Most mid-size companies know they have an AI tool problem. Employees are adopting AI tools faster than any review process can track, and IBM's research confirms it: only 37% of organisations have any governance policy in place for AI tool usage. The other 63% are not ignoring the issue; they are operating without the structure to address it.

The missing piece is not a policy document. It is a process: a lightweight, repeatable mechanism that applies before any new AI tool is deployed, that answers the right questions before data starts flowing, and that does not require a dedicated compliance team to run.

This guide covers what that process looks like, how to build it, and how to apply it retroactively to AI tools already in use without approval.

What Is an AI Tool Approval Process?

An AI tool approval process is a structured intake and review mechanism that applies before any new AI tool is deployed in an organisation. It is not a full enterprise procurement cycle. It is a defined set of questions, a tiering system that determines how deep the review needs to go, a designated reviewer for each tier, and a documented outcome that creates a record of the decision.

The purpose is to ensure that every AI tool entering the organisation has been assessed for data handling, security posture, contractual compliance, and cost before it starts processing company data. Without this, tools enter through expense accounts, browser extensions, and department trials, and the compliance clock starts running before anyone in IT or finance is aware the tool exists.

Why Mid-Size Companies Need a Formal AI Tool Approval Process in 2026

The case for a formal process rests on three converging pressures, each of which has intensified in 2026.

The first is scale of ungoverned adoption. UpGuard's 2025 research found that 81% of workers now use AI tools their organisation has not approved. IBM's data confirms the policy gap: only 37% of organisations have any AI governance policy in place. At a mid-size company with 200 to 500 employees, this translates to a significant volume of AI tools actively processing company data under no reviewed contract and no agreed data handling terms.

The second is the compliance cost of getting it wrong. IBM's 2025 Cost of a Data Breach Report found that incidents involving unsanctioned AI tools cost an average of $670,000 more than standard data breaches, and one in five organisations has already experienced a breach tied to unsanctioned AI usage. A formal approval process is the mechanism that prevents a tool from reaching that exposure point in the first place.

The third is the regulatory environment. The EU AI Act now applies to SMEs using high-risk AI systems. GDPR requires a data processing agreement for any AI tool that processes personal data. Gartner projects that AI regulation will cover 75% of global economies by 2030. An AI compliance policy and approval process is not a best practice for 2026: it is becoming a legal baseline. For the full picture of how these regulatory pressures apply to mid-size companies specifically, see Why AI Tools Are Your Fastest-Growing Compliance Risk.

The Five Questions Every AI Tool Request Should Answer

These five questions form the minimum viable review for any new AI tool. They are the core of a working AI governance policy and the basis for the approval decision.

1. What data will this tool access or process? Categorise the data: personally identifiable information, financial data, client data, regulated health data, source code, or internal communications. The data category determines the compliance obligations that apply and the depth of review required.

2. Where is that data stored and processed? Identify the vendor's data residency. Data processed in jurisdictions outside the company's operating markets may trigger additional compliance obligations under GDPR, data localisation regulations, or sector-specific frameworks. The vendor's privacy policy and data processing agreement are the primary sources for this answer.

3. Does the vendor hold current security certifications? At minimum: SOC 2 Type II or ISO 27001. Confirm the certification is current, not expired. For tools accessing sensitive or regulated data, ask whether the vendor has experienced a confirmed security incident in the last 24 months and how it was disclosed. For how vendor security assessments work in practice across the full SaaS and AI portfolio, see What Is a SaaS Vendor Risk Assessment and How Does It Work?.

4. Does the contract include a data processing agreement and an exit clause? A DPA is a GDPR requirement for any tool processing personal data. An exit clause allows the company to terminate without penalty if the vendor fails to meet security or compliance obligations. Both should be confirmed before approval, not after.

5. What is the business case and expected cost? Document what the tool is for, which team will use it, what the expected spend is over 12 months, and whether an already-approved tool covers the same need. This question prevents duplicate approvals and creates the budget record for renewal management.

How to Tier AI Tool Requests by Risk Level

Not every AI tool requires the same depth of review. Tiering keeps the process proportionate and fast for low-risk requests while ensuring critical tools receive appropriate scrutiny.

Critical tier: Tools that access sensitive data (PII, financial, health, or source code), operate in regulated environments, or connect to core business systems. These receive a full review across all five questions, require sign-off from IT and legal or compliance, and have a maximum review SLA of five business days.

Standard tier: Tools with limited data access that do not operate in regulated environments and are not integrated with core systems. These receive a streamlined review covering questions 1, 3, and 4, require IT sign-off only, and have a two-day review SLA.

Low-risk tier: Tools with no company data access: productivity tools, consumer AI tools used in isolated personal workflows, and tools that never touch company data or systems. These are logged and catalogued but require only a brief intake form and manager acknowledgement, with no formal IT review.

The tier assignment is made at intake based on the answer to Question 1. Most tools that arrive through expense accounts or department trials sit in the standard tier. The handful that reach critical tier are where the compliance exposure is highest, and the five-question review ensures they are addressed before data starts flowing.

See What AI Tools Are Running in Your Organisation Before You Build Your Approval Process

CostRoom maps every active AI, SaaS, and cloud tool across your portfolio so you know what you are approving against, what is already running without review, and where the compliance gaps are concentrated.

Book a Demo

Building the Approval Workflow Without a Dedicated IT Team

A working AI tool approval process can be operational in under a week. It requires four components, none of which need dedicated headcount to maintain.

Intake channel. A simple request form covering the five questions above: this can be a Slack form, an email alias, or a shared intake document. The intake channel is the single point through which all new AI tool requests flow. Communicating its existence to the company at the same time as the acceptable use policy is sufficient to establish it.

Designated reviewer per tier. For critical tier: IT Director and legal or compliance contact. For standard tier: IT Director or delegated IT team member. For low-risk tier: direct manager. The reviewer is responsible for the five-question assessment and the documented outcome, not for making the tool work or managing its implementation.

Documented outcome. Every review produces a written record: tool name, tier, review date, reviewer, decision (approved, approved with conditions, or declined), and the basis for the decision. This record is the evidence of due diligence if a regulator asks or a vendor is breached.

Review SLA. Two business days for standard tier, five for critical. Publishing the SLA prevents the approval process from becoming a bottleneck that employees bypass by going directly to expense accounts.

This structure integrates naturally into the broader AI tool governance framework. For the full governance model these components sit within, see AI Tool Governance for Mid-Size Companies: Managing Spend, Risk, and Compliance Together. For how AI governance connects to the broader AI, SaaS, and cloud spend picture, see Managing AI, SaaS, and Cloud Spend Together: A Guide for Mid-Size Companies.

How to Handle AI Tools Already in Use Without Approval

For most mid-size companies, the approval process needs to run in two directions simultaneously: forward for new tool requests, and backward for the tools already in active use without any review.

The retroactive review uses the same five-question framework and the same tiering system, applied to the existing AI tool inventory. Building that inventory is the prerequisite: without a complete picture of what is already running, the retroactive review is operating on incomplete data. For how to build the AI software inventory by reconciling finance, IT, and expense management data, see Why Mid-Size Companies Have More Uncontracted SaaS Spend Than They Think.

Once the inventory exists, work through it in tier order. Critical-tier tools without a reviewed DPA on record are the immediate priority: these represent the highest compliance exposure and should be addressed before anything else. For each tool on the retroactive list, the outcome is one of three: formalise with a reviewed contract and DPA, restrict data access until a contract is in place, or discontinue.

Continuing to use a tool without a contract after it has been identified through this process is a deliberate decision that creates documented exposure. The retroactive review converts that implicit risk into an explicit choice that the company owns.

CostRoom's Spend Analysis and Optimisation delivers the AI software inventory and contract gap analysis as an integrated engagement, identifying every active tool across the portfolio and flagging where a DPA is missing before the approval process runs retroactively.

Build Your AI Tool Approval Process on a Solid Inventory

CostRoom identifies every active AI tool in your portfolio, maps the contract and DPA gaps, and gives you the starting point your approval process needs to be effective from day one.

Book a Demo

Frequently Asked Questions

What is an AI tool approval process?

An AI tool approval process is a structured intake and review mechanism that applies before any new AI tool is deployed in an organisation. It covers five questions: what data the tool will access, where that data is stored and processed, whether the vendor holds current security certifications, whether the contract includes a data processing agreement and exit clause, and what the business case and expected cost are. The outcome is a documented approval or decline decision that creates a record of due diligence.

What should an AI governance policy include for mid-size companies?

An AI governance policy for a mid-size company should cover four elements: an acceptable use policy defining what data can and cannot be input into AI tools and which tools are currently approved; a tiered approval process for new tool requests; a designated reviewer for each tier with a documented review SLA; and an ongoing monitoring cadence that reassesses approved tools at renewal and flags significant vendor changes between renewals. The policy does not need to be lengthy to be effective; a one-page acceptable use policy and a clear intake process are sufficient to establish an AI compliance baseline.

How do you handle AI tools that are already in use without approval?

Apply the same five-question review framework retrospectively to every tool identified in the AI software inventory, working through them in risk-tier order. Critical-tier tools without a reviewed data processing agreement are the immediate priority. For each tool on the list, the outcome is one of three: formalise with a reviewed contract and DPA, restrict data access until a contract is in place, or discontinue. Continuing to use an identified tool without a contract is a decision that creates documented compliance exposure.

How long should an AI tool approval review take?

For standard-tier tools (limited data access, non-regulated environment), a two-business-day review SLA is achievable and appropriate. For critical-tier tools (sensitive or regulated data, core system integration), five business days allows time for a thorough assessment across all five review questions, including legal or compliance input where required. Publishing these SLAs prevents the approval process from becoming a bottleneck that employees bypass through direct expense purchases.