Workflow pilot
Run on the next 3-5 live AI policies. 30-45 days. Fixed-fee scope. Configure for your contract types and templates.
"Adopt AI Without Losing Control."
Heads of risk, compliance leads and commercial directors at contractors and FM businesses where AI use is scaling and procurement teams are starting to ask harder questions.
Step 2 of the engagement, alongside whichever workflow pack lands first. The Policy Pack lays the rules; the workflow pack puts them to work.
Every other pack, Bidroom, RAMS, Commercial Control all reference the Policy Pack as their AI-use audit trail. Particularly tight pairing with Contract Obligations Register where AI clauses sit alongside data-handling clauses.
AI use is scaling across the business. Procurement reviews now ask documented questions you can't answer in writing. Twelve-week stalls are starting to bite.
Audit current sanctioned + shadow AI services. Draft the AUP and classification rules against the actual data shape. Sign-off cycle planned with the governance sponsor.
Acceptable Use Policy + R/A/G Data Classification, the rules that let you give procurement a written answer.
Client contracts are starting to contain AI clauses. Supplier codes ask whether your AI use is documented. Disclosure language is being negotiated case-by-case.
Land the procurement disclosure schedule first. Slot AUP and audit-log structure in behind it. Use the schedule as the contract default, not the negotiation start.
Procurement Disclosure Schedule + AUP, designed for procurement acceptance without negotiation.
Technical control layer is yours to own. AUP exists in fragments. Logging is per-tool. Classification rules at the upload boundary are not formally documented.
Stand up the audit-log data model first. Classification rules + upload-boundary controls map onto specific workflow surfaces (Bidroom, RAMS, etc.). AUP follows.
Audit Trail + Immutable Log Structure + R/A/G Classification, the technical control layer made auditable.
AI clauses now sit in client contracts and supplier codes. Liability cap, sub-processing, IP exclusion language and audit rights, currently negotiated each time.
Use the disclosure schedule as the contract template. Sign off the AUP and DPIA against current operating reality. Clauses follow the policy, not the other way round.
Procurement Disclosure Schedule + DPIA Template, written for procurement-questionnaire compatibility.
AI is deployed across live workflows. Operating teams want clarity on what's allowed. Approval gates are inconsistent. Governance reporting is sketchy.
Roll out the AUP with training. Stand up the approval gates against the highest-risk workflow first. Quarterly governance review cadence agreed with the board.
Human Approval Gates + AUP, what's allowed, by whom, on what data, with what evidence.
Most contractors and FM businesses now have AI use somewhere in their operation, bid drafting, RAMS first-passes, variation narratives, customer service triage. Often without a documented acceptable-use policy, without classification rules at the upload boundary, and without an audit trail that procurement can read. The retrofit happens when a client asks a question the business can't answer in writing.
The cost is delay. Procurement reviews stall for twelve weeks because the AI-disclosure schedule doesn't exist. Audit responses are scrambled together from individual memories. Risk decisions get made by whoever was in the room. The Policy Pack lands the rules, the classification, the gates and the log structure, so AI scales with control, not in spite of it.
AI use exists across the operation; no documented AUP; classification rules undefined.
Canonical AUP, R/A/G classification rules, approval gates and DPIA template, procurement-questionnaire compatible.
Reviews stall for twelve weeks because the AI-disclosure schedule doesn't exist.
Schedule + contract clauses ready inside two weeks of policy sign-off; designed for acceptance without negotiation.
AI invocations not logged consistently; audit responses scrambled together from individual memories.
Every call carries a data class, model class, approver and output disposition, queryable per engagement, period and class.
Red-classified data can reach AI services because the upload boundary has no rules.
Three-tier R/A/G with technical controls at the upload boundary; Red blocked by default.
Risk decisions made by whoever was in the room.
Per-tier approval logic with named approvers; evidence row produced; audit-row lands automatically.
Drafts policy text, AUP, classification rules, approval gates, against your operating context
Cross-references procurement requirements (CCS framework, supplier-code templates) so the disclosure schedule lands on first read
Generates the audit-log data model, fields, retention, access controls
Produces the DPIA template tuned for construction-data AI scenarios
Surfaces gaps where current AI use sits outside the proposed policy
Maps the upload-boundary controls to specific workflow surfaces (Bidroom, RAMS, etc.)
Drafts contract schedules, IP, sub-processing, liability cap, for legal review
Doesn't decide your risk appetite, that's the governance sponsor and the board
Doesn't sign off the AUP, legal / compliance owns final approval
Doesn't override existing IT or data-protection policies, slots into them
Doesn't replace legal advice on liability cap or IP exclusion language
Doesn't audit your current AI use without scope agreement first
Doesn't enforce policy at runtime, that's the workflow surface (BuiltAI's or yours)
Doesn't make procurement decisions on which AI services are sanctioned
100% of AI invocations classified + logged
Every call carries a data class, model class, approver and output disposition
Zero Red-Classified Data Reaching Any AI Service
Upload-boundary classification + technical controls block the path
Procurement-Ready Disclosure Schedule per Client
Schedule template + contract clauses ready inside two weeks of policy sign-off
Audit Responses in Days, Not Weeks
Log structure is queryable; evidence is queryable; the answer is already documented
AI Scales with Control Rather Than Despite It
Operating teams know what's allowed; approval gates are visible; governance sponsor has reporting
Reduced Procurement Review Time
From 12-week scramble to 2-week conversation when the schedule is in place
Run on the next 3-5 live AI policies. 30-45 days. Fixed-fee scope. Configure for your contract types and templates.
BuiltAI's team produces AI policies on your behalf. Per-output or day-rate. Useful for capacity overflow.
Ongoing support across the full workflow. Continuous improvement. Monthly retainer.
30 minutes. Your data. No obligation.