two weeks · fixed

Find the AI nobody declared, before a client's compliance team does.

Every firm we audit is using more AI than its leadership believes. We find it — free tiers, browser extensions, personal accounts, tools bought on a company card and never registered — then assess what each one does to client confidentiality.

14undeclared tools found across nine firms (2026)2weeks, start to findings1register ready for tenders
not a law firm, and we say so
the problem

Nobody lies in the discovery interview. They just do not think of it as a tool.

A browser extension that summarises a PDF, a free-tier chatbot used to polish a letter, a transcription service on a phone. None of it was procured, all of it processes client content, and none of it appears in the register you were asked for last month.

  • Declared tools: assessed against your policy and your DPIA set
  • Undeclared tools: surfaced through interviews, expense lines and device checks you can run yourself
  • Every entry given a risk tier and an action
who this is for
Firms that have never inventoried AI use
Firms filling in an enterprise client's AI questionnaire
COLP or MLRO who suspects the policy is not being followed
01

Free 3-file check

Send three live files. We review them the way a reviewer would and send one page of findings in about 48 hours. No charge, no obligation.

02

A fixed number, in writing

If there is something worth fixing you get scope, deliverable, turnaround and fee stated plainly — the same day you ask.

03

Delivery, then evidence

Work runs to the dates in the proposal, and you finish with documents you can file, show a client or hand to an insurer.

questions we get asked

Straight answers, before you spend anything.

QDo you install monitoring software?+
No. We work from interviews, expense and procurement records, and checks you can run on your own devices. If you already have SSO or CASB logging, we read it with your IT lead.
QWill this get people in trouble?+
We recommend amnesty, and we mean it: the audit works only if people answer honestly. Findings are reported by pattern and tool, not by name.
QHow is this different from the DPIA pack?+
The DPIA pack documents the tools you know about and produces the policy set. This finds the ones you do not know about and re-tiers everything, including the tools that were already blessed.
QHow often should we repeat it?+
Annually, or whenever your use changes materially — which in most firms means annually. It pairs naturally with the annual governance audit.
MLR 2017 reg 21 · independent audit ISO/IEC 42001 readiness · not certification
// start here

Send three files.
We'll tell you what a reviewer would flag.

  • No charge and no obligation — you keep the findings either way
  • Turned around in ~48 hours, encrypted transfer only
  • Most firms find at least one issue they did not know they had
Book the free 3-file check → Talk to us about cost Or write to — replies usually the same day.