Buyer's guide / AI consulting
Good AI consulting makes the next decision smaller, clearer, and owned.
An AI consultant should turn a broad ambition into a traceable set of decisions: what to stop, what foundations to prepare, which assumption deserves a bounded test, and which delivery step is supported by evidence. The useful output is not a thick strategy deck. It is a decision system another team can inspect and use.
The short answer
Consulting is useful when it changes a real decision, not merely the vocabulary around it.
AI consulting is a bounded professional service that helps an organization frame an investment or operating decision, inspect relevant workflows and evidence, compare AI and non-AI options, test material assumptions, define responsibilities and controls, and leave a reasoned next path. The buyer remains accountable for facts, priorities, authority, risk, procurement, funding, and any decision to build, buy, deploy, or stop.
- Advice versus delivery
- Consulting defines and tests the basis for a decision. Delivery creates or changes an operating system. One engagement can include both, but the proposal should separate advisory evidence from software, data, integration, evaluation, change, and support work.
- Roadmap versus wish list
- A roadmap records dependencies, owners, evidence gates, constraints, unresolved risks, and reasons for order. A wish list ranks ideas without proving that the workflow, data, economics, authority, or operation can support them.
- Independent advice versus sales discovery
- A consultant may also sell implementation or a platform. That does not make the advice unusable, but incentives, assumptions, excluded alternatives, referral relationships, and the buyer's freedom to use another delivery path should be explicit.
Consulting outputs
Six outputs should carry the reasoning after the consultant leaves.
Names and formats can vary. What matters is that each output has a clear decision purpose, traceable evidence, accountable buyer input, stated uncertainty, and enough detail for independent review or a different delivery team.
Decision brief
01Buyer question: What exact decision must leadership make, who owns it, what options are open, and which evidence would materially change the answer?
- Useful when
- The request begins as a broad AI strategy, transformation, platform, agent, or productivity ambition and different stakeholders are answering different questions.
- Evidence needed
- Business goals, current measures, sponsor and operating owners, affected people, policy and regulatory context, constraints, existing commitments, candidate options, fixed dates, and known reasons to stop.
- Consulting work
- Separate goals, targets, hypotheses, constraints, preferences, facts, unknowns, decisions, and actions. Define the unit of analysis and the minimum evidence required before commitment increases.
- Buyer authority
- The buyer confirms the legitimate purpose, decision owner, business priority, non-negotiable constraints, affected stakeholders, acceptable uncertainty, funding authority, and who may reject the work.
- Useful output
- A concise decision statement, audience, options, assumptions, boundaries, evidence inventory, open questions, decision rights, decision date, success and stop conditions, and the next investigation required.
- Warning sign
- The consultant treats a desired technology as a settled problem definition, converts a target into an outcome claim, avoids naming the decision maker, or produces recommendations that cannot be disproved.
- Handoff test
- An internal owner can update the brief when facts change, explain why an option was accepted or rejected, and use it to govern later procurement and delivery without the consultant present.
Workflow opportunity portfolio
02Buyer question: Which real workflows deserve further attention, where could model inference add distinct value, and where are process change, integration, or ordinary software better options?
- Useful when
- The organization has many ideas, no common comparison method, and pressure to prioritize by novelty or executive enthusiasm rather than operating evidence.
- Evidence needed
- Representative workflows, users, triggers, inputs, outputs, systems, source records, decisions, handoffs, waits, effort, errors, exceptions, workarounds, volumes, outcome measures, and current initiatives.
- Consulting work
- Observe ordinary and difficult cases, define the present flow, identify the decision or bottleneck, compare change mechanisms, and record prerequisites, dependencies, affected people, failure consequences, owners, and evidence gaps for each candidate.
- Buyer authority
- Process owners and operators establish how work actually happens. Leaders decide which outcomes matter, which disruption is acceptable, and which candidates should stop regardless of technical possibility.
- Useful output
- A bounded candidate set with workflow maps, problem statements, non-AI alternatives, possible model contribution, baseline measures, prerequisites, authority, risk questions, uncertainty, and a justified stop, prepare, test, or proceed state.
- Warning sign
- Ideas are generated from job titles or generic lists, interviews replace observation, task speed is mistaken for workflow value, high-consequence exceptions disappear, and every candidate is kept alive to make the roadmap look ambitious.
- Handoff test
- The organization owns an editable portfolio whose entries can be rejected, merged, revised, or reprioritized as evidence changes, rather than a proprietary score with no visible reasoning.
Readiness and feasibility dossier
03Buyer question: Can a candidate be evaluated and operated with the available data, systems, people, permissions, controls, and change capacity, and which unknown matters most?
- Useful when
- A workflow appears valuable but the decision depends on data access or quality, integration, model behavior, review capacity, security, privacy, architecture, or operational ownership.
- Evidence needed
- Authoritative records, provenance, rights, data samples, schemas, interfaces, identity and access, current architecture, model or product options, users, review roles, failure costs, constraints, and operating environments.
- Consulting work
- Inspect evidence at the depth needed for the decision, profile representative data, trace interfaces and permissions, compare a simple baseline, identify risks and dependencies, and run a bounded disposable test only where a critical assumption cannot be answered otherwise.
- Buyer authority
- The buyer authorizes access, defines data and task meaning, appoints qualified reviewers, approves testing boundaries, decides whether evidence is representative, owns legal and risk judgments, and accepts or rejects remaining uncertainty.
- Useful output
- A versioned readiness record covering data, systems, identity, model task, evaluation, human review, security, privacy, accessibility, operations, cost drivers, dependencies, unknowns, and the exact evidence needed for the next gate.
- Warning sign
- A prototype is presented as production feasibility, sample data hides important variation, vendor benchmarks replace local evaluation, access is broader than necessary, or a binary readiness score conceals separate blockers.
- Handoff test
- Owners can trace every conclusion to evidence, reproduce any bounded test, distinguish missing evidence from a failed assumption, and give the dossier to procurement, delivery, security, or another consultant.
Governance and assurance plan
04Buyer question: Which roles, controls, evaluation, records, review, incident paths, and change triggers are proportionate to the intended use and its consequences?
- Useful when
- The candidate uses sensitive data, affects people, reaches consequential decisions or production actions, depends on outside providers, or will change after release.
- Evidence needed
- Intended and excluded uses, affected people, applicable obligations, organizational policies, decision rights, risk criteria, data flows, suppliers, system design, threats, evaluation needs, operating roles, incidents, and redress paths.
- Consulting work
- Map applicable responsibilities, risks, and evidence without treating one framework as a complete answer. Define decision authority, documentation, evaluation, review, access, monitoring, incident, contestability, change, supplier, audit, and retirement needs.
- Buyer authority
- Accountable legal, privacy, security, compliance, employment, finance, safety, clinical, product, operations, and leadership roles determine obligations, acceptable risk, approvals, redress, release, and continuing use.
- Useful output
- A responsibility and evidence map tied to the real lifecycle, with owners, criteria, records, open legal or professional questions, supplier duties, assurance methods, acceptance gates, incident routes, review cadence, and retirement triggers.
- Warning sign
- A generic principles deck is called governance, framework citations are presented as compliance, a named human review has no operating design, the consultant implies professional authority it does not have, or no one funds continuing assurance.
- Handoff test
- Governance becomes part of planning, procurement, evaluation, release, operation, change, incident response, and retirement, with buyer-held records and an escalation path that works without the consultant.
Cost and options estimate
05Buyer question: What must be funded to reach the next evidence gate, which assumptions drive the range, and how do AI, non-AI, build, buy, partner, delay, and stop options compare?
- Useful when
- Leaders need an investment boundary but the delivery shape, data work, provider use, evaluation burden, operating cost, and uncertainty are not yet stable enough for a responsible fixed promise.
- Evidence needed
- Technical baseline, work breakdown, scope options, data and integration needs, people and review effort, environments, security and assurance, supplier and usage models, delivery dependencies, support, maintenance, change, contingency, and exit.
- Consulting work
- Estimate transparent work and operating drivers, state ground rules and exclusions, use ranges where evidence is weak, test sensitivity to consequential assumptions, compare alternatives on a consistent basis, and define how actual evidence will update the estimate.
- Buyer authority
- The buyer owns budgets, value assumptions, finance treatment, procurement choices, opportunity cost, risk appetite, contingency, acceptable range, and the decision to approve, stage, defer, or reject investment.
- Useful output
- A scope-linked estimate with technical baseline, work breakdown, assumptions, exclusions, range or confidence treatment, supplier and usage sensitivity, buyer effort, lifecycle costs, risks, alternatives, update method, and next-gate budget.
- Warning sign
- A context-free price is treated as a commitment, expected savings are counted as achieved value, buyer labor and review vanish, provider usage is assumed constant, a wide scope has false precision, or uncertainty is hidden to win approval.
- Handoff test
- Finance, product, engineering, operations, and procurement can update forecast and actual cost against the same scope and assumptions, and can see when a changed model, provider, volume, risk, or requirement invalidates the estimate.
Sequenced roadmap and handover
06Buyer question: Which decisions come next, in what order, with which owners, dependencies, evidence gates, budgets, and conditions to pause, change, or stop?
- Useful when
- The organization has a supported set of preparation and delivery choices and needs a practical sequence that aligns business, data, architecture, risk, procurement, change, and operating ownership.
- Evidence needed
- Decision briefs, opportunity portfolio, feasibility evidence, governance plan, cost and options estimate, organizational capacity, current initiatives, dependencies, owners, dates, procurement path, and constraints.
- Consulting work
- Order work by information value, dependency, reversibility, consequence, operating readiness, and capacity. Define each milestone as an evidence-backed decision rather than a calendar promise, then review the sequence with those who must own it.
- Buyer authority
- The buyer sets priorities, allocates people and funds, approves procurement and delivery, accepts residual risk, resolves conflicts, appoints owners, and decides whether later work still merits commitment.
- Useful output
- A roadmap of stop, prepare, test, and proceed decisions with accountable owners, inputs, deliverables, evidence gates, dependencies, budgets, assumptions, risks, review dates, procurement needs, and transition into delivery or internal ownership.
- Warning sign
- The roadmap is a timeline without decisions, every idea becomes a project, ownership is assigned to job titles that never reviewed it, vendor selection is buried as an assumption, or the consultant alone can interpret the artifacts.
- Handoff test
- The responsible internal team can run the first decision review, update the roadmap, use another provider, and explain scope, evidence, tradeoffs, and stop conditions without a private scoring model or undocumented consultant knowledge.
Engagement scope matrix
Buy the smallest consulting scope that can resolve the real uncertainty.
A proposal may combine several scopes. Separate them anyway so cost, deliverables, participation, authority, evidence, and completion can be evaluated without mistaking orientation for assessment or assessment for delivery.
| Consulting scope | Question it answers | Useful evidence | Buyer must retain | Warning sign |
|---|---|---|---|---|
| Executive orientation | Which concepts, opportunities, responsibilities, and limits do decision makers need to understand? | Shared vocabulary, decision questions, examples with limits, risk context, and next learning needs. | Strategy, policy, priorities, risk, funding, and any decision to pursue an opportunity. | A presentation is sold as a strategy or produces a preselected platform decision. |
| Opportunity assessment | Which workflows deserve stop, prepare, test, or proceed decisions? | Observed workflows, baselines, alternatives, candidate briefs, prerequisites, owners, risks, and evidence gaps. | Process truth, desired outcomes, accepted disruption, priority, and candidate rejection. | Generic use cases or hidden scoring replace real workflow evidence and accountable choice. |
| Feasibility sprint | Does one critical data, model, integration, review, or operating assumption hold? | Bounded investigation, reproducible test, results by relevant case, limits, and next decision. | Access, task meaning, evaluation criteria, risk boundary, reviewers, and acceptance. | A demonstration grows into undeclared production or proves only the cases chosen to succeed. |
| Governance and assurance design | Which responsibilities and evidence are proportionate to the intended use? | Lifecycle roles, risk and evidence map, controls, review, incidents, assurance, change, and retirement. | Applicable duties, professional judgments, risk acceptance, approval, redress, and release. | Framework branding or a policy template is presented as local compliance or effective operation. |
| Procurement and provider diligence | How should options and suppliers be compared against the same requirement? | Outcome-based brief, evaluation criteria, data and supplier questions, evidence access, terms, and exit needs. | Commercial strategy, equal treatment where applicable, legal review, negotiation, award, and risk. | The adviser hides incentives, evaluates its own product, or makes requirements only it can satisfy. |
| Delivery roadmap and transition | What sequence of foundations, tests, procurement, and delivery decisions can the organization support? | Owners, dependencies, evidence gates, estimates, risks, milestones, handoff, and change method. | Priorities, resources, budget, delivery ownership, acceptance, release, and continued use. | Dates substitute for evidence gates or the roadmap is unusable without the original consultant. |
Consulting process
A credible process removes unsupported options as readily as it creates work.
The sequence should respond to the decision, not force every buyer through a branded framework. Each stage produces reviewable evidence and can end in a stop decision when the case no longer holds.
- 01
Frame one decision
Name the buyer, owner, options, workflow or portfolio boundary, current evidence, fixed constraints, affected people, assumptions, and what would justify stopping or expanding the work.
- 02
Observe and measure
Follow representative work, examine source records and systems, establish baselines, identify decision points and exceptions, and separate fact from interpretation and aspiration.
- 03
Compare real options
Evaluate process change, existing capability, integration, deterministic software, AI assistance, packaged products, custom delivery, partnerships, delay, and no change against the same criteria.
- 04
Test the critical unknown
Use focused source review, data profiling, technical investigation, user inquiry, assurance work, or a disposable prototype only where the result can change the decision.
- 05
Decide and transfer
Record stop, prepare, test, or proceed states; owners; evidence; cost and risk assumptions; dependencies; next gates; and editable artifacts another accountable team can use.
Selection criteria
Select for decision quality, evidence discipline, and usable transfer.
Credentials, sector experience, and references can matter when they are real and relevant, but no signal replaces a clear proposed method for the buyer's actual question, evidence, constraints, and retained authority.
- Decision and scope fit
- The consultant can restate the decision, distinguish orientation from assessment and delivery, explain who must participate, show how scope will change with evidence, and define completion without promising that AI is the answer.
- Traceable evidence and challenge
- Claims, assumptions, sources, observations, tests, limitations, disagreements, and stop reasons remain visible. The method welcomes operator review, independent challenge, negative findings, and direct access to the basis of recommendations.
- Delivery and operating realism
- The team can reason across workflow, data, software, integration, identity, model evaluation, people, security, privacy, accessibility, procurement, support, change, cost, recovery, and exit without pretending to hold authority it lacks.
- Independence, ownership, and handoff
- Commercial incentives and provider relationships are disclosed; the buyer owns or can use agreed artifacts; dependencies and licenses are clear; knowledge transfer is planned; and a different provider or internal team can continue the work.
Questions buyers usually ask next
Short answers without a disguised sales estimate.
The correct scope depends on the decision and the evidence already available. A consultant should be able to explain how each unknown changes participation, effort, risk, deliverables, and the next commitment.
- What does an AI consultant actually do?
- Depending on scope, a consultant can frame decisions, observe workflows, establish baselines, compare AI and non-AI options, assess data and system readiness, identify risk and governance needs, investigate technical assumptions, estimate cost drivers, support provider diligence, and create a sequenced roadmap. The proposal should name the outputs and exclude delivery work it does not include.
- How much does AI consulting cost?
- There is no responsible context-free figure. Effort changes with the number and variation of workflows, stakeholder access, evidence quality, data and system investigation, regulated or professional review, technical testing, option depth, procurement support, and handoff. Ask for a scope-linked range or price, assumptions, exclusions, buyer effort, expenses, change rules, and the cost of the next evidence gate.
- How long should an engagement take?
- Duration depends on the decision, scope, access, stakeholder availability, evidence condition, review needs, and whether a bounded test is required. Ask for stage outcomes and decision gates rather than accept a calendar alone. A short engagement can answer a narrow question; a wide transformation roadmap requires broader evidence and ownership.
- What are the strongest warning signs?
- Be cautious when a provider selects the solution before observing work, guarantees return or model performance, relies on generic use cases, hides scoring or incentives, excludes operators and risk owners, treats a prototype as feasibility, cannot name deliverables, or leaves no clear stop, handoff, ownership, or independent continuation path.
- How should we compare proposals?
- Normalize them against the same decision, scope, buyer participation, outputs, evidence access, assumptions, optional tests, cost drivers, timeline basis, conflicts, intellectual-property and license terms, data handling, review, completion, and handoff. Then assess whether the team can challenge the AI premise and leave reasoning that remains usable if another provider delivers the work.
Source basis
Sources behind the control model.
- 01
International Organization for Standardization
ISO 20700:2017 management consultancy servicesThe published public record identifies guidance for managing management-consultancy services. The complete standard is paid material, and the record does not validate a consultant, engagement, deliverable, or result.
- 02
International Organization for Standardization
ISO 21502:2020 project management guidanceThe public record describes high-level project-management guidance across predictive, incremental, iterative, adaptive, and hybrid approaches. The standard is paid and was under systematic review in 2026, so its record is context rather than a complete consulting method.
- 03
U.S. Government Accountability Office
Cost Estimating and Assessment GuideThe 2020 federal guide emphasizes scope, technical baseline, work breakdown, assumptions, data, methods, sensitivity, risk, documentation, validation, and updates with actual costs. Its program context is broader than a consulting quote and supplies no market rate.
- 04
FinOps Foundation
FinOps FrameworkThe live framework treats technology value and cost as an operating collaboration across engineering, finance, business, product, procurement, and other roles. It is flexible and non-prescriptive and does not produce an AI business case or estimate by itself.
- 05
National Institute of Standards and Technology
Artificial Intelligence Risk Management Framework 1.0The 2023 voluntary, non-sector-specific framework organizes AI risk work across Govern, Map, Measure, and Manage. It can structure consulting questions but does not choose an opportunity, certify a consultant, or determine a local risk decision.
- 06
National Institute of Standards and Technology
AI Risk Management Framework program pageThe live program page states that AI RMF 1.0 is being revised in 2026. It is included so the guide does not present the 2023 framework as fixed, mandatory, or sufficient for every sector and jurisdiction.
- 07
National Institute of Standards and Technology
AI RMF PlaybookThe page was updated in June 2026 and says the voluntary Playbook will change after the AI RMF revision. Its suggested actions can inform an engagement, but selecting items is not evidence that a local risk has been managed.
- 08
National Institute of Standards and Technology
Generative AI Profile for the AI RMFThe 2024 cross-sector profile identifies risks that generative AI can create or intensify and suggests lifecycle actions. It is voluntary guidance, not a complete assessment, professional opinion, or proof of acceptable use.
- 09
National Institute of Standards and Technology
SP 800-218A secure development profile for generative AIThe final community profile adds generative-AI practices for model producers, system producers, and acquirers and is used with the base Secure Software Development Framework. It does not establish implementation quality or supplier practice.
- 10
National Institute of Standards and Technology
SP 800-161 Revision 1 supply-chain risk managementThe federal publication addresses cybersecurity risk in acquired products and services across the supply chain. It helps frame provider and dependency diligence, but its broad government context does not prove commercial supplier security.
- 11
National Institute of Standards and Technology
Privacy FrameworkThe voluntary framework supports organizational privacy-risk management and explicitly lacks the force of law. It can organize consulting questions but cannot determine local rights, lawful use, or adequate privacy controls.
- 12
National Institute of Standards and Technology
Cybersecurity Framework 2.0The 2024 framework provides non-prescriptive cybersecurity outcomes for organizations of different sectors and sizes. It can support responsibility mapping but does not prescribe local controls or demonstrate that they operate effectively.
- 13
UK Government Office for Artificial Intelligence
Guidelines for AI procurementThe 2020 guidance covers multidisciplinary planning, data assessment, challenge-led requirements, provider evaluation, lifecycle cost, knowledge transfer, support, and end of life. It targets UK public bodies, is not exhaustive, and requires current commercial and legal judgment.
- 14
UK Department for Science, Innovation and Technology
Introduction to AI assuranceThe 2024 introduction frames assurance as measuring, evaluating, and communicating system trustworthiness through context-appropriate techniques. It is introductory UK guidance and does not certify a system, provider, consultant, or local claim.
- 15
UK Responsible Technology Adoption Unit
Portfolio of AI assurance techniquesThe living portfolio distinguishes impact assessment, evaluation, audit, certification, conformity assessment, and other techniques and says inclusion is not government endorsement. Examples do not establish fitness for a local engagement.
- 16
European Commission Public Buyers Community
Updated EU AI model contractual clausesThe March 2025 resource offers high-risk and light versions plus commentary for public procurement. The clauses need local tailoring and are not a complete agreement for intellectual property, acceptance, payment, delivery, law, or liability.
- 17
European Commission
AI Act regulatory frameworkThe current page summarizes the EU risk-based framework and staged application. Duties depend on jurisdiction, role, system, use, and date, and current amendments or guidance matter. This is context, not legal advice.
- 18
Information Commissioner's Office
AI and data protection risk toolkitThe UK regulator's toolkit considers risks to individual rights and freedoms. Its page says the material is under review after the Data (Use and Access) Act, so it is not a settled, universal, or complete compliance checklist.
- 19
Organisation for Economic Co-operation and Development
Explanatory memorandum on the updated definition of an AI systemThe 2024 memorandum explains the inference-centered definition adopted for the OECD AI Recommendation. It helps keep options precise, while laws, standards, buyers, and providers can use different definitions.
- 20
International Organization for Standardization
ISO/IEC 42001:2023 AI management systemsThe public record describes requirements for an organizational AI management system and continuing improvement. The complete standard is paid, and the record does not establish consultant certification, client conformity, or effective operation.
- 21
International Organization for Standardization
ISO/IEC 23894:2023 AI risk management guidanceThe public record describes customizable guidance for integrating AI-specific risk management into organizational activity. The complete standard is paid and cannot decide local risk acceptance or validate a consulting method.
- 22
UK National Cyber Security Centre
Guidelines for secure AI system developmentThe multi-agency 2023 guidance addresses secure design, development, deployment, operation, and maintenance for providers building or using AI systems. Local threats, duties, architecture, and control evidence still require assessment.
- 23
World Wide Web Consortium
Web Content Accessibility Guidelines 2.2The Recommendation supplies testable accessibility criteria for web content. Product states, documents, tools, and research interactions still need appropriate evaluation; a citation or isolated check does not establish conformance.
Start with one real workflow
A Systems Audit is the usual starting point. If the opportunity is already clear, we can move directly into a focused build.
Show Us the WorkflowStart with the free automation readiness checklistOBSERVEQUANTIFYDECIDEBUILD
