Founding clients · 2026 Free 2026 guide: private AI in law — deployment, costs, evaluation and a 90-day plan. Read it → Ask about a founding place
Probative Co / Services / AI audit
the AI practice · the independent check on your AI control environment

AI audit

Three audits that mirror what you already do for AML: what AI is actually in use, whether the outputs are right and evidenced, and whether the control environment works. Each gives you findings with ratings, owners and dates — and an independence statement you can file.

the thinking

You cannot govern what you have not found, and you cannot evidence what you have not tested

Most firms have a policy, a register with five rows, and no idea that the real number is closer to twenty. The use audit finds the truth; the output audit tests whether the work is actually right and whether the file shows it was checked; the annual audit keeps the whole thing true as the firm changes.

  • Undeclared tools are the norm, not the exception
  • Accuracy and documentation are separate problems with separate fixes
  • Independence matters here for the same reason it matters in AML
what you receive

Stated in advance, delivered as described.

AI use audit

Discovery across declared and undeclared tools, data-flow assessment per tool, risk tiering with a specific action each, and a register formatted for tender questionnaires.

AI output quality audit

A sample of AI-assisted work products tested for correctness and verification, plus a review of file notes and supervision trails. Failure modes reported by task type.

Annual governance audit

Control testing against your own AI policy and ISO/IEC 42001 ambitions: register, DPIAs, oversight logs, sample matters, findings with ratings and a remediation plan.

Board summary

One page per audit: exposure, what we tested, what we found, what it will take to close — with an independence statement attached.

Register refresh

Your AI register updated and re-tiered, so the next tender questionnaire is a copy-and-paste rather than a panic.

Remediation tracking

Owners and dates, and an optional follow-up check three months later to confirm the fixes landed.

how it runs

Four steps, no surprises.

STEP 1

Scope

A 30-minute call to choose the right audit, or the combination. Use audit first when nobody knows the inventory; output audit first when AI is already in production work.

STEP 2

Evidence gathering

Interviews, existing policies and registers, work-product samples. We recommend amnesty for undeclared tools, and we mean it — findings are reported by pattern and tool, not by name.

STEP 3

Testing

Documentation review, data-flow verification, accuracy testing on sampled outputs, and control testing against your own policy.

STEP 4

Findings and remediation

Findings with ratings, a plan with owners and dates, and a board page. We can present it to the board or the compliance committee if that helps.

options and fees

Fixed numbers. The invoice matches the proposal.

EngagementCostTurnaroundWhat it covers
AI use audit (shadow AI) $3,000 – $4,000fixed · 2 weeks ~2 weeks Find out what is actually being used — including the free tiers and browser extensions nobody declared — and what each one does to client confidentiality.
  • Discovery across declared and undeclared tools and workflows
  • Data-flow assessment per tool: location, retention, training use
  • Risk tiering with remediation actions
  • Refreshed AI register ready for tender questionnaires
  • One-page findings for the board
Contact us
Estimated range $3,000 – $4,000 · how quotes work
AI output quality audit $2,300 – $3,000fixed · 2 weeks ~2 weeks A sample of AI-assisted work products reviewed against the standard you would defend to a client or a court: correctness, verification, and whether the file shows what was checked.
  • Sample of AI-assisted outputs across practice groups
  • Accuracy and verification testing, with worked examples
  • Review of file notes and supervision trails
  • Failure-mode analysis by task type
  • Training recommendations tied to what we found
Contact us
Estimated range $2,300 – $3,000 · how quotes work
Annual AI governance audit $4,500 – $6,000annual · fixed 3 weeks The independent check on your AI control environment, mirroring what you already do for AML — so 'we review it annually' is something you can evidence.
  • Control testing against your own AI policy and ISO/IEC 42001 ambitions
  • Register, DPIA and oversight-log review
  • Sample testing of AI-assisted matters
  • Findings, ratings and a remediation plan with owners
  • Board summary and independence statement
Contact us
Estimated range $4,500 – $6,000 · how quotes work

Payment. 50% on booking, 50% on delivery unless the option says otherwise. Card payment through Stripe, or invoice with bank transfer. Card details never touch our servers. Larger deployments are billed to milestones agreed in writing before work starts.

who this is for
  • Firms that have never inventoried AI use
  • Firms filling in an enterprise client's AI questionnaire
  • Firms whose supervision model assumes humans catch everything
  • Firms wanting an annual AI assurance cycle to mirror their AML one
questions we get asked
QWill the use audit get people in trouble?+
No — that is why amnesty is the method. Findings are reported by tool and pattern, never by individual. If a firm wants names, that is a management decision, and we will say it undermines the exercise.
QHow do you test output quality without seeing client files?+
We need samples of work products and, ideally, the corresponding file notes. Redacted sets are fine; synthetic equivalents of the same task types also work, though real samples are more useful.
QDo you need monitoring software?+
No. Interviews, procurement records and checks your IT lead can run are enough. If you already have SSO or CASB logging we will read it with them.
QCan the annual audit be combined with our AML review?+
Yes, and several firms run them in the same quarter so the board sees one assurance pack rather than two.
QWill you tell us to stop using AI?+
No. We will tell you which uses are defensible with the right checks, which need tighter supervision, and which your firm should not automate — with the evidence for each conclusion.
MLR 2017 reg 21 · independent audit ISO/IEC 42001 readiness · not certification
// start here

Send three files.
We'll tell you what a reviewer would flag.

  • No charge and no obligation — you keep the findings either way
  • Turned around in ~48 hours, encrypted transfer only
  • Most firms find at least one issue they did not know they had
Book the free 3-file check → Talk to us about cost Or write to — replies usually the same day.