A regulated-client inquiry, reframed as a productized engagement that arcs from professional services into recurring managed operations — and positions Airiam as the client's standing AI governance function.
An attorney (tax LL.M.) at a CPA firm wrote in evaluating an enterprise AI toolset — Microsoft 365 Copilot or Claude / Claude Cowork — before the firm commits to anything. The request reads like an RFI, but it is unusually specific: he asked for guidance across five distinct areas, in order, with documentation and controls front and center.
Whether Copilot or Claude can run inside the firm's current Microsoft/cloud environment, and the licensing, tenant configuration, user-access, security, and infrastructure implications of each.
Realistic timeframe to implement, the procedures to add, configure, and govern either toolset, and the vendor security documentation, contracts, data-processing terms, and approvals required first.
He intends to build small internal Python apps and workflows, and needs a controlled sandbox to test them before production — including who administers it and what restrictions apply.
What he must supply before an app enters the sandbox: description, architecture, data-flow, dependencies, security notes, configuration, user-access assumptions, and a rollback plan.
The test plans, results, logs, and audit evidence required to promote an app, plus the change-management gates, monitoring, and support responsibilities for deployment.
He explicitly left the door open to a conversation — and stated he is not asking us to implement anything yet, only to define the requirements, controls, and process.
The tell is in asks 3–5: he wants to build and run internal AI apps and needs a governed path from sandbox to production. As an attorney at a CPA firm, his real currency is confidentiality, privilege, defensibility, and a clean paper trail. This is not a license sale — it is a managed AI enablement & governance engagement, squarely in our AI Trust Services lane.
Pursue this not as a tool decision but as a phased governance engagement — open with a fixed-fee assessment, and build it toward a recurring managed service.
Lead with control and defensibility. The decisive variable for a regulated firm is data terms and audit posture, not feature parity — and that is exactly where we add value.
Answer his five points in writing at summary level to prove we own the standards — then reserve the firm-specific work for a scoped, paid assessment rather than a free RFI response.
Push to a 30–45 minute scoping call that frames a fixed-scope Phase 0. The written reply earns the meeting; the meeting scopes the engagement.
One inbound becomes a repeatable, productized offering with revenue today and an annuity tomorrow — and it lands Airiam inside the client as their standing AI governance function.
We already hold the playbook, client one-pager, intake forms, promotion gates, sandbox standard, and monitoring — reusable across every future prospect.
The governed sandbox and documented AI SDLC are our differentiator — capability a pure advisory shop cannot match, and the reason we win.
Separation of duties, synthetic-data-only testing, and an audit-ready chain of evidence — matched to a client who lives and dies by defensibility.
Project work seeds a recurring contract; once we hold governance, Sentinel AI and FinOps become natural follow-ons.
Anthropic excludes its Cowork agent from audit logs even on Enterprise — precisely the gap our governance layer closes. The kind of detail an LL.M. respects.
For a CPA firm, the larger arc: Airiam becomes the outsourced AI risk function for their own client base over time.
Phases are sold sequentially but priced independently. A fixed-fee assessment is the paid front door; managed operations is the recurring destination.