AI
AI that a person still signs
We use AI on our own work every day — in security, in compliance and in the accounts. It made us faster. It did not make our judgement optional. Every report that leaves this office is still checked and signed by a named person here.
In practice
Where AI is already in our work
Not a promise about next year. This is what it does on a live engagement today, and what a person does with it before it reaches you.
| Division | What AI does | What a person does before it reaches you |
|---|---|---|
| Technology & Security | First pass over logs and alerts — reducing thousands of events to the handful worth reading. Drafting scripts and configuration files. Summarising vendor advisories. | We reproduce every finding by hand. Nothing is called a vulnerability in a report until one of us has seen it ourselves. |
| Compliance & Certification | Mapping your existing policies against the clauses of a standard, so a gap analysis starts from a draft instead of a blank page. First drafts of policies. Arabic and English versions of the same document. | Every clause mapping is checked against the standard text. Every policy is rewritten to match how you actually work, not how a template assumes you work. |
| Business Advisory | Reading figures out of PDF invoices, bank statements and supplier contracts. Flagging transactions that do not look like the rest of the ledger. First-pass categorisation. | Every extracted figure is tied back to its source document. Every flag is investigated before it is raised with you. |
| All three | Drafting, structuring and proof-reading our own documents. | The argument, the numbers and the recommendation are ours. |
Limits
Five things we do not do
This is the part most suppliers leave out, which is exactly why it is worth putting on the page.
We do not put your data into free or personal AI accounts. Client information goes into business accounts only, with training and retention settings configured, and only into tools on a list we keep and can show you.
We do not pass an AI conclusion to you as a finding. If we could not verify it ourselves, it does not go in the report.
We do not put AI-generated code into your live systems without review and testing. It is a first draft, read line by line, like any other developer’s work.
We do not use AI to sign anything. Reports, opinions and recommendations carry a person’s name, and that person answers for what is in them.
We do not train anything on your data, and we do not let a vendor do it either. Your documents are deleted on the schedule written into the contract.
In writing
Written into the engagement letter
None of the above is a promise you have to take on trust. All four appear in the document you sign.
Named accountability
Every deliverable names the person responsible for it. There is no output on this site or in your inbox that a machine is accountable for.
Data boundary
The engagement letter lists which of your data may be processed by an AI tool and which may never leave your environment. Agreed before any work starts.
Disclosure on request
Ask, and we will tell you which parts of a deliverable were AI-assisted and how each was checked.
No training, no retention
Your data is not used to improve any model, ours or a vendor’s, and it is deleted on the agreed schedule.
Straight answers
Ideas we usually talk clients out of
- A customer chatbot as the first project, when nobody has written the answers down yet. Write the answers first. Half the time that alone solves the problem, and it costs you nothing.
- Prediction — demand, churn, credit risk — on less than a year of clean history. There is nothing there to learn from.
- Replacing the person who checks the output. That person is the reason the automation is safe to run at all.
- Buying an AI platform before naming a process. The licence starts billing immediately and the use case arrives never.