ServicesVantageIndustriesCase StudiesInsightsAboutContactSchedule a Consultation
Home / Case Studies / Professional Services

Professional Services · AI Risk

Putting Governance Around AI Tools Already in Use

A professional services firm discovered its teams were using AI tools with client data and no rules. An AI risk assessment and a governance framework mapped to the NIST AI RMF let the firm keep the productivity gains and answer its clients' questions.

The situation

Illustrative scenario

A representative engagement. Details are generalized and no client is identified.

A professional services firm learned, from a client's security questionnaire, that it had no answer to the question 'which AI tools do your staff use, and what data goes into them?' An informal survey found several tools in use across teams, some with client material, and AI features quietly switched on inside software the firm already licensed. Leadership did not want to ban the tools; they wanted to know the risk and set rules they could defend.

What Summit did

The work, in the order it happened.

An AI risk assessment covering the tools in use, the data flowing into them, the vendor terms that governed that data, and the AI features embedded in existing software.

A governance framework mapped to the NIST AI Risk Management Framework's Govern, Map, Measure, and Manage functions, sized for a firm without a dedicated risk team.

An acceptable-use policy that names approved tools and the data classes each may receive, with a simple path for staff to request new tools.

A vendor AI review checklist for the firm's own procurement, and prepared answers for client questionnaires.

What the client received

Deliverables written to be used, not filed.

The AI risk assessment report with a tool-by-tool inventory, data flow, and risk rating.
An AI governance framework and acceptable-use policy adopted by the firm's leadership, with an owner and a review cycle.
A client-facing statement of the firm's AI governance and a questionnaire answer bank for the partners.

The outcome

The firm kept the tools that earned their place, retired those that could not meet its data terms, and answered the client's questionnaire with evidence. AI governance became a standing item in its quarterly risk review rather than a scramble.

This scenario reflects the kind of work Summit does under its AI Risk & Security Advisory service. It is illustrative; results depend on the organization.

This site