Why firms commission this

You cannot manage what nobody has written down.

In almost every business we visit, AI use is bigger than the leadership thinks. The marketing manager has a ChatGPT habit. A fee earner found a summarising tool. Someone switched on Copilot because it appeared in the ribbon one morning. None of it was signed off, none of it is written down anywhere, and every bit of it carries your firm's name and your clients' data.

That gap between what leadership believes and what is actually happening is the single biggest AI risk in most organisations. The assessment closes it. Fully, honestly and without pointing fingers at the staff who were only trying to do their jobs faster.

How it works

Built with your people, in your building

We do this with the stakeholders who know the business best. The practice manager who knows every process. The senior administrator everyone actually goes to with questions. The IT lead who knows what is installed. They know how work really gets done, which is often quite different from how the org chart says it gets done.

01

Workflow walkthrough

We sit with your key people and walk through how work actually flows: where data enters, who touches it, which tools are involved and where AI has quietly crept in. People tell us things in these sessions they had never thought to mention to anyone.

02

The AI risk inventory

Every tool, every use, every data flow goes into a single inventory. Sanctioned and unsanctioned alike. This becomes a living document your firm owns, not a report that gathers dust in a drawer.

03

Regulatory mapping

Each entry is mapped against the rules your firm answers to: UK GDPR, your sector regulator's expectations, and the EU AI Act's risk categories, including the Article 4 duty to ensure your staff are AI literate. You see exactly which obligations each use touches.

04

Findings, in plain English

You get a written picture of your exposure with a prioritised list of actions. No jargon, no padding, no fifty-page appendix. The kind of document you could hand to your insurer, your regulator or your board and be pleased with.

What you walk away with

Documents that earn their keep

Everything is written to be used, shown and updated. When the renewal questionnaire or the client query lands, you will already have the answer.

  • A complete AI risk inventory covering every tool and use across the business.
  • An exposure map tied to your specific regulatory obligations and the EU AI Act.
  • A prioritised action list: what needs attention now, soon and eventually.
  • A clear answer for insurers, regulators and clients who ask how you manage AI.
  • A natural foundation for training and governance work, if and when you want it.

Seen it work

This is where Browns started.

When Browns came to us, they had the right instincts and a very specific question: with data of this kind, what does responsible AI use actually look like? The assessment gave those instincts a structure, and everything that followed was built on it.

Read the full Browns case study to see how the assessment turned into training, governance and a team that uses AI with confidence.

Free · 5 minutes · Instant result

Not ready to talk? Find out where you stand first.

Eighteen questions across risk, people, governance and cybersecurity. Answer honestly and you get an instant AI readiness score, the specific gaps most likely to cost you, and clear next steps built around your answers.

Start the free risk check

No obligation. Seen only by us, never shared.

Find out what's really happening in your firm.

It starts with a free thirty minute conversation. Bring your worries, we'll bring straight answers.

Book a free intro call