Skip to main content

Business AI Review for practical, governed AI use

A short, practitioner-led review of the artificial intelligence (AI) tools your business already uses and pays for, so you can standardise where the work happens, set rules people can actually follow, and decide the next useful step without buying more technology by default.

Rory does this work himself. You speak to the person doing the review.

Discuss your AI use See what a Discovery Review involves

You already recognise at least one of these

This review is for businesses where AI use has already started. It is not an introduction to AI, and it is not a case for adopting it.

Staff signed up on their own

Individual ChatGPT or Claude accounts are appearing on expense claims, and nobody agreed which one the business is standardising on.

Licences nobody can account for

Copilot seats were bought, and there is no clear answer to who needs one, who is using it, or what changed as a result.

Client material is going into AI tools

Proposals, reports and client correspondence are being pasted into tools, and the rule for what is acceptable has never been written down.

Different teams, different subscriptions

Two or three overlapping products are being paid for because each team solved the problem separately.

Someone wants to connect it to something

There is a request to connect AI to SharePoint, the CRM or a finance system, and no shared view of what it would then be able to change.

Something has already been built

A flow, an agent or a custom assistant exists, and no one can explain what it touches or who signed it off.

If AI use has not started, or none of these sound familiar, start with a Discovery Review to decide the next useful step. It is not limited to AI.

What you decide, and what you leave with

Every finding ends in a decision with a named owner. All of it written down, in plain English, and yours to use whether or not MDE does the work that follows.

Keep, change or stop, per tool
Each AI product in use is assessed against what it is actually doing for the business. Some stay, some are consolidated, and some are cancelled. Removing a subscription is a legitimate outcome when the evidence supports it.
Where the work should happen
Which organisational workspace to standardise on, and what moving there would mean for billing, ownership and administration. The answer is driven by the controls you need, not by the tier with the most impressive name.
What staff may do, with which information
A short, readable table of approved, conditional and prohibited uses, written against the kinds of information your business actually handles rather than a generic policy template.
Which workflows deserve a closer look
Two or three candidates where AI would plausibly change the economics of the work, with an honest read on what each would take.
Whether to connect anything at all
A clear position on integration: what would be gained, what the system would then be able to reach, and whether a native capability you already own does the job.
Whether the next step is nothing
"Do less than you planned" is an available answer. If the sensible next step is to cancel two subscriptions and revisit in six months, that is what the review will say.
An inventory you can hand to anyone
Which AI tools and workspaces are in use, who owns them, who pays, and how they are actually being used, with what MDE verified kept separate from what it was told.
Information and action observations
Where your information is going, which connected apps are enabled, and where a control, an owner or a written rule is missing. Matters needing legal, privacy or security specialists are flagged, not answered.
Duplication and unused capability
Overlapping subscriptions, seats nobody uses, and capability you already pay for and have not switched on.
A 30/60/90-day action plan
Findings ranked by how much the decision matters, each with a named owner, a next action and a review date. Specific enough to take to your team or your board without translation.

Read → Draft → Stage → Write

Most disagreements about AI risk are really disagreements about which of these four things the system is allowed to do. MDE classifies every proposed use against this ladder before anyone designs anything. Each level requires everything the level below it required, and more.

  1. 1

    Read

    The tool finds or summarises information the person is already entitled to see. Copilot summarising a project folder sits here. This keeps the proposed action at retrieval and summarisation; the underlying permissions still need review.

  2. 2

    Draft

    The tool proposes a document, a reply or an answer for a person to accept, edit or reject. A drafted client proposal sits here. Accountability for what is sent stays with the person who sends it.

  3. 3

    Stage

    The tool prepares a change and stops, leaving it in a queue for approval. Staged CRM updates sit here. This needs a real approval queue, identity design and an audit trail, not just an intention to check.

  4. 4

    Write

    The tool changes a business record, sends an external message or executes a transaction on its own authority. This is the highest bar: least-privilege access, negative testing, rollback, a named owner and an escalation path.

Where the evidence does not support a higher level, the review says so and recommends Read or Draft. "A human is in the loop" is not a control unless that person has real information and real authority before the change happens.

Read the full boundary method

Why MDE

Microsoft-first, comparison-aware
MDE's Business AI Review is Microsoft-first: it starts with the Microsoft 365, Copilot and Power Platform estate the business already uses. When ChatGPT or Claude business products are already in scope, the review records the administrative controls and information boundaries that need checking.
Decision-grade, not a readiness score
The review ends in keep, change and stop decisions with owners. It does not produce a maturity rating, a readiness percentage or a roadmap you cannot act on next week.
Governance sized for your business
MDE works from Australia's current national guidance for AI adoption: an accountable owner, a short usage rule, a register of what is in use, testing and human control. It is scaled to a business of your size rather than an enterprise framework you would never operate.
A bias toward doing less
A review can recommend removing something. Checking duplicated tools and unused licences before committing to further work keeps the next decision grounded in the current state.

When MDE is not the right provider

Said plainly, because a review that turns into something else serves nobody.

You want ongoing AI support

MDE does not run a helpdesk. If you need someone on call for prompt help and day-to-day user support, an MSP or an internal owner is the right answer.

You want licences resold

The review does not supply, resell or arrange licences, and its findings are not a procurement recommendation. Detailed procurement advice without an architecture or governance mandate is not something MDE takes on.

You want prompt training at volume

MDE's Workshop, Training & IP engagement is for turning an agreed policy into practice. It is not a general AI skills programme delivered at volume.

You want autonomous decisions

MDE will not design a system that makes consequential decisions about people, such as employment, credit or service access, without a person who has the information and authority to intervene.

You want a compliance guarantee

MDE identifies exposure, designs controls and tells you what a specialist would need to look at. It does not certify you as compliant and does not give legal advice.

What can happen next

The review earns the right to a good next decision. Where further work is justified, it runs through MDE's existing engagements. There is no separate AI programme.

Front door

Discovery Review

Every engagement starts here. The Business AI Review is this review, scoped to the AI decision in front of you.

Then, if justified

Design Sprint

Where one workflow warrants proper design: data and identity boundaries, approval, logging, failure and rollback, before anything is built.

Then, if justified

Delivery Sprint

Where a design is approved and one reversible workflow is ready to build, with agreed acceptance checks.

Where practice is the gap

Workshop, Training & IP

Where a policy or method needs to be adopted, used well and sustained by the team. The outcome is reusable practice, not indefinite consultant dependence.

Where the estate keeps moving

Embedded Advisory & AI Assurance

Senior oversight where use cases, connectors and agents keep changing and someone needs to keep making the call.

Scope, exclusions and cost are agreed in writing before any review starts. Implementation is always a separate decision.

Start with the decision you are actually holding

Bring the subscriptions you are paying for, the question someone has asked you, or the thing somebody has already built. That is enough to begin.

Discuss your AI use

contact@mccluskeydigital.com