Professional Services · AI Risk
Putting Governance Around AI Tools Already in Use
A professional services firm discovered its teams were using AI tools with client data and no rules. An AI risk assessment and a governance framework mapped to the NIST AI RMF let the firm keep the productivity gains and answer its clients' questions.
The situation
Illustrative scenarioA representative engagement. Details are generalized and no client is identified.
A professional services firm learned, from a client's security questionnaire, that it had no answer to the question 'which AI tools do your staff use, and what data goes into them?' An informal survey found several tools in use across teams, some with client material, and AI features quietly switched on inside software the firm already licensed. Leadership did not want to ban the tools; they wanted to know the risk and set rules they could defend.
What Summit did
The work, in the order it happened.
An AI risk assessment covering the tools in use, the data flowing into them, the vendor terms that governed that data, and the AI features embedded in existing software.
A governance framework mapped to the NIST AI Risk Management Framework's Govern, Map, Measure, and Manage functions, sized for a firm without a dedicated risk team.
An acceptable-use policy that names approved tools and the data classes each may receive, with a simple path for staff to request new tools.
A vendor AI review checklist for the firm's own procurement, and prepared answers for client questionnaires.
What the client received
Deliverables written to be used, not filed.
The outcome
The firm kept the tools that earned their place, retired those that could not meet its data terms, and answered the client's questionnaire with evidence. AI governance became a standing item in its quarterly risk review rather than a scramble.
This scenario reflects the kind of work Summit does under its AI Risk & Security Advisory service. It is illustrative; results depend on the organization.
More scenarios
Security Due Diligence Ahead of a Healthcare Add-On
A private equity firm evaluating a healthcare technology add-on needed a clear picture of inherited cyber risk before closing. A structured assessment surfaced access-control and vendor-management gaps within two weeks, informing deal terms and a 90-day remediation plan post-close.
Read the scenario →Getting Audit-Ready Ahead of an Enterprise Contract
A growing healthcare technology company needed to meet HIPAA obligations to win a major enterprise contract. Acting as virtual CISO, the security program was built and led to audit-ready status within one quarter.
Read the scenario →Standing Up Governance Without Slowing the Business
A high-growth financial services firm had outpaced its informal security practices. Stepping in as virtual CISO, new governance, incident response, and board reporting structures were established without slowing product delivery.
Read the scenario →