TL;DR: AI compliance is not the same for a 3-person startup and a 50-person team with enterprise contracts. This article gives three checklists scaled to your team size, covering AI tool inventory, data protection, vendor management, incident response, and regulatory requirements that actually apply at each size. Includes triggers for moving between tiers.
The problem with most AI compliance checklists is that they are written for an imaginary organization: one with a legal team, a compliance officer, a dedicated vendor management function, and enough revenue to absorb $50,000 in annual compliance overhead.
That is not a 3-person startup. It is also not most 20-person teams.
One-size-fits-all compliance guidance fails small teams in two ways. It causes over-engineering (3-person teams reading ISO 42001 requirements they will never need) and it causes under-engineering (50-person teams processing customer data without a basic AI acceptable use policy). Both failures carry real costs.
This guide gives you three distinct compliance checklists, one for each team size tier, calibrated to what actually applies and what can realistically wait. Each checklist item notes whether it is legally required (and by which regulation) or a best practice recommendation.
How to use this guide
Find your tier based on current headcount. Work through the checklist for your tier. Then read the "triggers" section at the end to understand which events should move you to the next tier immediately, regardless of headcount.
If you are already above Tier 1 but have not done Tier 1 work, start there. The tiers are sequential foundations, not alternatives.
Tier 1: 1 to 10 employees
At this size, the goal is not to build a compliance program. The goal is to avoid the most common and most serious mistakes while keeping compliance overhead close to zero.
What is truly required
Legal basis for personal data processing (GDPR required for EU data; US state law required for California, Colorado, Virginia residents) The most fundamental requirement that applies regardless of team size. If your product or services collect personal data from EU residents, you need a legal basis for processing (typically legitimate interest or consent), a privacy notice, and a process for handling data subject requests. There are no small-company exemptions under GDPR.
Vendor data processing agreements (DPAs) for AI tools that handle personal data (GDPR required) If you use AI tools that process personal data of EU users on your behalf, you need a Data Processing Agreement with those vendors. Most major AI vendors (OpenAI, Anthropic, Google, Microsoft) offer standard DPAs. This is not optional and not paperwork that can wait.
Basic awareness of what AI tools can and cannot access (Best practice; liability reduction) Establish a one-page rule: what data can go into AI tools and what cannot. Customer PII, health data, financial data, and unreleased product information should not be pasted into AI tools without a DPA in place. This is not a policy document at this stage. It is a team understanding that should be written down and communicated.
What can wait
At 1 to 10 people, you generally do not need:
- A formal AI governance policy document
- An AI incident response plan (though having one page of "what we do if something goes wrong" is helpful)
- ISO 42001 certification or any paid compliance framework
- A dedicated compliance role or designated AI officer
- Formal vendor due diligence processes beyond DPA confirmation
Tier 1 checklist
- AI tool inventory created. List every AI tool the team uses, what it does, what data it can access, and whether a DPA is in place. Update quarterly. (AI tool register template provides the format.)
- DPAs in place for AI vendors processing EU personal data. Confirm each vendor has been counter-signed or click-accepted.
- Privacy notice published if you collect personal data from users.
- Team briefed on data handling rules. One conversation or a shared document: what goes into AI tools and what does not.
- EU AI Act risk tier assessed if you are building an AI product that will be sold in the EU. Determine whether your product falls into prohibited, high-risk, limited-risk, or minimal-risk categories. This costs nothing to assess and the answer determines your future compliance obligations.
Tier 2: 11 to 50 employees
At this size, the compliance picture shifts. You are almost certainly onboarding employees who are not founders, which means policies need to be written down. You may have enterprise or regulated-industry customers whose contracts include compliance requirements. You probably have a larger AI tool footprint than you fully realize.
The goal at Tier 2 is formalization without over-engineering. Write down the policies. Assign the owners. Set up basic processes. Do not build the compliance function of a 500-person company.
What is required
AI acceptable use policy (Required by enterprise contracts; required by some state laws for AI use with personal data; strongly required by best practice once you have employees) The policy does not need to be long. It needs to cover: which AI tools are approved for use, what data categories can and cannot be used with AI tools, what output review requirements apply before customer-facing use, and who to contact if something goes wrong. See AI acceptable use policy template small teams.
Vendor due diligence process for new AI tools (Required by GDPR for processors; required by enterprise contracts; required by best practice) Before adopting a new AI tool that touches personal data or customer data, a designated person reviews the vendor's security posture, data handling practices, and DPA terms. This does not need to be a 40-question RFP. It needs to be a documented minimum check. See AI vendor due diligence checklist 2026.
AI incident response plan (Required for GDPR (72-hour breach notification requirement); strongly recommended for all teams) When an AI tool causes a data breach, produces harmful output, or takes an action that harms a customer, you need a process. GDPR requires you to notify the relevant supervisory authority within 72 hours of discovering a breach involving EU personal data. You cannot do that without an incident response plan. The plan can be brief. It needs to exist.
Data classification for AI systems (Best practice; required by several enterprise contracts; required for GDPR compliance) Define what data is confidential, what is internal, and what is public. Map which AI tools can access which classification. This is the foundation of data governance for AI and a requirement in most enterprise security questionnaires.
Designated AI governance owner (Best practice; required by some enterprise contracts) At Tier 2, someone needs to own AI governance. It does not need to be a dedicated role. It needs to be an explicit part of someone's responsibilities with the authority to make decisions about AI tool adoption and usage.
Tier 2 checklist
- Everything in Tier 1 is in place. Start here.
- AI acceptable use policy written, communicated, and signed by all employees. Review annually or when major new AI tools are adopted.
- Data classification scheme defined with AI tool access mapped to classifications.
- Vendor due diligence process documented with minimum criteria for AI tool adoption approval.
- DPAs in place for all AI tools touching personal data, not just EU personal data (US state privacy laws are catching up).
- AI incident response plan exists with clear steps, owners, and GDPR breach notification process if applicable.
- Designated AI governance owner identified with the role documented in their responsibilities.
- EU AI Act compliance assessed if you sell to EU customers. Identify which risk tier your AI products fall into and what obligations apply. See EU AI Act compliance guide for small teams.
- US state AI laws assessed for your hiring tools, HR AI, and any AI used in customer decisions. Particularly relevant if you have employees or customers in NYC, Illinois, Colorado, or New Jersey. See AI regulatory readiness scorecard for software and biotech teams.
- AI tool inventory maintained and reviewed quarterly. Assign the owner from the previous step to keep this current.
- Customer contract AI requirements reviewed. Pull your top 5 customer contracts and check for AI governance, data handling, or security requirements that affect your AI tool usage.
Tier 3: 51 to 200 employees
At this size, informal governance breaks down. The team is large enough that different departments are adopting AI tools independently. The AI tool inventory requires active maintenance. You likely have contractual compliance requirements from enterprise customers. If you operate in regulated industries, sector-specific AI governance requirements apply.
The goal at Tier 3 is a functioning governance program: not a compliance department, but a documented, maintained, and periodically audited program with clear ownership.
What is required
Formal AI governance policy suite (Required by enterprise contracts; required for ISO 42001 preparation; required by several sector-specific regulations) At this size, the AI acceptable use policy needs to be part of a policy suite: an AI acceptable use policy, an AI risk management policy, a data classification and handling policy, and a vendor management policy. These should be reviewed annually and updated when regulations change.
NIST AI RMF or equivalent framework adoption (Best practice; required for Texas TRAIGA safe harbor; referenced in many enterprise contracts) At Tier 3, you should adopt a formal AI risk management framework and document your governance program against it. NIST AI RMF is the most practical free option. This is the foundation for any future ISO 42001 certification work. See ISO 42001 vs NIST AI RMF for small teams.
Audit readiness (Required for enterprise contracts and regulated industries; required for ISO 42001 certification) Your governance documentation should be complete enough that an external auditor could review it and confirm your program is functioning. This means dated policies, evidence of training, records of vendor reviews, and logs of governance decisions.
Training program for all staff (Required by EU AI Act for EU-market products; required by GDPR for staff handling personal data; required by most enterprise contracts) All employees who use AI tools should receive documented training on the AI acceptable use policy, data handling rules, and how to identify and report AI incidents. Training records should be maintained.
Designated AI governance role or committee (Required by ISO 42001; required by several enterprise contracts; required for regulated industries) At Tier 3, AI governance ownership needs to be formalized. This may be a designated role (AI Governance Lead), a committee (AI Review Board), or a defined cross-functional responsibility. The key requirement is a documented decision-making process for AI tool adoption, risk assessment, and incident response.
Tier 3 checklist
- Everything in Tiers 1 and 2 is in place. Start here.
- Formal AI governance policy suite documented and approved. Acceptable use policy, risk management policy, data classification policy, vendor management policy.
- NIST AI RMF Govern, Map, Measure, Manage functions documented for your AI systems.
- All-staff AI governance training completed with records maintained.
- Designated AI governance role or committee established with documented responsibilities and decision authority.
- Annual AI risk assessment process defined and completed for all material AI systems.
- Third-party vendor assessment program operating with annual reviews for material AI vendors.
- EU AI Act compliance program in place if you have EU market exposure. High-risk systems: technical documentation, human oversight, conformity assessment.
- Incident response program tested. Tabletop exercise or simulation of an AI incident completed within the last 12 months.
- Enterprise customer compliance requirements catalogued and mapped to your governance program.
- ISO 42001 gap assessment completed if enterprise contracts are referencing certification requirements.
- AI governance program reviewed by external advisor at least annually.
Triggers: events that move you between tiers immediately
Team size is a guide, not a hard gate. These events should immediately trigger the compliance work of the next tier, regardless of headcount:
Tier 1 to Tier 2 triggers:
- First EU customer or EU-based user (triggers GDPR obligations)
- First employee who is not a founder (triggers need for written policies)
- First enterprise contract with compliance requirements
- First regulated industry customer (healthcare, financial services, legal, education)
- Use of AI in any customer-facing product that makes decisions about people
- Use of AI in any HR decision (hiring, compensation, performance)
Tier 2 to Tier 3 triggers:
- First customer contract requiring security audit or compliance certification
- Operations in a state with sector-specific AI law (NYC LL144, Texas TRAIGA, Colorado SB 189)
- Launch of a high-risk AI system under EU AI Act definitions
- External funding round with institutional investors (investor due diligence typically requires evidence of governance)
- ISO 42001 certification request from a customer
- Regulatory inquiry or customer data breach involving AI systems
What you probably do not need
At every tier, there is pressure to do more than you need. Do not over-engineer:
- A 3-person team does not need ISO 42001. Unless a customer requires it in writing, the certification cost exceeds the benefit.
- A 15-person team does not need a dedicated compliance officer. Designated ownership of governance by an existing team member is enough.
- Any team does not need a compliance tool subscription until you have enough AI systems to warrant a management platform. Spreadsheets and shared documents work for most teams at Tiers 1 and 2.
The full cost picture is covered in AI compliance cost small teams 2026.
Related reading
- AI governance guide for small teams
- AI governance checklist 2026
- AI compliance cost small teams 2026
- AI spend governance: token budget controls
- Board AI governance reporting template 2026
- AI acceptable use policy template small teams
- AI tool register template for small teams
- AI vendor due diligence checklist 2026
- ISO 42001 vs NIST AI RMF for small teams
- AI regulatory readiness scorecard for software and biotech teams
- EU AI Act compliance guide for small teams
- AI compliance program maturity model 2026
- AI Governance Q3 Review Template: A Quarterly Audit Checklist for 2026
- AI Governance RACI Template for Small Teams: 12 Activities
- AI Vendor Due Diligence in 30 Minutes (Questions + Scoring Sheet)
