Skip to main content
Image coming soon

AI Governance for Professional Services General Counsel

$199.00
Adding to cart… The item has been added

A focused course, tailored for you

AI Governance for Professional Services General Counsel

Build the in-house AI governance program that holds when partners deploy AI on engagements and regulators ask how you supervised it.

Partners are deploying AI on client engagements faster than the Office of General Counsel can write the memos that supervise it. The course gives you the artefacts a Big Four legal function needs to authorise, govern, and evidence that supervision without becoming the friction that partners route around.

$199 one-time
Tailored to your situation. Access within 24 hours. 30-day money-back.

Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.

Why this course

An Office of General Counsel at a global professional services firm holds three open files at once on AI right now. A tax partner asking permission to use a retrieval tool on a client data room. An advisory partner who already used a tool on a pilot and wants the engagement letter cleaned up after the fact. An audit-side conflicts question about whether a non-audit AI tool can touch the same client without breaching independence. None of those questions get answered by a generic firm-wide AI policy. They get answered by a governance program with named artefacts: an AI use policy partners will actually read, an engagement letter rider that contemplates AI augmentation, a privilege protocol for prompts and outputs, a third-party tool diligence record, a partner attestation cycle, and a supervisory log that survives a regulator sweep. Without those artefacts, the OGC ends up issuing case-by-case memos that contradict each other across practices, partners route around the function to ship, and the supervisory record a regulator asks for in a future inquiry does not exist. This course builds the artefacts.

What you walk away with

  • Author a firm-wide AI use policy that partners across audit, tax, and advisory practices will read and follow without routing around it.
  • Draft an engagement letter rider that contemplates AI augmentation, allocates risk with the client, and survives client-side legal review.
  • Stand up a third-party AI tool diligence record that documents vendor due diligence, data handling, and the basis for approving each tool for engagement use.
  • Operate a partner attestation cycle that produces a supervisory log a future regulator sweep will accept as evidence of meaningful oversight.
  • Resolve the independence and conflicts question on AI tool use without case-by-case memos that contradict each other across practices.

The 12 modules

Module 1. The OGC's AI governance mandate at a Big Four
What an Office of General Counsel at a global professional services firm actually owns on AI: policy authorship, engagement risk review, supervisory record, regulator response. Where the mandate overlaps with independence, conflicts, privacy, cybersecurity, and risk management functions, and how to draw the lines so partners get one consistent answer rather than five conflicting ones. Includes a mandate memo template the OGC can publish to the partnership.
Module 2. Drafting a firm-wide AI use policy partners will follow
The structural elements of an AI use policy that survives partner pushback: scope, prohibited uses, permitted uses by practice line, client consent triggers, data classification overlay, third-party tool register reference, escalation path. Walks through how to avoid the policy that gets ignored because it is too long, too vague, or too restrictive. Includes annotated policy template tuned to professional services with audit, tax, and advisory practices.
Module 3. Engagement letter riders for AI-augmented work
The contract language that lets a partner use AI on a client engagement without exposing the firm to claims the client did not understand what was happening. Covers disclosure of AI use, data handling, output reliance, IP allocation, indemnity carve-outs, and the interaction with the client's own AI policies. Includes three engagement letter rider templates for audit, tax advisory, and consulting work.
Module 4. Privilege and confidentiality protocol for AI prompts and outputs
How to preserve attorney-client privilege and work-product protection when partners feed engagement data into AI tools. Covers what gets logged, what gets retained, what gets purged, the interaction with third-party tool retention policies, and how to instruct partners on prompt hygiene without making the protocol unworkable. Includes a one-page partner-facing privilege protocol and a longer internal procedure.
Module 5. Independence and conflicts for non-audit AI tools
The specific question the OGC at a firm with an audit practice has to answer that pure-advisory firms do not: when does a non-audit AI tool touching client data create an independence problem, when does a shared vendor across audit and non-audit engagements create a conflict, and how does the OGC document the analysis so the audit committee and the regulator are satisfied. Includes an independence-screening checklist for AI tools.
Module 6. Third-party AI tool diligence and the tool register
What the diligence record on each approved AI tool needs to contain to survive both regulator scrutiny and a client RFP question about which tools the firm uses on engagements. Covers vendor security posture, data residency, model provenance, training-data exposure, sub-processor chains, and the firm-side conditions on use. Includes a tool diligence template and a register schema with the fields a Big Four OGC actually needs.
Module 7. Client consent and notification for AI use on engagements
When the firm has to tell the client AI was used, when it has to ask permission, and how the answer differs by service line, jurisdiction, and client type. Covers the difference between disclosure in the engagement letter, ongoing consent for material AI use, and post-hoc notification when a tool was used unexpectedly. Includes consent template language for three client tiers.
Module 8. Partner attestation cycle and the supervisory log
The quarterly cycle that produces the record a regulator asks for in a sweep: every partner attests to what AI tools they used on which engagements, the OGC reviews exceptions, the log is signed and retained. Walks through what the attestation form has to ask, how to follow up on incomplete or implausible responses, and how to handle the partner who refuses. Includes an attestation form template and a supervisory log schema.
Module 9. Regulator response playbook for AI-related inquiries
How to respond when a regulator, audit oversight board, or client raises a specific question about how the firm used AI on a particular engagement. Covers the initial response, the document production scope, the privilege log, and the coordination with the engagement partner and the practice leader. Includes a response timeline and a sample initial response letter.
Module 10. Cross-border AI governance and the EU AI Act overlay
How the firm's global AI governance program absorbs the EU AI Act, UK and EU data protection rules, US state-level AI laws, and the patchwork of regulator guidance across the major markets the firm serves. Walks through which jurisdictional requirements bind the firm, which bind the client, and which bind both. Includes a jurisdictional applicability matrix and a cross-border engagement decision tree.
Module 11. Incident response when an AI tool causes harm on an engagement
The protocol for when an AI tool used on a client engagement produces a wrong output the partner relied on, leaks data into the wrong tenant, or causes a regulator-reportable event. Covers initial triage, client notification, internal investigation, partner discipline, insurance notification, and the post-incident policy update. Includes an incident response runbook tuned to AI events on professional services engagements.
Module 12. Operating the program: governance committee, metrics, partner reporting
How to keep the AI governance program alive after the first wave of memos has been written. Covers the standing AI governance committee, the metrics the OGC reports to firm leadership, the partner-level reporting back, and the annual policy refresh. Walks through the operating cadence that keeps the program credible to the partnership and defensible to regulators. Includes a governance committee charter and a quarterly metrics pack template.

How this addresses your situation

Specific modules that map to what you said you are dealing with.

Partner asking permission to use a third-party LLM on a client engagement: modules 2, 3, 6, 7 give the policy, the rider, the tool diligence, and the client consent answer in that order.
Audit-side conflicts question on whether an AI tool used on advisory work breaches independence: module 5 plus the screening checklist resolves it.
Regulator sweep on how the firm supervised AI use across engagements: modules 8 and 9 produce the supervisory record and the response.
Partner who already deployed AI on an engagement and is asking for cover after the fact: modules 3, 4, and 11 cover the engagement letter clean-up, the privilege analysis, and the incident protocol.

What you get with this course

  • Twelve written modules in the Art of Service learning environment, each with a clear OGC-level deliverable.
  • An annotated firm-wide AI use policy template tuned to professional services with audit, tax, and advisory practice lines.
  • Three engagement letter rider templates for audit, tax advisory, and consulting work.
  • A privilege and confidentiality protocol for AI prompts and outputs, partner-facing and internal versions.
  • An independence-screening checklist for non-audit AI tools.
  • A third-party AI tool diligence template and tool register schema.
  • A partner attestation form, supervisory log schema, and quarterly attestation cycle runbook.
  • A regulator response playbook with a sample initial response letter.
  • A jurisdictional applicability matrix covering the EU AI Act, UK and EU data protection, and US state-level AI laws.
  • An incident response runbook for AI events on client engagements.
  • A standing AI governance committee charter and a quarterly metrics pack template.
  • The hand-built implementation playbook tailored to a Big Four legal function, delivered alongside course access.

What you will have in hand by Day 1, Week 1, Month 1

Within 24 hours: account in the Art of Service learning environment is provisioned and the hand-built implementation playbook is delivered alongside it.

Week 1: modules 1-3 produce the mandate memo, the firm-wide policy draft, and the engagement letter rider drafts.

Week 2-3: modules 4-7 produce the privilege protocol, the independence screening, the tool diligence record, and the client consent language.

Week 4-5: modules 8-9 stand up the partner attestation cycle, the supervisory log, and the regulator response playbook.

Week 6: modules 10-12 close out the cross-border overlay, the incident response runbook, and the governance committee charter.

Before and after

Before

The OGC is issuing case-by-case memos on AI tool use that contradict each other across practices. Partners are routing around the function to ship engagements. Independence, conflicts, privacy, and cybersecurity functions each have their own informal stance. The supervisory record that a regulator would ask for in a future sweep does not exist as a coherent artefact.

After

A firm-wide AI policy is published and read. Engagement letters carry the rider. Each approved AI tool has a diligence record. Partners attest quarterly. The supervisory log is signed and retained. When the next AI memo lands on the OGC's desk, the answer is drawn from a single program, not invented on the call.

What happens if you do not address this

The OGC ends up the function that says no after the fact rather than the function that authorises in advance. Partners build their own workarounds, the supervisory record stays incoherent, and when the first regulator inquiry or client claim arrives, the firm cannot show what it knew, when it knew, or how it supervised what its people did. The cost of building the program in advance is small compared to the cost of reconstructing it under inquiry.

Who it is for

An attorney in the Office of General Counsel at a Big Four or large professional services firm responsible for AI governance across audit, tax, advisory, and consulting practices. Has authority to author firm-wide policy, sits in on engagement risk review, coordinates with independence, conflicts, privacy, and cybersecurity functions, and owns the response to regulator and client inquiries about how AI was used on engagements.

Who this is NOT for. Not for outside counsel advising firms on AI from the outside. Not for compliance officers without policy authorship authority. Not for AI engineers building the tools. The course assumes the reader has the standing to publish a firm-wide policy and sit in supervisory review, not to advise others on theirs.

How it arrives

Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.

Time investment. Roughly six weeks at four to six hours per week, working alongside the OGC's normal engagement load. Each module produces a named artefact that can be reviewed by the relevant function leader as it is built, so the work flows into the firm's existing governance cycle rather than running parallel to it.

Why $199 is the right number

The alternative is a Big Four-style outside firm engagement to author the same artefacts, which runs into six figures and produces documents the OGC then has to internalise anyway. Or a free patchwork of bar association guidance and vendor whitepapers, which describes the problem but does not produce the artefacts. This course produces the artefacts the OGC needs to publish, signed off by the OGC's own analysis rather than an outside firm's.

FAQ

Is this course tied to a specific AI vendor or tool?
No. The artefacts are tool-agnostic. The third-party AI tool diligence template and the register schema let the OGC document any vendor the firm decides to approve, and the engagement letter riders and privilege protocols work regardless of which model is behind the tool.
How does this interact with the firm's existing risk management and independence functions?
The mandate memo in module 1 is explicitly designed to draw the lines between OGC, independence, conflicts, privacy, cybersecurity, and risk management functions on AI questions. Each subsequent artefact references which function owns which input, so the program complements the existing risk architecture rather than duplicating it.
Does the course cover AI use on audit engagements specifically, or only advisory work?
Both. The independence module is built specifically around the audit-side question. The engagement letter rider templates include an audit-side version. The supervisory log schema captures audit engagement attestations alongside advisory and tax.
What if the firm operates in jurisdictions beyond the US and EU?
The cross-border module includes a jurisdictional applicability matrix and a decision tree that handles UK, EU, US federal and state, and key APAC and LATAM jurisdictions. The implementation playbook delivered alongside course access lets the OGC add jurisdictions specific to the firm's footprint.
Is there a refund if the program does not fit the firm's needs?
Yes. Thirty-day refund window, no questions, from the date of purchase.

30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.