Skip to content

AI exposure audits for law and accountancy firms in London

We show you every AI tool your staff are using, what client data is leaving through them, and fix it. In two weeks.

Two weeks. One page listing every AI tool in your firm and what client data passed through it. Fixed price.

Register of AI systems in use

Register of AI systems in use
SystemClient data passing throughApproved
ChatGPT, free tierMatter summaries, draft lettersNot approved
Meeting assistant, personal accountClient call transcriptsNot approved
Writing assistant, browser extensionEmails, client documentsNot approved
Microsoft Copilot, firm licenceDocuments inside the tenancyApproved
Page summariser, browser extensionEvery page viewed, including the case systemNot approved
Illustrative rows, not a client. The anonymised report from our own agency is published on 22 September 2026.

What a managing partner already knows.

  • Fee-earners paste matter details into free chatbots to save an hour.
  • Meeting assistants transcribe client calls to servers nobody in the firm chose.
  • The GDPR work done in 2018 did not cover any of this.

The SRA and ICAEW duty of confidentiality does not have an AI exception.

Five documents

What you receive on day fourteen.

The slide

Every AI tool in the firm, and what passed through each.

One page, tool by tool, presented to the partners. This is the moment the audit exists for.

Risk register

Each system scored against UK GDPR, the DPA 2018, ICO guidance and your professional confidentiality duties, as at the date of assessment.

  • UK GDPR
  • Data Protection Act 2018
  • ICO guidance on AI
  • SRA and ICAEW confidentiality duties

AI usage policy

A written policy your staff can follow: approved tools, prohibited uses, and what to do when something goes wrong.

Data protection impact assessments

DPIAs for the systems that need them, written to the ICO template.

Remediation roadmap

What to switch off, what to replace and what to keep, in order, with owners and dates.

Fourteen days

Two weeks, four phases.

  1. Days 1 to 3

    Discovery

    Interviews with partners and team leads, and a questionnaire that asks what people actually use.

  2. Days 3 to 6

    Scan

    Browser extensions, card statements, connected apps, mailbox invitations and meeting-tool settings. The scan finds what interviews do not.

  3. Days 7 to 11

    Assessment and legal review

    Each system scored in the assessment matrix. Legal conclusions reviewed independently.

  4. Days 12 to 14

    Report and presentation

    The five documents, and the slide, presented to the partners.

Delivery is two weeks from the day the last of your inputs arrives, not from signing.

22 September 2026

We did it to ourselves first.

Before the first client, we are running the full audit on our own agency, with the same questionnaire, the same scan and the same report. An agency that builds with AI coding tools and runs a multi-agent data-protection workflow has more to find than most law firms, which makes it a fair test.

The anonymised report is published here on 22 September 2026.

See the sample report
In every proposal

How we handle your data.

The first sharp question on every call is what tools we use to run the audit. The answer sits above pricing on purpose.

  • We collect questionnaire answers, tool inventories, log extracts and expense-line descriptions. We never collect message content, document content or client files.
  • Everything is processed on our own devices and in a private folder for your engagement. Log extracts are deleted 30 days after the final presentation.
  • Any AI assistant that touches your material runs under business terms that exclude training on inputs, or runs locally. Where in doubt, we use a spreadsheet and our own judgement.
  • A data-processing agreement is available on request.
Read the full data-handling sheet

Pricing.

Exposure Check

Any firm
Free

A 20-minute call and a one-page snapshot: the five most likely leakage points for a firm of your type, and the three questions you cannot currently answer.

Book a 20-minute Exposure Check

AI Exposure Audit

Small firm, 5 to 30 staff
£3,000 to £8,000

Discovery, scan, assessment, the five documents and the presentation. Two weeks.

AI Exposure Audit

Mid-size firm, 30 to 150 staff
£15,000 to £30,000

The same engagement over three to four weeks, with a second assessor.

Ongoing Oversight

After the audit, by headcount
£1,000 to £3,000 a month

Quarterly re-scan, policy updates when the rules change, an incident line, an annual staff refresher, and a monthly three-number email to the managing partner.

Ranges, not starting prices. You will have a fixed figure before you sign.

Who is behind it.

Riserbo is run by Jad Charaf, founder of a London web and automation agency whose privacy-policy and data-protection tooling forms a third of the audit kit. The scanning method and the assessment matrix were built for this work.

Legal conclusions are reviewed by an independent solicitor or data protection officer, arranged per engagement.

Professional certification in AI governance is in progress. We would rather say so than imply otherwise.

More about Riserbo

Do you know which AI tools your fee-earners used this week, and what client information went into them?

Twenty minutes on a call answers the first half. The audit answers the second.