Skip to content

Consulting and recruiting

AI governance policy for consulting firms: what to include

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

A consulting firm AI policy should settle five things: which tools are approved, what client data may enter them, when AI use is disclosed to clients, who reviews AI-assisted work before it leaves the firm, and which records are kept. The anchor rule: client confidential information goes only into approved tools, and only where the engagement contract allows it.

Key takeaways

  • Classify information first; tool rules are easier to follow when they follow data classes.
  • Engagement contracts override firm defaults, so record AI permissions per engagement in the PSA or CRM.
  • Every AI-assisted deliverable needs a named human reviewer who signs off before it reaches the client.
  • Approved tools should be on plans whose terms exclude training on firm and client content; check plan by plan, since terms differ.
  • A short policy that staff can apply beats a long one nobody reads.

What a consulting firm AI policy must settle#

A consulting firm AI policy must settle the decisions consultants face every day: whether a tool is allowed, whether this client's material may go into it, whether the client should be told, and who checks the result. If the policy leaves those to individual judgment, each engagement team will answer differently.

Clients expect written answers. Security questionnaires, procurement terms and renewal conversations ask which tools touch client data and how AI-assisted work is reviewed. A policy with evidence behind it turns those questions into a document request rather than a debate.

This outline is a starting point rather than finished policy text. Contract terms, client policies and applicable law differ, so counsel should review the final wording.

Copy-ready policy outline#

The outline below covers the sections most consulting firms need. Each heading can be a short paragraph in the finished policy; resist the urge to turn it into a manual.

  • Purpose and scope: who the policy covers, including contractors and subcontractors, and what counts as AI use.
  • Approved tools: a named list of tools and account types, with the contract terms that make each acceptable, such as no training on firm or client content.
  • Data classes and rules: what may enter which tool, by class of information.
  • Client data: the default rule, how engagement-specific restrictions are recorded, and who checks the contract.
  • Disclosure: when the firm tells clients that AI assisted a deliverable, and the standard wording.
  • Human review: who must review AI-assisted analysis, text or code before it reaches a client, and what they check.
  • Records: what is logged about AI use on each engagement, and where.
  • New tools: how staff request a tool and who approves it.
  • Incidents: what to do if client information enters an unapproved tool.
  • Training and updates: how staff learn the policy and what triggers a revision.

Data classes and where each may go#

Data classes make the policy usable, because a consultant can classify a document faster than they can interpret a clause. Five classes cover most consulting work.

Data classes and where each may go
Data classExamplesApproved business toolsPersonal or public accounts
PublicPublished reports, public filings, press coverageAllowedAllowed
Firm internalMethods, templates, internal reviews, proposalsAllowedNot allowed
Client confidentialClient data, interview notes, draft deliverablesOnly where the engagement contract permitsNot allowed
Personal dataClient employee names, survey responses, HR recordsOnly after a privacy check, with minimizationNot allowed
RestrictedMaterial nonpublic information, client-prohibited material, regulated dataNot allowed without written client approvalNot allowed

Client data rules and engagement-level overrides#

Client data rules start from the engagement contract, which overrides any firm default. Many confidentiality clauses limit the client's information to performing the services, some client policies ban third-party AI tools outright, and others allow them within the client's own environment.

The practical answer is a field in the PSA or CRM for each engagement: AI permitted, not permitted, or permitted with conditions, linked to the clause or client email that decided it. Engagement partners set it at kickoff; nobody should have to reread a contract mid-project.

Treat training separately from use. Applying an approved tool to a client's material for that client's work is one question; using that material to train or fine-tune a tool the firm keeps is a narrower one that usually needs explicit contract language or client consent. The policy should say so in one sentence and point to the firm's process for asking.

How to approve a tool: read the terms plan by plan#

Approving a tool means reading the vendor's terms for the specific plan the firm will buy, because one vendor can treat business and individual accounts differently. GitHub states that it does not use Copilot Business or Copilot Enterprise customer data to train AI models, while its documentation says that from April 24, 2026, interactions on individual Copilot plans may be used for training unless the user turns that setting off.

Microsoft's documentation for Microsoft 365 Copilot states that prompts, responses and data accessed through Microsoft Graph are not used to train foundation models. Zoom's terms state that it does not use audio, video, chat and similar communications content to train Zoom or third-party AI models, and Zoom notes that customers on separately negotiated contracts are governed by those contracts. Record what you checked and the date in the tool register, because terms and features change.

  • Training: can inputs, files or outputs train the vendor's or anyone else's models, and on which plans?
  • Retention: how long are prompts, files and outputs kept, and can admins shorten that?
  • Location: where is data processed, and which subprocessors are involved?
  • Controls: can admins manage sharing, connectors and newly released AI features?
  • Contract: do negotiated terms or a data processing agreement override the online terms?

Disclosure, review and records: owners and evidence#

Disclosure, review and record-keeping are where policies fail quietly, because nobody owns them. Assign each element to a role and decide what evidence proves it happened.

Disclosure, review and records: owners and evidence
Policy elementOwnerEvidence kept
Approved tool listIT or operationsTool register with contract terms and last review date
Engagement AI permissionsEngagement partnerPSA or CRM field linked to the contract clause
Client disclosureEngagement partnerStandard language in proposals or statements of work
Human reviewNamed reviewer per deliverableSign-off recorded in the project file
IncidentsGeneral counsel or privacy leadIncident log with the remediation taken
TrainingOperationsCompletion records by person

What a reviewer of AI-assisted work should check#

A reviewer of AI-assisted work checks substance, not style. Fluent text hides errors well, so the policy should name what the reviewer confirms before signing off, and the sign-off should be recorded in the project file.

The reviewer should be someone who could have produced the analysis without the tool, usually the engagement manager or partner, not the person who prompted it. Where a deliverable mixes AI-assisted and manual sections, the review covers the whole document, since errors often sit where the two meet.

  • Sources: every factual claim and figure traces to a source the reviewer can open.
  • Client facts: names, numbers and dates match the client's own documents.
  • Confidentiality: no other client's information appears in text, tables or charts.
  • Reasoning: recommendations follow from the analysis rather than from confident wording.
  • Ownership: the engagement team agrees with the conclusions and can defend them in the room.

Illustrative: a compliance consultancy writes its first policy#

Illustrative: a fictional compliance consulting firm learned that consultants were summarizing client policy manuals in personal chat accounts. The discovery came when a financial services client sent a security questionnaire asking which AI tools touched its documents.

The general counsel drafted a policy from the outline above, moved staff to business accounts whose terms excluded training on customer content, and added an AI permission field to every open engagement in the PSA. Proposals gained a short disclosure paragraph, and the tool register recorded the plan, terms and review date for each approved tool.

The questionnaire was answered with the policy, the tool register and the engagement record. The data classes also showed that the firm's methods and internal reviews were firm internal material, which later made a licensing fit check on those records quick to scope.

How the policy connects to licensing firm records#

The same data classes that govern AI tools also show which records a firm could ever license. SourceX considers only firm-owned material, typically the firm internal class, and carves out client confidential and restricted material in the Rights step of the SourceX five-step transaction: Supply, Rights, Preparation, Approval and Delivery.

For any package that proceeds, a SourceX Evidence Packet records provenance, licensing rights, permitted use, the privacy record and release authorization. A firm with a working AI policy has already done much of the classification that packet relies on.

Frequently asked questions

Should the policy ban public AI tools entirely?

Many firms allow public tools for public information only and ban everything else from them. That is easier to follow than a blanket ban, which tends to push use underground. The key is that firm internal, client confidential and personal data never enter personal or consumer accounts.

Do we need client consent to use AI on an engagement?

It depends on the contract and the client's own policies. Some clients allow approved tools by default, others require consent, and some prohibit AI use entirely. Ask at the start of each engagement, record the answer in the PSA or CRM, and revisit it if the scope changes.

How often should the policy be updated?

Update it whenever the approved tool list changes, a major client imposes new AI terms or relevant law changes, and review it on a regular schedule even when nothing has. Keep a short change log so clients and staff can see what changed and when.

Does the policy apply to subcontractors?

It should. Subcontractors and independent consultants often use their own tools, so flow the policy's key rules into subcontractor agreements, require approved tools or equivalents for client work, and confirm compliance before they receive client material. Include them in the incident process, since a leak through a subcontractor is still the firm's problem with the client.

What about AI meeting notetakers on client calls?

Treat them as their own category. Recording and transcription can trigger consent requirements that differ by state and country, clients may object, and transcripts are client confidential material. Require host consent, announce the notetaker, and check that vendor settings exclude training on recordings.

Sources

  • GitHub's Copilot Trust Center FAQ states that GitHub does not use Copilot Business or Copilot Enterprise customer data to train AI models. Source
  • GitHub's Copilot documentation states that starting April 24, 2026, interactions on individual Copilot plans may be used to train and improve AI models, and users can turn this off in settings. Source
  • Microsoft's enterprise data protection documentation for Microsoft 365 Copilot states that prompts, responses, and data accessed through Microsoft Graph are not used to train foundation models. Source
  • Zoom's Terms of Service (Section 10.2) state that Zoom does not use audio, video, chat, screen sharing, attachments or other communications-like Customer Content to train Zoom or third-party AI models. Source
  • Zoom's blog says updates to its online terms do not affect customers who buy directly under separate contracts. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify