Implement
Discover to evidenceAI Use Governance Sprint: from informal AI use to an accountable process
Three to four weeks that turn informal AI use into something you can describe, operate and show. Inventory, policies, an approved-tool matrix, an approval route for new uses, trained staff, and an evidence register with owners and review dates against every control. The flagship engagement, and the one most companies actually need.
- Published range
- $3,000–6,000 / engagement
- Timing after intake
- 3–4 weeks
- Quoted in India
- ₹1,50,000–3,00,000 / engagement
Fixed scope, not hourly. Quoted before we start, with the exclusions written down. The India figure is a separate price for a separate market, not a conversion.
How this is actually delivered
Discovery, assessment, design, implementation and the evidence register. Everything except the ongoing maintenance that follows it.
The scope is fixed before the work starts, which is why the price is a published range rather than an hourly estimate. Anything outside it is quoted separately rather than absorbed quietly or billed by surprise.
- Why companies buy this
- AI adoption outran company rules almost everywhere, and a policy document on its own does not close the gap. A company can have an excellent policy and no implementation at all - which is exactly what a serious buyer's diligence is designed to detect.
- What we actually do
- Three to four weeks across one entity and up to ten tools or use cases. We run interviews and a tool survey, classify each use, then design the operating process: an employee AI use policy with permitted, restricted and prohibited uses, an approved-tool matrix with the configuration conditions attached, rules for confidential material, client code and personal data, human-review requirements set by consequence rather than uniformly, a request form and approval route for new uses, an exception register and an incident escalation path. We configure the agreed controls with your technical owner, run a real approval scenario and an incident walkthrough, and train the roles that handle the material.
- Where it stops, and who takes over
- Statutory applicability in any specific jurisdiction, contract drafting and formal opinions go to qualified counsel. Penetration testing, model validation and independent certification sit with the appropriate specialists and are outside the sprint.
- What you can show afterwards
- A control and evidence register with owners, review dates and sampling limitations, acknowledgement records from training, decision records for each approval or exception, and a ninety-day action plan the sponsor has signed off.
What you receive
A working governance process: inventory, policy set, approved-tool matrix, approval route, trained staff and an evidence register with review dates.
One entity, up to ten tools or use cases. Excluded by default: penetration testing, formal model validation, independent audit or certification, comprehensive privacy remediation, litigation, 24/7 response, additional entities, and unrestricted foreign-law advice. Additional work needs a change order or a separate specialist engagement.
- An AI tool and use-case register with a data-flow summary, covering up to ten tools or use cases
- A short applicability memo: confirmed requirements, open questions, and what needs legal review
- An employee AI use policy with permitted, restricted and prohibited uses
- An approved-tool matrix with configuration conditions and review dates
- Rules for confidential material, personal data, source code and customer material
- Human-review requirements set by consequence and reversibility rather than applied uniformly
- A new-use request form, an approval workflow and an exception register
- A vendor checklist plus up to two baseline vendor reviews
- Incident reporting and escalation instructions
- One role-specific training session with an acknowledgement record
- A control and evidence register, management handover and a ninety-day action plan
- Two consolidated rounds of revisions
What it costs, and what it replaces
Both figures are published ranges for the same unit of work. Ours is fixed before we start; if our process gets faster, that is our gain and your price does not move.
How engagements are structured →Published range for this engagement, against the span of the whole card. In India the same scope is quoted at ₹1,50,000–3,00,000 — a separate price for a separate market, not a conversion. Where in the range a quote lands is set by scope, entities and how much usable evidence already exists.
Midpoint $4,500 per engagement
How the work runs
01
Week 0 - scope and engagement
Entity, sponsor, jurisdictions, use cases, deadline and data categories confirmed. Conflicts checked. The legal and non-legal split, confidentiality, data handling and acceptance criteria are agreed in writing before intake.
02
Week 1 - discovery
Interviews across leadership, IT and security, product and delivery, and HR and operations, plus a tool and vendor survey. The inventory draft comes out of this week, with its limitations recorded alongside it.
03
Week 2 - assessment and design
Each use case is classified by purpose, people affected, autonomy, geography and consequence. From that we draft the policy set, the tool matrix and the approval thresholds, and run the baseline vendor reviews.
04
Week 3 - implement and train
Agreed controls are configured with your technical owner. We run a real approval scenario and an incident walkthrough rather than describing them, then train the roles that handle the material, using their own work as the examples.
05
Handover and acceptance
The sponsor receives the documents, approves the decisions or records the exceptions, assigns owners and completes a walkthrough of the approval and incident processes. A delivered draft on its own is not an implemented programme, and we do not treat it as one.
06
Thirty-day follow-up
Included in the fee. We check whether the register has owners, whether the request workflow is actually being used, and whether review evidence exists - then recommend maintenance only if the change volume justifies it.
What we need from you
- A sponsor with the authority to approve decisions and assign owners
- Access to leadership, IT or security, product or delivery, and HR or operations for interviews
- Existing policies, customer clauses, vendor terms and any architecture diagrams
- Sample diligence questions you have been asked, and any incident history
- A technical owner who can actually change configuration when a control requires it
What we check before delivery
- Drafting works from approved facts and recorded decisions, never from assumptions about how the company operates
- A second qualified reviewer checks material legal conclusions and high-consequence technical recommendations
- Legal assertions link to dated primary sources; anything unresolved is recorded as an open question with an owner
- The sponsor signs off on accepted residual risk, and we state in writing that sign-off does not waive any legal duty
- Missing evidence and assumptions are recorded in the deliverable rather than smoothed over
When firms send us this
- Enterprise customers have started asking AI questions and the answers do not exist yet
- Staff are using AI tools on confidential material with no rule in place
- A security certification is done and AI is the obvious next gap
- Leadership wants one accountable process rather than six team-level habits
Questions about ai use governance sprint
Will this make us compliant with the EU AI Act?
No engagement can promise that, and you should be wary of one that does. Compliance depends on the applicable law, your role, the use case, how the system behaves and how you operate it over time. This sprint gives you a documented, owned and functioning process for a defined set of uses, identifies which obligations may apply, and names the questions that need qualified counsel in a specific jurisdiction.
Is this just a set of policy templates?
Policies are the cheapest part of this problem. The sprint spends most of its time on discovery, on decisions about your actual tools and data, on configuring controls with your technical owner, and on producing evidence. A company can have an excellent policy and no implementation at all - which is precisely what a serious buyer's diligence is designed to detect.
What happens if we do not implement what you design?
Then you have documents rather than governance, and the thirty-day follow-up will say so. We would rather record that plainly than let you show a customer something that is not operating.
Do you need access to our systems?
We work from what you show us and from a controlled workspace with least-privilege access. Configuration changes are made by your own technical owner, with us alongside - we do not take administrative control of your estate, and we do not deploy monitoring tools over your staff.
Firms who send us this usually also send
This engagement
Scope it in fifteen minutes.
AI Use Governance Sprint at $3,000–6,000 per engagement, delivered in 3–4 weeks after a complete intake. Scoping costs nothing, and we will say if a smaller engagement would serve you better.

