Clients want their consultants to use AI. They also watched Deloitte refund a government for a report with invented citations, and they have started writing AI clauses into their contracts and AI sections into their RFPs. What wins the work now is proof: which tools, on whose data, with what review, and who checked. AboveBoard verifies that proof and gives you a score, a badge and a registry entry procurement can click.
Enterprise security questionnaires now carry AI sections asking for evidence of AI-output review, controls that keep regulated data away from model endpoints, and proof that governance has been operating for 90 days or more (Asteros, May 2026). Outside-adviser RFPs are following (ABA Law Practice Magazine, Jul/Aug 2026). More than half of corporate legal and tax departments want their outside firms to use AI, but fewer than a third know whether they do (Thomson Reuters, Mar 2026).
Master services agreements increasingly include AI clauses: consent before the client's data touches AI, disclosure of AI-assisted deliverables, a ban on entering client information into external models, accuracy warranties, and flow-down to subcontractors. Each clause is an obligation your inventory and your review process have to be able to evidence, engagement by engagement.
When Deloitte Canada's $1.6M health workforce report was found to contain hallucinated citations, the provincial CPA regulator said it could not investigate because the work was management consulting, not public accounting (Canadian Accountant, Aug 2026). Consulting sits outside most professional-body oversight, which is why clients ask for independent evidence. Meanwhile Texas TRAIGA (Jan 1, 2026) treats substantial compliance with the NIST AI RMF as an affirmative defense (Baker Botts, Jul 2025), the FTC's July 7, 2026 policy statement targets undisclosed steering of AI outputs, and firms with EU clients are deployers under the EU AI Act's Article 4 literacy duty, enforced from August 2, 2026.
Seventy-eight percent of senior leaders lack full confidence they could pass an independent AI governance audit within 90 days, and only 20% have tested an AI incident-response plan (Grant Thornton, Apr 2026, n=950). KPMG withdrew an agentic-AI report in October 2025 and EY Canada pulled a study in May 2026 after fabricated sources were identified (ThePrint, Jul 2026; consulting.ca, May 2026). The firms selling AI governance have had their own reports hallucinate; partners have noticed.
ChatGPT, Claude, Gemini and Copilot for literature scans, synthesis, data analysis and first drafts; research assistants that cite sources; spreadsheet and code assistants. The category that produced every withdrawn Big Four report.
Slide and document generators, proposal automation, survey and interview analysis, transcription of client workshops. These carry client-confidential material and produce the thing the client pays for.
Agentic workflows that chain research, analysis and drafting with limited human touch; 15% of professional-services organizations already use agentic AI and 53% plan to (Thomson Reuters, Feb 2026). A changed prompt is a changed process.
Forty controls, eight per domain, scored on evidence. Here is how they read when your obligations are contractual and your product is a deliverable.
A written AI policy adopted by the partners, a named owner (often the COO or quality partner) with authority to halt a tool or an agent, an inventory of tools, agents and use cases including those used by subcontractors, a risk rating per engagement type, and a register of client contractual AI obligations.
Evidence examples: the policy with approval date; the register listing assistants, agents and deliverable tools with owners; the client-obligations register showing which MSAs restrict or require disclosure of AI; the quality-management cross-reference.
Client-confidential material classified against NDAs so consultants know what may never enter an unapproved tool, an approved-tool list, enterprise terms that prohibit training on inputs, single sign-on including for contractors, retention rules for prompts and drafts, and per-client consent where the contract requires it.
Evidence examples: the classification with engagement examples (client financials, interview transcripts, unreleased strategy); the vendor terms review log; the SSO and contractor-offboarding configuration; the consent record for an engagement whose MSA required it.
A written deliverable-review rule that every citation, figure and quotation in AI-assisted work is verified by a named reviewer before it leaves the firm; a QA log; an incident plan that covers a fabricated source reaching a client, including correction and refund decisions; monitoring of vendor and model changes; change control on prompts and agents; engagement-level tagging of AI-assisted work.
Evidence examples: the citation-verification checklist and a completed sample; the QA sampling log; the incident playbook step for client notification; the engagement record field that records AI use per deliverable.
Training completed by 90%+ of consultants, analysts, support staff and active subcontractors; role-specific modules; reviewer training on verifying AI output; signed acknowledgments including from contractors; partners who have completed a governance module.
Evidence examples: the completion report including contractors; the acknowledgment file; the partner-training record; the EU AI Act Article 4 literacy record for teams serving EU clients.
Statements of work and engagement letters address AI use; a published AI statement; a review step for AI claims in proposals and RFP responses; a standard answer bank for questionnaires; a complaints path; and a use-case review that keeps AI out of places clients would object to without notice.
Evidence examples: the SOW clause and opt-out handling; the proposal-review sign-off on an "AI-accelerated" claim; the last three RFP AI sections, consistent with each other and with the evidence file.
No firm is listed at any level with a zero on G1 (written policy), D3 (vendor terms reviewed) or O1 (human review before client-facing output). O1 is the control that would have caught the invented citations before they were invoiced.
Read the full rubricAnswered once from verified evidence, with a registry link and a year-stamped badge on the proposal. Consistency across bids is itself a differentiator.
When the client's AI clause asks for controls, you attach the report. When the professional liability application asks, you attach the same report. Coverage decisions remain the carrier's.
A plain-English report by domain with gaps and fixes, and a score that improves in the registry as the firm closes them.
AboveBoardAI issues a score and a verification under a private, voluntary standard; it is not an ISO certification, not a CPA audit or attestation, not legal advice, and not a guarantee that any deliverable is accurate. It verifies that the practices which catch errors exist and are evidenced on the review date. See What is an AI audit?
Take the free Snapshot. List every assistant, agent and deliverable tool in use, including by subcontractors, and pull the AI clauses from your ten largest client contracts. That is your register and your obligations list.
Adopt an AI acceptable-use policy (our template includes contractor language). Approve specific tools on firm accounts with enterprise terms. Have active subcontractors sign the policy.
Add a citation-and-figure verification step to deliverable QA with a named reviewer. Roll out Academy Foundations to staff and contractors; collect acknowledgments. Brief the partners and minute it.
Add the AI clause to SOWs and build the standard RFP AI answers tied to evidence. Start the full assessment; Snapshot answers carry over.
Growth Firm (50–249) $18,000; Established Firm (250–999) $42,000; Enterprise (1,000+) from $75,000. Every tier includes the assessment, independent review, score, badge, registry listing, board report and Academy Foundations. ISO/IEC 42001, by comparison, runs about $73,000 in year one for a 30-person firm and $185,000 for 120 people (certbetter, Jun 2026).
In October 2025 Deloitte Australia refunded more than A$97,000 on a A$440,000 government report after a fabricated court quotation and non-existent academic papers were found in it (CFO Dive, Oct 2025). In November 2025 a $1.6 million Deloitte Canada health workforce report for Newfoundland and Labrador was found to contain hallucinated citations, and in August 2026 the provincial CPA regulator said it could not investigate because the work was management consulting rather than public accounting (Canadian Accountant, Aug 2026). KPMG and EY Canada withdrew published reports in 2025 and 2026 after fabricated sources were identified.
Usually the contract decides. Client master services agreements and RFPs increasingly include AI clauses: consent before AI is used on their data, disclosure of AI-assisted work, prohibitions on entering their information into external models, and flow-down to subcontractors. Separately, any claim your firm makes about its own AI capabilities must be substantiated; the FTC's July 7, 2026 policy statement and the SEC's AI-washing cases make that explicit.
Treat them like any other vendor that touches client data: they sign your AI acceptable-use policy, they use your approved tools on your accounts where client data is involved, their AI-assisted work goes through the same deliverable review, and your inventory records which engagements they touched. Client contracts that restrict AI use flow down to them in writing.
Procurement teams are asking for the same things a reviewer verifies: a written AI policy, the list of approved tools and their contractual terms, controls that keep client data out of unapproved models, a documented human-review step for AI-assisted deliverables, training records, an incident plan and evidence that the controls have been operating. A verified AboveBoard Score lets you answer once and point to a registry entry.
AboveBoardAI is priced annually by headcount: $7,500 for firms of 1 to 49 people, $18,000 for 50 to 249, $42,000 for 250 to 999 and from $75,000 for 1,000 or more. Every tier includes the assessment, independent review, score, badge, registry listing, board report and Academy training for all staff. See pricing.