Case Study 5

Generative AI Policy and ChatGPT Governance for a Professional Services Firm

How a client-facing firm turned informal ChatGPT usage into a practical, governed productivity framework.

3 weeks
Professional Services
Generative AI policy, staff rules, and client-data safeguards
Problem

Staff were already using ChatGPT and other generative AI tools informally, creating uncertainty around client confidentiality, output quality, and accountability.

Intervention

Usage audit, risk classification, approved-use policy, prompt safety rules, client-data boundaries, review workflow, and staff briefing materials.

Outcome

The firm gained a practical AI usage policy, clearer staff confidence, and a safer path for using generative AI in drafting, research, and internal productivity workflows.

Client details are anonymised to protect confidentiality. Sector, scale, problem pattern, deliverables, and advisory method are preserved so the case remains useful for evaluation.

Overview

The firm did not need to be convinced that generative AI was useful. Staff were already using it. The real issue was that nobody had defined what safe, acceptable, and professional use looked like.

This engagement created practical rules for ChatGPT and generative AI usage without blocking productivity. The policy had to be short enough for staff to read, specific enough to guide behaviour, and strong enough to protect client confidentiality.

The challenge

Informal AI usage inside client-facing work

The firm had three overlapping problems: staff were experimenting independently, leaders did not know what data was being entered into tools, and managers had no shared standard for reviewing AI-assisted work.

Shadow AI usage

Staff were using public tools for drafting, summarising, research, and internal communication without an approved-use list.

Client-data uncertainty

There was no clear boundary around what client information could or could not be entered into generative AI systems.

Quality-control gaps

Managers lacked a standard review process for AI-assisted outputs before they reached clients.

Policy anxiety

Leadership wanted control, but did not want a heavy policy that would discourage useful experimentation.

Approach

Plain-language rules, not policy theatre

I began by mapping actual staff usage, then classified use cases by risk. The output was a practical policy and staff guide built around what the team was already doing, not an abstract legal document.

1

Usage audit

We identified where generative AI was already being used in drafting, summarising, research, administration, and client preparation.

2

Risk classification

Use cases were grouped as approved, conditional, restricted, or prohibited based on data sensitivity and output risk.

3

Data boundary design

We defined what information staff could never upload, what needed anonymisation, and what could be safely used for drafting support.

4

Staff guidance and review workflow

The final policy included examples, review steps, escalation rules, and manager responsibilities.

Deliverables

Practical governance assets

Generative AI usage policy

A plain-language policy covering approved uses, conditional uses, prohibited uses, and review requirements.

Client-data boundary rules

Clear guidance on confidential information, anonymisation, and sensitive-client material.

Review workflow

A practical process for reviewing AI-assisted outputs before client or public use.

Staff briefing guide

Examples of safe prompts, unsafe prompts, and when to escalate to a manager.

Outcome

Staff could use AI with clearer boundaries

The firm moved from informal AI use to an approved, explainable usage framework.

Staff gained practical examples of safe and unsafe use, reducing uncertainty.

Managers gained a review workflow for client-facing AI-assisted work.

The business preserved productivity gains while reducing confidentiality and quality-control risk.

Why this matters

Most firms already have AI adoption before they have policy

Generative AI policies should not be written as abstract compliance documents. They should reflect how staff actually work. The best policies help teams use AI more confidently because the boundaries are clear.

Buyer Questions

Questions this case study helps answer

Why does a professional services firm need a generative AI policy?

Professional services firms handle client information, advice, drafts, and confidential material. A policy gives staff practical rules before informal AI use becomes a quality or confidentiality risk.

Does the policy ban ChatGPT?

No. The policy defines safe, approved, conditional, and prohibited uses so teams can benefit from AI while protecting client trust and professional accountability.

What practical assets are delivered?

Typical deliverables include an AI usage policy, approved-use matrix, data boundary rules, staff guidance, review workflow, and management escalation criteria.

Chat with Me