Ask most consulting firm leaders whether their firm manages risk well, and most will say yes. Ask whether they could prove it to a client tomorrow, and the answers become considerably less clear. This is the gap that separates mature consulting firm compliance processes from the rest.
Most consulting firms take their conflicts and compliance obligations seriously, but there is a gap between the processes they have and the firm they’ve become: what exists was built for a smaller, simpler version of the firm, and the business has outgrown them. Across industries, 6 in 10 organizations agree that risk management must transform to meet today’s environment. Only 14% have fully made that change.
Why the pressure is intensifying
Consulting firms are subject to meaningful regulatory obligations in specific areas: anti-corruption frameworks including the UK Bribery Act and the US FCPA (Foreign Corrupt Practices Act), financial services regulations such as FCA and FINRA where applicable, government procurement ethics rules, and data protection requirements including GDPR.
These regulations don’t provide a comprehensive governance framework for the full scope of how a consulting firm operates. The governance of conflicts of interest, client acceptance integrity, and information barriers rests on the firm’s own systems and culture. When those systems are weak, exposures accumulate quietly. Every new client and hire compounds the compliance debt — the accumulation of commitments made without a system capable of tracking or proving them.
When firms are growing at speed, manual compliance processes demand that the firm addcompliance headcount proportionally, and that model doesn’t survive a doubling of client volume. Agentic solutions are what break that link — absorbing the routine work so the function stops growing with the caseload. But AI also amplifies what it’s built on — connected, structured data and governed processes let a firm move to agentic workflows quickly, while gaps in process, data, or security get automated right along with everything else. That’s the divide. Firms that put the foundation in place now compound the advantage as they scale. Firms that wait will automate later, at a higher cost, and spend the interval catching up to their peers.
For PE-backed firms, this dynamic has a harder edge. Investors expect higher margins and operational transparency, so they don’t accept a compliance function running on email, memory, and individual judgment.
The four stages of risk maturity
Firms don’t move from manual to strategic risk management overnight. They progress through recognizable stages, and knowing which one you’re in is the first step to closing the gap.
Stage 1: defensive compliance
Risk and strategic fit analysis is done inconsistently, with client acceptance and conflict checks running on email, goodwill, and memory. There is no standard form, which means no consistent record, which means no audit trail to reconstruct when a client asks six months later why a decision was made. Sanctions screening happens ad hoc. Engagement letters and contracts are managed individually, with no central repository and no reporting capability. Decisions live in Outlook threads.
Firms here aren’t necessarily small. Some process tens of thousands of intake reviews and conflict checks per year with a handful of staff, no automated triage, and a turnaround commitment that gets harder to meet as volume grows. The system runs on institutional memory, and when that memory walks out the door, or volume outgrows what any team can clear by hand, the exposure becomes acute and process delays frustrate both staff and clients.
Stage 2: coordinated oversight
Risk activities are partially centralized. Some automation exists around intake and conflict searches, but the review layer remains manual. Analysts receive undifferentiated results and must determine relevance themselves. Data quality is uneven across offices and practice areas. The function responds faster than at stage one but remains largely reactive, reviewing what happened rather than anticipating what’s emerging.
Most consulting firms, from boutique advisories to large global practices, sit between stages one and two. They have risk functions, policies, and some tooling, but these don’t connect in ways that deliver portfolio-level insight or real decision support. Intapp Intake, Intapp Conflicts, and Intapp Employee Compliance are designed for exactly this transition, moving core compliance workflows out of manual, disconnected processes into a consistent, auditable system.
Intapp Walls is a critical addition at this stage. When connected to the firm’s conflicts and risk systems, it enforces information barriers dynamically across document management, financial management, and service delivery environments in real time. That programmatic enforcement is what separates firms that have walls from firms that can prove their walls are working. As AI tools are introduced into firm operations, Walls for AI extends that enforcement to agent actions, allowing the firms to securely scale their AI adoption.
Stage 3: integrated risk intelligence
Risk operates across the firm with shared data, common frameworks, and consistent standards. Conflicts, information barriers, and delivery risks are monitored continuously. Risk insight informs strategic decisions before commitments are made. Partners access the information they need to make faster, better decisions without waiting for escalation.
Continuous monitoring of potential risks such as adverse media events, client M&A activity, changes to sanctions lists, new parties in the client’s ownership structure, or unexpected new people charging time on active engagements allows detection before any of these become material issues.
Stage 4: strategic risk enablement
Risk is embedded in the operating model. Leadership uses risk insight as a competitive differentiator, shaping client selection, pricing, staffing, and investment priorities. The compliance function scales to match firm growth without proportional headcount increases, because agentic solutions handle the routine and surface only what genuinely requires expert judgment.
Intapp Celeste is built for this stage. Its built-in playbooks bring structured best practices from across the professional services industry, covering how firms manage risk across intake, conflicts, information governance, and engagement delivery. Those playbooks are then configured to each firm’s specific policies, processes, and decision logic. Because the playbooks are pre-built, individual users don’t have to design compliance processes from scratch each time, which both drives consistency and avoids the token consumption that comes from ad hoc prompting across a large team. Celeste knows your firm’s data, terminology, and relationship patterns. Agents act like experienced colleagues, freeing human experts to focus on the judgment calls for high risk cases. At stage four, compliance posture becomes a competitive advantage: something the firm demonstrates to clients, regulators, and PE investors on demand.
A diagnostic for firm leaders
These questions are meant to prompt honest reflection:
- Can you articulate your firm’s cumulative exposure across client industries, geographies, and delivery models as a portfolio, not just engagement by engagement?
- If a client or a regulator asked to see the audit trail behind a conflict decision made six months ago, how long would it take you to produce it?
- When a significant opportunity surfaces, how long does a defensible risk assessment take, and is that fast enough to win?
- If you reviewed the rationale behind the last 20 client acceptance decisions, would you find a consistent framework or individual judgment calls with limited documentation?
- Do you have the clean, connected data and structured processes that agentic solutions need to be useful? Or would deploying AI today simply automate an inconsistent manual process?
Where the path leads
Advancing risk maturity is about connecting what already exists — people, processes, and data. That connected foundation is what makes faster, defensible decisions possible, and it’s what agentic solutions need to absorb the volume and complexity that manual processes can’t sustain.
We’d like to hear where your firm is on this spectrum and what has moved the needle. Join the conversation.