web analytics
Applications — 01

Find your $670K.

Your company is running more AI than you think, in more places than you know, costing more than you can defend. The AI audit ends the guessing. Built on three decades of operator experience and four published volumes of methodology.

Start Your AI Audit — $399 Schedule a 30-Minute Walkthrough

Built by SRJ Consulting & Services LLC · Stephen R. Jordan, three decades of senior leadership at Citi, Intel, McAfee, and Optiv · Methodology published across four volumes of The Operating Discipline for AI Library™

What this page delivers

The AI Business Enablement Audit™ is a structured, executive-grade evaluation of how AI is currently operating across a business, what it is costing fully loaded, and whether it is producing measurable outcomes. Three engagement tiers, priced from a single-operator $399 diagnostic through a six-figure custom recovery program. Most audits pay for themselves before they surface a single risk finding.

What's actually happening in your company right now

The number on the contract is not the number.

You signed a contract for one AI tool. You're paying for four.

The first one is on the master invoice. The second one is on your marketing director's corporate card. The third one is on a free-tier account someone in operations set up "just to test" eighteen months ago. The fourth one was bundled into your CRM upgrade and you didn't read the changelog.

That's the inventory problem. It compounds into the cost problem, which compounds into the performance problem, which compounds into the risk problem, which compounds into the governance problem. Every one of them is happening in your company right now. You just can't see them, because nobody has ever counted.

Here's what the research says is happening across mid-market operators with twenty-five or more employees:

Duplicated subscriptions

Finance procured one tool. Marketing procured another. Engineering procured Copilot and Cursor. Sales procured a Gong add-on. HR procured an AI screening tool. None of them know about the others. The consolidated invoice would be 30 to 40 percent lower if any one person owned the consolidation.

Shadow AI exposure

Employees pasting proposals, contracts, client lists, M&A documents, source code, internal memos, and HR complaints into consumer chatbots, every day, with no logging, no DLP controls, no record. Each paste is a future incident waiting for a regulator, a plaintiff, an acquirer's diligence team, or a journalist.

Wrong-tool productivity drag

Your people reach for whichever AI tool is loudest on LinkedIn this quarter. The tool is rarely the right fit for the task. The cost shows up as half-finished workflows, abandoned pilots, and a quiet erosion of trust in the technology, which means the AI investments you should make get blocked too.

Vendor leverage lost

Every uncoordinated AI purchase weakens your position at renewal. Consolidation is leverage. Fragmentation is the opposite. Most companies are negotiating from the worst possible position and do not know it.

Decision accountability gaps

Your AI tools are making hiring recommendations, pricing decisions, customer communications, and content choices. Nobody has written down who is accountable when one of them is wrong. When the wrong thing happens, and it will, the answer to "who approved this?" is "nobody, exactly."

Regulatory blind spots

The EU AI Act, the Colorado AI Act, NYC Local Law 144, SEC AI marketing guidance, FTC enforcement actions, OCC SR 11-7, NIST AI RMF, ISO 42001. Your company is in scope for at least three of these. You may not know which three.

The cumulative cost of these six failure modes across mid-market operators is roughly $670,000 per year. Your number is different. It might be lower. It is almost certainly higher. The audit tells you which.

A note on the $670K figure: the benchmark is drawn from SRJ's current advisory research across mid-market operators. As the audit platform completes its first hundred engagements, it will produce its own peer-distribution benchmarks, your number compared against actual industry data rather than against a single calculated average. Until then, the $670K is the right starting reference.

What the audit does

One questionnaire. Five dimensions. Four reports. A list of exactly what to fix.

The AI audit is not a survey. It is not a maturity model dressed up as a quiz. It is an operational diagnostic, the same instrument SRJ uses in its six-figure consulting engagements, made available at the lowest tier as a one-time $399 product for a single operator.

Tier 1 · $399 One-Time
The Snapshot

One-time payment, 35-minute questionnaire, four framework-attached reports delivered to your account.

  1. Sign up and pay $399 at aiauditforcompanies.com.
  2. Answer the questionnaire, about 35 minutes, 127 questions across five dimensions, for a senior operator who knows the business.
  3. Receive your findings, The Four Audit Outputs™, four framework-attached reports inside your account. Each names a gap, ranks it, and ties it to a documented recommended action with the relevant framework or template attached.
Tier 2 · Pricing on Request
The Assessment

The audit extended across your team, with variance analysis between what leadership thinks is happening and what the front line is actually doing.

  1. Multi-respondent rollout across your team, up to 25 respondents with confidential individual links.
  2. Variance analysis, the leadership view compared against the front-line view, with the gap surfaced and named.
  3. 90-minute findings call with Stephen, evidence-attached findings, document review of contracts and policies you choose to attach.
Tier 3 · Pricing on Request
The Engagement

A custom advisory engagement, scoped to your industry and your operating reality, with board-ready outputs and a named implementation roadmap.

  1. Discovery, on-site or remote, scoped to your business and your sector.
  2. Custom risk modeling and board-ready briefing materials tailored to your regulatory and operating context.
  3. Six-month implementation roadmap with named owners, milestones, and review cadence.
Three tiers, side by side
The audit at three commitment levels.
Tier Price What you get Delivery Best for
Tier 1: The Snapshot $399 one-time Four framework-attached reports (The Four Audit Outputs™) 35-minute self-service questionnaire, results delivered to your account A single operator who needs to see what is actually happening now
Tier 2: The Assessment Pricing on request Multi-respondent rollout, variance analysis, 90-minute findings call Up to 25 confidential respondent links; document review; live call with Stephen A leadership team that suspects a gap between what they think is happening and what the front line is doing
Tier 3: The Engagement Pricing on request Discovery, custom risk modeling, board-ready briefing, six-month implementation roadmap Custom advisory engagement scoped to your industry and operating reality An organization ready to fund an operating-model change with named owners and milestones

The Snapshot is live. Start now, or schedule a walkthrough first.

Start Your AI Audit
Exactly what you get, exactly what it does

Here is what the audit produces for you, in detail.

The audit is built on five dimensions of operational exposure. Each dimension produces a 0-100 score. The five dimensions feed four cross-cutting framework reports, The Four Audit Outputs™, that map to the four-volume Operating Discipline for AI Library™. What follows is the specific deliverable list: every score, every report, every template, every recommended action that lands in your account when you complete the audit.

4.1 · The Five Dimensions Scored

Every audit produces a score, a maturity bracket (Critical / Concerning / Developing / Sound / Mature), and a named gap list across these five dimensions:

1. Tool Inventory

  • Total count of AI tools active in your stack, official, unofficial, vendor-bundled, and personal
  • Per-tool ownership: who is accountable for each tool, or whether the tool has no owner at all
  • Per-tool purpose: what business problem each tool was acquired to solve
  • Per-tool data sensitivity: what categories of company data each tool can access
  • Shadow tool exposure: tools running on personal accounts, free tiers, or browser plugins outside IT visibility
  • Vendor-bundled AI: AI features quietly enabled inside your existing tools (Microsoft Copilot, Salesforce Einstein, Adobe Firefly, HubSpot AI, Notion AI, Slack AI, Google Workspace AI, and forty-plus more)

2. Cost Mapping

  • Total monthly AI spend across the company, consolidated across all departments and all payment methods
  • Duplicate spend identified by name and dollar amount
  • Underutilized seats: tools paid for and not used
  • Hidden cost vectors: API overages, per-seat creep, automatic plan upgrades, expired-trial conversions
  • Consolidation opportunity: estimated dollar savings from consolidating overlapping vendors
  • Vendor leverage assessment: which contracts you can renegotiate now versus which require waiting for renewal

3. Performance Measurement

  • Per-tool outcome tracking: whether each tool is actually moving the metric it was bought to move
  • Adoption rate per tool: percentage of intended users actually using each tool weekly
  • Workflow integration depth: whether AI is bolted on, partially integrated, or fully embedded in the operating workflow
  • ROI defensibility: which tools you can defend to the board with measurable outcomes, and which you cannot
  • The Performance Reality Test™: a structured comparison of what the vendor promised against what your team is actually getting

4. Risk Exposure

  • Data leakage exposure: which tools have access to regulated data (PHI, PII, financial records, customer data, IP) and whether that access is logged
  • Vendor dependency risk: which vendors you could not replace within 90 days without operational disruption
  • Regulatory exposure mapped to your specific frameworks: NIST AI RMF, ISO 42001, EU AI Act, Colorado AI Act, NYC Local Law 144, SR 11-7, SOC 2, HIPAA, FERPA, state AI laws where applicable
  • Decision accountability gaps: AI-influenced decisions with no named human accountable
  • Incident readiness: whether your incident response plan covers AI-specific failure modes (hallucination, prompt injection, training data leakage, model drift, vendor outage, biased output)
  • Contract risk: AI-related indemnification, liability caps, data-use clauses, and termination rights across your vendor portfolio

5. Governance Gaps

  • Policy presence: whether a Standing AI Adoption Policy™ exists and whether it has been ratified
  • Board awareness: whether the board has been briefed on AI exposure and on what cadence
  • Operating cadence: whether an AI Operating Calendar™ exists with named owners and recurring review milestones
  • Decision authority: who can approve a new AI tool, at what spend thresholds, with what review
  • Training and acceptable use: whether employees have been trained, whether acceptable-use rules exist, whether anyone has signed an attestation
  • Audit trail: whether AI-influenced decisions are logged in a way that survives regulatory or legal scrutiny
4.2 · The Four Framework Reports You Receive

Each of the five dimensions feeds into four cross-cutting reports, The Four Audit Outputs™, each tied to a published volume of methodology:

The AI Business Enablement Audit™ Report

Volume I methodology, the five-dimension scorecard
  • Five dimension scores with bracket assignment (Critical / Concerning / Developing / Sound / Mature)
  • A ranked list of the top 10 specific gaps across all five dimensions
  • Estimated dollar exposure for each top-tier gap
  • Recommended sequence for closure with effort-to-impact assessment
  • Industry comparison once enough peer data exists in the platform

The AI Readiness & Performance Assessment™ Report

Volume II methodology, six-module readiness score
  • Six module scores: Workflow, Data, People, Leadership, Performance, Operational Friction
  • Per-module maturity assignment on the Ad hoc → Emerging → Defined → Managed → Optimizing scale
  • The Cumulative Readiness Index, a single number that tells you where your overall AI operating maturity sits
  • A "next bracket" map: what specifically would move each module up one maturity level
  • The Workflow Readiness Review™, workflow-by-workflow assessment of where AI is helping versus where it is creating drag

AI Risk & Governance Review™ Report

Volume III methodology, six-step process
  • Governance maturity scored across six steps: Data Exposure, Decision Accountability, Vendor Risk, Regulatory Crosswalk, Incident Readiness, Board Reporting Cadence
  • Maturity scale assignment: Absent → Reactive → Defined → Integrated → Continuous
  • Regulatory crosswalk: your exposure mapped specifically to NIST AI RMF, ISO 42001, EU AI Act, Colorado AI Act, NYC LL 144, SR 11-7, SOC 2, and sector-specific regimes (HIPAA, FERPA, GLBA, FDA where applicable)
  • Cross-cutting signal flags: any of the six review steps where your score indicates immediate executive attention
  • A specific list of governance artifacts you do not have but should: policies, calendars, attestations, decision logs, board briefing templates

The AI Efficiency & Process Optimization™ Report

Cross-volume methodology, operational efficiency overlay
  • Outcome alignment scoring: which AI investments are aligned to a stated business outcome versus which are operating without a tied outcome
  • Process redesign assessment: where AI has been bolted on versus where workflows have been actually redesigned to take advantage of AI
  • Friction inventory: the specific operational friction points where AI is making work harder, not easier
  • AI theater identification: where AI is generating activity that looks productive but produces no measurable outcome
  • The 90-day operational sequence: the three highest-leverage process changes you can make in the next quarter
4.3 · Plus, Every Report Includes:

These are not extras. They are integral to the deliverable, operationally usable artifacts that turn the diagnostic into action:

  • An Outcome Alignment Map™ for the top three gaps, showing the specific business outcome each gap is blocking and the line between fixing the gap and unlocking the outcome
  • A draft Standing AI Adoption Policy™ customized to your stated decision-making style (consensus-driven, executive-led, board-mediated), ready to ratify or edit
  • A populated AI Integration Checklist™ for whatever's next on your roadmap, adapted from the audit findings to your specific adoption sequence
  • An AI Performance Scorecard™ template you can run against in 90 days to validate whether the recommended actions actually moved the metric
  • An AI Operating Calendar™ outline showing the recurring governance cadence your company should be running: quarterly board briefing, monthly executive review, weekly operating standup
  • A regulatory crosswalk document mapping your specific exposure to each applicable framework, usable as evidence in audits, due diligence, board materials, or regulatory responses
4.4 · Operational Mechanics

The boring details that matter for actually using the platform:

  • Time commitment: roughly 35 minutes for a senior respondent who knows the business. Save-and-resume supported across multiple sessions.
  • Skip logic: the questionnaire adapts to your role and your answers. A CFO sees different questions than a CISO, and answers in one section gate or unlock questions in later sections. You will not be asked things that do not apply.
  • Honesty mechanics: "Don't know" is a valid answer and scores neutrally rather than negatively. The system is built to surface uncertainty, not punish it.
  • Multi-respondent (Tier 2 and above): up to 25 respondents on a single audit depending on company size. Each respondent gets a confidential link. Their individual answers are not visible to other respondents or to leadership, only the aggregated, anonymized findings appear in the report.
  • Evidence attachments (Tier 2 and above): you can attach existing documents (vendor contracts, policies, board materials, system inventories) which SRJ reviews and integrates into the findings.
  • Storage: all reports are stored in your account for re-download for 12 months. PDFs can be exported and shared with your board, your auditors, or your acquirer's due-diligence team.
  • Trademark protection: every framework name in your report is properly attributed. You can cite the methodology by name in board materials and the citations will reference published work.
The methodology authority

Every score traces to a published page. Every recommendation traces to a written framework.

The AI audit is not a black box. Every dimension, every score, every recommended action traces directly to a numbered chapter in The Operating Discipline for AI Library™, SRJ's published four-volume methodology authored by Stephen R. Jordan, drawing on three decades of senior leadership at Citi, Intel, McAfee, and Optiv.

If your report says you score Concerning on governance, you can open the relevant volume and read precisely what Concerning means, what Developing would look like, and what the operational moves are between the two.

This is the difference between an opinion and an audit.

Ten sectors. One operating discipline.

Built for executives accountable for AI outcomes, across every sector where AI has entered the workflow.

SRJ Consulting serves ten sectors. The audit instrument operates the same way in each, because the five dimensions are universal. The contextual mapping (which regulations apply, which AI patterns are emerging in your industry, which risks are sector-specific) adapts automatically based on your responses.

Sector not listed? The framework still applies. The audit scores against universal dimensions (tool inventory, cost, performance, risk, governance) that operate the same way in any industry where AI has entered the workflow.

Specifically, the audit is the right instrument if you are any of the following:

An AI audit from SRJ Consulting is a structured operating diagnostic. It measures, in one thirty-five minute questionnaire, what AI tools are actually running inside the business, what they cost, whether they are producing the value the business is paying for, where they create risk, and whether anyone is actually accountable for any of it. The output is a scored report a leadership team can put in front of a board, an auditor, an acquirer, or an insurance carrier.

This page covers the depth that the headline sections above do not. Below: what the AI audit actually measures, how it differs from a security audit or governance review, when to run it, how to read the reports, and where it fits in your operating routine.

What this page covers

What an AI audit actually measures

An AI audit measures five dimensions of operating reality at the same time. Tool inventory. Cost mapping. Performance and value delivered. Risk and exposure. Governance and accountability. These are not abstract categories. Each one resolves to specific questions, with specific scoring, and specific recommendations in the resulting report.

The reason all five run together is that they are tangled together in practice. A tool that is not on anyone’s inventory has no cost owner, no performance baseline, no risk classification, and no accountable executive. Auditing any one dimension in isolation produces a partial picture that misses the dimensions that actually matter. The audit’s value is in measuring all five at once.

How an AI audit differs from a security audit

A security audit asks whether the systems running AI are configured safely. It asks whether the business running those systems knows what it is doing with them. The two are complementary, not substitutes. A company can pass a security audit on Monday and still be exposed to material AI-related operating risk on Tuesday because no one has measured what is running, what it costs, or what it produces.

SRJ also offers The AI IT Security Audit™ for the security perimeter, which sits inside Pillar II of the practice. The Pillar I AI audit on this page is the operating diagnostic. Most leadership teams need both, in that order, with the operating audit run first because it usually surfaces the issues that drive the security questions.

When to run your first AI audit

The right time to run an AI audit is whenever any of three conditions is true. First, your board has begun to ask the AI exposure question and you do not have a defensible answer ready. Second, you are about to enter a deal, a renewal, or a diligence process where AI posture will be examined. Third, more than twelve months have passed since the last time anyone systematically measured what AI is running in the business.

After the first one, the recommended cadence is annual at minimum, semi-annual for businesses with active AI rollout, and quarterly for businesses where AI touches customer outcomes or regulated workflows. The questionnaire is the same instrument each time, which is the point: the audit becomes a trend line, not a one-time photograph.

Reading the AI audit reports

Each audit produces four PDF reports at the $199 tier, plus the Tier 1 snapshot for free. The Composite Scorecard is the executive overview: one page, five dimension scores, one combined posture rating. The Operating Reality report names what is running and what it actually costs. The Risk Exposure report names where the operating risk is concentrated and how concentrated it is. The Action Plan names the next ten things to do, in order.

Read the Action Plan first. It is sequenced by impact and feasibility, so the first three items are the ones most leadership teams can move on within thirty days without new budget. The Risk Exposure report is the one to take into the next board meeting. The Operating Reality report is the one to share with the CFO.

AI audit versus a full governance review

The AI audit is a measurement instrument. The AI Risk & Governance Review™ is a remediation engagement. The audit tells you what is true today and where the gaps are. The review designs the policies, accountability structures, and decision frameworks that close those gaps over the following ninety to one hundred eighty days.

Most leadership teams that engage SRJ start at Tier 1 or Tier 1 Plus, use the report to align the executive team on the actual exposure, and then commission the governance review only for the dimensions where the audit revealed material weakness. The audit and the review are designed to compose; you do not need to commission the larger engagement to get value from the diagnostic.

Methodology references behind the AI audit

Every score traces to a published page in The Operating Discipline for AI Library™. The scoring rubric for the risk dimension is anchored to the NIST AI Risk Management Framework. The governance dimension scoring is anchored to ISO/IEC 42001. The performance dimension uses the AI Performance Scorecard™ from the published library. The other applications in the suite are listed on the applications page.

The point of citing the methodology is not academic. It is operational. When the report names a finding and a recommendation, that finding traces to a framework, that framework traces to a numbered chapter, and that chapter is publicly available. There is no proprietary black box. The score is defensible because the methodology is published.

Frequently asked questions about the AI audit

Who answers the questionnaire? Typically the COO, CFO, or general counsel, or a designate with operating visibility. It does not require technical fluency. It requires honest answers from someone who can see across the business.

How long does the AI audit take? About thirty-five minutes for the questionnaire. The reports are generated immediately. Most leadership teams spend the next sixty to ninety minutes reading and discussing the output. The full cycle from start to leadership briefing is typically completed inside a single afternoon.

Is the questionnaire data shared? No. The audit is run for the engaging business only. No aggregate benchmarks are derived without explicit written consent. Privacy posture is in the published policy.

Methodology source

Every score traces to a published page.

The AI audit is built directly on The Operating Discipline for AI Library™, Stephen R. Jordan’s four-volume Pillar I methodology. Each scoring dimension, each maturity bracket, and each recommended action traces to a numbered chapter and a written page.

Volume I establishes the five-dimension audit framework. Volume II adds the readiness and performance scoring. Volume III specifies the governance review. Volume IV — The AI Efficiency & Process Optimization™, the closing volume of Pillar I, AI Business Services™ — converts findings into measurable operational savings. Together the four volumes are the operating discipline behind every score the audit produces.

Next steps after your AI audit

The most common next step after the audit is a thirty-minute leadership briefing, where the report is walked through with the executive team and the first three Action Plan items are assigned to named owners with thirty-day deadlines. The second most common next step is a scoped engagement against one dimension that scored materially low, typically governance or risk.

If your report scores green across all five dimensions, the recommended next step is to set the audit on an annual cadence and move on. If it scores yellow on two or more dimensions, the recommended next step is the leadership briefing. If it scores red on any dimension, the recommended next step is a Tier 3 engagement, scoped to the dimension in question, starting immediately.

Find your $670,000.

Or whatever your specific number turns out to be. The Snapshot is live, $399 one-time. The advisory is there if you need it.

Start Your AI Audit — $399 Schedule a 30-Minute Walkthrough
Schedule a Free AI Consultation