One to two weeks, a fixed fee agreed before we start, and five deliverables you keep. Most of the work happens without interrupting your people; the parts that need them take about an hour each.
Not what the policy says, and not what people would say in a meeting. A short anonymous staff survey, plus two or three interviews, tells us which tools are in play, what kind of client information has touched them, and whether those are consumer accounts or business-tier ones with no-training terms.
You don't need a new security plan. You need the one you have to say something about AI. The addendum drops into it and covers the parts that are currently silent.
The list lives in a dated annex rather than buried in the body — because a list inside a policy document is a list that never gets updated.
Prohibited data classes in language a preparer can apply at speed, not a taxonomy that needs interpreting.
The Qualified Individual's role for AI, how a new tool gets approved, and what the firm does the day a disclosure is discovered.
A two-page acceptable-use policy in plain English, plus a one-page desk card for the moment someone is deciding in real time. Then 60–90 minutes of live training, recorded, so the people who join next season get the same version.
Dated documentation that the assessment happened, what it found, what you decided, what you adopted, and who was trained. Everything above is how we get here. This is the thing that has value if anyone ever asks.
Firms above roughly fifteen people usually need tool selection and configuration, vendor due-diligence review, and a rollout plan alongside the review. A smaller annual refresh — policy, re-training, a look at what's changed in the tool landscape — makes sense for some firms and not others. We'll tell you which you are; there is no automatic renewal and we don't pretend one is mandatory.