Plainstart Back to the kit

Article

How to Build an Approved AI Tools List (and Keep It Short)

An approved AI tools list is a short document that tells your staff which AI tools they are allowed to use at work, under what conditions, and who to ask if they want to add something new. That is all it needs to be.

Most businesses skip this step, then discover six months later that three different teams have been feeding customer data into four different tools, none of which have been checked. This article gives you a practical way to build the list and maintain it without creating a bureaucratic burden.


Why a Short List Beats a Long One

The purpose of an approved list is to make the default decision for your staff. When someone sits down to work, they should not need to think about whether a tool is acceptable. The list answers that question in advance.

A long list defeats this purpose. If your approved list has forty tools on it, your staff will not read it. They will not remember it. They will not know which of the forty applies to their situation.

A short list, five to ten tools for most small businesses, does something different. It is readable in two minutes. It can be pinned to your intranet, printed, or attached to your onboarding pack. When a new tool is not on it, the absence is obvious.

Short also means you have actually checked each entry. Every tool on a long list is a tool someone vetted once and then forgot about. Every tool on a short list is a tool someone actively chose to keep.


What to Check Before Adding a Tool

Before any AI tool goes on your approved list, answer these five questions. If you cannot answer them, the tool is not ready to be approved.

1. Where does the data go?

Read the privacy policy and terms of service. Find out whether the vendor trains its models on your inputs. Find out where data is stored, and whether that location is compatible with your obligations under applicable data protection law. If the tool handles personal data about your customers or staff, this question is not optional.

General guidance, not professional advice. If you have specific compliance obligations under GDPR, state privacy laws, or sector regulations, check with a qualified professional before approving tools that handle personal or sensitive data.

2. What happens in a data breach?

Check whether the vendor has a published security page, an ISO 27001 certification, or a SOC 2 report. Check whether they have a breach notification obligation in their terms. If they do not say anything about security, that is itself an answer.

3. Is there a business account with appropriate controls?

Consumer accounts and business accounts are usually governed by different terms. A business or enterprise plan often includes data processing agreements, admin controls, and audit logs that the free tier does not. Approve the business tier, not the consumer version.

4. What does it cost, and who authorises it?

Recurring subscriptions accumulate. Before approving a tool, confirm who holds the account, who pays the invoice, and who can cancel it. Tools that are approved but unbudgeted tend to become shadow spend.

5. Does it duplicate something you already have?

If you already use Microsoft 365 Copilot and someone wants to add a separate AI writing tool, ask whether both are genuinely needed. Duplication increases cost, increases the number of places data lives, and increases the number of vendor relationships you need to maintain.


A Worked Example: A Five-Line Approved List

This is what an approved list looks like for a small professional services business with twelve staff. It is not a template. It is an illustration of the format and level of detail that works.


Approved AI Tools, Marchfield Consulting, last reviewed April 2025

ToolApproved useAccount typeData restrictionOwner
Microsoft 365 CopilotDrafting documents, summarising emails, meeting notesBusiness (M365 E3)No client data in prompts without DPA confirmedIT lead
ChatGPT (OpenAI)Internal drafting, research, brainstormingTeam account, privacy mode onNo personal data, no confidential client informationOperations manager
Grammarly BusinessEditing and proofreading written outputsBusiness accountNo client dataOperations manager
Otter.aiTranscription of internal meetings onlyBusiness accountExternal or client meetings require consent from all participantsIT lead
Adobe FireflyCreating internal graphics and presentation visualsBusiness account via Adobe CCNo images of real individualsDesign lead

Three things to notice about this list. First, it fits on one page. Second, every row specifies what the tool cannot be used for, not just what it can. Third, there is a named owner for each tool, not a team or a department.


How to Handle Requests Without Becoming a Bottleneck

The most common reason AI governance breaks down is not that people ignore the rules. It is that the process for getting a new tool approved is slow or unclear, so people stop asking and just use what they want.

Fix this with a simple intake form, not a committee.

The form should ask:

  • What is the tool?
  • What do you want to use it for?
  • Have you checked where the data goes?
  • Is there a business account available?
  • Does it duplicate something already on the list?

The person who receives the form, more on this below, should be able to make a provisional decision within five business days. If the tool needs legal or security review, that is a separate track, but most tools for a small business do not. Most requests can be decided by checking three pages of documentation and applying the five questions above.

Set a public expectation. Tell staff that requests will be answered within five business days. If they do not hear back within that window, they can follow up with the named owner. This small commitment prevents the situation where a request disappears and the staff member concludes that approval is impossible and routes around it.

Provisional approval is fine. You can add a tool with a note that says "approved for limited use, under review, do not use with client data" while a fuller assessment is under way. This is better than a long delay.


Who Owns the List

One person needs to own the approved list. Not a team. Not a committee. One person who is accountable for keeping it current, receiving new requests, and making or escalating decisions.

In a small business, this is usually the operations manager or the person who handles IT decisions. In a slightly larger business, it might be a compliance officer or a head of operations. The title does not matter. The accountability does.

The owner does not need to make every decision alone. For tools that handle significant volumes of personal data, or tools used in regulated activities, the owner should escalate to whoever handles legal and compliance. But the owner is the single point of contact. Staff know who to ask. Decisions do not get lost between departments.

Put the owner's name on the face of the document. Update it when ownership changes.


How Often to Revisit It

Review the list every six months. That is the right cadence for most small and medium businesses. AI tools change quickly enough that an annual review will miss things. A quarterly review is more than most businesses need.

At each review, go through every tool on the list and ask:

  • Are we still using this?
  • Have the vendor's terms changed?
  • Has our use of the tool changed since we approved it?
  • Are there new risks or incidents we should account for?
  • Is there anything on the not-approved list that now meets the bar?

Remove tools that are no longer used. Downgrading from "approved" to "under review" is fine if circumstances have changed. The list should reflect what your business actually does, not what it intended to do when the list was first written.

Set a calendar reminder six months from the date on the document. Put the next review date on the face of the document so it is visible.

Outside the scheduled review, the owner should also revisit individual entries if there is a significant event: a vendor data breach, a change in the tool's ownership, a material change to terms of service, or a reported incident involving the tool in your business.


The Relationship Between the Approved List and Your AI Usage Policy

The approved list is a schedule to your AI usage policy. It does not stand alone. Your policy sets the rules for how AI can be used. The list specifies which tools those rules apply to.

If you do not have an AI usage policy yet, that is the right place to start. The policy establishes what your staff are and are not allowed to do with AI at work, what data they can use in prompts, what they must check before acting on an AI output, and what to do if something goes wrong. The approved list then names the specific tools that are permitted under those rules.


Plainstart publishes a free AI Usage Policy template for small and medium businesses. It is a plain-language document you can adapt and put in front of your staff. No registration wall. Download it at Plainstart and pair it with your approved tools list.

AI adoption, done properly.

Free download

The AI Usage Policy your team can actually follow

One page, plain language, ready to put in front of staff today. No cost, no catch.

Get the free policy