AI Agent & Tool Audit

An AI usage and risk review: find the AI already running inside your firm.

Most AI audits ask whether you are ready to adopt AI. By the time anyone asks, the question is out of date: your people are already using it. A chatbot on a personal login, a note-taker sitting in client calls, an assistant bundled into software you already pay for. We find what is running, what each thing can reach, and who uses it — starting from your own systems, not a questionnaire.

Book your audit
  • £3,000 + VAT, fixed and one-off
  • Two weeks from agreed access
  • Five written documents
  • No obligation to go further

What we typically find

Five things that are almost always already there.

None of these need anyone to have done anything wrong. Each one is a decision somebody made quickly, months ago, that nobody has looked at since.

The note-taker nobody approved

An AI assistant that joins client calls, transcribes them and keeps the recording on a third party’s servers. One person clicked Allow months ago. That click rarely expires and nobody reviews it.

The free chatbot on a work email

A draft letter or a client’s figures pasted into a free AI account to tidy up. Free tiers may keep and learn from what they are given, and it is not an account you control or can audit.

The assistant that sees too much

Switch a firm-wide AI assistant on and it inherits every file its user could technically open. Papers nobody would have found by browsing become findable by asking a question in plain English.

The add-on with the run of the browser

An extension installed in two clicks can be granted permission to read every page that user opens, including your case or practice management system.

The licence you already pay for

AI features switched off inside a subscription you renew every year, while somebody quietly expenses a second tool that does the same job less safely.

What you get

Five deliverables, not a slide deck.

Everything below is written down and handed over. You keep all of it whether or not you work with us.

Workflow register

A written record of every workflow we reviewed and how it runs today — the baseline everything else is measured against.

Opportunity assessment

Every candidate ranked on impact against effort, so the argument for what comes first is visible rather than asserted.

Risk and control review

Evidence-backed findings on how client and business information may reach AI services, with recommended safeguards and priority actions. Built from what your systems record, not from a questionnaire.

Draft AI-use policy and 30/60/90-day plan

Practical guidance short enough for management to approve and staff to follow, with proposed owners, a named first project and what should follow it.

AI tool register

Every AI tool and agent we identify, its users, what each can reach, and a recommended approval status for each one. This is the document most firms have never had. More on the method behind it in our shadow AI audit.

A pilot scope and fixed quote

If you want to go further, one workflow scoped and priced in writing. Entirely optional.

Scope and limits

What we can see, and what we cannot.

Any review that claims to find every instance of AI use in a firm is overselling. Here is the honest boundary, written down before you buy rather than explained afterwards.

We separate three things

Observed activity, potential exposure, and areas we cannot verify. Each finding is labelled, so you know which of the three you are reading and how much weight it carries.

Where visibility stops

Personal accounts, unmanaged devices and unavailable logs limit what any review can see. We record those gaps as gaps rather than quietly leaving them out.

Access you authorise

Access is granted by you, limited to the agreed scope, and read-only where the system supports it. We review settings, permissions and available records rather than routinely inspecting the contents of your documents.

What this is not

A scoped advisory review, not a certification, a legal opinion or a guarantee of compliance. Remediation, implementation and any ongoing monitoring are scoped separately.

How it works

Two weeks. The first move is ours, not yours.

We pull the evidence first

We read your tenant — app consents, sign-in activity, permissions and licence state — before we ask anyone a single question. Access is read-only, scoped to the minimum the audit needs, granted by you, and switched off when we are done. We never read the contents of your files.

Then we talk to your people

Working sessions with up to five of your team, mapping how the week actually runs. What they tell us is reconciled against what the systems show.

You get the five documents

The five registers and reviews, delivered together with a findings discussion and a prioritised action plan. Target delivery is two weeks from receipt of the agreed access and information, subject to your team’s availability.

Governance built in

The AI governance audit, included.

Your team is almost certainly using AI already, approved or not. Every readiness audit includes a governance and shadow-AI check, so the plan you leave with is one a client or regulator could read.

Shadow AI, surfaced

We map which AI tools are actually in use across your team — including the free chatbots nobody mentioned — and what company or client data is going into them.

Policy and compliance gaps, named

UK GDPR, the EU AI Act and sector rules (SRA, FCA, ICAEW, CQC) each touch how you can use AI. We check your current position and give you the shortest path to compliant, starting with a one-page AI policy.

Why it is urgent in regulated work

A 2026 English court ruling confirmed that unapproved AI use can waive legal privilege. If you handle privileged, regulated or client-confidential data, ungoverned AI is a live risk, not a future one. More in our guides to UK AI compliance and SRA-compliant AI.

Built on platforms you already trust

Anthropic OpenAI Google Gemini Amazon Web Services Microsoft

FAQ

Good questions.

What does the audit cost?

A fixed, one-off fee of £3,000 plus VAT. It covers the tenant evidence work, sessions with up to five of your team, and all five written deliverables. You keep every document either way, and there is no obligation to go further.

How long does it take?

Two weeks from start to report. The evidence work happens first, then the working sessions, then the documents land with a walkthrough call.

Do we have to commit to anything?

No. The audit stands on its own. If you want to go further, the next step is a small 4 to 6 week pilot on one workflow, quoted in writing first.

Is our data safe?

Yes. We look at how your systems are used, not your confidential data. Anything we build later is UK-hosted, with your permission, and never used to train public models.

Does the audit cover AI governance and compliance?

Yes. Every audit includes an AI governance check: which AI tools your team already uses (approved or not), what data goes into them, and whether your policy would satisfy a client or regulator who asked. You leave with the gaps named and a fix for each.

What is shadow AI and why does it matter?

Shadow AI is staff using unapproved tools like free ChatGPT for work. Surveys put it at around 7 in 10 UK employees, and in regulated work the stakes are real: a 2026 English court ruling confirmed unapproved AI use can waive legal privilege. The audit surfaces what is actually in use and closes the gap.

Book your audit

Two weeks. Five documents. Yours either way.

Send a sentence about where your week gets stuck and we will book you in. You keep all five documents either way — no obligation.

0330 043 7414 · hello@nerdster.ai · Mon–Fri 9–5:30

Book your AI readiness audit

Tell us a little about your business and we'll book you in within one working day.

By sending this you agree we can contact you about your enquiry. We never sell your data or add you to a list.