Approving Tools Without a Procurement Function

A small business does not have a procurement department. There is no formal process for evaluating and approving new software. Yet every day, someone on your team might want to try a new AI tool. They read about it online, hear about it from a friend, or find it solves a problem they are facing. How do you say yes or no without slowing down your business and without making decisions based on incomplete information?
The answer is a simple approval process that takes fifteen minutes per tool and gives you visibility over what is happening. This is not bureaucracy. It is practical risk management. You do not need a vendor evaluation matrix or a procurement committee. You need one person responsible for asking the right questions and you need to ask those questions consistently.
When someone on your team wants to use a new AI tool, they should ask their manager or the person responsible for approvals. That person should ask five questions. First, what problem does this tool solve? Second, what data will go into it? Third, what happens to that data according to the tool’s terms of service? Fourth, can we achieve the same outcome using an already-approved tool? Fifth, is the cost justified by the benefit?
The first question ensures the tool solves a real problem, not a theoretical one. A team member might want to use an AI tool because it is trendy, not because it actually helps. If the tool does not solve a clear problem, you do not need it. The second question ensures you understand what you are feeding into it. The third question ensures you know the data handling terms. Most vendor terms of service have a data section that is three to five paragraphs. If you cannot find it, the vendor probably does not take data confidentiality seriously and you should look elsewhere. The fourth question prevents tool sprawl. If you already have a tool that can solve the problem, adding another tool just creates complexity. The fifth question ensures the cost makes sense. A 5 pound per month tool is not worth it if it saves two hours per year. A 50 pound per month tool makes sense if it saves ten hours per month.
Once you have asked these five questions, you make a decision. You either approve the tool, ask for more information, or decline. Write down which tools are approved and store that list somewhere accessible to your team. Update your two-page AI policy to include the newly approved tool. If you decide to use the tool, someone must take responsibility for the account, for paying the bill, and for ensuring the tool is used according to the guidelines in your policy.
There is a second layer of decisions for tools that process sensitive data or make important business decisions. If a tool uses customer data or affects customer outcomes, you need slightly more scrutiny. Does the vendor have a track record? Are they likely to exist in three years? What is their security and confidentiality track record? Can you see third-party reviews or case studies from similar businesses? A fifteen-minute conversation with a vendor can answer most of these questions. Small vendors are often happy to speak with potential customers, especially paying customers.
For most AI tools, the decision can be quick. ChatGPT paid tier and Anthropic’s Claude are established, well-resourced vendors with long-term viability. A marketing team can feel confident approving these. For lesser-known tools or tools from new companies, a slightly longer evaluation might be needed. This is not risk aversion. It is proportionate caution.
Documentation matters here too. For each approved tool, keep a short record of the approval decision. Write down when it was approved, by whom, and what problem it solves. Keep a copy of the data handling section from the vendor’s terms. This record is not for auditors. It is for you. If a new team member asks whether a tool is approved, you have an answer. If the vendor’s terms change, you have a copy to compare against. If a problem ever arises with the tool, you have a record of who made the decision and why.
