Your staff are already using AI on client work. Patrick’s evidence-based assessment shows you exactly where that creates risk — and gives you the answers partners, clients, and insurers are starting to ask for.
No hype. No tools to resell. A report you could hand to your managing partner as-is.
Not a questionnaire. We look at the real thing — tool usage, policies, vendor terms, sample workflows — quietly and confidentially, and give you certainty either way.
Quiet AI use is the normal state of most firms right now — not a failure. The risk isn’t that AI is in the building. It’s that nobody can currently answer where, with what data, and under what rules.
That’s an answerable question. It just needs looking at properly.
Every sector meets AI differently. These are the patterns documented across firms like yours — the starting map for an assessment, published openly. Run the checks yourself this week; the assessment verifies everything against evidence.
{{ dutiesText }}
Findings with evidence, a fix for each, and language you can reuse when clients and insurers ask. Here’s a page from a sample report:
Client data is reaching unapproved AI tools through well-meaning staff. Nothing here is unusual or malicious — but three gaps need closing before a client or insurer asks the question you can’t yet answer.
Evidence: 14 of 85 staff used public AI tools on client work in the sample month; 3 instances included client-identifiable data.
Fix: approved-tool route with a redaction standard — keeps the productivity, removes the leak.
Evidence: two client questionnaires answered ad hoc this quarter; PI renewal asked about AI use for the first time.
Fix: a firm-wide position and disclosure language, backed by a usage register.
Evidence: transcription and document tools process client material with no AI terms reviewed and no processing addendum on file.
Fix: a vendor review checklist and contract addenda for the four tools that matter.
“The firm governs AI use under a written policy: approved tools only, no client-identifiable data in public models, and partner review of AI-assisted client work. Usage is logged and vendors are reviewed annually.”
Every report ends with the paragraph you’ll need for questionnaires, renewals, and partner meetings — and the 90-day sequence that makes it accurate.
If RFPs start asking “are you ISO 42001 certified or implementing it?” — and in some markets they have — you’re most of the way there: we run the gap analysis and pre-audit preparation; an accredited body certifies.
A form can’t show you where AI actually touches client work. So we look at it directly — usage, policies, vendor terms, sample workflows — quietly and in confidence, and hand you certainty either way.
Who is using what, on which client work, with what data — seen, not guessed.
Policy, review standards, and vendor controls vs. where a firm like yours should be.
Every finding paired with its fix, ordered by risk and effort. No transformation program.
Ready language for client questionnaires, insurer renewals, and the next partner meeting.
Short, role-based courses built from your policy and approved tools — for when clients ask whether your team is actually trained. And they will. Completion is tracked, so you can attest it in questionnaires and renewals — and for EU-exposed firms, the same records serve as EU AI Act Article 4 evidence, with enforcement live from August 2026.
Confidential by default. Findings stated against evidence, benchmarked against firms in your sector. If you’re in good shape, the report says so — plainly.
Book the assessment →When the assessment finds something, most firms close it with AI Compliance in a Box — the policy pack and controls from your fix sequence, written from your evidence rather than a template.
It’s there if you need it. Plenty of firms take the report and handle the fixes themselves — that’s a fine outcome too.
Ask about it after your assessmentOur clients trust us with confidential financial information. AI tools are part of how we work; this policy makes that use safe, consistent, and defensible.
No client-identifiable data in any tool that isn’t on the Approved Register. Redact first — names, numbers, identifiers out.
AI-assisted client deliverables are reviewed by the engagement partner before release.
Fast honesty fixes; silence compounds. No one gets in trouble for reporting first.
A · Yes — under a written AI Use Policy: approved tools only, no client-identifiable data in public models, and partner review of AI-assisted deliverables.
A · An approved-tool register, a redaction standard, quarterly policy review, and a same-day incident procedure. Usage is logged and auditable.
Also in the box: vendor review checklist · contract addenda · client-data desk cards for each team — each traced to a finding in your report.
Why it matters: the draft is client-identifiable. Approved tools and redaction keep the speed without the exposure — the exact rule in your policy.
It’s step 4 of onboarding — assigned automatically on day one, logged the day they complete it. Nobody has to remember.
ISO/IEC 42001 gap analysis and pre-audit preparation when certification becomes worth it — your Box already maps to the standard. The same artifacts answer the AI questions in SOC 2-scope client audits.
An annual re-assessment plus maintained register, questionnaire answers, and policy cadence — tools change quarterly, and what you tell clients should stay true.
Built for firms of 20–250 people that handle confidential client work — accounting, consulting, legal-adjacent, HR, risk advisory, engineering and design.