Practical AI and automation checks for Swiss SMEs

AI tools can become useful very quickly. That is part of their value — and part of the risk.

Many companies do not start with a formal “AI project”. They start with one useful prompt, one browser extension, one copied spreadsheet, one connected mailbox, or one automation between email, cloud storage, CRM, and a spreadsheet.

For Swiss SMEs, the practical question is not only whether AI tools should be used. The better question is:

What data, access, ownership, and review rules should be in place before AI tools touch company information?

This does not require a heavy governance programme. It does require a clear view of where company data goes, who controls the accounts, and which workflows are becoming business-relevant.


1. Check what data may enter AI tools

The first risk is often simple: employees use AI tools to make work easier, but nobody has clearly defined what information is allowed.

Common examples include:

  • client names and contact details,
  • contracts, proposals, invoices, or financial information,
  • HR or employee information,
  • internal pricing, strategy, or operational details,
  • technical exports, logs, source code, or configuration details.

A practical starting point is to define three categories:

  1. Allowed — public or non-sensitive information.
  2. Sensitive — information that requires care, approval, or a business-grade tool.
  3. Prohibited — information that should not be entered into external AI tools.

The rule should be short enough that employees can actually follow it.


2. Check whether the tool is personal or company-controlled

A useful AI or automation workflow can quickly become dependent on one person’s account.

Questions to ask:

  • Is the account personal or company-owned?
  • Who can reset access if the user is unavailable?
  • What happens when an employee leaves?
  • Are important workflows connected to one person’s mailbox, browser session, laptop, or API key?
  • Does management know which tools are business-critical?

If an automation matters to the business, it should not depend only on one individual’s personal account.


3. Check which systems are connected

AI and automation tools become more sensitive when they are connected to business systems.

Typical connections include:

  • email and shared mailboxes,
  • cloud storage,
  • CRM or customer databases,
  • accounting or invoicing tools,
  • spreadsheets,
  • ticketing or support systems,
  • internal dashboards or reporting tools.

A simple one-page map is often enough for a first review:

Source system → AI/automation tool → destination → owner → data involved → risk

This helps the business see where data moves, who owns the workflow, and where controls may be missing.


4. Check API keys, credentials, and access rights

API keys and connected accounts often become invisible passwords for business processes.

They deserve the same discipline as privileged access.

Questions to ask:

  • Are API keys stored in scripts, spreadsheets, notes, or shared documents?
  • Are service accounts used where appropriate?
  • Are permissions limited to what the workflow actually needs?
  • Is multi-factor authentication enabled for important accounts?
  • Can access be revoked quickly if something changes?
  • Is there a recovery process if an account or key is lost?

The goal is not to stop useful automation. The goal is to prevent fragile or overly powerful access from becoming invisible.


5. Check where human review is required

AI-generated output can be useful, but not every output should be used directly.

SMEs should define human review points for higher-risk tasks, such as:

  • client communication,
  • legal or contractual wording,
  • financial decisions,
  • HR or employee matters,
  • technical/security recommendations,
  • public content,
  • operational decisions with client impact.

Practical examples:

  • AI may draft a client email, but a human approves it before sending.
  • AI may summarise a document, but a person checks the conclusion before relying on it.
  • AI may support data checks, but exceptions are reviewed by the process owner.

This keeps AI useful while reducing avoidable errors.


6. Check documentation and continuity

A workflow does not need a large manual, but it should be understandable by someone other than the person who built it.

Minimum documentation can include:

  • what the workflow does,
  • who owns it,
  • which systems it connects,
  • what data it processes,
  • which accounts or API keys it uses,
  • what happens when it fails,
  • how to pause, change, or recover it.

This matters because many AI and automation risks only become visible when something breaks, a key employee leaves, or a connected tool changes.


7. Start with a lightweight review

For most SMEs, the first step does not need to be a large AI governance programme.

A practical first review can focus on:

  • listing current AI tools and automations,
  • identifying sensitive data exposure,
  • mapping the most important workflows,
  • checking account ownership and recovery,
  • reviewing API keys and connected access,
  • defining simple usage rules,
  • prioritising quick wins.

The outcome should be understandable by management and useful for the people running the workflows.

Good security guidance for SMEs should also stay connected to the broader basics: account protection, phishing resilience, backups, patching, and clear responsibilities. The Swiss National Cyber Security Centre provides general security information for businesses here: NCSC information for companies.


How Clearpoint can help

Clearpoint helps Swiss SMEs review AI and automation usage, map practical risks, and turn informal tool adoption into safer operating rules and clear next steps.

A focused review can cover:

  • AI tool usage and company-data handling,
  • workflow automation and integrations,
  • accounts, API keys, access, and ownership,
  • documentation and continuity,
  • human review points,
  • practical quick wins and next-step priorities.

If your team is already using AI tools or automation and you are not fully sure what data, accounts, or workflows are connected, start with a short conversation.

View the AI & Automation Security Review