An AI strategy earns its name only when it changes decisions.
Many firms create a polished document for board approval, store it and return to a growing collection of disconnected experiments. The source article uses an unsupported claim that 88% of transformations fail and an unverified consulting-firm anecdote to dramatise that pattern. Neither is necessary. A document with no owners, decision gates, funded work or review rhythm is observably a report, rather than an operating strategy.
The aim is a concise record of where the firm will apply AI, which conditions must hold, who accepts the risk and how evidence will alter the plan.
1. A current state that includes unofficial use
Begin with what already exists. A board needs more than a maturity score.
Inventory approved and unapproved tools, tasks, data, suppliers, owners, user groups, spend, incidents and experiments. Assess the systems and information needed for the most plausible uses. Include skills, governance and the ability of teams to change a complete workflow.
Separate observed fact from interpretation. “Documents lack consistent matter metadata” is more useful than “data maturity is low”. Record the evidence date and gaps because the baseline will change.
Unofficial use matters. Prohibiting a public tool does not show whether people are pasting client information into it. Use confidential staff research and existing security evidence to understand real behaviour without creating a punitive exercise that drives it further underground.
2. A small portfolio linked to firm objectives
Prioritise a few consequential opportunities rather than compiling an exhibition of what AI can do.
Each opportunity should state:
- The user and task
- The current problem and baseline
- The intended client, colleague or risk outcome
- Information and system dependencies
- Material harms and affected people
- Alternatives, including conventional automation or process change
- The smallest test and a stop condition
Value and feasibility alone are insufficient. A use can be feasible and commercially attractive while remaining unacceptable because of confidentiality, professional duty, discrimination, client contract or the consequence of error.
The portfolio should also include work the firm will not pursue and why. That shows the strategy has made choices.
3. Readiness gaps attached to each opportunity
“Improve data” is too broad to fund. Name the specific gap between the current workflow and the proposed one.
For document retrieval, this might be inconsistent permissions, missing retention rules, poor metadata, uncertain client rights or no evaluation set. For client communication, it might be the absence of an approved source, named reviewer or send control. For forecasting, it may be insufficient historical comparability.
Assign an owner, evidence and decision to every gap. Estimate range and elapsed time only after considering internal availability and assurance. Some gaps should stop a use rather than become a platform programme.
This section prevents firms from buying a model before resolving the workflow and information conditions that determine whether it can help.
4. Governance as decisions in calendars
A statement about “responsible AI” has little operational value. Governance needs named authority and repeatable gates.
Define:
- Who may propose and sponsor a use
- Who classifies risk and affected data
- Which Legal, Privacy, Security, Compliance, HR or professional owners review it
- Who approves a pilot and any move into live use
- Who monitors performance, incidents and supplier change
- Who can pause or retire the system
- What the board receives and decides
The NIST AI Risk Management Framework offers a voluntary structure around governing, mapping, measuring and managing AI risk. UK firms also need advice tailored to applicable law, regulation, professional duties and contracts. The ICO provides AI and data-protection guidance for uses involving personal data.
Record decisions, evidence, model and prompt versions where relevant, incidents and material changes. Human oversight must identify the person, source material, authority and time required; the phrase alone is not a control.
5. A roadmap with gates, rather than distant promises
The source prescribes a 12-month plan and dismisses longer projections. A rolling horizon is more useful. Detail the next decision period and keep later work conditional on evidence.
A roadmap might sequence:
- Establish ownership, inventory and prohibited practices.
- Prepare one workflow and evaluation set.
- Run a controlled comparison against current work.
- Review value, harms, user behaviour and complete-workflow cost.
- Approve, change or stop.
- Expand only after permissions, support and monitoring are ready.
Show dependencies and capacity. Several pilots competing for the same subject-matter experts cannot all be “priority one”. Procurement, data preparation, security review, staff consultation and client communication may determine elapsed time.
Include exit planning. The firm needs access to its data and records, a route to stop processing and a plan for work that depends on the supplier.
6. Investment in money and attention
Licence cost is a small part of many AI uses. Include:
- Workflow and integration design
- Data preparation and permissions work
- Evaluation by qualified people
- Legal, privacy, security and sector assurance
- Training and change support
- Monitoring, incident response and supplier review
- Continuing human effort
- Exit or replacement
Use ranges and explain the assumptions. The source gives an illustrative £40,000 to £60,000 pilot and 15 to 20 internal days. Those figures have no benchmark and should not guide a board. Build the range from the selected workflow and people required.
Count the whole task. Faster drafting can move effort into source preparation, review and correction. A strategy should fund the new operating model, rather than celebrate one step in isolation.
7. Evaluation that can change the decision
“Improve efficiency” and “use AI responsibly” cannot determine whether to continue.
Measure against a baseline and a suitable comparator. Depending on the use, include quality, material error, omissions, time, rework, cost, user adoption, affected-person outcomes, security events and client feedback. Examine variation across tasks and groups instead of relying on an average.
Set thresholds before the test where practical. Define failures requiring immediate pause. Preserve examples of difficult cases and near misses so that learning is not reduced to a dashboard.
Claims about productivity or revenue require causal restraint. If a pilot coincides with training, process change and new data, the result belongs to the combined intervention unless evidence can separate it.
Keep the board document readable
The source insists on 10 to 15 pages, a two-page summary and a 20-minute board discussion. Those can be useful design constraints, yet they are not universal standards.
The main document should contain decisions, responsibilities, ranges and measures. Detailed use-case research, technical architecture, legal analysis and evaluation protocols can sit in controlled appendices or linked artefacts. A board member should be able to locate:
- The current exposure
- The chosen opportunities and exclusions
- The next decision and requested authority
- Investment and capacity
- Principal risks and owners
- Evidence that will return to the board
Do not embed a named vendor or model in the strategic objective. Supplier decisions need a procurement and assurance record and will change faster than the firm's purpose. Technical detail still matters; it belongs with the people making the technical decision.
Make review part of governance
Distinction's WHNN® framework uses the What and How for the Now and Next to create a repeating decision rhythm. A quarterly review may suit many firms, although higher-risk uses can need more frequent monitoring and a small firm may use a different board cadence.
Review what was committed, what changed, what evidence arrived, which risks or external conditions moved and what should happen next. Update the strategy incrementally and retain the decision history. The document stays alive because it has work to do.
A successful strategy is not the document the board approves. It is the set of choices the firm can still explain after pilots, incidents, supplier changes and evidence have challenged the original plan.
If you want a template for the AI strategy document that covers all seven sections, applies the 10-15 page constraint, and includes the quarterly review format - ready to populate for your firm's specific situation - download it below.
And if you'd rather produce the strategy document through a facilitated session that structures the current state assessment and opportunity prioritisation in a single day - book an AI strategy session. We've run these for professional services firms from 100 to 500 people, and the output is a document your board will actually read. Which, as we've established, is the whole point.



