AI Assurance / High-trust firms

    Prove how AI touches client work.

    Petrichor helps communications firms, law firms, and government contractors show that sensitive information stays controlled and expert judgment remains accountable.

    $150,000 fixed fee · 20 to 22 weeks · up to 8 high-risk workflows

    The pack is what the client can show. The operating system is what makes the pack true.
    01The gap

    The commercial problem

    Most firms can describe their intentions. Few can produce the proof.

    A policy says what should happen. A client, procurement team, or general counsel wants to know what happens in the work they are trusting you to perform.

    01

    Where is AI used, and where is it prohibited?

    02

    What happens to sensitive, privileged, embargoed, controlled, or contractual information?

    03

    Which tools are approved, and what do their terms actually commit them to?

    04

    Where do human review, professional judgment, and final accountability remain mandatory?

    05

    What current evidence supports the answer, and what happens when something changes?

    02The trace

    The evidence standard

    Trace every external claim to operating reality.

    Select any layer of the chain. If one link is missing, the statement is not ready to put in front of a serious client.

    Claim

    A precise external statement, such as: approved AI tools do not train on client content under the firm’s contracted configuration.

    03The output

    The client-facing artifact

    One controlled answer for clients, counsel, security, and procurement.

    The Assurance Pack is concise enough to forward and specific enough to evaluate. Client annexes handle legitimate differences without creating a new policy for every account.

    01

    Executive assurance letter

    A concise position with version, coverage date, assurance boundary, and next review date.

    02

    Approved-use and data position

    Where AI may assist, what information may enter, which tools are allowed, and what remains prohibited.

    03

    Human accountability model

    The decisions and outputs that require expert review, named ownership, and escalation.

    04

    Client choice and restrictions

    A practical route for opt-out, consent, disclosure, tool, matter, account, or contract-specific limits.

    05

    Evidence and evaluation summary

    The workflow tests, quality checks, provenance rules, staff activation, and evidence-freshness status.

    06

    Response library and annexes

    Controlled answers for questionnaires, RFPs, outside-counsel reviews, procurement, and demanding clients.

    Six-slide boardroom overview

    Six slides built for an executive conversation. Share the PDF with your team; the executive brief carries the detail.

    04The editions

    One system / Four obligation libraries

    The architecture stays constant. The scrutiny changes by sector.

    EditionSensitive boundaryClient-visible outcome
    Advertising agencies Explore edition →Client data, brand assets, audience data, rights, talent and likeness, claims, disclosure, media platforms.Support an account-level permission decision with bounded workflows, current evidence, and human accountability.
    CommunicationsEmbargoed announcements, crisis facts, executive vulnerabilities, strategy, media intelligence.Protect sensitive retainers and make responsible AI visible to client leadership.
    General counsel Explore decision track →Proposed provider AI use, client information, rights, claims, vendor treatment, and retained decision authority.Review one bounded use against current evidence, explicit conditions, exclusions, and change triggers.
    Government contractingFCI/CUI boundaries, technical and proposal data, program information, prime and contract restrictions.Support bid and contract readiness with a documented assurance layer without implying certification.
    05The build

    Implementation

    Build the answer. Test it under pressure. Keep it current.

    01Typically four weeks

    Establish the boundary

    Inventory actual AI use, sensitive information, client obligations, tools, owners, and high-consequence workflows. Leadership approves exactly what the firm will and will not assure.

    02Typically eight to ten weeks

    Build the system

    Encode workflow controls, use-case factsheets, vendor responsibilities, human review, task-specific tests, evidence records, the client pack, and the response library.

    03Typically six to eight weeks

    Activate and prove

    Run role-specific activation, an executive tabletop, a material-change test, and a realistic client or procurement challenge. Close material evidence gaps before launch.

    04Ongoing

    Keep it true

    Refresh evidence, reassess changed tools and workflows, maintain client restrictions, track exceptions, review incidents, and independently challenge the system.

    Proof gate

    The firm responds to a realistic assurance request within 24 hours without unsupported claims or material evidence gaps.

    06The value

    The business case

    Ground the investment in operating value, not fear.

    The business case is built from the firm’s own numbers. Generic breach averages and invented win-rate lifts do not belong in the base case.

    01

    Safe capacity unlocked

    People × validated hours × working weeks × realizable value × conservative attribution.

    02

    Assurance labor removed

    Client, RFP, audit, and questionnaire events × current review hours × loaded reviewer cost.

    03

    Revenue supported

    Client, panel, bid, or contract value × buyer-approved assurance influence × contribution margin.

    Risk reduction is reported separately. It enters the model only when the customer has credible incident probability and loss data.

    Illustrated qualification case

    $900KConservative annual value
    $150KFlagship investment
    Gross value multiple

    The numbers are illustrative. A real case proceeds only when the buyer validates at least 4× conservative first-year value using the firm’s own operating data.

    07The engagement

    Commercial architecture

    One flagship system. One optional front door.

    The engagement is scoped to build an assurance system the firm can operate, defend, and keep current. The Diagnostic exists for firms that need to establish the boundary and business case before committing to the full build.

    Flagship engagement

    AI Assurance System

    $150,000 fixed fee

    Delivery
    20 to 22 weeks
    Coverage
    Up to 8 high-risk workflows
    Activation
    Up to 150 staff

    Build the client-facing assurance pack, evidence system, operating controls, response library, staff activation, executive challenge, and ongoing review architecture.

    Optional entry

    AI Assurance Diagnostic

    $25,000 fixed fee

    Delivery
    4 weeks
    Coverage
    3 sensitive workflows
    Decision
    Evidence map and quantified case

    Fully credited toward the flagship when the AI Assurance System is contracted within 30 days.

    Investment gate

    Proceed only when the buyer validates at least 4× conservative first-year value. If the case does not clear that threshold, the flagship should not be sold.

    08The standard

    Aligned / Not overclaimed

    Built to withstand scrutiny without pretending to be a certification.

    The control spine can map to recognized frameworks. Sector and client obligations sit on top. Qualified advisers remain responsible for legal, privacy, cybersecurity, and certification conclusions.

    This work does not: provide legal advice, determine privilege, assess or certify cybersecurity compliance, guarantee factual accuracy, eliminate AI risk, or guarantee that a client, regulator, insurer, contracting officer, or procurement team will accept the firm’s position.

    Primary source series

    The Conditions of Yes examines the market architecture behind buyer permission, provider status, live scope, and the proof serious AI-enabled work now requires.

    Read the five-piece series →

    09Questions

    A fast first read

    Questions serious buyers ask first.

    01What is an AI Assurance Pack?

    An AI Assurance Pack is a concise, client-facing set of statements and evidence explaining where AI is used, how sensitive information is handled, which tools are approved, where human judgment remains mandatory, and how the firm keeps those statements current.

    02How is this different from an AI policy?

    A policy expresses intent. Assurance connects that intent to specific workflows, accountable owners, approved tools, client restrictions, operating controls, current evidence, test results, exceptions, and review dates.

    03Is this an ISO/IEC 42001 certification program?

    No. The system can map relevant practices to ISO/IEC 42001, the NIST AI Risk Management Framework, and the CSA AI Controls Matrix, but Petrichor does not claim certification or replace a qualified certification body.

    04Does Petrichor provide legal or cybersecurity advice?

    No. The work complements qualified legal, privacy, cybersecurity, professional-responsibility, and compliance advisers. It does not determine privilege, certify security, or provide legal advice.

    05What is the first step?

    The flagship engagement is the $150,000 AI Assurance System. When the firm needs to establish the evidence and economic case first, a four-week, $25,000 Diagnostic maps three sensitive workflows. The Diagnostic is fully credited if the flagship is contracted within 30 days.

    The flagship engagement

    Build the answer your most demanding client will accept.

    The AI Assurance System turns policy, tools, workflows, evidence, and human accountability into one client-ready operating system. The investment is $150,000 fixed fee.