
AI is already inside your business. Nobody approved it.
An independent audit of your real AI exposure: what your staff are already using, what your data is training, and where the governed upside is.
In one recent independent audit by our principals, 30% of employees were using unapproved AI tools with company data. No policy, no controls, no board visibility. Meanwhile the same board was being pitched six-figure 'AI transformation' projects by vendors with an obvious interest in the answer. Both problems have the same fix: an independent, evidence-based picture of where you actually stand.
Book Your AI AuditShadow AI
Staff are pasting client data, contracts and financials into free AI tools right now. Ungoverned, unlogged, and invisible to your board until it becomes a breach notification.
Vendor AI Theatre
Every provider you have is suddenly an AI company, and every proposal assumes the answer is buying more from them. Nobody selling you AI can tell you honestly whether you need it.
Board Anxiety, No Evidence
Your board is asking what AI means for the business. 'We're looking into it' is not an answer that survives a second asking.
Data Not Ready
AI initiatives fail on data quality and access control, not on model choice. Most mid-market environments are not ready, and no vendor will volunteer that.
What We Test
- Shadow AI discovery: which tools are actually in use, by whom, with what data
- Data readiness: quality, access controls and governance of the data AI would touch
- Policy and governance gaps against emerging Australian regulatory guidance
- Vendor AI proposals on your desk, independently stress-tested
- Genuine AI opportunities ranked by value and feasibility for your business model
- A governed rollout path: policy, approved tooling, controls and training
The Deliverable
The AI Position Report
A board-ready assessment of your real AI exposure and opportunity, with nothing to sell behind it.
- Shadow AI usage map with risk ranking
- AI usage policy ready to adopt
- Data readiness assessment with remediation priorities
- Opportunity shortlist: where AI genuinely pays in your business
- Board briefing pack: from anxiety to an evidence-based position
The five readiness dimensions we assess
Data maturity
AI initiatives fail on data long before they fail on models. We assess quality, accessibility, classification and lineage of the data any AI initiative would touch, and whether your business actually knows what it holds.
Governance and policy
Who is accountable for AI output, what data may never leave the building, how usage is logged and reviewed. Discovery first, policy second: a policy written before you know what staff actually use is fiction.
Infrastructure and security
Whether your identity, access and data-loss controls extend to AI tools, and what your current stack can support without new spend. Often more than vendors suggest.
Team capability
Where AI fluency actually sits in your workforce (the shadow AI users are, inconveniently, your most motivated adopters) and what training converts risk into capability.
Strategic alignment
Which AI opportunities genuinely map to your business model and margin structure, ranked by value and feasibility, as opposed to which ones vendors are currently selling hardest.
The Australian regulatory context
AI governance in Australia is not a green field: existing law already applies. The Privacy Act 1988 and the Australian Privacy Principles govern personal information entering AI tools today, including staff pasting client records into consumer chatbots. Australia's AI Ethics Principles set the voluntary framework regulators expect boards to be conversant with, and the Government's mandatory-guardrails work for high-risk AI signals where the compliance line is moving. For regulated sectors, APRA's operational-risk expectations (CPS 230) reach any AI dependency in critical operations. The audit maps your actual usage against this landscape, so your board's AI position is grounded in obligations, not vibes.
Self-assessment versus independent audit
| Internal self-assessment | Independent AI audit | |
|---|---|---|
| Shadow AI discovery | Relies on staff self-reporting the tools they were never authorised to use | Discovery-based: network, expense and telemetry evidence |
| Vendor proposals | Assessed by the team that shortlisted them | Stress-tested by a party earning nothing from the outcome |
| Board credibility | Management marking its own homework | Independent evidence directors can minute |
| Data readiness | Assumed from system documentation | Tested against the actual state of the data |
From assessment to governed rollout
Foundation (weeks 1-4, the audit)
Usage mapped, exposure quantified, policy adopted, approved tool list stood up with contractual data handling.
Pilot (the first 90 days)
Two or three high-value use cases from the opportunity shortlist, run under the new controls with measurable success criteria.
Scale (quarter two onward)
What the pilots prove, the business adopts; what they disprove dies cheaply. The working group reviews the tool landscape quarterly, because it changes quarterly.
Straight Answers
2x value identified, or you don't pay.
The 4-Week Commercial IT Health Check is fixed fee, non-disruptive, and guaranteed in writing: if we don't identify value worth at least twice our fee, we refund it.
