top of page

Put AI to Work. Keep It Inside the Lines.

Clear rules, approved tools, trained people, and a small number of workflows that save hours you can actually count. Installed in weeks, then handed to your team to run.

A-professional-technical-shot-of-a-modern-boardroom-table-with-empty-chairs-and-natural-da

It Is Already Happening

Someone in your organization pasted a client document into a chatbot this week. Probably several people, probably through a personal account, and probably because it worked.

You do not have a list of which tools are in use, who owns them, or what has gone into them. And you cannot point to a single hour saved, because nobody set a baseline to measure against.

So you are carrying the exposure of adoption without the return on it. That is the worst of both positions, and it is the most common one.

This page is for you if: your staff are using AI faster than your policy can keep up, you are being pitched AI tools you have no way to evaluate, or you have been told AI will save time and cannot find the evidence in your own numbers.

Rules, Tools and Results, In That Order

Five phases, each with defined entry criteria, fixed deliverables and exit criteria that have to be met before the next one starts.

Data Dashboard Display

Design

one to two weeks

We agree the posture, the policy scope, the data that never goes near a model, and which two or three workflows get built, with acceptance criteria written down. It ends in a memo your sponsor signs. No sign-off, no build.

Modern White Hallway

Embed

two to four weeks

We train your people on their own tasks, not on generic prompts. Runbooks for every workflow, and coaching for the named owners. Then the adoption check, which is three questions any member of your staff should be able to answer without looking anything up: What can I use AI for? What can I never share? How do I request a tool? If they cannot, we are not finished. Then a formal transition sign-off.

Long Road

Diagnose

one to two weeks

The AI Readiness Audit. We interview across operations, client-facing teams and IT, inventory the tools actually in use including the ones nobody approved, find the six to ten workflows where time is genuinely lost, and score you across seven domains. You get a maturity scorecard, three to five costed opportunities and a ninety-day roadmap. Fixed fee, and it stands on its own if you go no further.

Blueprints On Desk

Establish

two to four weeks

We publish the acceptable-use policy and the no-go data card, stand up the intake form, approval workflow and tool register with named owners, run one real vendor review end to end as a worked example, build the selected workflows with human checkpoints, and record the measurement baseline.

Modern Conference Room

Sustain

quarterly, optional

We re-score the domains, review the register and any incidents against baseline, refresh the approved-tools list as the market moves, and give your sponsor an independent read. The tool landscape changes every quarter. Part of what this buys is somebody else keeping up with it.

What You Get

1 / The Facts

A scored maturity picture across seven domains, a populated inventory of what is actually in use including the shadow tools, and the workflows where your time is really going.

2 / The Rules

An acceptable-use policy in language your staff will actually follow, a one-page no-go data card, and a single intake route with a named decision-maker and a published turnaround time.

3 / The Method

A repeatable way to assess any AI vendor: risk tiering, a due diligence questionnaire, a scorecard and a decision memo. So the next pitch takes days to evaluate rather than months or nothing at all.

4 / The Results

Two or three workflows implemented on live work with human checkpoints, runbooks, named owners, and a measured before and after. Something you can put in front of a board.

What This Does for Your Position

At some point your board, your partners or your regulator will ask what your organization is doing about AI. That question is coming, and the honest answer today is probably a shrug and an anecdote.

The difference between an executive who looks in control of this and one who does not is not how much AI they have deployed. It is whether they can hand over a document: what is in use, who owns it, what rules apply and what it has actually saved. Ninety days from now that document either exists or it does not.

The question is coming.
The document takes weeks.

Enablement with Guardrails

There is no single correct posture, so we make the choice explicit and put your sponsor's name on it. Our default is enablement with guardrails: usage is encouraged inside clear boundaries, enforcement starts with training rather than blocking, and controls tighten as the risk rises.

That works because every tool and every vendor gets a risk tier.

- Low risk means sanitized inputs, no integrations, individual productivity: approved in days.

- High risk means personal, client-confidential or regulated data, or broad integration into your systems: security, privacy and legal review, a documented decision, and a re-approval date.

 

Anything unclear defaults to the higher tier until it is proven otherwise.

The point of tiering is speed, not caution. Most requests are genuinely low risk, and if they are treated with the same ceremony as the dangerous ones, your staff will stop asking and go back to personal accounts.

We aim for a capability that is properly defined and consistently practised, with depth added where it pays back. We do not promise a best-in-class AI operation, because over-promising is how AI programmes talk themselves into a backlash.

National Institute of Standards and Technology, AI Risk Management Framework 1.0, 2023

Which is why the posture is a decision your sponsor signs, and why low risk moves fast.

Where We Stop

We do not give legal advice.

Where the work touches contract wording, intellectual property clauses or how a regulation applies to you, your counsel reviews and owns that. It is written into every report and policy we produce, and we would rather say it early than have it discovered late.

 

We do not become your AI department.

Tool and workflow ownership transfers to named people on your side at Embed, and that gate is written down before we start. We install and assure the capability. We do not operate it.

 

We will tell you when the answer is not yet.

If the underlying process is too chaotic to automate, the Audit says so and stops there. Automating a broken process just produces broken output faster.

 

And we are the wrong firm for you if you would rather not know.

The first thing we do is inventory what is actually in use, including the tools nobody approved. Some organizations do not want that written down. That is a reasonable preference and an honest reason not to hire us.

Frequently Asked Questions

What if we already have a policy?

Then the question is whether anyone follows it and whether it is connected to anything. A policy without an intake route, an inventory, an owner and training is a document, not a control. The Audit will tell you which one you have.

 

Won't our people just find a way around the rules?

They will, if the rules are slower than the work. That is why the posture is enablement with guardrails and why low-risk requests are answered in days. Governance that gets in the way does not get followed, it gets bypassed.

 

Can you just give us the templates?

We could, and plenty of people will give them to you free. Templates are not the hard part. Getting them adopted, owned, and connected to a workflow that saves measurable time is the hard part, and that is what the engagement is.

 

How do we know it actually saved anything?

Because we record a baseline before we build, and measure against it afterwards. If a workflow does not pay back, we would rather find that in week three than in year two.

 

What about our regulator, or our professional body?

The framework aligns with the PMI Standard for Artificial Intelligence in Portfolio, Program and Project Management, and we map to the guidance that applies to your sector. What your regulator requires of you is a question for your counsel, and we will say so.

What does it cost?

The Readiness and Risk Score is free. The Audit is a fixed fee, agreed before we start. The build is fixed scope, priced from what the Audit finds. No hourly billing.

Thirty minutes will tell you whether you have a problem worth fixing.

bottom of page