Skip to main content
AI Advisory & Governance

Your firm can use AI.
The question is who makes it safe.

Most firms in regulated or high-stakes work are stuck between two bad options: ban AI and fall behind, or let staff use public tools and put client data somewhere it should never go. There is a third path. We help you adopt AI responsibly, and we build the infrastructure that makes it real.

AI is an access shift, not a revolution. Enterprise-grade automation is now within reach of smaller firms for the first time. The value was never the model. It is the judgment around it: deciding what data can go where, building verification into every step, and keeping a person on the decisions that carry real risk.

Start the Conversation

Fixed-fee discovery, then a pilot, then optional retainer. You know the scope and the price before any work starts.

No resale, no vendor commissions We govern and we build Designed to survive an examination
Built for firms where the data carries an obligation
SEC-registered investment advisersAccounting and forensic firmsLaw and litigation-exposed practicesRegulated boutiques, 20 to 250 staff
65%+
of employees use AI tools their employers do not know about
$0
what most regulated firms have spent on an AI acceptable-use policy
Zero
client records on personal AI accounts once classification and enterprise controls are in place

Everyone is selling AI. Almost nobody is making it safe to use.

Every software vendor has rebranded their product as AI-powered. Every firm with a slide deck is offering to build you a custom assistant. What a firm handling regulated or privileged data actually needs is different: someone who will tell you which tools are worth the cost, which create real exposure, and what has to be true before your team starts pasting client information into a chatbot.

That conversation does not happen when the person across the table earns margin on what you buy. It happens when they have no stake in it. We are independent, and we both advise and build, so the recommendation and the thing we hand you are pointed at the same outcome.

Two tracks. One firm. Same independence.

Govern what you already have, and build what you do not. Most firms need some of both, and the first call decides the mix.

Govern it

Acceptable-use policy, data classification, approved-tools lists, and training that hold up when a cyber insurer, an enterprise client, a SOC 2 auditor, or a regulator asks how you control AI.

  • AI acceptable-use policy keyed to a real data classification
  • GREEN, YELLOW, RED classification tied to authorization, not document type
  • Shadow AI discovery and inventory
  • Approved-tools lists, certification, and staff training
  • SOC 2 and examination-ready AI governance
  • Microsoft 365 Copilot readiness and governance
AI governance for regulated firms

Build it

Enterprise Claude configured so client data stays under your controls. Document workflows that automate the repetitive work with an audit trail and a human sign-off. Internal tools that replace the manual scripts your team holds together by hand.

  • Enterprise Claude workspaces configured to your policy: no-training commitments, SSO, retention controls
  • Document intake and classification with audit trails
  • Human review designed into every step that touches client records
  • Internal applications that replace manual scripts and spreadsheets
  • Identity, access, and managed-browser patterns for safe AI use

What this looks like in a regulated firm

Two anonymized engagements. Names left out at client request. The work is real.

Financial ServicesSEC-registered investment adviser, ~35 staffCase study

AI adoption under governance built to survive an examination

Problem

A regulated adviser wanted to use AI, but could not put non-public client data into a consumer AI tool. Their infrastructure was aging, a fleet-wide reliability issue had dragged on for months, and they had no AI governance an examiner would accept.

What we did

We led the SOC 2 program end to end, rebuilt the Azure Files and network architecture, and isolated the true root cause of the reliability issue. We designed conservative, examination-ready governance with a GREEN, YELLOW, RED classification keyed to authorization, and proved out how the most sensitive workloads stay in-house.

Outcome

The firm adopted AI under rules an examiner can read, with non-public client data under enterprise terms and the most sensitive workloads kept in-house, and began replacing manual operational workflows with custom applications. The governance patterns now carry across other regulated clients.

0
Non-public records on personal AI accounts under the governance we wrote

A single DoubleChecked engagement. Identifying details anonymized at the client's request. Full client introductions available on a discovery call.

Professional ServicesForensic accounting practice, work product cross-examined at trialCase study

Document intake automated without giving up a single point of defensibility

Problem

A forensic practice was losing billable hours to manual document intake, but every technology choice had to be defensible under cross-examination. Off-the-shelf automation that could not be explained on the stand was not an option.

What we did

We migrated the firm to a private two-tier Azure Files architecture reachable only over an encrypted VPN, built governance keyed to authorization rather than document type, and delivered a custom document-intake automation with verify-before-confirm logic, an append-only audit trail, and human-only ratification.

Outcome

The repetitive document work is automated and fully auditable, while the expert analysis stays with the human who has to answer for it. Autonomy is capped on purpose, so every step the system takes can be explained on the stand.

100%
Of automated document steps captured in an append-only audit trail

A single DoubleChecked engagement. Identifying details anonymized at the client's request. Full client introductions available on a discovery call.

A Fractional Chief AI Officer, on your side of the table

Most firms between 20 and 250 staff do not need a full-time AI executive. They need senior AI leadership part-time: someone who owns the strategy, the governance, and the build decisions, and who has no incentive to sell you more than you need.

That is what we provide. It folds into a Virtual CTO engagement, also called fractional CTO, as a named lane, or it stands on its own. Either way, the only thing for sale is judgment, backed by the engineering to act on it.

You work directly with Justin, not an account team. When an engagement calls for deep skill in one spot, he pulls in trusted senior practitioners he has worked with for years, including past VPs of Engineering, security pros, and audit and compliance specialists.

We are not an AI agency. We do not earn margin on the tools you adopt. We make AI safe and useful for firms that cannot afford to get it wrong.

See the Fractional Chief AI Officer engagement

What we bring to an AI engagement

  • Independent evaluation of tools with no vendor relationships
  • Security and compliance context from your existing risk posture
  • Engineering that runs inside your environment, not a third-party black box
  • Written findings you can take to your board, your insurer, or an examiner
  • Experience translating technical decisions into business language
A productized way to start

Get your whole team onto Claude, safely

Most engagements are scoped to your firm, but one thing is productized: rolling a team onto Claude with the configuration, policy, and training to use it without creating exposure.

Claude Teams & Enterprise Rollout & Training

Claude Teams or Enterprise, configured to your policy. We co-develop your AI business rules, train every team on them, and certify your people on your own rules, with three months of adoption support.

Flat fee
defined scope, no surprises
quoted after a 45-minute call

Not sure which track you need?

Most of these conversations start with someone who knows AI in their business needs attention but is not sure what to do about it. A 45-minute call is enough to tell you whether you need governance, a build, or both.

Book a 45-Minute Call

No commitment. We tell you honestly whether we can help and what that would look like.

Not ready for a call?

Take the AI Readiness Assessment

Nine questions, five minutes, no email required. A clear read on whether your firm can adopt AI without putting client data, a renewal, or an examination at risk, plus where to focus first.

Start the assessment
5 min

Free, anonymous, scored instantly. No email required.

AI Readiness Checklist

The questions every regulated firm should answer before adopting AI

Free Guide
Free Executive Resource

The Regulated Firm's AI Readiness Checklist

Six questions that decide whether your firm can adopt AI without putting client data, a renewal, or an examination at risk. Walk them before your next audit, not after.

  • Where client data is leaving your environment through personal AI accounts
  • Whether your AI controls would survive a SOC 2 audit or an examination
  • Where a human, not the model, needs to ratify the output

We respect your inbox. Unsubscribe at any time.

Common questions

Weighing Copilot? Read what to do before rolling out Microsoft Copilot.

Make AI safe to use in your firm.

Start with a 45-minute call. We will tell you honestly whether you need governance, a build, or both, and what that would look like.

Book a 45-Minute Call

Fixed-fee discovery, then a pilot, then optional retainer. No resale, no vendor commissions.