A mid-sized IT services consultancy didn't set out to adopt AI. It arrived the way most AI arrives in a business like this: bundled into a Microsoft licensing renewal.
Copilot in Word and Outlook. GitHub Copilot in the delivery team's IDEs. A handful of consultants quietly trialling ChatGPT on the side, unrecorded. None of it was wrong to use. None of it was governed either.
What changed wasn't the technology. It was a client. A financial services client asked, as part of standard vendor due diligence, to see the company's AI governance posture before renewing a contract. There wasn't one to show.
We ran our Executive AI Readiness Review: seven pillars, forty-four questions, each one marked Red, Amber, or Green against where the organisation genuinely stood, not where it hoped to stand.
Six of seven pillars landed Red: Strategy & Leadership Alignment, People, Skills & Culture, Responsible AI & Governance, Financial Readiness & ROI, and Regulatory, Legal & Client Exposure. Only Data & Digital Infrastructure and Process & Automation Value scored Amber. The worst of them wasn't the one you'd expect.
Responsible AI & Governance scored 8 Red answers out of 11, the single weakest pillar in the entire assessment. Underneath that score: no live inventory of every AI tool in use, including the ones adopted without approval. No named owner or documented approval record for AI systems already in production. No process to reconstruct how a specific AI-assisted decision was made, months after the fact. No incident response process for an AI-specific failure, such as AI-suggested code shipped to a client with a vulnerability inside it.
And underneath all of that, a structural problem: governance was split three ways. UK sales, EU consulting, and India delivery each managed their own approval process for AI tools, independently. Nobody sat above all three.
Data governance sits inside the Governance pillar of ESG for a reason. It was always the same control.
GRI 102-15 expects a formal risk management framework. CSDDD Article 4 expects clear accountability for the risks a business creates. Most disclosure regimes expect a named structure that can answer for how decisions get made. Those aren't AI-specific requirements. They're the same governance controls this assessment tests.
And the two are no longer separate systems in practice. The supplier questionnaires feeding Scope 3 disclosures, the HR data behind diversity and safety reporting, the emissions and energy figures behind a carbon target: increasingly, AI tools draft, summarise, or process that data somewhere along the way, often the same Copilot and GitHub Copilot tools this company had never inventoried.
A business that cannot say which AI tool touched a piece of data, who approved it, or how to reconstruct that decision later, cannot fully stand behind the ESG figures that data eventually feeds. The AI governance gap and the ESG governance gap aren't two findings. They're one control failure, showing up in two different assessments, because they were always the same control.
This company sells its AI-enabled delivery capability to regulated clients, financial services clients specifically, who are themselves accountable to regulators for the vendors they use. The moment one of those clients asks how the company governs the AI touching its data, the honest answer was: informally, inconsistently, and without evidence.
Nobody in this story was negligent. Consultants used Copilot because it was already licensed. Engineers used GitHub Copilot because it made them faster. Leadership didn't build a governance function because nobody had asked them to, until a client did.
That's the pattern we see most often. The gap isn't intent. It's evidence. A capability that works isn't the same as a capability that can be demonstrated, documented, and defended under scrutiny, and increasingly, that's exactly what clients, regulators, and insurers are starting to ask for.
If a client asked you today to show, not tell, how you govern the AI already running inside your business, and the ESG data it touches, could you produce it in an afternoon? Or would you be building the answer from scratch, under pressure, with a contract on the line?