Skip to content

Find out what you are running

We go through every AI tool, licence and system in the business. We work out what each one costs and returns, and hand you a written picture you can make decisions from.

Most companies cannot list their own AI

Ask a leadership team how many AI tools the company uses and you get a guess, usually low by half. Departments buy their own. Vendors ship features nobody switched on. Someone wired an API into a spreadsheet two years ago and has since left. Until you can list them, you cannot say what you spend, what comes back, or what a customer would find if they asked.

What the work involves

Where an item carries a clause reference, it points at the operative legal text and you can read it yourself. Where it carries none, it is good practice rather than a codified duty. We mark the difference because it changes how you should rank it.

  1. 01

    Tool and system inventory

    We work through the card statements, the single sign-on logs, the vendor list and the teams themselves, and build a register of every AI tool in use. The card statements find more than the interviews do.

  2. 02

    Spend and usage

    What each licence costs, how many seats are active against how many you pay for, and what the token bills come to. Unused seats are the easiest saving on the table and they are almost always there.

  3. 03

    Does it do what it was bought to do

    For each system in real use: the job it was bought for, whether it does that job, and what evidence exists either way. Where nobody measured, we write that down rather than estimating.

  4. 04

    Risk and exposure

    Where personal data travels, which systems shape decisions about people, what each vendor's terms let them do with your inputs, and which of those a customer questionnaire would catch.

  5. 05

    Classification against the rules that bind you

    If you serve European customers or handle Indian personal data, each system gets a risk tier and a role. The role you hold determines which obligations follow, so getting it wrong invalidates every answer after it.

    EU AI Act Arts. 5, 6, 50 · DPDP Act 2023
  6. 06

    Findings and a ranked list

    One document holding the register, the numbers, the risks and what to do about each, ordered by what it costs against what it saves. Written for the person who has to present it.

How this usually runs

What moves the price is how many systems you turn out to be running, which is the one number nobody knows at the start — most companies are low by half. The first step is fixed price for that reason: you find out the size of the problem before you commit to the size of the engagement.

  • Rapid audit, 1 to 2 weeks

    Fixed price. Inventory, spend and a headline risk read. Suits companies under 200 people, or a single business unit inside a larger one.

  • Full audit, 3 to 5 weeks

    Adds interviews, outcome evidence, per-system classification and a board pack. This is where most clients start.

  • AIAuditSense first

    Run our own audit engine over a product or a repository before you talk to us. The first check is free and takes two minutes, and it tells you whether buying an audit is worth your while.

What you get

  • Register of every AI tool and system in use, with owner, purpose and status
  • Spend breakdown by tool, with seats paid set against seats active
  • Outcome evidence for each system in production, or a plain statement that none exists
  • Risk and exposure summary, including what each vendor's terms permit
  • Per-system classification where the EU AI Act or the DPDP Act applies
  • Ranked recommendations, each with an effort and a saving attached
  • Board pack a non-specialist director can read and act on

A good fit if

  • Leadership teams who cannot say how many AI tools the company uses
  • Companies whose AI spend grew faster than anyone tracked it
  • Businesses about to start an AI programme who want a baseline first
  • Anyone who has been sent a customer AI questionnaire

Before you ask

How much of our time does this take?

Six to eight hours of your people's time across the whole audit, spread across interviews and evidence gathering. We do the collation.

What if it turns out we are in worse shape than we thought?

That is the usual result and it is the point of doing it. The report ranks the findings so you fix what matters and leave the rest alone.

Can you audit one department rather than the whole company?

Yes. Marketing and customer support are the two we get asked for most, because that is where tools arrive without going through procurement.

Do we have to buy anything afterwards?

No. Some clients take the report and do the work themselves, which is a good outcome. We take no vendor commissions, so nothing in the recommendations points you at a purchase we benefit from.

Start with a scoping call

Thirty minutes. Tell us what you run and where it is going wrong, and we will tell you what we would look at first.