Skip to content

AI Governance & Audit Trail

Risk mitigationFixed FeeFor Subcontractors, Main Contractors & Clients10 working days

I establish what AI your commercial team is actually using, map where its output reaches a contractual document, and hand you a working governance position: what is permitted, what is prohibited, what gets checked, what gets recorded, and who owns each. Two questions no contractor has answered yet: what is the team allowed to put into a model, and if a model touched a valuation, can you show afterwards what it produced and who checked it.

The problem

The exposure is not that somebody used a chatbot. It is that AI output reached a document with contractual effect, unchecked, and you are bound by it. A payment application whose variation narrative describes the work wrongly is a served error. A pay less notice whose basis of calculation was assembled from records that do not say that will not survive testing. A quantum schedule is where an invented clause or case reference does the most damage.

The second exposure is not yours to accept. A team pasting a subcontractor's tender into a tool is disclosing somebody else's confidential information, which arrived under the subcontract's own confidentiality provisions. You can decide what risk to take with your information. You cannot decide it for theirs.

The third arrives later. In eighteen months a figure is challenged and the question is how it was built. If nobody can say what was AI-assisted, what was checked, and against which records, the answer is a shrug, and a shrug in that setting costs more than the figure.

The solution

First an honest picture of what is actually in use, including the tools nobody approved, because unapproved use is the exposure and a review that misses it misses the point. Then the map: which commercial processes AI touches, where its output reaches something contractual, what data goes into which tool, what is checked before it leaves and whether the check is real or nominal, and whether anybody could say afterwards what was AI-assisted. What comes back is a governance position your team can run: permitted uses, prohibited uses, the checking requirement, the record requirement, and an owner against each, with a register of every tool and use, and the exposures sequenced by what an error would cost. The audit trail is the half nobody else selling AI governance can do, because it is a contemporaneous-records question wearing an AI hat, and contemporaneous records are what this practice is built on.

This is a commercial review, not a legal one. Questions of data protection law, regulatory obligation or liability go to your solicitor, and the report says so where they arise.

Fee fixed in writing after a scoping call.

What you receive

The free AI Use Policy template gives you a starting position today, and for some teams it is enough. This service is for the point where AI has reached the documents you serve: it replaces a hopeful policy with a governance position built on what your team actually does, and leaves behind the one thing that matters when a figure is challenged later, a trail that shows what was produced, what was checked, and by whom.

The Handover Pack accompanies the work with its dates and sources, likely outcomes and responses, scope boundaries and ready-to-send correspondence where needed.

Turnaround: ten working days.

The working days start when the agreed scope and required inputs are available. Optional items do not hold the start unless the agreed scope says otherwise.

How it works

  1. You tell me how AI is actually being used

    Honestly, including anything nobody signed off. Amnesty first, governance second; a review built on the official answer governs a fiction.

    • A

      An honest account of how AI is used now

      Essential

      Without it: The review has nothing real to test: it can only describe the approved position, which is almost never where the exposure sits

      Where to find it: A conversation, not a form; it works best with the people who actually use the tools in the room.

      Why I need it: It is the whole basis of the review

    • B

      The tools actually in use, approved or not

      Important

      Without it: The register only covers what the interviews turn up, so a tool nobody mentions stays invisible and the review says nothing about it

      Where to find it: Names and plans are enough; I do not need the passwords.

      Why I need it: What is in use, not what is licensed

    • C

      Who uses them

      Essential

      Without it: The tools are named with nobody accountable for using them, and governance has no one to attach to

      Where to find it: The same conversation as point 1: have each person give their name or role as they answer.

      Why I need it: Governance follows the people, not the licences

    • D

      The commercial processes they touch

      Optional

      Without it: The report simply runs narrower: it says the list was not received and covers only what the interviews turned up

      Where to find it: Whoever produces each document can name them fastest.

      Why I need it: The exposure sits where AI touches contractual output

    • E

      Any existing policy, and the confidentiality provisions in the contracts in use

      Important

      Without it: Every contract row in the comparison stays marked unverified, and the report cannot conclude on any of them

      Where to find it: The policy as issued to the team, not the draft. The confidentiality clauses sit in the signed staff and subcontractor contracts held in your commercial files.

      Why I need it: What exists is the baseline or the problem

    Copies are fine. Send what you have and I'll tell you what's missing. Download the client request PDF or editable Word version to pass to whoever holds the files.

    Everyone asked directly

    Each person is asked individually about their own use, so the governance position covers what really happens, not the official answer.

  2. I map every use to its commercial process

    Every tool and habit mapped to the process it touches and the output it contributes to.

  3. I find where output reaches something contractual

    A notice, an application, an assessment, a report. That is where the exposure sits.

  4. I establish the data position

    What goes into which tool, where it goes, and whether any of it is somebody else's confidential information.

    Contracts, not assumptions

    Every confidentiality point cites the contract actually signed, not a standard form; anything unverified is marked as unverified.

  5. I test the checking and record positions

    What is verified before it leaves, by whom, and whether anyone could say afterwards what was AI-assisted.

  6. I score the exposures and design the position

    The exposures sequenced by what an error would cost, and the governance position built: permitted, prohibited, checked, recorded, owned.

  7. You adopt the position and name the register's owner

    It is finished when the register has one, because a register nobody owns is a document, not a control.

I hand over a governance position your team can run

See the full outcome in What you receive.

Free Service Pack

A step-by-step Handbook, with the templates and working documents you need to carry out the work it covers yourself. You supply your own project information and records.

Follow the Handbook's scope and stopping points, and obtain independent advice where required. The pack is not project-specific advice or independent sign-off.

The free AI Use Policy template gives you a starting position today, and the Safe AI in Commercial Construction Work guide is the thinking behind it; the two are the front door to this service. And where the question is whether the records could support more AI rather than how to govern what is already in use, Data Readiness for AI is the test to run.