Skip to content
Get in touch 

What seven UK AI audits kept finding

Seven AI audits, and the same findings kept surfacing: ungoverned personal AI, the ask to search the firm's own documents, and data deciding the route.

Ibrahim Mizi Ibrahim Mizi  · 6 min read
Seven drawn core samples standing in a row, with one seam marked at the same depth in each

OpenKit has now run seven AI audits, for organisations with very little in common. They include a programme management consultancy, a commercial design and build business, a healthcare diagnostics body, an international oil and gas service provider, a London estate agency and a UK-listed lighting manufacturer. The smallest has around twenty staff and the largest is an enterprise division. Seven organisations that different should produce seven different sets of findings, and mostly we kept writing the same ones. This article is the countable version of what repeated.

Someone is already paying for AI before anyone set a rule

In three of the seven audits, AI was already in use before anyone had set a rule for it. At one we counted five to six individual ChatGPT subscriptions bought on company cards and used on customer and financial data, with nothing managing them centrally. At a consultancy, the firm’s most advanced AI practice was running on personal paid accounts, while colleagues who wanted to adopt were holding back because no sanctioned route existed. At a design and build business we documented six separate instances of shadow AI across four interview sessions.

This is a commercial finding as much as a governance one. The subscriptions people have already bought are the first saving an audit identifies, and consolidating them onto a managed tier puts the spend where finance can see it. The data going into those personal accounts was rarely data anyone had agreed could leave the building.

People ask to search their own documents before anyone suggests it

We walk into every audit expecting to hear about content generation. What we hear about first, in the same three engagements, is retrieval. At the consultancy, five of the ten people we interviewed raised the same request unprompted: let me ask a question in plain English and have it answered from our own documents. At the design and build business the request surfaced in every interview session. At the third, it showed up as a workaround everyone had normalised, with people downloading files and emailing reworked versions around.

The request came up often enough that we built a product for it. Marella answers questions across a firm’s own approved documents and keeps the source passage attached, so whoever checks the answer can open what it came from.

That inverts the usual buying order for anyone planning an AI programme. Most of what gets sold is generation, and what staff ask for is search across documents the firm already has, which is a data problem before it is an AI problem.

Where the data lives decides the recommendation

In at least four of the seven audits, data sovereignty or data readiness shaped the core recommendation. EMQN, a healthcare diagnostics body handling assessment data across borders, needed sovereign EU hosting, and we analysed seven European hosting providers before recommending an architecture. Thorlux required UK-region processing for its building occupancy data. An international oil and gas service provider went fully on premises, because pipeline integrity data could not leave its own infrastructure. And at the consultancy, the honest recommendation was that a document migration had to come before any AI at all, since the firm’s knowledge sat on an inconsistently filed server AI could not reach. One live programme folder alone held 129 gigabytes across about 45,000 files.

Where your data lives, and what state it is in, will decide more of your AI roadmap than any model choice.

Every audit produced a counted number

All seven audits put a figure on what the work costs today, measured from the client’s own operation rather than from an industry benchmark. Stow Brothers’ admin came to 172 hours a month, of which around 50 were reclaimable in the first pilot. Thorlux’s proof of concept validated roughly 6.5 million occupancy records against the live dashboard and benchmarked seven language models for the reporting job. At EMQN the tested marking accuracy came out at 93 to 96 percent per criterion, with more than 200 assessor hours a year projected back. At House of Hackney, 20 hours a week of finance reconciliation is now automated.

The anonymous engagements counted just as concretely. One firm was sending 41 sales invoices a month as 41 individually written emails. In a live session, an analysis one interviewee put at three hours by hand came back in about five minutes. At another firm, a contract extraction that takes six hours was demonstrated in twenty to thirty minutes including verification.

The report says no as well as yes

In at least two of the seven audits, the deliverable included a written list of workflows where we advised against using AI, one of those lists eight items long. Both lists were specific, tied to accountability or to data that should not move, rather than a general caution. And in at least two of the seven, the recommendation was gated behind a pilot with an explicit go or no-go decision before anything scaled, including a two-stage pilot inside the oil and gas engagement.

A document that only says yes is a brochure.

What this means if you are weighing an audit

The pattern across seven engagements is that the valuable findings were rarely the ones anyone predicted. Clients came in expecting a conversation about tools, and got a counted case built from their own invoices and interview transcripts, with a shorter list of things worth doing first than they had imagined. If you want to see how we get to those findings, what an AI audit actually looks like walks through the method, and the AI Audit and Transformation page lays out the engagement that carries an audit through to the first working rollout. If you want a reading on where you stand before you talk to anyone, the free AI readiness check gives you a score out of 100 and suggested next steps.

Ibrahim Mizi

Ibrahim Mizi

Co-founder & CEO · Full-Stack AI Engineer · OpenKit

Co-founded OpenKit in 2020 and runs the consultancy side end to end. Eight years of full-stack development, then production AI for SMEs and the public sector.

What do AI audits most often find?

Across the seven audits OpenKit has run, the same findings keep repeating: staff already paying for AI on personal accounts before any rule exists, an unprompted ask for plain-English search over the firm's own documents, and the location and condition of the data deciding what gets recommended. Every one of the seven also produced a counted number for what the work costs today, measured from the client's own operation, and some produced a written list of workflows where we advised against AI.

How long does an AI audit take?

A standard OpenKit audit completes within four weeks. Across the seven engagements behind this post the range was two to eight weeks, because scope varies: a two-week workflow mapping for an estate agency sits at one end and an eight-week audit inside an enterprise engineering workflow at the other.

Do AI audits ever recommend against using AI?

Yes, in writing. In at least two of the seven audits the deliverable included an explicit list of workflows where we advised not to use AI, one of them eight items long.

Where do the numbers in this article come from?

Every figure attached to a named client is already published in that client's case study in the OpenKit portfolio. The remaining figures come from audit engagements whose clients are anonymised, and each one was verified against the engagement's own records before publication. Nothing here is an industry benchmark or an extrapolation.

Take the question to an audit.

If this raised a question about your own operation, the AI Audit and Transformation is where we answer it. It runs within four weeks, two of audit and interviews, then two writing up the report, the plan and the costings. You leave with a written report your board can read in one sitting alongside a prioritised 12 month roadmap with a cost against each line. Your fee is fixed and agreed before anything starts.

Find your first workflow.

We start with a conversation, audit where AI actually pays back, and leave you with a costed plan for what to build first. We reply within one working day.