A policy is not an audit trail: what operational AI governance actually requires
Written expectations describe intent. Assurance requires a record of what a system did, who reviewed it and on what basis.
Coming soonAI Governance & Implementation for Accountancy and Law Firms
We help accountancy and law firms implement AI with the governance, evidence and human oversight required to use it confidently - today and under tomorrow’s scrutiny.
Your firm may already be using AI. The harder question is whether you can prove it’s being used safely.
Regulator
Compliance and enforcement
Insurer
Risk assessment and coverage
Client
Trust and confidentiality
Built for regulated professional services
The gap
Most firms are past the question of whether to use AI. What is usually missing is the record: a policy sets out what should happen, but it does not show what actually happened on a matter, an engagement or a client file.
Where AI is working well, the risk is quieter. The system produces useful output, but the decision points, review steps and audit trail that make that output defensible were never designed in. The result is an evidence gap - and evidence is what a regulator, an insurer or a client will ask for.
Staff adopt tools faster than policy changes. Usage spreads through teams before anyone has assessed the data, the vendor or the review point.
Policies exist and training has been delivered, but the controls are not embedded into the workflows where the work is actually done.
Systems work reliably, yet decision logs, defined review points and audit trails are missing - so nothing can be reconstructed after the fact.
The path
A proven four-step path that closes the gap between innovation and assurance - so you can adopt AI with confidence and scale responsibly.
Governance × Implementation
Policy-only consultancy
“A policy tells people what should happen.”
Useful as a statement of intent. It does not produce a record of what a system did or who accepted the outcome.
Alacrix
Alacrix connects governance to implementation - so the controls, evidence and human oversight exist inside the way AI is actually used.
One engagement designs the control environment and builds the workflow, rather than treating them as separate projects.
Build-only automation
“A working automation proves only that it works.”
Delivery without a control design leaves the firm carrying the regulatory and professional exposure alone.
Who we help
Firms whose licence to operate depends on confidentiality, professional judgement and the ability to evidence how work was performed.
Law firms
Midsize practices are already using AI for drafting, review and research. The task now is to make that use consistent with confidentiality obligations, professional duties and the supervision expectations your clients and insurer assume are in place.
Accountancy firms
Mid-tier practices are automating preparation, review and reporting work. Governance keeps the review controls, working-paper trail and professional judgement intact as more of the process becomes machine-assisted.
How governed implementation works
Controls that sit outside the system are optional in practice. Alacrix designs the control environment at the same time as the implementation, so every run of the workflow produces its own evidence.
The result is an operational record: what entered the process, which controls applied, what the model did, who reviewed it, what was decided and what was retained.
AI input
Document, message or data enters the workflow.
Control
Permitted-use, data and confidentiality checks apply.
AI action
The model extracts, drafts, classifies or reconciles.
Human review
A named person reviews at a defined threshold.
Decision
The outcome is approved, amended or rejected.
Evidence
Inputs, versions, reviewer and rationale are logged.
Entry point
AI Risk & Readiness Audit
A short one-to-three day diagnostic that maps current AI use across the firm, identifies material governance gaps, prioritises risks by exposure and produces an implementation roadmap you can act on.
Designed for mid-tier accountancy practices and midsize law firms.
Deliverables
Insights
Written expectations describe intent. Assurance requires a record of what a system did, who reviewed it and on what basis.
Coming soonReview steps bolted on to a live workflow become optional in practice. Oversight has to be a designed part of the process.
Coming soonProfessional indemnity conversations are moving from whether a firm uses AI to how its use is controlled and evidenced.
Coming soonBook an audit
Start with an AI Risk & Readiness Audit and find the gap between current use, current controls and defensible practice.