01 Assess · AI Risk & Readiness Audit
Start with what you’re already using.
A short, focused diagnostic of how AI is currently used across your firm, what that exposes you to, and what needs to change first. One to three days, run without disrupting fee-earning work.
At a glance
- Duration
- One to three days
- Format
- Interviews, tool review, artefact review
- Disruption
- Minimal; scheduled around the firm
- Output
- Findings, risk ranking and roadmap
- Designed for
- Mid-tier accountancy and midsize law firms
Who this is for
Firms that are already using AI, and want to know where they actually stand.
- Managing Partners who need a clear view of exposure before scaling adoption
- COOs who suspect tool use has outrun the firm's policy position
- Heads of Risk and Compliance preparing for regulator, insurer or client questions
- Innovation and technology leads who want a prioritised plan rather than a wish list
- Firms mid-consolidation or under PE ownership, where diligence standards are rising
Outcomes
What changes for the firm
A factual picture
An evidenced view of where AI is used across the firm, replacing assumption with observation.
Risk you can rank
Gaps assessed by likelihood and consequence, so effort goes to the exposures that matter.
A sequenced plan
A roadmap with owners, effort and order - deliberately scoped to what the firm can absorb.
What Alacrix does
We look at practice, not just policy.
The audit works from what is happening now: the tools in use, the work they touch, the reviews that exist and the records that survive. Findings are written for partners and risk leaders, not for a technical audience.
- Structured interviews across fee-earning, operations, risk and IT
- Review of AI and automation tools in active or trial use
- Sampling of work where AI contributed, to test the evidence trail
- Review of existing policy, training material and vendor terms
- Mapping of each use case against risk, oversight and evidence criteria
- Debrief session with leadership and a written findings pack
Diagnostic scope
What we examine
Six categories, applied consistently to every use case we find.
AI inventory
Which tools are in use, by whom, for what work, and under whose approval - including the tools that arrived without a decision.
Data & confidentiality
What client and firm data reaches each tool, where it is processed and retained, and whether that is consistent with your obligations.
Human oversight
Where a person reviews output, whether that review is defined and meaningful, and what happens when they disagree with the system.
Vendor & tool risk
Contractual terms, training-data handling, model change management, subprocessors, security posture and exit position.
Evidence & audit trail
What is recorded when AI contributes to work - inputs, versions, reviewer, rationale - and what could be reconstructed later.
Policy & training
Whether written expectations match observed practice, and whether staff know what is permitted, prohibited and escalated.
Deliverables
What you leave with
Governed, not generic
A diagnostic that leads somewhere.
The audit is not a maturity score. It is the first artefact of a control environment: it names use cases, owners, risks and the specific evidence that is currently missing.
- Findings are tied to specific workflows, not general categories
- Every gap is expressed as a control that is absent, weak or unevidenced
- Recommendations state who owns the fix and what proof will exist afterwards
- The roadmap is sequenced to unlock more AI use, not to slow adoption
Engagement process
How the work runs
- 01
Discover
Establish what is in use and where. Interviews, tool review and a look at the work AI already touches.
- 02
Assess
Test each use case against data handling, oversight, vendor risk and evidence. Identify what would fail scrutiny.
- 03
Prioritise
Rank the gaps by exposure and effort, then set a sequenced roadmap with owners and a defensible endpoint.
Next step
Find the gap before someone else does.
Book an AI Risk & Readiness Audit and get an evidenced view of current use, current controls and the distance to defensible practice.