re-ai-gov Join the waiting list

Kennisbank

AI governance in law, consulting and accountancy

A sector built on judgment and confidentiality

Professional services do not sell a product but a judgment: advice, an analysis, a second opinion. That makes the way AI is handled different from sectors where AI mainly speeds up processes. Here, AI touches directly on the core of the profession — the thinking work itself, and the confidentiality of what a client has shared to make that thinking work possible. A lawyer who feeds a language model with documents from a file, a consultant who has a draft analysis checked by a chatbot, an accountant who has figures summarised by an external system: in each case, information moves that should really have stayed within the walls of the firm and the trust relationship with the client.

The ratio between what organisations here have officially purchased and what employees actually use is generally out of balance. Where in sectors with a lot of operational process AI is often rolled out via an IT department, the pressure in advisory and legal firms is mainly individual: someone with a deadline and an AI tool that works faster than the colleague next to them. That makes shadow AI here not exceptional but plausible as the norm — precisely in a sector where time is billed and speed is rewarded.

Why the IT list is rarely the full picture here

An overview of software licences shows what has been purchased, not what is being used. In professional services, moreover, a large part of staff work with their own devices, their own browser extensions and their own subscriptions to AI services that cost nothing to try. A partner or senior adviser who uses a language model to check a draft memo appears in no IT dashboard whatsoever. Yet that is precisely the use with the highest risk: it touches on client confidentiality, on professional privilege, on the question of who is responsible for what when advice has been partly shaped by an algorithm.

Asking without consequences

The only way to know what is actually happening is to ask — and asking only makes sense if nothing is at stake for the person answering. An employee who suspects that admitting to AI use will lead to a conversation about underperformance will answer in the negative or not at all. An inventory that starts from trust rather than control gets a different picture: not complete, but more honest than a list that only adds up what has been approved.

Role and risk level, not one AI policy for everything

AI use in this sector does not fall into a single category. A tool that checks facts in a legal document carries a different risk than a tool that summarises an internal process document. A system that helps draft tax advice going to a client requires a different kind of oversight than a tool that organises minutes. Governance that works starts by distinguishing these roles and risk levels, and attaches an appropriate level of oversight to them — not based on what the system is called, but on what the system does and for whom the outcome is ultimately intended.

Connecting to what already exists, not building alongside it

Firms in this sector often already have structures for risk management: file review, four-eyes principles, compliance checks, quality control. An AI governance approach that stands apart from that becomes an extra layer that nobody takes on. It makes more sense to have an approach that connects to the existing risk structure: the same owners, the same reporting lines, the same rhythm of review, with AI use as part of what is already being examined rather than a separate track.

Demonstrability towards the board and oversight

A director or General Counsel who is asked how AI use is safeguarded within the firm has little use for an impression. Demonstrability requires a documented inventory: which tools, which role, which risk level, which agreements about what may and may not be done with it. That is not primarily accountability to the outside world — it is first and foremost an instrument for the board itself, to know what it is steering, before a regulator, client or the firm's own risk committee asks the question.

How this relates to other sectors

The way shadow AI arises and the way governance can connect to it differs by sector. Those wishing to compare how this issue plays out where many systems and customer contact converge will find that in AI governance in financial services; those wishing to see how it plays out in a sector that itself builds and uses AI products can read that in AI governance in the ICT sector; and for a picture of how it works at organisations with a lot of operational staff and little central IT control there is AI governance in retail.

From inventory to work allocation

An inventory of AI use shows what is running and who is using it, but does not answer the question that comes next: which part of the work itself can actually be transferred to AI, and which part cannot. That is a different calculation, per task rather than per tool. FTE TO AI's werkscan makes that calculation: per task it is determined which part of the work is suitable to be taken over by AI, as a follow-up step to the overview produced by the Responsible AI Scan.

Andrewde assistent van de Responsible AI Scan

Vraag maar. Governance begint bij weten wat er draait — ook wat niemand heeft goedgekeurd.

Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.