Attend CSC13
Talk Title: AI Governance for Small and Midsize Businesses
Abstract:
AI governance sounds like it requires a dedicated risk officer or a governance committee—resources most SMBs simply don't have. This session breaks the concept down to what it actually is: the decisions your company makes about which AI tools you use, who's allowed to use them, what data they touch, and who's accountable when something goes wrong. No new department required, just a few new questions layered onto processes you already run.
From there, we'll walk the current compliance and risk landscape: the federal patchwork of executive action and agency enforcement (FTC, EEOC, CFPB, FDA), the EU AI Act's risk-tiered obligations for any company with EU customers or users, and the state laws actually shaping day-to-day exposure.
Next, we turn to shadow AI—the gap between the tools a company approved and the tools employees are actually using. We'll unpack why bans backfire, why adoption consistently outpaces policy, and what that means for visibility into risk.
We close on accountability: when an AI vendor's tool generates work product from your data, who owns the output, and who's liable if it's wrong? Most companies have never asked their vendor that question—we'll show you which ones to ask.
Speaker Bio
Richard Stevenson is the Managing Partner of RSAA and a recognized “Cyber-CPA” with more than 15 years of experience in cybersecurity, compliance, and assurance services. He specializes in SOC reporting, ISO 27001, HIPAA, and emerging AI governance and risk frameworks, helping organizations align security, compliance, and business objectives in a modern digital environment.