact assessment | Art. 26, 27 (if applicable) |
| Vendor records | Govern, Manage | Annex A third-party relationships | Art. 26 (instructions), Art. 53 information |
| Disclosure SOP, asset register | Manage | Annex A information for interested parties | Art. 50 |
| Incident runbook, calendar | Manage | Clauses 9, 10 | Art. 26 monitoring, Art. 73 incidents |

## Quality checklist before you submit

- Every inventory entry has an owner, a classification with reasoning and a review date.
- Any Annex III use has a deployer-duty plan dated before 2 December 2027, or a documented decision to stop.
- Every chatbot and voice agent has tested disclosure wording.
- Every real-person likeness has a consent record.
- Every standard/enhanced vendor has a questionnaire and DPA where relevant.
- The pack states clearly that it is not legal advice and lists items to confirm with counsel.
- Total length is something leadership will actually read: aim for under 30 pages plus registers.

## How to present it

Prepare a 10-minute briefing for leadership: the inventory heat map, the three biggest risks and their mitigations, the decisions needed (for example "continue or stop the hiring pilot"), and the calendar. Governance succeeds when leaders make informed decisions, not when documents exist.

## Video lecture: Capstone: build an AI governance pack for an SME

Lecture coming soon · 13 chapters · about 8 minutes. Read the full transcript below.

1. Capstone: SME governance pack
2. Why build the pack
3. Crescent Digital's six AI uses
4. Analogy: a fire safety file
5. Thirteen artifacts
6. Steps 1 and 2
7. Steps 3 to 6
8. Step 7: incident runbook
9. Quality checklist
10. Common mistakes
11. Presenting to leadership
12. Watch me do it: the pack front page
13. Present and decide

## Lecture transcript

### Capstone: SME governance pack

This is where everything comes together. You're going to build a complete AI governance pack for a small business: the kind of pack that answers a demanding enterprise client's AI questionnaire, meets the EU AI Act duties that apply, and still gets read by the people who have to follow it. Use your own organization, a client, or our case company, Crescent Digital, a thirty-person agency in Lahore and Dubai with clients across the Gulf, the UK and Germany.

### Why build the pack

Why build a full pack instead of just reading about governance? Because the pack is what you'll actually use: to answer client questionnaires in hours instead of weeks, to onboard staff, to respond calmly to an incident, and to show regulators and partners that you take AI seriously. Building it once, properly, turns everything in this course into a reusable asset for your business or your clients.

### Crescent Digital's six AI uses

Crescent Digital uses AI in six ways: generative text and images for content; a client-branded chatbot for a dental clinic group with patients in the UAE and UK; AI voice-overs, including a cloned voice of one client's founder; meeting transcription; lead scoring in its own CRM; and a pilot tool that pre-screens job applicants for its own hiring. Pause for a second and guess which of these carries the heaviest obligations. If you said the hiring pilot, you're right. It's an Annex three high-risk use.

### Analogy: a fire safety file

An analogy for the capstone: think of this pack like a building's fire safety file. There's a floor plan showing where everything is, which is your inventory. There are rules for occupants, your policy and acceptable use. There are inspection records, your assessments and vendor checks. There are signs on the walls, your disclosures. There's an evacuation plan, your incident runbook. And there's a calendar of drills and inspections. An inspector expects all of it, but the real goal is that people know what to do.

### Thirteen artifacts

Your pack has thirteen artifacts, and you've already built drafts of most of them in earlier lessons. A signed AI policy. A traffic-light acceptable-use page and approved tools list. A RACI. The AI inventory with classifications and risk scores. A jurisdiction register. Impact assessments for anything above your threshold. Vendor due diligence records. A disclosure procedure and synthetic asset register. A data protection addendum. An AI literacy plan. An incident runbook. A compliance calendar. And a framework mapping to NIST, ISO and the AI Act.

### Steps 1 and 2

Step one, inventory and classify. For Crescent, the dental chatbot needs chatbot disclosure for UK and EU exposure and careful data protection, because patients may mention health details. The founder's voice clone is a deepfake wherever EU audiences see it, so disclose it and keep written consent. The hiring pre-screen is high-risk, with deployer duties from December twenty twenty-seven and automated decision rules already in force. Step two: decide what's out of bounds. And here's a mature governance move: a small agency might decide the hiring pilot isn't worth the governance cost and stop it. That's a legitimate outcome.

### Steps 3 to 6

Steps three to six. Draft the policy, acceptable use and RACI with AI help, edit them to match reality, and get leadership to sign. Complete combined impact assessments for the dental chatbot and, if you continue it, the hiring tool, including data protection modules. Send questionnaires to the chatbot platform, transcription, voice and hiring vendors. Then write the disclosure procedure with approved wording in English and Arabic, set up the synthetic asset register, document lawful bases and retention, and finalize the literacy plan.

### Step 7: incident runbook

Step seven is the incident runbook and calendar. The runbook defines what counts as an AI incident: harmful or false output reaching a client or the public, data exposed through an AI tool, an AI system acting outside its permissions, a missing disclosure, a bias or deception complaint, or a vendor security incident. Then five moves: contain within an hour, assess within four, notify the right people, including the privacy lead and, where required, the data protection authority within seventy-two hours, fix the root cause with a regression test, and learn within ten working days.

### Quality checklist

Before you submit, run the quality checklist. Every inventory entry has an owner, a reasoned classification, and a review date. Any Annex three use has a plan dated before December twenty twenty-seven, or a documented decision to stop. Every chatbot and voice agent has tested disclosure wording. Every real-person likeness has a consent record. Every significant vendor has a questionnaire and processing agreement. The pack says clearly it isn't legal advice and lists items to confirm with counsel. And it's short enough that leadership will actually read it: aim for under thirty pages plus registers.

### Common mistakes

Common mistakes in capstone packs. Writing for an imaginary company instead of documenting what actually happens. Producing sixty pages that leadership will never read, when twenty focused pages plus registers is better. Skipping the decisions: a pack that lists risks but asks leadership for nothing hasn't done its job. And forgetting the maintenance plan: without owners, review dates and a calendar, the pack is out of date within a quarter.

### Presenting to leadership

A final tip for presenting: lead with the heat map and one sentence per risk, not with the law. Leaders respond to: here's what we use, here's where the real risk is, here's what we're doing, and here's what we need from you. Keep the legal detail in the appendix for anyone who wants it. Then ask for one or two clear decisions, and schedule the next review before you leave the room.

### Watch me do it: the pack front page

Watch me do it. I open the governance pack folder for Crescent Digital and assemble the front page, which is the only page most leaders will read. At the top: a heat map built from the register's risk scores. The hiring pre-screen sits top right, the dental chatbot and the founder voice clone sit in the middle, content tools bottom left. Below it, three risk sentences. One: the hiring pilot is high-risk, with deployer duties from December twenty twenty-seven and automated-decision rules already live. Two: the dental chatbot may receive health details, so it needs disclosure, minimization and a no clinical advice rule. Three: the voice clone needs signed consent and a disclosure line, both now done. Then the decisions box: continue or stop the hiring pilot, and approve the literacy plan budget. Then the next three calendar dates. Finally, the index: thirteen artifacts, each with a link, an owner and a review date, and one line stating that this pack is not legal advice, with two items listed for counsel. One page, and every claim on it links to evidence behind it.

### Present and decide

Finally, present it. Prepare a ten-minute leadership briefing: the inventory heat map, the three biggest risks and what you're doing about them, the decisions you need from leadership, like whether to continue the hiring pilot, and the calendar. Governance succeeds when leaders make informed decisions, not when documents exist. That's the course. You can now read the EU AI Act with confidence, use NIST and ISO frameworks, navigate the UK, US, Gulf and Pakistan, and build a practical governance pack. Go build yours.

## Key takeaways

- A proportionate SME governance pack has about 13 artifacts, most built from earlier lessons, and should stay short enough to be read.
- Classification drives effort: chatbots and deepfakes need disclosure, Annex III uses need deployer plans before 2 December 2027, or a decision to stop.
- An incident runbook defines AI incidents and sets contain, assess, notify, fix and learn steps with timelines.
- Governance succeeds when leaders make informed decisions; present the heat map, top risks and decisions needed.

## Try it

Assemble the 13-artifact governance pack for your organization or the Crescent Digital case, run the quality checklist, and deliver a 10-minute leadership briefing with decisions needed.

- [Previous: Data protection and AI: GDPR and its cousins](https://optimizeall.com/learn/ai-governance-eu-ai-act/data-protection-and-ai-in-marketing)
- [All lessons of AI Governance & Regulation: EU AI Act, NIST AI RMF and ISO/IEC 42001](https://optimizeall.com/learn/ai-governance-eu-ai-act)
