A new AI tool can look harmless at first. An employee wants help drafting emails. A software provider adds an AI assistant. A manager finds a service that can screen applicants, summarize customer calls, or recommend prices. The business question is not simply whether the tool uses AI. It is whether this particular use could expose sensitive information, affect people, create a costly error, or leave the company relying on a vendor it has not examined.
This AI risk assessment checklist for small businesses is designed for that decision. It will not produce a certification or settle every legal question. It gives an owner or manager a consistent way to decide which uses are routine, which need safeguards, and which deserve specialist review.

What an AI risk assessment should accomplish
A useful assessment connects the tool to a real business use. It records who owns the decision, what information the tool receives, who may be affected, how people will review the output, and what the vendor has disclosed. The result may be approval, approval with conditions, a pause for more information, or a decision not to proceed.
The National Institute of Standards and Technology organizes its voluntary AI Risk Management Framework around four functions: Govern, Map, Measure, and Manage. NIST describes the work as continuous and iterative, not as a one-time ordered checklist. A small-business process can borrow that logic without pretending that a short form is the full framework.
1. Define the proposed use
Write down what the tool will do in plain language. “Use AI for marketing” is too broad. “Draft first versions of social posts from public product information, with a manager approving every post” is specific enough to review.
Record the business owner, intended users, expected benefit, and the decision or activity the output will support. If the purpose changes later, review the tool again. A service approved for brainstorming may need a different decision before it is used with customer records or employment information.
2. Identify the information the tool will receive
List the data employees may type, upload, connect, or expose through an integration. Look for customer details, employee records, financial information, contracts, confidential business plans, credentials, health information, and regulated data.
Ask whether the same result can be achieved with less sensitive information. Check the vendor’s terms and privacy documentation to learn whether prompts and files are retained, shared with service providers, used to train models, or available to administrators. The Federal Trade Commission has warned AI companies that privacy and confidentiality commitments must match their actual practices. Your own promises to customers and employees matter too.
3. Consider who could be affected by a wrong output
An error in an internal brainstorming list is usually easier to correct than an error used to approve a loan, select a job candidate, set a price, diagnose a problem, or communicate legal or financial guidance. Note who may be affected and how difficult it would be to detect and reverse a mistake.
Higher-impact uses may require legal, privacy, security, employment, or industry advice. The checklist helps identify that need; it does not replace it.
4. Decide what human review is required
“A human is involved” is not enough. Name the person or role responsible for checking the output. Explain what they will verify, what source information they can use, and when they must reject or escalate a result.
Employees also need permission to challenge the tool. If speed targets reward automatic acceptance, a review step may exist only on paper.
5. Complete an AI vendor risk assessment
An AI vendor risk assessment questionnaire should focus on facts that change your decision. Ask the vendor:
- What data does the service collect, retain, and use?
- Can customer inputs or outputs be used to train or improve models, and can that use be disabled?
- Which subprocessors or outside model providers support the service?
- What access controls, logging, deletion options, and incident-notification practices are available?
- How does the vendor evaluate accuracy, harmful outputs, bias, security, and changes to the system?
- What happens to company data when the contract ends?
Request documentation that matches the risk. A low-impact writing aid may not warrant the same evidence as a system that handles payroll data or influences employment decisions.
6. Set safeguards and approval conditions
Practical safeguards might restrict the data employees can enter, limit the tool to approved accounts, require source checking, prohibit automated external decisions, add management approval, or require a pilot before wider use. Assign an owner to each safeguard. A condition without an owner is unlikely to last.
Record the decision and the reason behind it. This gives the business a usable history when a customer, insurer, auditor, employee, or future manager asks how the tool was approved.
7. Schedule the next review
AI services change quickly. Review the use when the vendor changes its model or terms, the business connects new data, the tool begins supporting a more important decision, an incident occurs, or a new requirement applies. Set a review date even if none of those events happens.
Keep an AI use inventory
An AI use inventory template gives the business one place to see what is already in use. At minimum, record the tool, vendor, purpose, business owner, users, information involved, people affected, approval status, safeguards, and next review date. Include AI features inside existing software, not only standalone chatbots.
Start by asking department leaders which tools employees use and which existing platforms have recently added AI features. Make it safe for employees to disclose unsanctioned use. The first inventory is meant to improve visibility, not create a surprise disciplinary exercise.
When a starter guide is enough
A compact process may be enough when the business has a limited number of AI uses and needs a credible place to begin. Our AI Risk Management Starter Guide turns the steps above into six consistent PDF forms, including an AI use inventory template, an initial risk screen, and an AI vendor review form.
A business with many tools, multiple reviewers, formal policy needs, or regular reporting will outgrow a set of individual forms. The Small Business AI Governance Toolkit — Professional Edition adds a centralized Excel control center, policy material, manager guidance, employee training, and a broader operating process.