The letter arrives on a Tuesday. It's from the Small Business Administration, and it informs your business that it has been selected for an AI Readiness Review under the AI for Main Street Act compliance program. Your stomach drops. You've heard the term "AI readiness assessment" thrown around at your local SBDC workshop, but nobody told you what actually happens during one, what reviewers look for, or how to prepare your team before the clock runs out.
This scenario is playing out for small business owners across the country right now. The AI for Main Street Act created a new compliance landscape that many businesses are only beginning to understand. An SBA AI Readiness Review is not an audit designed to punish small businesses. It is a structured evaluation of whether your organization has the operational foundations, staff training, and governance practices to responsibly deploy AI tools. But that distinction matters very little if your team walks into the review unprepared.
This guide is a literal room-by-room walkthrough. It covers every department, every documentation checkpoint, and every conversation your team needs to have before a reviewer sits down across the table from you. Follow the steps in sequence, and you will not just survive the review. You will walk out with a stronger, more defensible AI operation than most of your competitors.
What an SBA AI Readiness Review Actually Evaluates
Before you can prepare, you need to understand what reviewers are actually measuring. An AI readiness assessment for small businesses under the current SBA framework is not a pass/fail test. It is a tiered evaluation across four core domains: governance and policy, staff competency and training, data handling and privacy, and vendor accountability.
Reviewers are looking for evidence, not promises. They want to see written policies, training completion records, vendor contracts with AI-specific clauses, and documentation of how your business makes decisions when an AI system produces a result that affects a customer or employee. If your answer to most questions is "we handle that informally" or "our team just knows," you are going to struggle.
The review typically unfolds across three stages. The first is a document submission phase, where you provide policies, org charts, training logs, and vendor agreements before the review date. The second is a walkthrough interview, where reviewers speak with your leadership and at least one frontline staff member. The third is a tool demonstration, where you may be asked to show a live AI system in use and explain how oversight is maintained.
Understanding this structure changes how you prepare. You are not memorizing answers. You are building systems that generate the right answers naturally, and that show reviewers that your business has genuinely thought through the implications of the AI tools it uses.
For broader context on what the legislation actually mandates at the federal level, the plain-language breakdown of AI for Main Street Act requirements is essential reading before you begin this preparation process.
Step 1: Conduct Your Internal AI Inventory (The Discovery Room)
Estimated time: 3–5 hours across your leadership team. Complete this before any other step.
You cannot prepare for an AI readiness review if you do not know what AI tools your business is actually using. This sounds obvious. In practice, most small businesses are shocked by what surfaces during a thorough inventory. Customer service chatbots, AI-assisted email drafting tools, automated scheduling software, AI-powered ad platforms, accounting software with embedded machine learning features, and HR tools that use algorithmic scoring all qualify as AI systems under the current SBA framework.
How to Run the Inventory
Start by gathering every department head or team lead in one room, virtual or physical. Give each person a blank form with the following fields: tool name, vendor name, what the tool does, what data it accesses, who approved its use, and whether a written agreement exists with the vendor. Set a timer for 20 minutes and have everyone list every software tool, app, plugin, or automation their team uses, regardless of whether they think it contains AI.
Once lists are compiled, cross-reference against your current software subscriptions, credit card statements for the past 12 months, and your IT or admin's list of approved logins. You will almost certainly find tools that were adopted by individual employees without formal approval. These shadow AI tools are among the highest-risk items from a compliance standpoint.
Categorizing What You Find
Sort your inventory into three categories. Category A covers tools where AI directly influences a decision that affects customers, employees, or finances. This includes loan recommendation tools, AI-generated customer communications, hiring screeners, and dynamic pricing engines. These receive the most scrutiny. Category B covers tools where AI assists human decision-making but a human reviews and approves the output. Writing assistants, AI-drafted reports, and predictive analytics dashboards typically fall here. Category C covers tools where AI operates entirely in the background on non-sensitive processes, like spam filtering or autocomplete suggestions.
This categorization forms the backbone of your compliance documentation. Reviewers will want to see that you have thought through where AI has consequential influence versus where it is simply a convenience feature.
Common Mistakes at This Stage
- Forgetting to include free or freemium tools. Many small businesses use free tiers of AI tools without formal vendor agreements. These still require documentation.
- Assuming that because a vendor does not market their product as "AI," it does not qualify. Check the vendor's own documentation for terms like "machine learning," "predictive," "automated scoring," or "intelligent recommendations."
- Leaving the inventory as a spreadsheet that only one person can access. Your inventory needs to live in a shared location that reviewers can reference, with a version date and a named owner.
Step 2: Build Your Governance Foundation (The Policy Room)
Estimated time: 6–10 hours to draft; 1–2 weeks to finalize with legal review if budget allows. This is your most important compliance asset.
The single most common reason small businesses struggle during an AI readiness review is the absence of written governance documentation. A governance policy does not need to be a 50-page legal document. For most small businesses, a clear, organized policy document of 5–10 pages covering the core requirements will satisfy reviewers.
What Your AI Governance Policy Must Cover
Your policy document needs to address six core areas. First, scope and definitions: clearly state which tools and processes the policy applies to, and define what your business means by "AI system" to avoid ambiguity. Second, approval and onboarding: describe the process by which a new AI tool can be adopted. Who has authority to approve? What review steps are required before a tool goes live? Third, human oversight requirements: for every Category A tool identified in your inventory, document who is responsible for reviewing AI outputs before they are acted upon, and how often that review happens.
Fourth, data access controls: specify what categories of data each AI tool is permitted to access, and explicitly prohibit unauthorized data sharing with AI vendors. Fifth, incident response: describe what your team does if an AI system produces an error, discriminatory output, or data breach. Who is notified? What is the escalation path? Sixth, policy review schedule: state when the policy will be reviewed and updated. Annually is the minimum; semi-annually is better given how quickly AI capabilities change.
Assigning a Named AI Compliance Point Person
Reviewers will ask who is responsible for AI compliance in your organization. For very small businesses, this may be the owner or a senior manager who takes on the role alongside other responsibilities. The title does not matter. What matters is that one specific named individual is identified in your policy as the person accountable for AI governance decisions. This person should be able to speak to your AI inventory, your vendor agreements, and your training records without hesitation.
Pro Tip: The One-Page Summary
Alongside your full policy document, create a one-page summary that any employee can read in five minutes. This summary should answer: what AI tools do we use, what are employees allowed and not allowed to do with AI, and who do they contact if something goes wrong. This document is not just for reviewers. It is the artifact that proves your governance is actually embedded in how your team operates, not just filed away in a folder.
Step 3: Train Your Frontline Team (The Training Room)
Estimated time: 2–4 hours per employee for initial training; ongoing 30-minute quarterly refreshers. Training logs are required documentation.
A governance policy that your team has never read is not a governance policy. It is a liability. Reviewers will speak with at least one frontline employee during the walkthrough interview, and they will ask that employee basic questions about your AI tools and policies. If the employee looks blank, the review outcome is compromised regardless of how good your paperwork is.
What Effective AI Training Looks Like for Small Business Teams
Effective training for an AI compliance checklist small business context does not mean turning your team into AI engineers. It means making sure every employee who interacts with an AI tool understands three things: what the tool does and does not do, what they are responsible for checking before acting on AI-generated output, and how to report a concern or error.
For most small businesses, training can be delivered in a 90-minute in-person or video session covering your AI inventory, a walkthrough of your governance policy, and role-specific guidance on the tools each team member uses. This should be followed by a short written acknowledgment that the employee attended and understood the material. That acknowledgment is your training log entry.
Role-Specific Training Modules
Generic training is better than nothing. Role-specific training is what impresses reviewers. Consider building short supplementary modules for each functional area of your business.
- Customer-facing staff: Training should focus on how to handle situations where an AI-generated recommendation or response needs to be corrected or overridden. Practice scenarios where the chatbot gives wrong information and the employee must step in.
- Finance and accounting: Training should cover what AI-assisted outputs in your accounting software mean, what thresholds trigger human review, and how to document when an AI recommendation was rejected.
- Hiring and HR: This is the highest-risk area for compliance failures. Training must cover the prohibition on making hiring decisions based solely on AI scoring, and the documentation required when AI tools are used in any part of the hiring process.
- Marketing and sales: Training should address AI-generated content policies, what disclosures may be required, and how to handle AI-personalized outreach in compliance with relevant privacy standards.
Documenting Training Completion
Your training log needs to record: employee name, training date, training topics covered, trainer or facilitator name, and employee signature or digital acknowledgment. Store these records centrally and make them accessible for the review. A simple shared folder or your HR system works fine. The format matters less than the consistency and completeness of the records.
The SBA's own guidance on federal AI training curriculum for small businesses provides useful benchmarks for what training content should cover. The breakdown of what the federal AI training curriculum actually teaches is a helpful resource for aligning your internal training content with what reviewers expect to see covered.
Step 4: Audit Your Vendor Agreements (The Contract Room)
Estimated time: 4–8 hours to review existing contracts; additional time for renegotiation if gaps are found. Start this early, vendor responses can take weeks.
One of the most underestimated compliance gaps for small businesses is the vendor contract. Most small businesses accept the standard terms of service for software tools without reading them carefully, and those terms rarely contain the AI-specific protections that the SBA compliance framework expects to see.
What Reviewers Look for in Vendor Agreements
For every Category A and Category B tool in your AI inventory, reviewers will want evidence that your vendor agreement addresses the following: data ownership and data use restrictions (does the vendor have the right to use your customer data to train their AI models?), data security standards (what protections does the vendor maintain?), incident notification obligations (how quickly must the vendor notify you of a breach or system error?), and AI system transparency (does the vendor provide documentation of how their AI makes decisions?).
Many standard SaaS terms of service fall short on data use restrictions in particular. It is common for software vendors to reserve the right to use anonymized customer interaction data to improve their models. Depending on the sensitivity of that data, this may create a compliance exposure that your business needs to address through a negotiated data processing addendum or by switching to a vendor whose terms are more restrictive.
Building Your Vendor Compliance Matrix
Create a simple table that maps each AI tool to the contract provisions that satisfy each compliance requirement. Where a provision is missing, note the gap and the remediation step you are taking. This matrix demonstrates to reviewers that your business actively manages vendor relationships rather than assuming vendors are compliant by default.
| Compliance Requirement | Status in Vendor Contract | Risk Level | Remediation Action |
|---|---|---|---|
| Data ownership clause | ✅ Present and favorable | Low | No action needed |
| Training data use restriction | ⚠️ Ambiguous language | Medium | Request DPA addendum from vendor |
| Breach notification timeline | ✅ 72-hour notification clause | Low | No action needed |
| AI decision transparency documentation | ❌ Not addressed | High | Request model card or explainability documentation from vendor; document request in file |
| Subprocessor disclosure | ⚠️ Generic reference only | Medium | Request updated subprocessor list |
| Security standards certification | ✅ SOC 2 Type II referenced | Low | Request copy of current certification |
What to Do When Vendors Won't Negotiate
Smaller software vendors, particularly those offering low-cost or free tools, often decline to negotiate custom contract terms. In these cases, you have two options. First, document in your compliance file that you requested improved terms and were declined, along with the date and method of the request. This demonstrates good faith. Second, assess whether the tool's risk level justifies its continued use given the contract gap. For Category A tools with unresolvable contract gaps, switching to a more compliance-ready vendor is the stronger position.
Step 5: Prepare Your Data Handling Protocols (The Data Room)
Estimated time: 4–6 hours to document existing practices; additional time if gaps require new controls. This step has the highest potential for uncovering surprises.
Data handling is where many small businesses have the most exposure, not because they are doing anything deliberately wrong, but because data practices that evolved organically over years often lack the explicit documentation that a compliance review requires. The AI for Main Street Act requirements place particular emphasis on how businesses manage customer and employee data that flows through AI systems.
Mapping Your Data Flows
For each AI tool in your inventory, document the specific data inputs the tool receives. A customer service chatbot, for example, may receive customer name, account history, purchase records, and the content of the customer's message. Each of these data types needs to be mapped against your data classification policy (which you may need to create if it does not exist) and against any applicable regulatory requirements, such as state privacy laws like the California Consumer Privacy Act or sector-specific rules for healthcare or financial services.
Create a simple data flow diagram for each Category A tool. This does not need to be a sophisticated technical diagram. A flowchart showing what data enters the system, what the system does with it, what output is generated, and where that output goes is sufficient for most review contexts.
Data Minimization and Retention
Reviewers will ask whether your AI tools receive only the data they need to function, or whether they have broader access than necessary. This is the principle of data minimization, and it is a core expectation in modern AI governance frameworks including those referenced in NIST's AI Risk Management Framework.
For each tool, document the access controls in place. If your CRM integrates with an AI analytics tool, does that tool have read access to your entire customer database, or only the relevant subset of records? If it has broader access than needed, restricting that access before the review is both a compliance improvement and a genuine risk reduction.
Retention policies also matter. How long does the AI vendor retain data processed through their system? How long do you retain AI-generated outputs? For Category A tools where AI outputs influence decisions, maintaining records of what the system recommended and what decision was ultimately made is a best practice that reviewers will look for favorably.
The Employee Data Sensitivity Issue
If any of your AI tools process employee data, including productivity monitoring tools, AI-assisted performance reviews, scheduling optimization tools, or hiring screeners, this requires separate and more detailed documentation. Employee data carries heightened sensitivity under both privacy law and the AI for Main Street Act compliance framework. Your documentation should clearly state what employee data each tool accesses, what employees were informed about this use, and how employees can request information about how AI-generated assessments of their work have influenced employment decisions.
Step 6: Run a Mock Review Walkthrough (The Rehearsal Room)
Estimated time: 2–3 hours for the mock review plus debrief. Schedule this at least two weeks before the actual review date to allow time for remediation.
Documentation and policy are necessary but not sufficient. The interview component of an AI readiness review catches businesses off guard because written preparation does not automatically translate to confident, accurate verbal responses under pressure. A mock review walkthrough is the most valuable preparation investment you can make in the final weeks before your review date.
How to Structure the Mock Review
Designate one person, ideally someone not deeply involved in the compliance preparation process, to play the role of the SBA reviewer. Give them the list of standard review questions (covered in the FAQ section of this guide) and have them conduct a 45–60 minute interview with your AI compliance point person and one frontline employee separately.
During the mock review, the "reviewer" should probe for specificity. If your compliance point person says "we have a policy for that," the reviewer should ask to see it immediately and ask the point person to explain a specific provision. If the frontline employee says "I know we're not supposed to use AI for hiring decisions," the reviewer should ask what they would do if their manager sent them an AI-generated candidate ranking and asked them to use it. These follow-up questions are where preparation gaps surface.
The Document Retrieval Test
During your mock review, time how long it takes to locate and present any document the reviewer asks for. If locating your AI inventory takes more than 90 seconds, your document organization needs work. Reviewers are not impressed by businesses that clearly have good policies somewhere but cannot find them during the review. Create a compliance binder, physical or digital, that contains every required document in a logical order that mirrors the review structure.
What to Do With Mock Review Findings
After the mock review, hold a debrief where the "reviewer" notes every question that produced a hesitant, incomplete, or incorrect response. Prioritize these gaps by risk level and assign a remediation owner and a completion deadline. Any gap that cannot be fully remediated before the review date should be documented with an explanation of the steps being taken, which is far better than having no awareness of the gap at all.
Step 7: Prepare Your Technology Demonstration (The Show Room)
Estimated time: 1–2 hours to prepare and rehearse. Technical issues during a live demonstration are a significant red flag for reviewers.
The tool demonstration phase of an AI readiness review is often the most anxiety-producing for small business owners, because it requires showing a live system to someone who may ask unexpected questions about how it works. The goal of this step is to make that demonstration feel controlled, clear, and confident rather than improvised.
Selecting Which Tools to Demonstrate
You will typically be asked to demonstrate one or two of your Category A tools. Select the tools that your team uses most fluently and for which your governance documentation is most complete. Prepare a standard demonstration scenario in advance: a realistic use case that shows the tool performing its intended function, a human reviewing the output, and the oversight step being applied before any action is taken.
For example, if you use an AI-assisted customer communication tool, your demonstration might show: a customer inquiry arriving, the AI generating a draft response, your employee reviewing and editing the draft, the employee checking the response against your communication policy, and the approved response being sent. This walkthrough shows the reviewer exactly where human oversight occurs and that it is a genuine part of your workflow, not a theoretical policy commitment.
Preparing for Technical Questions
Reviewers may ask technical questions about how a tool makes its recommendations. You do not need to be an engineer to answer these questions well. What you need is the vendor's documentation about how the tool works, typically a help center article, a model card if the vendor provides one, or the product documentation describing the underlying methodology. Have these documents printed or easily accessible during the demonstration.
If a reviewer asks a question you cannot answer, the correct response is: "I don't have that information available right now, but I can follow up with our vendor and provide it to you in writing within [specific timeframe]." This response demonstrates honesty and a functioning vendor communication process, both of which are positives.
Rehearsing the Demonstration
Run your demonstration at least twice in the week before the review. Ensure that login credentials work, that the tool performs as expected in your demonstration environment, and that any data shown during the demonstration does not inadvertently expose real customer personal information. Use anonymized or test data for the demonstration wherever possible.
Step 8: Align Your Marketing and Customer-Facing AI Use (The Storefront Room)
Estimated time: 2–3 hours to audit and document. This step is frequently overlooked but increasingly scrutinized.
Marketing is often where small businesses have the most AI tools with the least governance documentation. AI-powered advertising platforms, AI-generated content tools, personalization engines, and chatbots all fall within the scope of an AI readiness assessment for small businesses, and the customer-facing nature of these tools makes their compliance posture particularly visible.
AI Disclosure in Customer Communications
Your compliance documentation should address whether and how you disclose AI use to customers. The current requirements vary depending on the nature of the interaction. AI-generated marketing content does not typically require explicit disclosure in the same way that an AI system making a consequential decision about a customer's eligibility for a service would. However, your policy should state clearly what disclosures your business makes and why, rather than leaving this to individual employee judgment.
For businesses using AI chatbots for customer service, the question of disclosure is more pressing. A customer who believes they are speaking with a human and later discovers they were interacting with an AI has a legitimate grievance that can damage trust and, in some regulatory contexts, create legal exposure. Your policy should state whether your chatbot identifies itself as AI, and your training records should confirm that customer-facing staff know how to handle questions about whether they are speaking with a human or a bot.
AI in Advertising: What Reviewers Notice
If your business uses AI-optimized advertising platforms, reviewers may ask how you ensure that AI-driven targeting decisions do not result in discriminatory audience exclusions. This is particularly relevant for businesses in housing, credit, employment, or healthcare-adjacent industries, where the FTC has provided guidance on AI-related advertising claims and targeting practices.
Your documentation should note which advertising platforms you use, confirm that you have reviewed their non-discrimination policies, and describe any manual oversight steps your team applies to campaign targeting settings. For businesses running sophisticated AI-optimized campaigns, understanding how audience targeting intersects with compliance is an area where getting specialist input adds real value. The guide on audience targeting strategies in digital advertising covers the technical dimensions of this in useful detail.
Step 9: Create Your Compliance Documentation Package (The Filing Room)
Estimated time: 3–4 hours to compile and organize. This is the deliverable that reviewers interact with most directly.
Everything you have built in Steps 1 through 8 needs to exist in a coherent, organized, and accessible documentation package. This is not bureaucracy for its own sake. A well-organized compliance package communicates to reviewers that your business treats AI governance as an operational priority, not a checkbox exercise.
The Core Documentation Set
Your compliance documentation package should contain the following items, organized in this order:
- Executive Summary (1 page): Business name, AI compliance point person, date of last policy review, number of AI tools in use by category, and a brief statement of your business's approach to responsible AI use.
- AI Inventory (complete spreadsheet): All tools across all categories with the fields described in Step 1, version-dated.
- AI Governance Policy (full document): Your policy covering all six areas described in Step 2, signed by your business owner or CEO.
- Training Records: Completion logs for all employees, organized by role, with dates and topics.
- Vendor Compliance Matrix: The table from Step 4, with any gap remediation actions documented.
- Data Flow Documentation: Flow diagrams or written descriptions for each Category A tool.
- Incident Log: A log of any AI-related incidents, errors, or complaints since your business began using AI tools. An empty log is acceptable and should be noted as such, with the date the log was established.
- Vendor Agreements (relevant excerpts): Copies of relevant contract sections or full agreements for Category A tools.
Version Control and Dating
Every document in your package must have a version date and a named owner. Reviewers are trained to notice when documents appear to have been created in a rush immediately before the review. A governance policy dated three days before your review is a red flag. Begin building these documents as early as possible so that they have realistic version histories that reflect ongoing development rather than last-minute creation.
Digital vs. Physical Organization
Whether you organize your compliance package digitally or physically is less important than consistency. If you use a digital folder structure, ensure that every team member who might need to access a document during the review has the appropriate permissions and knows where to find it. A shared drive folder with clearly named subfolders for each document category works well for most small businesses.
Step 10: Brief Your Entire Team the Day Before (The Ready Room)
Estimated time: 30–45 minutes. This step is short but critical for managing review-day nerves and ensuring consistency.
The night before or the morning of your AI readiness review, bring your entire team together for a brief, focused preparation session. This is not the time for new information. It is the time to reinforce what everyone already knows and to make sure the day runs smoothly.
What to Cover in Your Team Brief
Walk through the review schedule so everyone knows when reviewers will be on-site or on the call, which team members will be interviewed, and what the demonstration sequence will be. Remind frontline staff that the review is not adversarial and that honest, specific answers are always better than vague reassurances. If they do not know the answer to a question, they should say so clearly and direct the reviewer to your compliance point person.
Review the one-page AI policy summary from Step 2. Go through your AI tool list and make sure every team member can name the tools their role uses and explain their oversight responsibilities in one or two sentences. Run one final document retrieval test: ask someone to pull up three different items from your compliance package and time how long it takes.
Managing the Human Element
Compliance reviews are evaluated by human reviewers who are influenced by how professional, prepared, and transparent a business appears. A team that is clearly nervous, gives contradictory answers, or visibly scrambles for documents creates a negative impression even when the underlying compliance posture is solid. A calm, organized, well-briefed team creates a positive impression even when a few documentation gaps remain. Both the substance and the presentation of your preparation matter.
Building a thorough AI strategy for your small business goes beyond review preparation. If you want to understand how to position your business competitively under the new legislative landscape, the guide to winning AI strategy for small businesses under the Main Street Act offers a forward-looking framework that complements the compliance-focused work in this guide.
The AI Compliance Checklist: Your Master Pre-Review Verification
Use this checklist in the final 48 hours before your review. Every item should have a clear "yes" with documentation to back it up. Any "no" or "in progress" items should be noted with the specific action being taken.
| Compliance Area | Checkpoint | Status | Document Location |
|---|---|---|---|
| AI Inventory | Complete, version-dated, all tools categorized A/B/C | ☐ | |
| Governance Policy | Written, signed, covers all 6 required areas | ☐ | |
| Compliance Point Person | Named in policy, briefed and ready | ☐ | |
| Training Records | All employees documented, signed, organized by role | ☐ | |
| Vendor Agreements | Reviewed, matrix complete, gaps documented with remediation | ☐ | |
| Data Flow Documentation | Complete for all Category A tools | ☐ | ☐ |
| Incident Log | Established with date, entries or documented as empty | ☐ | |
| Mock Review | Completed, findings remediated or documented | ☐ | |
| Tool Demonstration | Rehearsed, credentials verified, test data ready | ☐ | |
| Marketing AI Audit | Disclosure policy documented, targeting review complete | ☐ | |
| Team Brief | Scheduled and completed the day before or morning of review | ☐ |
Frequently Asked Questions About SBA AI Readiness Reviews
How do I know if my business has been selected for an AI readiness review?
The SBA notifies businesses selected for review in writing, typically by mail and email to the contact address on file with the SBA or your most recent federal business registration. If you receive a notification, it will specify the review date, the format (in-person, virtual, or hybrid), and the documentation you are required to submit in advance. If you are unsure whether a communication is legitimate, verify by contacting your regional SBA office directly using contact information from the SBA's official local assistance finder.
What if my business uses AI tools but was not aware they qualified as AI under the Act?
This is one of the most common situations reviewers encounter, and it is handled constructively when the business can demonstrate that upon becoming aware of the requirement, it took steps to inventory and document its tools. The inventory process in Step 1 of this guide addresses this directly. Starting the process immediately after learning of your review date is far better than claiming no AI tools are in use when evidence suggests otherwise.
Does every employee need to be trained, or only managers?
Every employee who uses an AI tool in the course of their work needs documented training on that tool and on the relevant sections of your AI governance policy. Managers and your compliance point person need more comprehensive training covering governance, oversight responsibilities, and incident response. Employees who do not use any AI tools in their role do not need to be included in training logs, but it is worth noting in your documentation that certain roles have been assessed as outside the scope of AI tool use.
How far back do my training records need to go?
Training records should cover the period from when your business first began using any AI tool that qualifies under the SBA framework. If you only began using AI tools recently, your records will naturally be recent. If your business has been using AI tools for several years, you may need to reconstruct training documentation for earlier periods or, where that is not possible, document the gap and show robust current training in place.
What happens if we fail the review?
An AI readiness review does not result in a binary pass/fail outcome for most small businesses. Reviewers typically produce a findings report that identifies areas meeting compliance standards and areas requiring remediation. Businesses are given a specified timeframe to address findings before a follow-up assessment. Repeat or severe non-compliance, particularly involving data misuse or discriminatory AI practices, can result in more significant consequences including restrictions on SBA program participation. This makes genuine preparation far more valuable than a surface-level compliance performance.
Do we need a lawyer to prepare for the review?
Legal review of your vendor contracts and governance policy is valuable if your budget allows it, particularly for businesses in regulated industries like healthcare, financial services, or childcare. For most general small businesses, a well-researched internal preparation process following the steps in this guide can produce a review-ready compliance posture without requiring legal counsel. If you do engage legal support, brief your attorney specifically on the AI for Main Street Act requirements rather than requesting a generic contract review.
How do I handle an AI tool that my vendor has discontinued or significantly changed since we started using it?
Document the change in your AI inventory with the date the tool changed or was discontinued. If the tool was replaced by a new or updated version, treat the new version as a fresh entry in your inventory and ensure it goes through your standard approval and documentation process. Discontinued tools should be marked as inactive in your inventory with the date of discontinuation. Do not delete historical entries, as reviewers may ask about tools that were in use before the review date.
What if a vendor refuses to provide any documentation about how their AI works?
Document the refusal in your vendor compliance matrix, including the date and method of your request. This documentation demonstrates good faith on your part. Assess whether the tool's category and risk level justify continued use given the lack of transparency. For Category A tools where you cannot obtain any explanation of how the AI makes decisions, this is a significant compliance risk that you should escalate to your compliance point person for a decision about continued use.
Is there a standard set of questions that SBA reviewers ask during the walkthrough interview?
While the SBA does not publish a standardized question bank publicly, the review consistently covers: what AI tools the business uses and how they were selected, who is responsible for AI governance, how employees are trained, what happens when an AI system makes an error, how customer data is protected when used in AI systems, and how the business ensures AI tools do not produce discriminatory outcomes. Your mock review in Step 6 should rehearse confident, specific answers to all of these.
Can an SBDC help us prepare for the review?
Yes, and this is one of the most underused resources available to small businesses. Small Business Development Centers (SBDCs) across the country have received guidance on supporting businesses through AI readiness preparation under the AI for Main Street Act. Many SBDCs offer free or low-cost consulting sessions specifically for this purpose. Contact your nearest SBDC as early as possible, as availability can be limited during periods when reviews are concentrated in your region.
How often will my business be subject to AI readiness reviews going forward?
The current framework does not specify a mandatory review frequency for most small businesses. Reviews are triggered by a combination of random selection, complaint-driven investigation, and participation in specific SBA programs that include AI governance as a condition of participation. The most reliable way to avoid compliance problems is to maintain your governance documentation and training records on an ongoing basis rather than treating this as a one-time exercise.
What is the difference between an AI readiness assessment and an AI audit?
An AI readiness assessment for small businesses under the SBA framework is a forward-looking evaluation of whether your governance, training, and operational practices are sufficient to responsibly manage your AI tools. An AI audit is typically a more intensive, backward-looking review of specific AI system decisions to assess whether they were accurate, fair, and compliant. Readiness reviews are the more common experience for small businesses. Full audits are typically reserved for businesses where specific concerns have been raised about the outcomes of their AI systems.
Key Takeaways
- Start with your AI inventory. You cannot prepare for an AI readiness review without knowing exactly which tools qualify as AI under the SBA framework. Shadow AI tools adopted by individual employees without formal approval are a common and high-risk surprise.
- Written governance is non-negotiable. A policy that exists only in practice, not on paper, does not satisfy reviewers. Your governance document must cover scope, approval processes, oversight requirements, data controls, incident response, and review schedules.
- Training records must name individuals. A general statement that "staff have been trained" is not sufficient. Reviewers need to see named employees, training dates, topics covered, and signed acknowledgments.
- Vendor contracts have specific AI compliance gaps. Review every agreement for data use restrictions, breach notification timelines, security certifications, and transparency documentation. Document gaps and remediation steps.
- Data flow documentation is required for Category A tools. Know exactly what data each consequential AI tool receives, what it does with that data, and where the output goes.
- Run a mock review at least two weeks before the real one. The interview component of the review requires verbal fluency with your compliance posture, not just written documentation. Mock reviews surface gaps that paperwork audits miss.
- Your compliance documentation package needs version dates and named owners. Documents that appear to have been created in a rush immediately before the review undermine your credibility regardless of their content.
- SBDCs are a free resource. Contact your nearest Small Business Development Center as early as possible in the preparation process. Many offer AI readiness preparation support specifically tied to the current legislative requirements.
- Ongoing compliance beats one-time preparation. The most defensible position is a governance system that generates current, accurate compliance documentation naturally, rather than a sprint to prepare documents for a specific review date.
Turning Review Preparation Into Lasting AI Governance
The business owner who received that Tuesday letter from the SBA has a choice. They can treat the AI readiness review as a deadline to be cleared and then return to business as usual. Or they can use the preparation process described in this guide as the foundation of a genuine, ongoing AI governance practice that protects their business, builds customer trust, and positions them to take advantage of AI capabilities confidently as the technology continues to evolve.
The ten steps in this guide are not just a compliance checklist. They are the building blocks of an operational AI governance system. An AI inventory that is updated whenever a new tool is adopted. A governance policy that is reviewed twice a year. Training records that grow as new employees join and existing employees receive refreshers. A vendor compliance matrix that is checked whenever a vendor updates their terms. An incident log that captures and learns from every error.
Businesses that build these systems do not dread the next review. They welcome it, because the review confirms what they already know: their AI operations are well-governed, their team is prepared, and their customers' data is protected. That confidence is worth far more than any single compliance outcome.
If your business is navigating the requirements of the AI for Main Street Act and looking for strategic guidance on how to build an AI capability that is both compliant and genuinely competitive, the resources and frameworks available through current SBA programs and trusted small business advisors represent an investment that pays dividends well beyond the review room.





