Services / Discover / Service No. 01 Where most engagements start

Shadow AI Audit.

A short, fixed-scope engagement that finds every AI tool your team is actually using, maps the data flows, and hands you a risk-ranked report. It's the natural place to start.

FORMATFixed-price discovery
TIMELINE3–4 weeks
LEADNamed on contract
// 01
What It Is

Most leadership teams underestimate how much AI they're already running.

Every department is using something. Marketing is using ChatGPT for copy. Sales is using a meeting transcription tool. Engineering has Copilot and Cursor. HR is testing a hiring assistant. Finance pasted last quarter's actuals into Claude to "see what it would say." None of it is in your CIO's inventory.

A Shadow AI Audit fixes that — without forcing you to run it yourself or wait six months for an internal initiative to spin up.

// 02
What You Get

Five named, structured deliverables. Not a deck.

Every Shadow AI Audit produces the same artifacts so you can compare engagements quarter over quarter and your team can act without asking.

// 03
How It Works

Four weeks. Four phases. One readout.

Same playbook every engagement — you know exactly what's happening and when. One named lead signs off at every gate.

01

Kickoff & setup

60-min kickoff call. Confirm scope, name stakeholders, schedule department-head interviews, draft the employee comms message.

Day 1
02

Data collection

Pull SaaS spend reports, procurement records, browser extension inventory, DLP/CASB logs. Anonymous 5-question employee survey goes out.

Week 1
03

Interviews + categorization

30-min structured interviews with each department head. Categorize discovered tools by use case, data class, oversight gap. Apply risk-ranking rubric.

Weeks 2–3
04

Drafting + readout

We draft the deliverables, review, and sign off. Then a 90-minute live readout with your leadership team. Q&A.

Week 4
// 04
Common Findings

What these audits are built to surface. You're probably not the exception.

A few patterns are common enough across mid-market AI deployments that we design the audit to look for them directly. Knowing them in advance doesn't make the audit less valuable — it makes the conversation faster.

[ 01 ]

Customer data is leaking into LLMs.

In organizations of this size, it's common for at least one team to be pasting customer-identifiable data into a consumer ChatGPT account or similar. Usually not malicious — usually someone trying to be helpful who never read the data terms.

[ 02 ]

Two or three teams are paying for the same capability.

Marketing has Jasper, Sales has Copy.ai, Operations has ChatGPT Team. Three subscriptions, similar feature set, no shared learning. Consolidating the overlap is often where the audit pays for itself.

[ 03 ]

High-risk use case nobody is monitoring.

Often a hiring AI, a customer service bot, or a financial document automation that one team rolled out, that materially affects people, and that has zero oversight. Not deliberately hidden — it just never came up at leadership.

[ 04 ]

Cost growth that isn't being attributed.

AI line items are growing 10–25% month-over-month, charged on department credit cards, never landing in your IT budget. Procurement has no view. Finance treats it as miscellaneous SaaS.

// 05
Who It's For

Mid-market companies. Operationally serious. Not yet under regulatory pressure.

// GOOD FIT IF

  • ↗ 50–2,000 employees, deploying AI across multiple departments.
  • ↗ COO, VP Ops, or CIO has been asked "what's our AI strategy" by the board.
  • ↗ You suspect there's more AI use than you can name.
  • ↗ You want a defensible answer before something embarrassing happens.

// NOT THE RIGHT FIT IF

  • ↘ You're already in active EU AI Act conformity work — go to GovernMy.ai.
  • ↘ You want a deck and a strategy session — go to a strategy consultancy.
  • ↘ You want a software dashboard, not a human review — go to a governance SaaS vendor.
// 06
After the Audit

No high-pressure upsell. Just options.

After the readout you'll have a clear roadmap. From there, there are three common paths:

// PATH A

Take the roadmap and run it yourselves.

No retainer, no follow-on. We hand off completely. If your team has the internal capacity and prefers this, we don't push back.

// PATH B

Move to an Operate retainer.

We become your standing operational layer — quarterly reviews, training cadence, vendor work, executive briefings. The natural next step when you want it handled.

// PATH C

Pick one Implement project.

Often the AI Policy & Trust Pack, Vendor & Tooling Selection, or a specific AI Use Case Rollout flagged in the audit. Project-based, contained.

Ready to know what you're actually running?

Book a 30-minute scoping call. We'll confirm fit, walk through the playbook, and quote a fixed price.