AI exposure audits for law and accountancy firms in London
We show you every AI tool your staff are using, what client data is leaving through them, and fix it. In two weeks.
Two weeks. One page listing every AI tool in your firm and what client data passed through it. Fixed price.
Register of AI systems in use
| System | Client data passing through | Approved |
|---|---|---|
| ChatGPT, free tier | Matter summaries, draft letters | Not approved |
| Meeting assistant, personal account | Client call transcripts | Not approved |
| Writing assistant, browser extension | Emails, client documents | Not approved |
| Microsoft Copilot, firm licence | Documents inside the tenancy | Approved |
| Page summariser, browser extension | Every page viewed, including the case system | Not approved |
What a managing partner already knows.
- Fee-earners paste matter details into free chatbots to save an hour.
- Meeting assistants transcribe client calls to servers nobody in the firm chose.
- The GDPR work done in 2018 did not cover any of this.
The SRA and ICAEW duty of confidentiality does not have an AI exception.
What you receive on day fourteen.
The slide
Every AI tool in the firm, and what passed through each.
One page, tool by tool, presented to the partners. This is the moment the audit exists for.
Risk register
Each system scored against UK GDPR, the DPA 2018, ICO guidance and your professional confidentiality duties, as at the date of assessment.
- UK GDPR
- Data Protection Act 2018
- ICO guidance on AI
- SRA and ICAEW confidentiality duties
AI usage policy
A written policy your staff can follow: approved tools, prohibited uses, and what to do when something goes wrong.
Data protection impact assessments
DPIAs for the systems that need them, written to the ICO template.
Remediation roadmap
What to switch off, what to replace and what to keep, in order, with owners and dates.
Two weeks, four phases.
Discovery
Interviews with partners and team leads, and a questionnaire that asks what people actually use.
Scan
Browser extensions, card statements, connected apps, mailbox invitations and meeting-tool settings. The scan finds what interviews do not.
Assessment and legal review
Each system scored in the assessment matrix. Legal conclusions reviewed independently.
Report and presentation
The five documents, and the slide, presented to the partners.
- Days 1 to 3
Discovery
Interviews with partners and team leads, and a questionnaire that asks what people actually use.
- Days 3 to 6
Scan
Browser extensions, card statements, connected apps, mailbox invitations and meeting-tool settings. The scan finds what interviews do not.
- Days 7 to 11
Assessment and legal review
Each system scored in the assessment matrix. Legal conclusions reviewed independently.
- Days 12 to 14
Report and presentation
The five documents, and the slide, presented to the partners.
Delivery is two weeks from the day the last of your inputs arrives, not from signing.
We did it to ourselves first.
Before the first client, we are running the full audit on our own agency, with the same questionnaire, the same scan and the same report. An agency that builds with AI coding tools and runs a multi-agent data-protection workflow has more to find than most law firms, which makes it a fair test.
The anonymised report is published here on 22 September 2026.
How we handle your data.
The first sharp question on every call is what tools we use to run the audit. The answer sits above pricing on purpose.
- We collect questionnaire answers, tool inventories, log extracts and expense-line descriptions. We never collect message content, document content or client files.
- Everything is processed on our own devices and in a private folder for your engagement. Log extracts are deleted 30 days after the final presentation.
- Any AI assistant that touches your material runs under business terms that exclude training on inputs, or runs locally. Where in doubt, we use a spreadsheet and our own judgement.
- A data-processing agreement is available on request.
Pricing.
Exposure Check
A 20-minute call and a one-page snapshot: the five most likely leakage points for a firm of your type, and the three questions you cannot currently answer.
Book a 20-minute Exposure CheckAI Exposure Audit
Discovery, scan, assessment, the five documents and the presentation. Two weeks.
AI Exposure Audit
The same engagement over three to four weeks, with a second assessor.
Ongoing Oversight
Quarterly re-scan, policy updates when the rules change, an incident line, an annual staff refresher, and a monthly three-number email to the managing partner.
Ranges, not starting prices. You will have a fixed figure before you sign.
Who is behind it.
Riserbo is run by Jad Charaf, founder of a London web and automation agency whose privacy-policy and data-protection tooling forms a third of the audit kit. The scanning method and the assessment matrix were built for this work.
Legal conclusions are reviewed by an independent solicitor or data protection officer, arranged per engagement.
Professional certification in AI governance is in progress. We would rather say so than imply otherwise.
More about RiserboDo you know which AI tools your fee-earners used this week, and what client information went into them?
Twenty minutes on a call answers the first half. The audit answers the second.