The engagement

How an AI Safeguard Review works.

One to two weeks, a fixed fee agreed before we start, and five deliverables you keep. Most of the work happens without interrupting your people; the parts that need them take about an hour each.

Fixed fee, agreed up front Built for firms of 3–50 No software to buy
Step one

Find out what is actually being used.

Not what the policy says, and not what people would say in a meeting. A short anonymous staff survey, plus two or three interviews, tells us which tools are in play, what kind of client information has touched them, and whether those are consumer accounts or business-tier ones with no-training terms.

The survey is anonymous for a reason, and it only works if you back it. People do not report their own mistakes to their employer. Before it goes out we will ask you to promise, in writing, that the answers won't be used for discipline. If you can't make that promise the survey still runs — but it measures a floor, not the truth, and we'll tell you that rather than quietly hand you a flattering number.
Step two

Write it into the plan you already have.

You don't need a new security plan. You need the one you have to say something about AI. The addendum drops into it and covers the parts that are currently silent.

Approved tools, and a dated register

The list lives in a dated annex rather than buried in the body — because a list inside a policy document is a list that never gets updated.

What must never go in

Prohibited data classes in language a preparer can apply at speed, not a taxonomy that needs interpreting.

Who is responsible, and what happens

The Qualified Individual's role for AI, how a new tool gets approved, and what the firm does the day a disclosure is discovered.

We won't let you adopt it into a vacuum. Section by section, the addendum only takes effect once the firm has recorded at least one approved tool covering a use the assessment actually found — or a deliberate decision to allow no AI use at all. Adopting a ban with nothing in its place takes away how the work was getting done and guarantees the policy is contradicted within a week.
Step three

Give staff something they will actually read.

A two-page acceptable-use policy in plain English, plus a one-page desk card for the moment someone is deciding in real time. Then 60–90 minutes of live training, recorded, so the people who join next season get the same version.

Step four

The evidence pack — which is the actual product.

Dated documentation that the assessment happened, what it found, what you decided, what you adopted, and who was trained. Everything above is how we get here. This is the thing that has value if anyone ever asks.

Chorusse is not a law firm or an accounting firm, and none of this is legal, tax or accounting advice. We will recommend, in writing and in the engagement file, that your counsel reviews the addendum before you adopt it. We also won't tell you that you are legally required to hold documents you may well be exempt from — where something is elective good practice rather than an obligation, we say so.
Beyond the review

Larger firms, and the year after.

Firms above roughly fifteen people usually need tool selection and configuration, vendor due-diligence review, and a rollout plan alongside the review. A smaller annual refresh — policy, re-training, a look at what's changed in the tool landscape — makes sense for some firms and not others. We'll tell you which you are; there is no automatic renewal and we don't pretend one is mandatory.