§ CISO Learning Journey · Phase 3 · Tool Evaluation

The Big 4 advisory model, and why a PowerPoint is not a governance program.

Deloitte, PwC, EY, and KPMG do genuinely excellent AI-governance work. The problem isn’t the quality of the deliverable — it’s that a deliverable is a snapshot, and AI governance is a moving target.

By Lindsay Hiebert · Founder · CISSP

If you hand a Big 4 firm your AI-governance problem, you will get back serious work: interviews, a current-state assessment, a gap analysis, a roadmap, and a polished report. For a large, complex enterprise with the budget and a dedicated program office to operationalize it, that can be exactly right. This piece is not a knock on the work. It’s about what happens to that work the day after it’s delivered.

What the engagement actually is

A typical AI-governance advisory engagement runs $40K–$150K over a 6–12 week cycle and ends in a deliverable — frequently a slide deck and a written assessment. Three things follow from that structure, and none is a criticism of the consultants:

  • It is point-in-time. The assessment describes your AI surface and your regulatory exposure as they were during the engagement window.
  • It is a deliverable, not a system. A report tells you what to do; it doesn’t keep itself current or produce the ongoing evidence.
  • It is re-purchased, not refreshed. When the picture changes, you scope another engagement — another six figures, another six to twelve weeks.

Why a snapshot fails at AI governance specifically

AI governance is not a domain where a snapshot ages gracefully. The AI surface changes monthly: an embedded AI feature flips on inside a SaaS tool you already pay for, three new agents get wired to company data, an employee adopts a tool that didn’t exist at kickoff. The regulations move too — the EU AI Act’s obligations phase in on their own calendar, Colorado’s SB 26-189 arrives January 1, 2027, and delegated acts keep shipping. A governance assessment written in Q1 is, through no fault of its authors, a historical document by Q3.

This is the difference between Due Care and Due Diligence. Due Care asks whether you put reasonable safeguards in place — a good engagement demonstrates that on the day it ships. Due Diligence asks whether you are continuously verifying they still work — and a slide deck, by construction, cannot. A PowerPoint is an argument that you were careful once. It is not evidence that you are still governing.

The durable artifact is a program, not a report

What survives an auditor, an underwriter, and a board across time is not the best single assessment — it’s a continuously-maintained program that re-runs as the AI surface and the regulations change, and produces the living artifact chain each time: a regulation-anchored AUP, a documented risk assessment of the AI actually in use this month, an Executive Risk Report and board memo, and a verification URL. The value isn’t the document; it’s that the document is never stale.

For a 50–2,000-employee company, the economics settle it. A six-figure engagement every time the picture moves is not a program — it’s a series of snapshots with gaps between them. A subscription that refreshes the citations, the endpoint registry, and the risk picture every month, and regenerates the artifact on demand, is the program — at a fraction of a single engagement’s cost. Where you genuinely need bespoke human advisory (a novel model-risk question, an M&A diligence), buy it — but buy it on top of a living program, not instead of one.

A great assessment tells you where you stood. A program proves where you stand.

Engagement cost and duration ranges reflect published Big-4 AI-governance advisory pricing; the full cost comparison and its sources live on the SanctumShield home page and at /beyond-sig. The monthly-refresh commitment behind “never stale” is documented on /whats-new.

Free Shadow AI Risk Audit

See what your current stack is missing — in 12 questions.

The SanctumShield free Shadow AI Risk Calculator runs in your browser. No account, no email, no credit card. Twelve questions, instant risk score, three primary findings tailored to what you submit.

CISO Learning Journey: Week 13 of 27 · Phase 3 (Tool Evaluation) · see the full series →

The Big 4 Advisory Model and Why a PowerPoint Is Not a Governance Program — SanctumShield