Founding clients · 2026 Free 2026 guide: private AI in law — deployment, costs, evaluation and a 90-day plan. Read it → Ask about a founding place
Probative Co / Services / DPIA & AI policy pack
fastest route in · fixed fee · one week

DPIA & AI policy pack

Everything a firm needs to show it has assessed and governed the AI tools already in use — including the ones fee-earners adopted without telling anyone. Assessed against UK GDPR article 35, written for lawyers rather than technologists, delivered in five to seven days.

the thinking

Why this is where most firms should start

It is a fixed fee, it takes a week, and it produces the document set that enterprise clients, insurers and the ICO all ask for first. In practice it also surfaces the AML problems, because the discovery conversation is about what people actually do rather than what the policy says.

  • Article 35 requires an assessment, not an intention
  • Most firms have no inventory of AI use at all
  • A policy read once is worth less than a page people keep
what you receive

Stated in advance, delivered as described.

Completed DPIA per tool

Purpose, data flows, location of processing, retention, training use, risks and mitigations — written against your firm's facts, not a generic template.

AI acceptable-use policy

Two pages, plain English, aimed at fee-earners. The three prohibitions are unmissable; the permissions are specific enough to be followed.

Vendor assessment questionnaire

The 24 questions to send any new AI supplier, with the answers that should end the conversation marked as such.

Transparency and privacy wording

Client-facing notice language you can publish, covering AI use in service delivery.

Staff one-pager

One page of may and may not, formatted to be printed, laminated and actually consulted.

Board note

A short summary of exposure and what changed, suitable for minuting.

how it runs

Four steps, no surprises.

STEP 1

Discovery

A 60-minute session with the people who know what is in use, plus a short written questionnaire for the rest of the firm.

STEP 2

Tool inventory

We list every tool in use, declared or otherwise, and confirm the data-flow position for each — from vendor documentation where it exists, from the vendor where it does not.

STEP 3

Assessment and drafting

DPIAs completed per tool; policy and notices drafted around your practice rather than a generic model.

STEP 4

Walkthrough

A 45-minute session with the compliance desk and, if you want, the fee-earners who will have to live with the policy.

options and fees

Fixed numbers. The invoice matches the proposal.

EngagementCostTurnaroundWhat it covers
DPIA & AI policy pack $1,200 – $1,500fixed 5–7 days Everything needed to show you have assessed and governed the AI tools already in use — including the ones fee-earners adopted without telling you.
  • A completed DPIA for each AI tool in use (UK GDPR art 35)
  • AI acceptable-use policy written for fee-earners, not technologists
  • Vendor assessment questionnaire for new AI suppliers
  • Transparency and privacy notice wording you can publish
  • One-page staff guide: what may and may not go in
Contact us
Estimated range $1,200 – $1,500 · how quotes work

Payment. 50% on booking, 50% on delivery unless the option says otherwise. Card payment through Stripe, or invoice with bank transfer. Card details never touch our servers. Larger deployments are billed to milestones agreed in writing before work starts.

who this is for
  • Any firm where staff use AI and no DPIA exists
  • Firms whose enterprise clients have started asking about AI governance
  • Firms handling confidential or privileged material in tools nobody assessed
  • Firms about to embark on ISO/IEC 42001 or a private AI deployment
questions we get asked
QDo you need access to our systems?+
No. We work from interviews, a short questionnaire and what you can tell us about usage. SSO or CASB logs make the inventory faster but are not required.
QIs this legal advice?+
No. It is data-protection and governance work by a consultancy, not a law firm. Where something needs legal advice we say so and step back.
QWhat if we use twenty tools?+
The fixed fee covers tools in normal use. If the inventory runs unusually wide we tell you before doing the extra work, with a number attached.
QDoes this cover the SRA's expectations?+
It gives you the document set that answers them: a register, assessments, a policy and a staff guide. The behaviour side is training, which we run separately.
QIs this enough for ISO/IEC 42001?+
It is a strong starting document set. The scored gap analysis is the next step and tells you what else the standard expects.
MLR 2017 reg 21 · independent audit ISO/IEC 42001 readiness · not certification
// start here

Send three files.
We'll tell you what a reviewer would flag.

  • No charge and no obligation — you keep the findings either way
  • Turned around in ~48 hours, encrypted transfer only
  • Most firms find at least one issue they did not know they had
Book the free 3-file check → Talk to us about cost Or write to — replies usually the same day.