Why Alacrix

Not policy-only. Not build-only.

Firms usually have access to two kinds of help. Consultants who write the policy, and builders who make the system work. The exposure sits in the space between them - and that space is where we work.

Our position

We close the gap between “we’re using AI” and “we could prove to a regulator, an insurer or a client that we’re using it safely” - with a working system, not just a policy document.

Comparison

Where each approach stops.

Both alternatives do useful work. The issue is scope: neither is accountable for the join between what the firm says it does and what the system actually does.

How Alacrix compares with policy-only consultancy and automation builders
CapabilityPolicy-only consultancyAutomation builderAlacrix
StrategyAdvisory framing and risk postureTooling and delivery scopeAdoption strategy tied to risk appetite and commercial return
PolicyCore strength; documented in detailGenerally out of scopeWritten to the firm's real use cases and kept current
Workflow implementationTypically out of scopeCore strength; systems get builtDelivered with the control design agreed first
Human oversightDescribed as a requirementOptional, depending on the briefDesigned as a step in the workflow with defined thresholds
Audit trailRecommended in principleLimited to system logsSpecified as an evidence requirement and configured
Decision logsRarely operationalisedNot usually includedCaptured per run: inputs, version, reviewer, rationale
Staff trainingAwareness-level sessionsTool training onlyRole-based training on permitted use and review duties
Ongoing monitoringPeriodic review engagementsSupport and maintenanceGovernance cadence with control testing and reporting

Principles

How we work, and what we will not claim.

These principles decide what we build, what we advise against, and how we describe a firm's position to its own leadership.

Evidence before assurance claims

We do not describe a firm as compliant, safe or ready. We show what the record contains and let the evidence carry the claim.

Controls inside workflows

A control that requires someone to remember it is not a control. Ours execute as part of the process people already follow.

Human accountability

Every AI-assisted decision has a named person who is accountable for accepting it, and a record of that acceptance.

Minimum necessary complexity

The smallest control set that makes a use case defensible. Over-engineered governance is abandoned governance.

Sector-specific implementation

Accountancy and law have distinct obligations, review cultures and client expectations. Generic frameworks fail on the detail.

Confidence, not caution

The purpose of governance is to let a firm adopt more AI, faster, with less residual exposure - not to slow the firm down.

The commercial case

Governance is what lets you move faster.

Firms that cannot evidence control eventually restrict use. Approvals stall, pilots stay pilots, and the capacity gains never arrive. The constraint is rarely the technology - it is the absence of a defensible position.

A firm that can show what its systems do, who reviews them and what is recorded can extend AI into more of its work, answer client and insurer questions in a single conversation, and treat governance as a commercial asset rather than an overhead.

Next step

See where your firm currently stands.

The audit is the fastest way to establish the distance between current use, current controls and defensible practice.