AIRIAM · AI TRUST SERVICES Internal opportunity brief

AI Enablement & Governance

A regulated-client inquiry, reframed as a productized engagement that arcs from professional services into recurring managed operations — and positions Airiam as the client's standing AI governance function.

Prepared for Kuk · CEO Catalyst Rinaldi CPA — J. Walker, LL.M Owner Greg Status Reply drafted · assets productized
01 The business challenge

What the client is actually asking for

An attorney (tax LL.M.) at a CPA firm wrote in evaluating an enterprise AI toolset — Microsoft 365 Copilot or Claude / Claude Cowork — before the firm commits to anything. The request reads like an RFI, but it is unusually specific: he asked for guidance across five distinct areas, in order, with documentation and controls front and center.

ASK 01

Implementation feasibility

Whether Copilot or Claude can run inside the firm's current Microsoft/cloud environment, and the licensing, tenant configuration, user-access, security, and infrastructure implications of each.

ASK 02

Timing & process

Realistic timeframe to implement, the procedures to add, configure, and govern either toolset, and the vendor security documentation, contracts, data-processing terms, and approvals required first.

ASK 03

A sandbox for app testing

He intends to build small internal Python apps and workflows, and needs a controlled sandbox to test them before production — including who administers it and what restrictions apply.

ASK 04

Documentation for in-house apps

What he must supply before an app enters the sandbox: description, architecture, data-flow, dependencies, security notes, configuration, user-access assumptions, and a rollback plan.

ASK 05

Testing & migration to production

The test plans, results, logs, and audit evidence required to promote an app, plus the change-management gates, monitoring, and support responsibilities for deployment.

HIS CLOSE

"Email first, or a meeting?"

He explicitly left the door open to a conversation — and stated he is not asking us to implement anything yet, only to define the requirements, controls, and process.

What this really is

The tell is in asks 3–5: he wants to build and run internal AI apps and needs a governed path from sandbox to production. As an attorney at a CPA firm, his real currency is confidentiality, privilege, defensibility, and a clean paper trail. This is not a license sale — it is a managed AI enablement & governance engagement, squarely in our AI Trust Services lane.

02 Executive recommendation

What Airiam recommends

Pursue this not as a tool decision but as a phased governance engagement — open with a fixed-fee assessment, and build it toward a recurring managed service.

01 — Reframe

Sell governance, not seats

Lead with control and defensibility. The decisive variable for a regulated firm is data terms and audit posture, not feature parity — and that is exactly where we add value.

02 — Protect the IP

Don't give the consult away

Answer his five points in writing at summary level to prove we own the standards — then reserve the firm-specific work for a scoped, paid assessment rather than a free RFI response.

03 — Convert

Earn the meeting

Push to a 30–45 minute scoping call that frames a fixed-scope Phase 0. The written reply earns the meeting; the meeting scopes the engagement.

03 Airiam business value

Why this is worth pursuing

One inbound becomes a repeatable, productized offering with revenue today and an annuity tomorrow — and it lands Airiam inside the client as their standing AI governance function.

Productized, not bespoke

We already hold the playbook, client one-pager, intake forms, promotion gates, sandbox standard, and monitoring — reusable across every future prospect.

"We run it, not just advise"

The governed sandbox and documented AI SDLC are our differentiator — capability a pure advisory shop cannot match, and the reason we win.

Defensible by design

Separation of duties, synthetic-data-only testing, and an audit-ready chain of evidence — matched to a client who lives and dies by defensibility.

Land and expand

Project work seeds a recurring contract; once we hold governance, Sentinel AI and FinOps become natural follow-ons.

Honest credibility hook

Anthropic excludes its Cowork agent from audit logs even on Enterprise — precisely the gap our governance layer closes. The kind of detail an LL.M. respects.

A path to their clients

For a CPA firm, the larger arc: Airiam becomes the outsourced AI risk function for their own client base over time.

04 The offering — services to managed service

One engagement, four phases, one arc

Phases are sold sequentially but priced independently. A fixed-fee assessment is the paid front door; managed operations is the recurring destination.

Professional services Managed service
P0Fixed fee

Readiness & Governance Assessment

We doTenant, identity & DLP review; data classification; platform decision; governance framework. ~2–3 weeks.
Client getsA platform recommendation and a phased roadmap they can act on — no obligation to implement.
P1Project

Platform Enablement

We doLicensing, tenant config, conditional access, sensitivity labels, and access-governance remediation.
Client getsThe chosen platform stood up inside their compliance boundary, with controls validated before users get access.
P2Project

Governed Sandbox + AI SDLC

We doStand up the isolated sandbox, intake forms, promotion gates, and monitoring hookup. Our differentiator.
Client getsA safe, documented path from idea to production for their Python apps — synthetic data only.
P3Recurring

Managed AI Operations

We doOngoing governance, continuous monitoring, tiered support, and periodic re-assessment.
Client getsA standing AI governance function — and Airiam earns the recurring revenue anchor.

The bigger arc

  • Each engagement compounds: the same standards and assets serve the next prospect at near-zero marginal cost.
  • Professional-services fees fund the relationship; the managed-service contract is the durable, recurring annuity.
  • Once we are the client's AI governance function, Sentinel AI and FinOps are natural cross-sells.
  • With a professional-services firm, the long game is becoming the outsourced AI risk function for their clients.
What I need from you

To move

  1. A green light to pursue this as a standard AI Trust Services offering and to respond to the client.
  2. A nod to Daniel to confirm the BAA-backed path and isolated-sandbox infrastructure are feasible on the implied timeline.