Executive assurance letter
A concise position with version, coverage date, assurance boundary, and next review date.
AI Assurance / High-trust firms
Petrichor helps communications firms, law firms, and government contractors show that sensitive information stays controlled and expert judgment remains accountable.
$150,000 fixed fee · 20 to 22 weeks · up to 8 high-risk workflows
The pack is what the client can show. The operating system is what makes the pack true.
The commercial problem
A policy says what should happen. A client, procurement team, or general counsel wants to know what happens in the work they are trusting you to perform.
Where is AI used, and where is it prohibited?
What happens to sensitive, privileged, embargoed, controlled, or contractual information?
Which tools are approved, and what do their terms actually commit them to?
Where do human review, professional judgment, and final accountability remain mandatory?
What current evidence supports the answer, and what happens when something changes?
The evidence standard
Select any layer of the chain. If one link is missing, the statement is not ready to put in front of a serious client.
Claim
A precise external statement, such as: approved AI tools do not train on client content under the firm’s contracted configuration.
The client-facing artifact
The Assurance Pack is concise enough to forward and specific enough to evaluate. Client annexes handle legitimate differences without creating a new policy for every account.
A concise position with version, coverage date, assurance boundary, and next review date.
Where AI may assist, what information may enter, which tools are allowed, and what remains prohibited.
The decisions and outputs that require expert review, named ownership, and escalation.
A practical route for opt-out, consent, disclosure, tool, matter, account, or contract-specific limits.
The workflow tests, quality checks, provenance rules, staff activation, and evidence-freshness status.
Controlled answers for questionnaires, RFPs, outside-counsel reviews, procurement, and demanding clients.
Six-slide boardroom overview
Six slides built for an executive conversation. Share the PDF with your team; the executive brief carries the detail.
Need the detailed operating architecture? Download the 13-page executive brief.
One system / Four obligation libraries
| Edition | Sensitive boundary | Client-visible outcome |
|---|---|---|
| Advertising agencies Explore edition → | Client data, brand assets, audience data, rights, talent and likeness, claims, disclosure, media platforms. | Support an account-level permission decision with bounded workflows, current evidence, and human accountability. |
| Communications | Embargoed announcements, crisis facts, executive vulnerabilities, strategy, media intelligence. | Protect sensitive retainers and make responsible AI visible to client leadership. |
| General counsel Explore decision track → | Proposed provider AI use, client information, rights, claims, vendor treatment, and retained decision authority. | Review one bounded use against current evidence, explicit conditions, exclusions, and change triggers. |
| Government contracting | FCI/CUI boundaries, technical and proposal data, program information, prime and contract restrictions. | Support bid and contract readiness with a documented assurance layer without implying certification. |
Implementation
Inventory actual AI use, sensitive information, client obligations, tools, owners, and high-consequence workflows. Leadership approves exactly what the firm will and will not assure.
Encode workflow controls, use-case factsheets, vendor responsibilities, human review, task-specific tests, evidence records, the client pack, and the response library.
Run role-specific activation, an executive tabletop, a material-change test, and a realistic client or procurement challenge. Close material evidence gaps before launch.
Refresh evidence, reassess changed tools and workflows, maintain client restrictions, track exceptions, review incidents, and independently challenge the system.
Proof gate
The firm responds to a realistic assurance request within 24 hours without unsupported claims or material evidence gaps.
The business case
The business case is built from the firm’s own numbers. Generic breach averages and invented win-rate lifts do not belong in the base case.
People × validated hours × working weeks × realizable value × conservative attribution.
Client, RFP, audit, and questionnaire events × current review hours × loaded reviewer cost.
Client, panel, bid, or contract value × buyer-approved assurance influence × contribution margin.
Risk reduction is reported separately. It enters the model only when the customer has credible incident probability and loss data.
Illustrated qualification case
The numbers are illustrative. A real case proceeds only when the buyer validates at least 4× conservative first-year value using the firm’s own operating data.
Commercial architecture
The engagement is scoped to build an assurance system the firm can operate, defend, and keep current. The Diagnostic exists for firms that need to establish the boundary and business case before committing to the full build.
Flagship engagement
$150,000 fixed fee
Build the client-facing assurance pack, evidence system, operating controls, response library, staff activation, executive challenge, and ongoing review architecture.
Optional entry
$25,000 fixed fee
Fully credited toward the flagship when the AI Assurance System is contracted within 30 days.
Investment gate
Proceed only when the buyer validates at least 4× conservative first-year value. If the case does not clear that threshold, the flagship should not be sold.
Aligned / Not overclaimed
The control spine can map to recognized frameworks. Sector and client obligations sit on top. Qualified advisers remain responsible for legal, privacy, cybersecurity, and certification conclusions.
This work does not: provide legal advice, determine privilege, assess or certify cybersecurity compliance, guarantee factual accuracy, eliminate AI risk, or guarantee that a client, regulator, insurer, contracting officer, or procurement team will accept the firm’s position.
Primary source series
The Conditions of Yes examines the market architecture behind buyer permission, provider status, live scope, and the proof serious AI-enabled work now requires.
A fast first read
An AI Assurance Pack is a concise, client-facing set of statements and evidence explaining where AI is used, how sensitive information is handled, which tools are approved, where human judgment remains mandatory, and how the firm keeps those statements current.
A policy expresses intent. Assurance connects that intent to specific workflows, accountable owners, approved tools, client restrictions, operating controls, current evidence, test results, exceptions, and review dates.
No. The system can map relevant practices to ISO/IEC 42001, the NIST AI Risk Management Framework, and the CSA AI Controls Matrix, but Petrichor does not claim certification or replace a qualified certification body.
No. The work complements qualified legal, privacy, cybersecurity, professional-responsibility, and compliance advisers. It does not determine privilege, certify security, or provide legal advice.
The flagship engagement is the $150,000 AI Assurance System. When the firm needs to establish the evidence and economic case first, a four-week, $25,000 Diagnostic maps three sensitive workflows. The Diagnostic is fully credited if the flagship is contracted within 30 days.
The flagship engagement
The AI Assurance System turns policy, tools, workflows, evidence, and human accountability into one client-ready operating system. The investment is $150,000 fixed fee.