From Frameworks to Feasible Practice: A Modular AI Governance Blueprint for Consulting SMEs
Abstract
Purpose: To address the growing gap between Artificial Intelligence (AI) governance expectations and the practical capacities of consulting small and medium enterprises (SMEs).
Methodology/Approach: Conceptual review and comparative analysis of leading governance regimes and standards, followed by mapping to enterprise risk management models commonly used to manage organisational risks.
Findings: The paper shows that consulting SMEs face compounded barriers (limited compliance capacity, data constraints, cultural resistance, algorithm aversion, and regulatory uncertainty) that make comprehensive governance unrealistic. It derives a modular governance blueprint that supports gradual implementation aligned with quality management and risk appetite.
Research Limitation/Implication: The blueprint requires operationalisation into checklists, templates, and measurable indicators and should be validated across multiple SME cases and AI use scenarios.
Originality/Value of paper: The key contribution is translating heterogeneous AI governance sources into a feasibility-first governance logic for SMEs, framed as a quality and trust enabler rather than a compliance-only burden.
Full text article
References
Armour, J., & Sako, M. (2020). AI-enabled business models in legal services: From traditional law firms to next-generation law companies? Journal of Professions and Organization, 7(1), 27–46. https://doi.org/10.1093/jpo/joaa001
Aven, T. (2016). Risk assessment and risk management: Review of recent advances on their foundation. European Journal of Operational Research, 253(1), 1–13. https://doi.org/10.1016/j.ejor.2015.12.023
Batool, A., Zowghi, D., & Bano, M. (2025). AI governance: A systematic literature review. AI and Ethics, 5(3), 3265–3279. https://doi.org/10.1007/s43681-024-00653-w
Benraouane, S. A. (2024). AI management system certification according to the ISO/IEC 42001 standard: How to audit, certify, and build responsible AI systems. Abingdon, Oxon: Routledge.
Brundage, M., Avin, S., Clark, J., Toner, H., Eckersley, P., Garfinkel, B., Dafoe, A., Scharre, P., Zeitzoff, T., Filar, B., Anderson, H., Hurley, H., Crootof, R., Evans, O., Kaspersen, P., O’Heigeartaigh, S., & Amodei, D. (2020). Toward trustworthy AI development: Mechanisms for supporting verifiable claims. Proceedings of the AIES Conference. https://doi.org/10.48550/arXiv.2004.07213
Committee of Sponsoring Organizations of the Treadway Commission. (2017). Enterprise Risk Management—Integrating with Strategy and Performance. New York, NY: COSO.
Dietvorst, B. J., Simmons, J. P., & Massey, C. (2015). Algorithm aversion: People erroneously avoid algorithms after seeing them err. Journal of Experimental Psychology: General, 144(1), 114–126. https://doi.org/10.1037/xge0000033
European Commission. (2021). Proposal for a regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) and amending certain Union legislative acts (COM(2021) 206 final). Retrieved from https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52021PC0206
Floridi, L., Cowls, J., Beltrametti, M., Chatila, R., Chazerand, P., Dignum, V., Luetge, C., Madelin, R., Pagallo, U., Rossi, F., Schafer, B., Valcke, P., & Vayena, E. (2018). AI4People—An ethical framework for a good AI society: Opportunities, Risks, Principles, and Recommendations. Minds and Machines, 28(4), 689–707. https://doi.org/10.1007/s11023-018-9482-5
Fraser, J. R. S., & Simkins, B. J. (2016). The challenges of and solutions for implementing enterprise risk management. Business Horizons, 59(6), 689–698. https://doi.org/10.1016/j.bushor.2016.06.007
Helfert, M., Doucek, P., & Maryška, M. (2013). The “Enterprise Architect” – A new approach to business informatics management. Quality Innovation Prosperity, 17(1), 67–87. https://doi.org/10.12776/qip.v17i1.171
Institute of Internal Auditors. (2020). The IIA’s Three Lines Model: An update of the Three Lines of Defense (Position paper). Retrieved from https://www.theiia.org/globalassets/documents/resources/the-iias-three-lines-model-an-update-of-the-three-lines-of-defense-july-2020/three-lines-model-updated-english.pdf
ISO. (2018). ISO 31000:2018 Risk management—Guidelines. Geneva, Switzerland: ISO.
ISO/IEC. (2023). ISO/IEC 42001:2023 Artificial intelligence—Management system. Geneva, Switzerland: ISO.
Jobin, A., Ienca, M., & Vayena, E. (2019). The global landscape of AI ethics guidelines. Nature Machine Intelligence, 1(9), 389–399. https://doi.org/10.1038/s42256-019-0088-2
Laux, J., Wachter, S., & Mittelstadt, B. (2024). Three pathways for standardisation and ethical disclosure by default under the European union artificial intelligence act. Computer Law & Security Review, 53, 105957. https://doi.org/10.1016/j.clsr.2024.105957
Logg, J. M., Minson, J. A., & Moore, D. A. (2019). Algorithm appreciation: People prefer algorithmic to human judgment. Organizational Behavior and Human Decision Processes, 151, 90–103. https://doi.org/10.1016/j.obhdp.2018.12.005
Maryška, M., Nedomová, L., & Doucek, P. (2020). Risk management and IT risk management processes and implementation: How Covid-19 has changed them. In J. Ministr (Ed.), Proceedings of the 23rd International Conference on Information Technology for Practice (IT4P-2020) (pp. 151–160). Ostrava, Czech Republic: Czech Society for Systems Integration.
Mehrabi, N., Morstatter, F., Saxena, N., Lerman, K., & Galstyan, A. (2021). A survey on bias and fairness in machine learning. ACM Computing Surveys, 54(6), 1–35. https://doi.org/10.1145/3457607
OECD. (2024). Recommendation of the Council on Artificial Intelligence (OECD/LEGAL/0449). Retrieved from: https://legalinstruments.oecd.org/en/instruments/oecd-legal-0449
Papagiannidis, E., Mikalef, P., & Conboy, K. (2025). Responsible artificial intelligence governance: A review and research framework. Journal of Strategic Information Systems, 34(2), 101885. https://doi.org/10.1016/j.jsis.2024.101885
Radu, R. (2021). Steering the governance of artificial intelligence: national strategies in perspectives. Policy and Society, 40(2), 178–193. https://doi.org/10.1080/14494035.2021.1929728
Raji, I. D., Gebru, T., Mitchell, M., Buolamwini, J., Jost, J., & Barnes, D. (2020). Closing the AI accountability gap: defining an end-to-end framework for internal algorithmic auditing. Proceedings of the ACM Conference on Fairness, Accountability, and Transparency, 33–44. https://doi.org/10.1145/3351095.3372873
Sánchez, E., Calderón, R., & Herrera, F. (2025). Artificial intelligence adoption in SMEs. Applied Sciences, 15(12), 6465. https://doi.org/10.3390/app15126465
Schein, E. H. (2017). Organizational Culture and Leadership (5th ed.). Hoboken, NJ: Wiley.
Schiff, D., Rakova, B., Ayesh, A., Fanti, A., & Lennon, M. (2021). Explaining the Principles to Practices gap in AI. IEEE Technology and Society Magazine, 40(2), 81–94. https://doi.org/10.1109/MTS.2021.3056286
Tabassi, E. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0). Gaithersburg, MD: National Institute of Standards and Technology.
Veale, M., & Zuiderveen Borgesius, F. (2021). Demystifying the draft EU AI Act. Computer Law Review International, 22(4), 97–112. https://doi.org/10.9785/cri-2021-220402
Veber, J., Nedomová, L., & Doucek, P. (2016). Corporate Digital Incident Investigation. Quality Innovation Prosperity, 20(1), 57-71. https://doi.org/10.12776/qip.v20i1.656
Yang, J., Blount, Y., & Amrollahi, A. (2024). Artificial intelligence adoption in a professional service industry: A multiple case study. Technological Forecasting and Social Change, 201, 123251. https://doi.org/10.1016/j.techfore.2024.123251
Authors
Copyright (c) 2026 Ludmila Jiříčková, Petr Doucek

This work is licensed under a Creative Commons Attribution 4.0 International License.
This is an open access journal which means that all content is freely available without charge to the user or his/her institution. Users are allowed to read, download, copy, distribute, print, search, or link to the full texts of the articles in this journal without asking prior permission from the publisher or the author. This is in accordance with the BOAI definition of open access. This journal is licensed under a Creative Commons Attribution 4.0 License - https://creativecommons.org/licenses/by/4.0.
Authors who publish with the Quality Innovation Prosperity agree to the following terms:
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution License that allows others to share the work with an acknowledgement of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgement of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work.
