Why Alacrix
Not policy-only. Not build-only.
Firms usually have access to two kinds of help. Consultants who write the policy, and builders who make the system work. The exposure sits in the space between them - and that space is where we work.
Our position
We close the gap between “we’re using AI” and “we could prove to a regulator, an insurer or a client that we’re using it safely” - with a working system, not just a policy document.
Comparison
Where each approach stops.
Both alternatives do useful work. The issue is scope: neither is accountable for the join between what the firm says it does and what the system actually does.
| Capability | Policy-only consultancy | Automation builder | Alacrix |
|---|---|---|---|
| Strategy | Advisory framing and risk posture | Tooling and delivery scope | Adoption strategy tied to risk appetite and commercial return |
| Policy | Core strength; documented in detail | Generally out of scope | Written to the firm's real use cases and kept current |
| Workflow implementation | Typically out of scope | Core strength; systems get built | Delivered with the control design agreed first |
| Human oversight | Described as a requirement | Optional, depending on the brief | Designed as a step in the workflow with defined thresholds |
| Audit trail | Recommended in principle | Limited to system logs | Specified as an evidence requirement and configured |
| Decision logs | Rarely operationalised | Not usually included | Captured per run: inputs, version, reviewer, rationale |
| Staff training | Awareness-level sessions | Tool training only | Role-based training on permitted use and review duties |
| Ongoing monitoring | Periodic review engagements | Support and maintenance | Governance cadence with control testing and reporting |
Principles
How we work, and what we will not claim.
These principles decide what we build, what we advise against, and how we describe a firm's position to its own leadership.
Evidence before assurance claims
We do not describe a firm as compliant, safe or ready. We show what the record contains and let the evidence carry the claim.
Controls inside workflows
A control that requires someone to remember it is not a control. Ours execute as part of the process people already follow.
Human accountability
Every AI-assisted decision has a named person who is accountable for accepting it, and a record of that acceptance.
Minimum necessary complexity
The smallest control set that makes a use case defensible. Over-engineered governance is abandoned governance.
Sector-specific implementation
Accountancy and law have distinct obligations, review cultures and client expectations. Generic frameworks fail on the detail.
Confidence, not caution
The purpose of governance is to let a firm adopt more AI, faster, with less residual exposure - not to slow the firm down.
The commercial case
Governance is what lets you move faster.
Firms that cannot evidence control eventually restrict use. Approvals stall, pilots stay pilots, and the capacity gains never arrive. The constraint is rarely the technology - it is the absence of a defensible position.
A firm that can show what its systems do, who reviews them and what is recorded can extend AI into more of its work, answer client and insurer questions in a single conversation, and treat governance as a commercial asset rather than an overhead.
Next step
See where your firm currently stands.
The audit is the fastest way to establish the distance between current use, current controls and defensible practice.