What you get is AI that survives being questioned once it is running, whether
the question comes from a regulator, an auditor, a client, or somebody in your own
organisation asking where an answer came from. Here is what it costs. It is slower
at the start: if you want a tool live this month, you will find we want the first
two weeks for establishing what it is allowed to reach. That is a real delay, and
we are not going to dress it up as a benefit.
It also produces findings you may not want. Mapping who can open what, ahead of
giving a model access to any of it, tends to surface permissions nobody intended
to grant, and once that is written down somebody has to deal with it. We will say
which of it is quick to fix and which is not. An organisation that would honestly
rather not know is taking a reasonable position, and it means we are the wrong
firm for them.
The two weeks are what stop the build being unpicked later. That is the whole
trade, and we have chosen it deliberately.
And the audit put hours against the processes that cost you most, so there is a
number to come back to. Once the AI is live we come back to it, and we say
plainly whether those hours moved. A finding that a tool saved less than we
expected is worth more to both of us than a case study.