Professional services firms do not need an industry adoption percentage to establish the governance problem. Ask fee earners which AI tools they use, what information they enter and how they check the output. Then compare the answers with the firm's approved systems, client terms and quality controls.
If the answers are inconsistent or unknown, AI use has moved ahead of the operating controls.
A 40-page policy and a standing committee do not solve that problem by themselves. Governance has to change what happens on a Tuesday afternoon when a junior associate uses an AI tool to draft a client memo. It should make the permitted tool, data boundary, review standard and escalation route clear at the point of work.
We'll deal with governance when it becomes an issue. Right now we're just trying to get a few tools working.
Governance can feel like the brakes when a firm is trying to learn. The tools already in use are part of the issue. An unreviewed output sent to a client, confidential data entered without checking the service terms, or AI-assisted work handled outside the firm's quality process creates an immediate control question.
The appropriate framework depends on the firm's services, obligations, data and use cases. The practical version below gives a managing partner a starting structure; it is not legal or regulatory advice and should be adapted with the firm's compliance, information-security and data-protection specialists.
The risks you can't wish away
Start by being specific about what the firm is governing for. The consequence changes with the task, information, user and recipient.
Regulatory and professional obligations come first. The FCA's current approach to AI is principles-based and relies on existing frameworks, including Consumer Duty and senior-management accountability. The exact duties depend on the firm and use case. For solicitors, the SRA has warned about inaccurate AI-generated material and the risk to confidentiality and privilege when information is entered into tools without appropriate safeguards. Its AI warning notice and existing confidentiality guidance should be read against the firm's circumstances. Accountancy firms should do the equivalent exercise against their professional, contractual and data-protection obligations.
Then there's reputational risk. I sat with a senior partner at a mid-sized law firm earlier this year - good firm, careful people, the sort of practice that takes its obligations seriously. An associate had used an AI tool to draft a section of advice. The tool hallucinated a case reference. The advice went out to the client. They caught it because the client's in-house counsel happened to check the citation. The partner's exact words were: "If that client had been less diligent, we'd have been in front of the SRA." What struck me wasn't just the near-miss. It was that the associate wasn't being reckless - they were trying to be efficient, using a tool that had worked fine a dozen times before. Nobody had told them what to check for, or what the firm's position was on AI-assisted drafting. That's a governance failure, not a people failure.
The reputational consequence may extend beyond the factual error if the client expected a different process or level of disclosure. That makes client terms, matter-specific judgement and quality control part of the governance design.
Client trust risk is subtler. Clients engage a professional firm for judgement, expertise and discretion with information. Discovering that confidential material was processed through an unexpected system can change that relationship even when no visible error occurred. Decide what the client has agreed, what the firm must disclose and which uses require specific consent or prohibition.
Internal risk may already exist outside an official programme. During an engagement review for a consulting client, I asked which AI tools the team was using. The list included free-tier tools, consumer products without enterprise controls and an entire workflow built around a service whose data-processing terms had changed. The firm had no approved list, guidance or process for discovering what was in use. A tool inventory is therefore an early governance task, not an administrative afterthought.
These risks are reasons to govern AI use, including the activity that began before the first official deployment.
Four dimensions, not forty pages
A usable governance framework can be organised around four questions. The supporting controls may be simple or extensive according to risk; the questions should remain easy to answer.
The first is oversight: who decides? Before any new AI application goes live, someone needs to approve it. Not a committee - a named person or a defined process. The test is: if a partner wants to use a new AI tool for client work next Monday, who do they ask? If the answer is "nobody" or "I'm not sure," you don't have oversight.
Name the person who owns the intake process and define who supplies information-security, privacy, professional-risk and business approval. A lower-risk internal drafting aid may follow a short route. A system that acts on client data or influences a consequential outcome needs deeper assessment. Set service levels for decisions so people have a usable route and do not bypass it.
The second is accountability: who's responsible? For each AI application you deploy, someone needs to own the quality and compliance of its outputs. The principle that makes this straightforward: it should be the same person who'd be responsible if a human did the work. If a partner is responsible for the accuracy of client advice, they're responsible for that advice whether it was drafted by a trainee, a paralegal, or an AI tool. The technology changes; the accountability doesn't.
Avoid transferring accountability to a central AI group that is remote from the matter. The person responsible for the client outcome should remain involved, supported by technical and risk owners with authority over the system. The correct arrangement can include a committee for high-risk decisions; it should still identify who owns the use case and who can stop it.
The third is transparency: who needs to know? This isn't about disclosing everything to everyone. It's about mapping out who needs to know that AI is being used, and how much they need to know.
For clients, decide with legal and professional-risk advisers whether engagement terms, matter-specific disclosure or consent are required. A generic sample clause may be inadequate for the service, tool or information involved, so this article does not prescribe one. Regulated firms should map existing outcome, accountability, record-keeping and confidentiality duties to the use case. Internally, fee earners need an accessible list of approved tools, prohibited uses, review expectations and a route for questions.
The fourth is monitoring: who checks? Someone specific, at defined intervals, with a record. AI tools change - they update their models, alter their terms, change how they process data. The regulatory landscape evolves. Your own use cases expand. A governance decision that was sound in January might not hold in July.
Set review frequency and triggers according to risk. A material model or terms change, expanded data access, a new client-facing action, an incident or a change in law may require review before the next scheduled date. Keep a record of the approved version, purpose, owner, tests, incidents and decision. A spreadsheet may be sufficient for a small inventory; a larger programme will need stronger change control.
Sector-specific wrinkles
The four dimensions apply across professional services, but each sector has specific considerations worth calling out.
For legal firms, start with the SRA duties on confidentiality, competence and accurate work, then assess the service terms, technical architecture, retention, provider access and any use of inputs to improve a model. Obtain advice on privilege and disclosure for the actual workflow. The SRA's August 2026 warning makes this a current operational issue rather than a speculative future one.
For financial services firms, identify which FCA and PRA rules apply to the firm, activity and system. Consumer Duty, senior-management accountability, operational resilience, data protection and model-risk controls may be relevant in different combinations. Do not present one model-risk statement as a universal AI rule. Build a regulatory owner and current-source review into the approval process.
For consulting firms, include client IP and contractual purpose in the assessment. While reviewing one consulting client's engagement terms, I found no provision addressing client data processed through AI tools. The firm needed to decide whether provider terms, technical separation, access control and its own reuse of material matched its promises to clients. Review the standard terms and the real workflow together; contractual language without an operational control will not protect the information.
What this looks like on a Tuesday
I keep coming back to this test: does your governance change what happens on a normal working day? If it does not, it is documentation without operating control.
Practical governance for AI in professional services needs four visible components. First, give users a short AI use standard written in plain language. It should cover approved tools, prohibited data and uses, required checking, record keeping and escalation. Detailed assessments and procedures can sit behind it. I've seen firms overthink the user document spectacularly, producing policies so comprehensive that nobody reads them. The version we helped a mid-sized accountancy firm put together had three front-page sections: approved tools, prohibited uses and escalation. Its compliance officer later described it as the most-read document on their intranet. The lesson was about accessible guidance, not an arbitrary page limit.
A named AI lead. Give one person responsibility for the inventory, intake route and governance rhythm. Approval may require other accountable specialists, particularly for high-risk uses. In many mid-sized firms the coordinating role can sit alongside the responsibilities of a technology, compliance or operations leader, provided they have time and authority.
A proportionate approval process. When someone wants to use a new AI tool for client work, the route should capture its purpose, users, data, system access, provider terms, output consequence, accountable owner, tests and client approach. Triage low-risk and high-risk proposals into different paths, give the requester a decision date and retain the record.
A review rhythm and change triggers. Ask whether the tool, terms, regulation, data access, use or performance has changed. Review high-risk systems more often and act immediately after a material incident or change. This keeps governance current rather than fossilised.
The time required depends on the inventory and risk. A firm can establish ownership and an interim route quickly, while assessment, technical control and contractual work may take longer. Publish the safe interim position rather than leaving staff without guidance while the complete framework develops.
Start with enough control to learn
There's a particular flavour of perfectionism in professional services that I find genuinely frustrating sometimes. It manifests as: "We can't start the AI programme until the governance is perfect." Which is just another way of saying "We can't start."
Governance needs to be usable and proportionate from the start. Establish a clear standard, named ownership, an approval route and a risk-based review rhythm. Those controls give fee earners a legitimate way to learn while the firm develops evidence and strengthens the framework.
Once the framework is operating, reviews and incidents reveal issues the original design did not anticipate. The AI lead develops expertise through the work, and the standard can be refined against real situations. Evolution should be recorded and governed rather than assumed to happen naturally.
If you're thinking about how governance fits into a broader operating rhythm - how it connects to your strategic planning and quarterly prioritisation rather than living as a separate workstream - that's exactly what WHNN® is designed for. It builds governance into the quarterly cycle rather than treating it as a standalone exercise.
If you want the minimum viable governance framework - AI use policy, accountability structure, approval process and review format - download the template here. Each element is ready to customise. Use it as a starting structure and obtain the legal, regulatory, security and data-protection input appropriate to your firm.
If you'd rather design the governance framework in a structured working session, book an AI governance workshop. We'll bring the framework and work through your context, decisions and follow-up actions with the people who will own them.



