Make responsibilities clear
Governance means deciding who is responsible, how decisions get made and what happens when something goes wrong. In a small team, a short set of shared rules can go a long way.
The aim is to make the business easier to run. Add detail where the risks need it; keep everyday instructions easy to find and follow.
Know what needs an owner
Give each important system or activity a named owner. One person can cover several areas, but “everyone looks after it” is hard to act on when something breaks.
| Area | The owner should know |
|---|---|
| Accounts and access | Who can sign in, who has admin access and how to remove or recover it. |
| Business data | Where it lives, who can use it, how long it is kept and how to recover it. |
| Security and incidents | What protections are expected and who coordinates a response. |
| Suppliers | What each provider does, what they control and how to leave. |
| Compliance | Which obligations apply, who checks them and when specialist advice is needed. |
Write rules people can follow
Start with account access, passwords and MFA, device use, data handling, software updates and use of AI tools. For each, explain the rule, who owns it and what to do if it cannot be followed.
A short instruction that people use is more useful than a long document nobody opens. Keep the current version somewhere the whole team can find it.
Make risks visible
List the most likely or most damaging problems, their likelihood and impact, and what you are doing about them. Assign an owner and a review date. This is the start of a risk register.
Company access should survive one person leaving. Use delegated access or a documented recovery route; this does not mean giving everyone administrator permissions.
Know what to do when something goes wrong
A lost laptop, exposed password or unavailable system needs a clear response. Decide who coordinates it and where people should report problems before an incident happens.
- ReportHow alerts and concerns reach the right person.
- CoordinateWho assesses the impact and gets help.
- RespondHow to contain the problem and restore service safely.
- ReviewWhat happened and what needs to change.
Keep a record of events and changes. Include how you would communicate with the team, customers or others affected, and who checks whether any reporting obligations apply. The response will depend on the incident; this is a planning outline.
The NCSC’s response and recovery guidance gives small organisations a practical starting point.
Keep control when suppliers help
Before granting access, agree what a supplier will do, which systems they need and how long access should last. Give individual accounts with the permissions needed for the work.
If changing supplier would leave you unable to run your own systems, address the access and handover gaps while the relationship is still working.
Know what personal data you hold
Start with an inventory: what personal data you collect, why you need it, where it is stored, who can access it and how long you keep it.
Your obligations depend on the data, activities and where you operate. Small teams can have responsibilities from the outset. Use the ICO’s small-organisation guidance for UK personal-data work, and get specialist advice when requirements are unclear or the data is sensitive.
Review the arrangements as you grow
Revisit responsibilities when someone joins or leaves, you add a supplier, or the business starts handling different data. Schedule access and policy reviews too, so changes do not depend on someone noticing a problem.
- New people: can they find the rules and the person responsible?
- New systems: are ownership, access and recovery recorded?
- New risks: do existing controls still fit the work?
Unclear ownership and important changes without review are signs that the arrangements need attention.