Consulting and recruiting
AI strategy for a mid-size consulting firm: a 2026 playbook
By SourceX Editorial · Updated
Short answer
An AI strategy for a mid-size consulting firm should settle five decisions: how the firm uses AI internally, how it reprices work AI makes faster, which IP it productizes, how it governs client data, and what it does with its own engagement records. Score each part on one page, name an owner, and fix the weakest part first.
Key takeaways
- A mid-size firm's AI strategy is five linked business decisions, not a tool purchase.
- Repricing has to keep pace with internal AI use, or the time savings flow to clients as fewer billed hours.
- Client data rules belong in contracts and a short policy before staff upload engagement files to any AI tool.
- Methods, benchmarks and project reviews the firm owns can become products or licensed records; client deliverables usually cannot.
- A one-page scorecard with an owner for each part keeps the strategy from stalling in partner meetings.
What should an AI strategy cover at a 50 to 500 person consulting firm?#
An AI strategy for a mid-size consulting firm should answer five business questions rather than pick a chatbot. Large firms announce AI programs built on dedicated labs and platform deals; a firm of a few hundred people needs a plan its partners can run alongside billable work.
The five parts connect. Internal AI use changes how long a project takes, which forces a pricing decision. Pricing pressure makes productized IP more attractive. Both depend on clear rules for client data, and all of them raise the question of what the firm's own records are worth.
- Use: where AI goes into proposals, research, analysis and delivery, and who checks its output.
- Reprice: which offerings move from hourly billing to fixed, outcome or subscription fees.
- Productize: which methods, benchmarks and diagnostics become tools or subscriptions.
- Govern: what client data may touch which AI tools, under which contract terms.
- Decide on records: whether engagement history stays internal, feeds products or is licensed.
Part 1: Put AI to work on delivery, not just email#
Internal AI use pays off fastest in work that repeats across engagements: first drafts of proposals, interview synthesis, desk research summaries, slide production and searches for past project teams with the right experience. Those tasks have clear inputs and a reviewer who already knows what good looks like.
Give each use a named owner, write down which tools are approved, and require a human review step before anything reaches a client. Keep a simple log of where AI touched a deliverable. Many clients now ask about AI use in RFPs and security questionnaires, and a log lets you answer from records instead of memory.
Avoid buying licenses for everyone and measuring nothing. Pick two or three workflows, record how long they took before and after, and expand only where quality held.
Part 2: Reprice the work AI makes faster#
Repricing is the part most firms postpone, and postponing it hands the efficiency gain to clients. If a market scan now takes a fraction of the analyst time it used to, hourly billing turns that productivity into lost revenue.
Sort your offerings by how much of the effort is repeatable analysis and how much is judgment, access and change management. Repeatable analysis is where hours shrink first, so it is where pricing should change first.
| Offering type | AI effect on effort | Pricing response |
|---|---|---|
| Research and benchmarking reports | Large drop in analyst hours | Fixed fee per report or a subscription |
| Diagnostics and assessments | Faster data gathering and scoring | Fixed fee for a defined scope |
| Implementation and change programs | Modest, because the work is people-heavy | Time and materials or milestone fees |
| Performance improvement work | Faster baselining and tracking | Base fee plus an outcome component |
| Advisory retainers | Faster preparation, same judgment | Retainer priced on access, not hours |
Part 3: Productize the IP you already own#
Productized IP turns a method the firm repeats into something a client can buy without a full engagement team. Good candidates are maturity assessments, benchmark comparisons, operating model templates and diagnostic questionnaires that partners already reuse.
Start with an honest inventory. Many firms believe they have proprietary methods, but the method lives in a few partners' heads and in slide decks that differ by engagement. A method is ready to productize when it is written down, has been applied consistently and its outputs can be checked against results.
Separate what the firm owns from what clients own. Frameworks, internal playbooks and anonymized benchmarks are usually firm property; final deliverables and client data often are not, depending on the MSA and statement of work.
Part 4: Govern client data before anyone uploads it#
Client data governance decides which engagement files may enter which AI tools, and the answer comes from contracts as much as from IT. Most MSAs and NDAs limit use of client confidential information to the engagement, and newer ones address AI tools directly.
Write the policy in a page or two. A policy staff can remember beats a long document nobody opens.
- Read your largest clients' MSAs for confidentiality, data use, subcontractor and AI clauses, and note which ones prohibit third-party processing.
- Approve AI tools in tiers: tools with no-training and limited-retention terms for client material, general tools for public research only.
- Set a rule for client data in prompts, including whether redaction is required first.
- Update the engagement letter template so new clients agree to how AI is used on their work.
- Train staff with examples from your own practice, not a generic policy deck.
Part 5: Decide what to do with your own records#
A firm's own records are the part of an AI strategy most mid-size firms never examine. Proposals and win/loss notes, staffing and resourcing history, project reviews, internal playbooks and knowledge base articles describe how expert work actually gets done, which is what AI developers want to learn from.
There are three routes: keep the records internal to power your own search and drafting tools, use them to build products, or license a prepared, de-identified package to an AI developer while keeping ownership. The routes can coexist when license terms limit field of use and exclude anything that gives your products their edge.
How SourceX approaches this part: SourceX runs the SourceX five-step transaction (Supply, Rights, Preparation, Approval and Delivery) and looks at records through the SourceX Enterprise Data Value Framework. The first fit check uses metadata only, client-owned deliverables are carved out in the rights review, and the firm approves every step before anything is delivered.
The one-page AI strategy scorecard#
The scorecard gives the partner group one view of all five parts. Rate each part red, amber or green every quarter, name one owner, and record the evidence behind each rating rather than an opinion.
Read the ratings together. A firm that is green on use but red on repricing is subsidizing its clients. A firm that is red on governance should pause any expansion of AI use until the policy is written.
| Part | Question to answer | Evidence of green | Typical owner |
|---|---|---|---|
| Use | Which workflows use AI, with what review? | Approved tool list and a usage log | COO or head of delivery |
| Reprice | Which offerings no longer bill by the hour? | Price book with fixed, outcome or subscription lines | Managing partner |
| Productize | Which methods are written down and reusable? | Documented method with consistent outputs | Practice leaders |
| Govern | What client data may enter which tools? | Clause review of major MSAs and a short policy | General counsel or COO |
| Records | What will we do with our engagement history? | Inventory of systems, years and rights status | CEO with finance and legal |
Illustrative: a regional operations consultancy runs the scorecard#
Illustrative: a fictional operations consulting firm with offices across the Midwest scores itself at a partner offsite. Use comes out amber because analysts draft proposals with an AI assistant but nobody logs it. Repricing is red because every offering still bills by the hour. Governance is red because nobody has read the AI language in its largest clients' MSAs.
The firm fixes governance first, approving one enterprise AI tool with no-training terms and updating its engagement letter. It then converts its warehouse network diagnostic to a fixed fee. For records, it inventories proposals in its CRM and project reviews in SharePoint and its PSA, finds client deliverables mixed into the same folders, and starts tagging firm-owned material before deciding whether to license any of it.
Frequently asked questions
Does a mid-size consulting firm need a chief AI officer?
Usually not as a new hire. Most firms of this size give the strategy to an existing leader, often the COO or a partner with delivery responsibility, and protect part of that person's time. What matters is that each of the five parts has a named owner and that partners review the scorecard on a fixed schedule.
Should partners or junior staff lead AI adoption?
Both, in different roles. Analysts and managers usually find practical uses first because they do the repeatable work. Partners need to lead repricing and client data governance, because those decisions change contracts and fees. When only junior staff adopt AI, the firm tends to give away the time savings without changing what clients pay.
How should we explain our AI use to clients?
Be specific and brief. Tell clients which tasks use AI, which tools are approved, what happens to their data and who reviews outputs. Put the core of it in the engagement letter and keep a longer version for security questionnaires. Clients generally respond better to a clear policy than to discovering AI use on their own.
Does licensing our records conflict with productizing our IP?
Not necessarily. Products usually depend on current benchmarks and methods, while AI developers often want older, de-identified examples of how expert work was done. Non-exclusive terms, field-of-use limits and exclusions for live benchmarks let a firm do both. The firm decides which records stay internal before any license is discussed.
What if our records are scattered across shared drives, email and a PSA?
That is normal and does not block the strategy. Start with an inventory that names each system, the years of history it holds and whether its contents are firm-owned or client-owned. Consolidation can follow later. A scattered archive that is well described is more useful than a tidy one nobody has examined.
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.