Short answer
Start by mapping where AI is already being used, what data goes into those tools, who relies on the output, and where review or approval is missing. The aim is to bring AI use into the open and decide which workflows deserve control, support or a safe stop.
Next step
Want Rohit to apply this to your firm?
If this resource matches a live decision, book a call or use the paid clarity session page so the route is obvious from the guide itself.
Start with the workflow, not the policy
A founder-led SME often discovers AI through scattered experiments: meeting notes, proposals, customer replies, spreadsheets, browser extensions or automation features inside tools the business already pays for. Before writing a policy, map where the work happens and which uses actually affect customers, staff decisions, data or delivery quality.
List the tools before judging them
Ask teams which AI tools, browser extensions, meeting assistants, writing aids and automation features they already use. Include personal accounts, free tools, shared logins and built-in product features. Keep the first pass factual: tool, user, purpose, data type, output and who relies on it.
Look for sensitive data boundaries
The risky point is usually not that a tool exists. It is what staff paste, upload, connect or summarise with it. Mark any use that touches client information, customer records, contracts, HR data, financial details, credentials, commercial plans or regulated work. If the data position is unclear, treat the use as amber until it is reviewed.
Ask staff without creating a witch hunt
People are more likely to be honest if the exercise is framed as safe adoption. Ask what AI is helping with, where outputs are useful, where they are unreliable and where people feel exposed. A punitive tone drives shadow AI deeper underground and makes the business less safe.
Score each use red, amber or green
Green uses are low-risk, non-confidential and reviewed by a person. Amber uses may be useful but need clearer rules, supplier checks or human review. Red uses involve sensitive data, client work, important decisions or unclear ownership and should be paused or redesigned before continuing.
Turn the findings into a controlled next step
The checklist should end with practical actions: approved low-risk uses, prohibited uses, workflows that need a risk assessment, tools that need supplier review, and one named owner for the next decision. The best outcome is not a spreadsheet. It is a short list of workflow improvements Pattrn can help map, govern or implement safely.