The most common question from anyone who decides to take AI governance seriously isn't "what does the law require?" — it's "where do I start?". And the answers doing the rounds tend to fail at both extremes: the twelve-month transformational project that never gets off the ground, or the afternoon checklist that doesn't survive the first serious question. The operative truth sits in between: a well-sequenced month leaves an SME with the foundations laid and real evidence in hand. This is the roadmap, week by week, with no promise of arrival — with a promise of method.
Week 1 — Know what you have
Everything starts where we've spent months insisting it should: the inventory. Bring the area leads together for an hour and ask the uncomfortable question: which AI tools does each team use — including the ones nobody formally authorised? The module that switched on with the last CRM update, the assistant someone uses on their own initiative, the chatbot in the booking software. For each system, the minimum record: what it does, who uses it, what data it touches, who the provider is.
Close the week with an honest snapshot of where things stand. If you want a structured shortcut for that first snapshot, the free diagnostic gives it to you in a few minutes: which obligations apply to you based on what you already use. The snapshot isn't the evidence — but it tells you where to look first.
Week 2 — Know what each thing requires of you
With the list in front of you, classify. No advanced degree needed: most systems at an SME fall clearly into minimal risk (AI-assisted office tools, forecasting, internal tools), a few trigger transparency (anything that converses with customers or generates content), and the warning sign is always the same: systems that evaluate or decide on people — candidates, employees, customers. Those are the ones that call for immediate rigour: a data protection impact assessment, guarantees of human intervention, and their slot on the high-risk calendar.
The week's deliverable isn't the classification on its own: it's the classification with its reasoning written down. "This system is X because it does Y" — one sentence per system. That's the difference between an opinion and auditable evidence.
Week 3 — Set the rules and train (with a record)
Two pieces done together because they feed each other. The AI use policy: one or two pages covering what matters — which systems are authorised, what's prohibited (starting with pasting confidential data into unassessed tools), what to do when a result looks anomalous, how a new tool gets brought in. And Article 4 training, which doesn't require buying anything: a free baseline resource plus an internal session on your systems and your newly written policy. All of it recorded: who, what, when. For due-diligence purposes, training without a record doesn't exist.
Week 4 — Transparency and first evidence
The final week turns what's been built into visible compliance: verification of the chatbot's disclosure (with its division of roles), a labelling criterion for generated content, an editorial workflow for published text, and the ten AI vendor due-diligence questions sent to your two or three main providers. And the final gesture that ties it all together: an evidence folder — physical or digital, it doesn't matter — where every record generated this month lives, dated.
Day 31
Let's be honest about what you have at the end: not "total compliance" — that phrase doesn't mean anything, and anyone who promises it is selling you smoke. You have something better, and real: a living inventory, a reasoned classification, an operating policy, recorded training, verified transparency and a folder that proves it. That is: the ability to answer anyone who asks with confidence, and the foundations on which everything else — the deeper assessments, high risk when its calendar arrives, agents when they arrive — gets built without starting from zero.
On day 31, governance isn't finished; it's under way and under control, which is the only state in which governance genuinely exists. And someone coordinates it, named and mandated — because next month there'll be a new tool, a provider that changes its model, and a regulatory date drawing closer. Method over heroics. Always.
This article is for informational purposes only and does not constitute legal advice.