The Exposure Assessment — Patrick
01 — The AI Exposure Assessment · for professional-services firms

Find out where AI is quietly exposing your firm — before your clients or board ask.

Your staff are already using AI on client work. Patrick’s evidence-based assessment shows you exactly where that creates risk — and gives you the answers partners, clients, and insurers are starting to ask for.

No hype. No tools to resell. A report you could hand to your managing partner as-is.

See what we check in your sector Read a sample report first
The method is on the page — no forms, no email, no sales call
02 — What it is
The AI Exposure Assessment

Not a questionnaire. We look at the real thing — tool usage, policies, vendor terms, sample workflows — quietly and confidentially, and give you certainty either way.

10 business days·Fixed scope·Confidential
What you get
AI Usage & Exposure Map Governance Gap Report 90-Day Fix Sequence Answers you can use Employee training & records
See the full assessment ↓
03 — If this sounds familiar

You’re not behind. But you probably can’t see everything.

Quiet AI use is the normal state of most firms right now — not a failure. The risk isn’t that AI is in the building. It’s that nobody can currently answer where, with what data, and under what rules.

That’s an answerable question. It just needs looking at properly.

You suspect staff are pasting client work into public AI tools — you just can’t see it.
A client questionnaire just asked how you govern AI. You drafted the answer very carefully.
Your professional-indemnity renewal added AI questions this year.
A partner asked “are we okay on AI?” and the honest answer was “I think so.”
You’d rather find the answer yourself than hear it from a client.
04 — The method · by sector

What we look for in a firm like yours.

Every sector meets AI differently. These are the patterns documented across firms like yours — the starting map for an assessment, published openly. Run the checks yourself this week; the assessment verifies everything against evidence.

What we check across {{ sectorLabel }} Documented patterns · verified per firm
The obligations in play

{{ dutiesText }}

The quiet patterns we find
{{ q }}
The scrutiny arriving
{{ s }}
Checks worth running this week
{{ c }}
The assessment verifies each of these against your actual usage, policies, and vendors — and pairs every finding with its fix. See what the report finds →
05 — What you actually receive

A report you could hand to your managing partner.

Findings with evidence, a fix for each, and language you can reuse when clients and insurers ask. Here’s a page from a sample report:

AI Exposure Assessment — Executive Findings
Hartwell & Byrne LLP · accounting · 85 staff · names changed, findings representative
Sample
Summary for leadership

Client data is reaching unapproved AI tools through well-meaning staff. Nothing here is unusual or malicious — but three gaps need closing before a client or insurer asks the question you can’t yet answer.

HighClient data in public AI tools

Evidence: 14 of 85 staff used public AI tools on client work in the sample month; 3 instances included client-identifiable data.

Fix: approved-tool route with a redaction standard — keeps the productivity, removes the leak.

HighNo standard answer for clients or insurers

Evidence: two client questionnaires answered ad hoc this quarter; PI renewal asked about AI use for the first time.

Fix: a firm-wide position and disclosure language, backed by a usage register.

MediumVendors using AI on your client data

Evidence: transcription and document tools process client material with no AI terms reviewed and no processing addendum on file.

Fix: a vendor review checklist and contract addenda for the four tools that matter.

Language you can adapt — once it’s true

“The firm governs AI use under a written policy: approved tools only, no client-identifiable data in public models, and partner review of AI-assisted client work. Usage is logged and vendors are reviewed annually.”

Every report ends with the paragraph you’ll need for questionnaires, renewals, and partner meetings — and the 90-day sequence that makes it accurate.

Full report: 18–24 pages · evidence appendix · ordered 90-day fix sequence How the assessment works ↓
Standards Readiness Map — later in the same report
where your fixes land against the frameworks clients are starting to cite
Sample
What you’ll have
What the framework asks
Standing
AI Use Policy, with a named owner
ISO/IEC 42001 — documented AI policy, leadership commitment, defined roles
Covered
Approved-Tool Register + vendor reviews
ISO/IEC 42001 — AI risk assessment & third-party controls; the AI questions in SOC 2-scope client audits
Covered
Incident Procedure, rehearsed
ISO/IEC 42001 — incident response and corrective action
Covered
Training with a completion log
ISO/IEC 42001 — competence & awareness; EU AI Act Article 4 — documented literacy measures
Covered
AI system impact assessments
ISO/IEC 42001 — the certification step beyond day-to-day governance
If certifying

If RFPs start asking “are you ISO 42001 certified or implementing it?” — and in some markets they have — you’re most of the way there: we run the gap analysis and pre-audit preparation; an accredited body certifies.

06 — The engagement · 10 business days · fixed scope

The AI Exposure Assessment.

A form can’t show you where AI actually touches client work. So we look at it directly — usage, policies, vendor terms, sample workflows — quietly and in confidence, and hand you certainty either way.

01

AI Usage & Exposure Map

Who is using what, on which client work, with what data — seen, not guessed.

02

Governance Gap Report

Policy, review standards, and vendor controls vs. where a firm like yours should be.

03

90-Day Fix Sequence

Every finding paired with its fix, ordered by risk and effort. No transformation program.

04

Answers you can use

Ready language for client questionnaires, insurer renewals, and the next partner meeting.

05

Employee AI training · the extra layer

Short, role-based courses built from your policy and approved tools — for when clients ask whether your team is actually trained. And they will. Completion is tracked, so you can attest it in questionnaires and renewals — and for EU-exposed firms, the same records serve as EU AI Act Article 4 evidence, with enforcement live from August 2026.

Confidential by default. Findings stated against evidence, benchmarked against firms in your sector. If you’re in good shape, the report says so — plainly.

Book the assessment →
07 — If gaps turn up · a quiet follow-on

Most gaps don’t need a transformation. They need documents and habits.

When the assessment finds something, most firms close it with AI Compliance in a Box — the policy pack and controls from your fix sequence, written from your evidence rather than a template.

It’s there if you need it. Plenty of firms take the report and handle the fixes themselves — that’s a fine outcome too.

Ask about it after your assessment
AI Use Policy
Hartwell & Byrne LLP · page 1 of 6
Sample
1 · Why this policy exists

Our clients trust us with confidential financial information. AI tools are part of how we work; this policy makes that use safe, consistent, and defensible.

2 · The rule everyone remembers

No client-identifiable data in any tool that isn’t on the Approved Register. Redact first — names, numbers, identifiers out.

3 · Review standard

AI-assisted client deliverables are reviewed by the engagement partner before release.

Why not a template: §2 is written against finding 01 — the three real incidents — not a hypothetical.
Owner: COO · reviewed quarterly · v1.2 · mapped to NIST AI RMF
Approved-Tool Register
Appendix A · maintained monthly
Sample
Claude · Team workspaceApproved
Zero-retention terms on file; client data with partner sign-off.
ChatGPT · personal accountsNot approved
No agreement in place — where finding 01 happened.
Fireflies · transcriptionConditional
Internal meetings only until the AI addendum is signed (finding 03).
Document AI · in the DMSApproved
Contracted, logged, auditable.
Why not a template: built from your usage map. A generic register can’t know what your staff already use.
AI Incident Procedure
one page · same-day steps · rehearsed quarterly
Sample
If client data reached an unapproved tool:
1Tell the AI owner the same day. No blame attached.
2Record what went in, which tool, which client.
3Owner checks the tool’s retention terms, deletes where possible, logs the outcome.
4If client-identifiable data was involved, the client hears it from us — with the fix already made.

Fast honesty fixes; silence compounds. No one gets in trouble for reporting first.

Why not a template: it names your owner, your tools, and the same-day promise in your questionnaire answers — so the procedure and your answers can’t drift apart.
Questionnaire & Renewal Answers
used verbatim · kept current as usage changes
Sample
From a client security questionnaire
“Does your firm use generative AI when delivering our work?”

A · Yes — under a written AI Use Policy: approved tools only, no client-identifiable data in public models, and partner review of AI-assisted deliverables.

From a professional-indemnity renewal
“What controls govern staff use of AI tools?”

A · An approved-tool register, a redaction standard, quarterly policy review, and a same-day incident procedure. Usage is logged and auditable.

+ 12 more, covering the questions that appear most often — updated whenever your register changes.
Why not a template: every sentence points at a control that actually exists — verified by the assessment. Nothing you’d have to walk back.

Also in the box: vendor review checklist · contract addenda · client-data desk cards for each team — each traced to a finding in your report.

And when clients ask “is your team trained?”

we run the training — and hold the record
AI Training & Completion Records
role-based modules · we deliver them · we keep the log
Sample
A module your team actually takes
Client Data & AI · Question 3 of 6
A client emails their draft accounts and asks for a quick summary. What do you do first?
Paste them into a personal ChatGPT account to save time.
Use an approved tool — or redact names and numbers first, then summarize. Correct
Forward it to whoever on the team is quickest with AI.

Why it matters: the draft is client-identifiable. Approved tools and redaction keep the speed without the exposure — the exact rule in your policy.

4 short modules · role-based · ~15 minutes · refreshed as your register changes
And the record that proves it
Name · roleStatusDate
Priya N. · Tax manager✓ Complete12 Jun
Daniel O. · Audit senior✓ Complete11 Jun
Susan L. · Partner✓ Complete9 Jun
Marco R. · New starter, wk 1Due · day 1
New employee starts?

It’s step 4 of onboarding — assigned automatically on day one, logged the day they complete it. Nobody has to remember.

Why not a template: we deliver the course and keep the completion log — so when a client or insurer asks “is your team trained on AI?”, the answer is a dated record, not “we think so.”
If the asks escalate
Standards readiness

ISO/IEC 42001 gap analysis and pre-audit preparation when certification becomes worth it — your Box already maps to the standard. The same artifacts answer the AI questions in SOC 2-scope client audits.

Year two and beyond
Kept Current

An annual re-assessment plus maintained register, questionnaire answers, and policy cadence — tools change quarterly, and what you tell clients should stay true.

Know for certain.

Built for firms of 20–250 people that handle confidential client work — accounting, consulting, legal-adjacent, HR, risk advisory, engineering and design.

Start with the sample report Free to read · no contact needed
How it works from here
1Read the sample report and run your sector’s checks yourself — free, no contact.
2If the checks turn something up, book a 30-minute call — we walk through what the assessment would verify.
3If certainty matters, the assessment confirms it against evidence in ten business days.