From advisory function to operating model.
Legal, compliance, risk, privacy, security and internal audit are all being asked the same question, and most cannot yet answer it with evidence. We rebuild the function around defined process, ready data and measured outcomes, then apply AI to it.
book a 45-minute call →see your function →
Three pressures, one question.
The question is no longer whether the function adopts AI. It is whether it can show what changed.
Demand outgrows capacity
Legal, compliance and risk demand rises with every new market, product, counterparty and regulation. Headcount does not. For a decade the gap has been absorbed by people working harder and by external spend. Both routes are now exhausted.
The board wants a plan
“What is the function doing about AI?” is no longer a curiosity question. What is expected back is not a licence count but a plan with a cost, a sequence, a timeline and an outcome someone can measure.
The function carries the AI risk
The same people are asked to govern the enterprise’s use of AI. That makes their own adoption a governance question as much as a productivity one, and it raises the standard they are held to.
It is rarely a technology problem.
The functions that pull ahead are not the ones that bought earliest. They are the ones that did the unglamorous work first: naming the work types, fixing the data, writing the playbooks and deciding who is allowed to decide.
the gap is not budget · it is sequence
Tools have been bought
A generative assistant, perhaps a review or monitoring tool, often a licence already bundled into an existing enterprise suite.
Usage is uneven
A handful of enthusiasts, a majority who tried it once, and almost no one whose working day has actually changed shape.
Nobody captured the “before”
Benefits are asserted in board papers, believed by no one, and quietly dropped from the next update.
The data is not ready
Precedent, controls and evidence sit in inboxes and personal drives. Records are scanned, untagged and effectively unsearchable.
There is no rule for AI itself
No documented position on privilege, confidentiality, client or personal data, retention, or which tools third parties may use on your matters.
AI amplifies the process it is applied to.
Applied to a defined process, AI compounds it. Applied to an undefined one, it compounds the inconsistency. Which is why the first question is never “which tool?”, but “what, exactly, are we asking it to do, and on what data?”
You cannot automate an unmapped process
If nobody can describe how work actually travels from request to outcome (who touches it, how often it goes back, where it waits), then no tool can shorten that journey. Process definition precedes tooling. Always.
AI is only as good as the corpus beneath it
Retrieval, drafting and extraction all rest on a maintained, correctly tagged repository of the function’s own positions, controls and evidence. Building it is a data exercise, not a licence purchase.
Adoption is behavioural, not technical
Tools do not change how a team works. Playbooks, training, incentives, workload relief and visible leadership do. Budget for the change programme, not only for the software.
What an AI-enabled function looks like.
Six domains where the work actually sits, described as a shift rather than a tool list. Choose the function you run.
From advisory function to operating model: one front door, grounded drafting, playbook-led contracting and spend under measurement.
Intake & matter management
Work arrives by email, favour and corridor conversation; no single record of what Legal is carrying.
One front door. Requests classified and routed automatically; routine questions answered first-line from prior advice.
Knowledge & research
Know-how lives in inboxes and individual memory, and leaves when people leave.
Search and drafting grounded in the function’s own positions, cited to source, with external monitoring by jurisdiction.
Contracting
Every agreement drafted, reviewed and negotiated by a lawyer, whatever its value.
First-pass review against playbook; low-risk agreements self-served by the business; obligations extracted and monitored.
Disputes & litigation
Case status reconstructed on request; exposure reported late and inconsistently.
Consistent case records with deadline tracking, portfolio-level exposure reporting, supervised review at document scale.
Spend & panel
Invoices approved on trust; budgets set annually and rarely revisited.
Automated invoice review against billing guidelines; matter-level budget tracking; panel performance compared on cost.
Obligations
Manual assessments and record-keeping absorbing scarce specialist time.
Assisted intake and scoping, drafting support for assessments, obligations mapped to real controls.
Capability is layered, and carried by what sits beneath.
Most functions attempt the top tier first. That is the single most common reason these programmes stall.
Strategic partner
an outcome, not a purchase
Insight
data strategy · demonstrable value
Modernise
resourcing · cost · change management
Data & operations
matter and control data · analytics · demand management · vendors
Foundations
process mapping · work-type taxonomy · knowledge · skills
Foundations are not a technology spend
Taxonomy, data model, delegation of authority, playbooks. Cheap, unglamorous, and the reason everything above them works.
Each tier makes the next one cheaper
Skip one and every tier above it costs more, takes longer and delivers less than the business case promised.
The top tier is an outcome
“Strategic partner” is what the business calls you once the tiers beneath are quietly working. It cannot be bought directly.
Every use case scored on four axes.
Then screened for feasibility in your actual environment, not in an abstract maturity model.
Volume
How often does the task recur? High-frequency, repeatable work returns the investment fastest and proves the case soonest.
Complexity
How much professional judgement is genuinely required? Low-judgement steps are the safe starting point, not the boring one.
Risk
What is the consequence of an error, and can a human review step catch it before it leaves the function?
Data readiness
Does the underlying corpus exist, and is it tagged well enough for a model to work against it today?
Strategic bets
remediate foundations first
Priority pilots
start here
Deprioritise
revisit later
Quick wins
cheap proof, low risk
A route that does not require betting the function.
Three phases, two decision gates. Each gate is a real decision supported by a deliverable, not a change request. Nothing is committed beyond the phase in progress.
Baseline & Diagnostic
- Mobilisation, ambition and constraints agreed with the function head
- Structured sessions with each functional lead; practitioner interviews across grades
- Time-allocation and cycle-time baselining against a common work-type taxonomy
- Data and tooling readiness assessed in your actual environment
Gate 1 · Baseline, use-case scoring and a costed sequence
Diagnostic report · prioritised use-case portfolio
Design & Foundations
- Work-type taxonomy, data model and delegation of authority documented
- Target process design for the prioritised use cases
- AI use policy for the function: confidentiality, privilege, retention, human review
- Business case with the kill rule agreed in advance
Gate 2 · Playbooks, templates, triage rules and delegation documentation
Operating model pack · assurance framework
Adoption & Measurement
- Deployment of the prioritised use cases with domain owners
- Training design, communications and behaviour change
- Measurement against the Phase 1 baseline, reported quarterly
- Assurance evidence maintained as the function operates
Nothing is committed beyond the phase in progress
Playbooks & training · quarterly benefits pack for the board
Benefits measured, not asserted.
The most common reason an AI programme loses board support is that nobody captured the “before”. A baseline is the cheapest insurance a function head can buy: it makes the next budget conversation a matter of record, not belief.
Baseline before anything changes
Time allocation by work type. Cycle times end to end. Handoff counts, rework rates, exception volumes. External spend by matter type and firm. Captured once, before a single tool is switched on, because it cannot be reconstructed afterwards.
Agree the kill rule in advance
Decide before you start what result would cause you to stop. A pilot without a stopping condition becomes a permanent line item nobody will defend.
Report in the board’s language
Cost avoided. Cycle time reduced. Share of work self-served by the business. Exposure reported on time. Not licences deployed, prompts run, or hours of training delivered.
Six functions, one method.
AI-Enabled Legal Function
From advisory function to operating model: one front door, grounded drafting, playbook-led contracting and spend under measurement.
AI-Enabled Compliance Function
Horizon scanning, policy, monitoring and training rebuilt around one obligations register that the business can actually read.
AI-Enabled Risk Function
From colour-coded heatmaps to quantified exposure, with controls, incidents and scenarios on one shared record.
AI-Enabled Privacy Function
Records, assessments and data subject rights handled at volume without adding specialist headcount.
AI-Enabled Security Function
Assurance, supplier risk and regulatory reporting handled with the same rigour as the SOC, without the manual evidence chase.
AI-Enabled Internal audit Function
From annual sampling to continuous, evidence-led assurance, with the audit trail generated as work happens.
We ran this programme on ourselves first.
Senior practitioners who have run these functions, built AI governance for global groups, and rebuilt their own business around AI.
Practitioners who have run these functions
Firm partners with fifteen-plus years post-qualification, who have led privacy, legal and governance functions at group level, not a pyramid of juniors billing time against a methodology.
Adoption and assurance as one programme
We build AI governance frameworks and we build operating models. Designed together they cost less than two sequential efforts and survive the first hard question.
Independent, and white-label by design
No reseller, referral or commission arrangement with any technology vendor we may assess. Deliverables are built to be presented internally as your own work, under your own name.
We ran this programme on ourselves first
Pritect began as our own internal tool for running privacy, security and governance programmes. We launched it commercially in 2026. The argument we make to your function is the one we already tested on our own P&L.
What a first conversation looks like.
No obligation beyond the conversation, and nothing you cannot use afterwards regardless of what you decide.
A 45-minute call
The shape of your function, the tooling already in place, the data you can realistically reach, and what the board has actually asked you for.
A short written read-out
Where we think the sequence should start, what it would cost to find out properly, and what you can do yourself without us.
A decision, not a proposal cycle
If a baseline is the right next step we scope it. If the foundations are the whole job, we will say so; that is a legitimate outcome, and a cheaper one.