Diagnostic · Before the AI spend, not after

Find out where AI is worth using, and where it is not

What AI is already being used in your business, what it is worth applying to next, what it would cost, and which of it you should not do — ranked, costed, and yours to execute with anyone.

  • Every opportunity ranked by cost and risk
  • The AI already in use, written down
  • A plan you can execute with anyone

Most owner-led businesses arrive at AI from the wrong end: a tool gets bought, someone is asked to find a use for it, and a year later nobody can say whether it saved anything. The question worth answering first is narrower and duller. Where in this specific business does probabilistic software do work a person is currently doing by hand, and what does it cost to get it wrong there?

That question has a real answer, and it is usually shorter than people expect. Some of the repeated work is a process problem that automation would only make faster. Some of it is genuinely well suited to a language model. Some of it should not be touched, because the cost of a confident wrong answer lands on a client, a patient, or a regulator.

This audit produces that ranking, the evidence behind it, and the number attached to each item. It is deliberately decoupled from the build: the plan is written so you can hand it to an internal team or another firm.

Fit

Who this is for

A good fit

  • Your team is already using AI tools you did not choose, approve, or write down.
  • You have been pitched an AI project and cannot tell whether the business case is real.
  • You know which tasks eat the week, but not which of them a model could actually do.
  • You work with confidential, financial, or health information and need the boundary decided before adoption, not after.

Not a fit

  • You want a single tool recommendation and have already decided what the answer is.
  • You want a certification, an attestation, or a regulator-facing compliance report.
  • The business has no repeated work at volume yet, in which case the constraint is demand, not tooling.

Symptoms

You're in the right place if

  • Staff are pasting client information into consumer chatbots and nobody has said whether that is allowed.
  • You are paying for AI features inside tools you already own and cannot tell whether anyone uses them.
  • Every vendor conversation opens with the solution rather than with what it replaces.
  • You suspect a model could handle the intake, the summarising, or the first draft, but not which one is worth doing first.
  • A partner, insurer, or client has started asking how your firm uses AI, and the answer is currently improvised.
  • You have been quoted for an AI build and have no basis to judge the number.

Scope

What you get

01

An inventory of the AI already in use

What tools people are actually using, what information goes into them, and under whose account. This is almost never nothing, and it is almost never what the owner expects. It is the single fastest way to find the risks worth closing this month.

02

The repeated work, costed

Every candidate task ranked by frequency multiplied by time multiplied by the cost of getting it wrong. The same ranking the automation work uses, because the honest answer for a given task is often a deterministic script rather than a model, and the ranking is what makes that visible.

03

A suitability judgement per task

Whether the output can tolerate being probabilistic, whether a wrong answer is recoverable, whether a person is reviewing it anyway, and whether the input is even available in a form a model can read. Tasks that fail these tests are named as such rather than quietly dropped.

04

Cost and effort estimates that include the running cost

Build effort, licence and usage cost at your actual volume, and the review time the design implies. An automation that needs a person checking every output has a labour cost, and it belongs in the business case rather than in a footnote.

05

The data and confidentiality boundary

Which information may go to which vendor, what has to stay inside systems you control, and what your existing obligations already require — professional conduct rules, privacy law, and the client agreements you have signed. Written as decisions your team can follow, not as a policy nobody reads.

06

A prioritised plan with a first step

Two or three items worth doing first, in order, with what each requires and what it should produce. Plus the list of things not worth doing, which is usually the more valuable half of the document.

Process

How the work runs.

01

Inventory

What tools are in use, by whom, with what information. Interviews with the people doing the work rather than a survey of what the owner believes is happening.

02

Cost the work

Repeated tasks ranked by frequency, time, and the cost of an error. This is the same ranking the automation work uses; AI is one of several possible answers to it.

03

Test suitability

Each candidate assessed for tolerance of probabilistic output, recoverability of a wrong answer, review burden, and whether the input exists in a usable form.

04

Write the plan

Ranked recommendations, costs including running cost, the data boundary, and an explicit not-worth-doing list. Delivered as a document, walked through on a call.

Outcomes

What changes, and what does not.

These are the kinds of change this work produces. No numbers appear here, because no client result has been measured and published yet. When one has, it will appear in Work with its baseline, method, and time window.

  • You can name every AI tool touching business information, and who is accountable for it
  • The first project is chosen on cost and risk rather than on what a vendor was selling
  • Work that should stay manual is identified before someone automates it
  • The confidentiality boundary is a written decision instead of an individual judgement call
  • You can read an AI quote and tell whether the business case behind it is real

Tooling

What the review covers

Categories of use, not endorsements. Where a deterministic rule is cheaper and more testable than a model, the plan says so.

Assistants in tools you own

  • CRM and inbox features
  • Document and meeting summaries
  • Spreadsheet and reporting assistants

Customer-facing

  • Intake and triage
  • After-hours answering
  • First-draft replies
  • Website chat

Internal

  • Document extraction
  • Classification and routing
  • Search over your own files

Controls

  • Data boundary
  • Human review points
  • Logging and retention
  • Vendor terms

What this is not

  • It is not a compliance certification. ISO/IEC 42001 certification and formal assurance are separate exercises with an accredited auditor, and this is not a substitute for one.
  • It is not legal advice. Where an obligation is genuinely unclear, the plan says so and points at the rule rather than guessing on your behalf.
  • It is not a sales document for a build. The recommendation is frequently that a given task is not worth automating at all, and the plan is written to be executable by someone else.
  • It is not a model benchmark. Which vendor scores highest this quarter matters far less than whether the task tolerates a wrong answer.

Straight answers

Common questions.

If yours is more specific, put it in the audit form.

support@ariadne.fyi
How is this different from the growth system audit?

The growth system audit diagnoses the path from a stranger finding you to revenue being recorded, across nine checkpoints. This one looks at the repeated work inside the business and asks where probabilistic software belongs. They overlap at automation and measurement. If you are unsure which you need, start with the growth system audit — it is the broader diagnosis and it will tell you whether AI is anywhere near your actual constraint.

Do we need an AI policy?

Canada has no AI-specific statute in force for private businesses, so what applies is what already applied: privacy law, your professional obligations, and the confidentiality terms in your client agreements. A short written decision about what information may go where usually satisfies more of that than a long policy document. If you want a recognised structure to grow into, NIST’s AI Risk Management Framework is voluntary and free to use, and ISO/IEC 42001 is the certifiable equivalent.

What if the answer is that we should not use AI?

Then that is the finding, and it is worth knowing before a project starts rather than after. It is rarely the answer for a whole business, though. More often two or three narrow tasks are clearly suitable, a larger number are marginal, and the remainder are either process problems or genuinely require judgement.

Will you tell us to buy a specific tool?

Only where a specific tool is the answer, and the reasoning will be in the document. Ariadne holds no reseller relationships and takes no vendor commissions, which is the only reason a tool recommendation from anyone is worth reading.

How much does it cost?

It depends on the size of the business, how many people touch the repeated work, and how much of it is already documented. Scope and price are confirmed in writing before anything starts, and if it is not a fit you will be told at that point rather than after an invoice.

Your practical starting point

Find out which AI work is worth doing, and which is a process problem.

The audit inventories what is already in use, ranks the opportunities by cost and risk, and names the ones not worth doing. You keep the plan whether or not you build it here.

Request a growth system audit