Control the risk

Use AI without handing your data to someone else

Your team is already pasting client data into public AI tools. We put the policy, access controls and vendor review in place that let you say yes to AI safely — sized for a mid-sized business, not an enterprise compliance department.

The problem

Why this keeps going wrong

The uncomfortable fact is that AI governance is no longer a decision you get to make in advance. Your staff adopted these tools themselves, on their own accounts, months ago. The only open question is whether the business has any visibility or control over it.

That matters for three reasons that are becoming concrete rather than theoretical. Client due-diligence questionnaires now ask about AI controls directly. Professional indemnity insurers have started asking. And UAE data protection obligations apply to information you put into a third-party tool exactly as they apply to information you store yourself.

The instinct is to ban it. Bans do not work — they move usage onto personal devices where you have no visibility at all, and they cost you the efficiency your competitors are getting. What works is a sanctioned route good enough that nobody needs the unsanctioned one, plus enough monitoring to know the difference.

You will recognise this if

  • You could not produce a list of AI tools in use if a client asked tomorrow.
  • A client DDQ or insurance renewal has asked about AI and you improvised the answer.
  • Staff are using personal accounts for work involving client information.
  • You handle regulated, financial or health data and have no written AI position.
  • Somebody has already had a near-miss and it prompted an uncomfortable conversation.

How we do it

The engagement, week by week

No discovery phase that never ends. Every stage produces something you can hold.

  1. Week 1

    Establish what is actually in use

    Anonymous survey plus, where you have the tooling, network and SaaS discovery. We are explicit that this is not a disciplinary exercise, because an accurate picture is worth far more than a tidy one. In every engagement we have run, the real number exceeds what management expected.

    You get: An inventory of tools, users, data categories and current exposure.

  2. Week 2

    Write the policy with the people it governs

    We draft with a working group drawn from the teams who will live under it, not in isolation. It stays under ten pages and covers approved use, prohibited use, what data may never leave the business, and how somebody requests a new tool. If a rule cannot be explained in a sentence, it will not be followed.

    You get: A signed-off AI usage policy, plus a one-page version people will actually read.

  3. Week 2–3

    Review vendors and configure them properly

    For each tool you want to keep: where data is processed, how long it is retained, whether it trains on your inputs, what the contractual position is, and what the security posture looks like. Then we configure the approved ones correctly — because most of these tools are considerably safer on their enterprise tier with training disabled, and most businesses have never changed the defaults.

    You get: An approved-tool list with the configuration applied, and a rejected list with reasons.

  4. Week 3–4

    Controls, monitoring and a review rhythm

    Least-privilege access to tools and to the data behind them, guardrails against the accidental-paste failure mode, visibility into usage, and a scheduled review so the policy does not go stale within a quarter. We also write the language you need for client questionnaires and insurer forms.

    You get: Access controls in place, monitoring live, a review calendar, and client-facing wording.

What you get

Deliverables, not a workshop

  1. AI usage policy

    Approved and prohibited use cases, written in plain language and under ten pages.

  2. Access & data controls

    Rules for client, financial and regulated data, plus guardrails against accidental leakage.

  3. Vendor review

    Data handling, retention and security posture assessed before any tool is approved.

  4. Monitoring & review cycle

    Visibility into usage and output quality, with a scheduled policy review.

Included

  • Discovery of sanctioned and unsanctioned AI usage
  • A written, signed-off AI usage policy with a practical one-page summary
  • Vendor data-handling and security-posture review for the tools you intend to keep
  • Configuration of approved tools: retention, training opt-out, access scope
  • Least-privilege access design across tools and underlying data
  • Usage monitoring and a scheduled review cycle
  • Response wording for client DDQs and insurer questionnaires
  • Practical training for staff, delivered in a session rather than as a PDF

Not included

  • Legal advice — we work to your obligations, we do not opine on them
  • A full ISO 27001 or SOC 2 certification programme, though this is compatible with one
  • Penetration testing or general information security assessment beyond AI tooling
  • Acting as your outsourced Data Protection Officer

If you need any of these, we will say so and point you at someone who does them well.

How you judge us

What we measure

Agreed at kick-off, reported against at the end. If we cannot move these, the engagement did not work and we would rather both of us know that early.

  1. Tools discovered versus tools previously known
  2. Percentage of staff who have read and acknowledged the policy
  3. Approved tools correctly configured for retention and training opt-out
  4. Time to answer a client AI due-diligence question, from "we will get back to you" to same-day

FAQ

Governance & Security: your questions

Are we too small for this?

The exposure does not scale with headcount — it scales with the sensitivity of the data your people handle. A twelve-person advisory firm dealing with client financials carries more meaningful risk than a two-hundred-person business that handles nothing confidential.

Our staff will not like being monitored.

The monitoring is at tool and category level, not keystroke surveillance, and we recommend being completely transparent about what is and is not observed. Framed as "here is what you are now allowed to do", this lands very differently from framing it as an investigation.

What if we find something serious in week one?

We stop and deal with it. Establishing scope and materiality comes first; the policy work resumes afterwards. This has happened, and handling it properly is the point of looking.

Does this give us ISO 27001 or SOC 2?

No, and anyone telling you a four-week engagement does is overselling. It is designed to be compatible with those programmes and will materially reduce the AI-related work if you pursue one later.

How is this kept current when the tools change monthly?

The policy is written around data categories and behaviours rather than product names, so it survives the tools changing. The approved-tool list is the part that moves, and the review cycle is what keeps it honest.

Start with a conversation, not a proposal

Thirty minutes. We will tell you whether this is the right place to start for you — including if it is not.