A firm can buy AI, but it cannot buy the data foundation AI needs to be useful. That has to be built, engagement by engagement, starting with the same problem every accounting and consulting firm recognizes: engagement content scattered across email, shared drives, personal devices, and a Microsoft 365 environment nobody fully governs.
Gartner predicts that through 2026, organizations will abandon 60% of AI projects unsupported by AI-ready data. Now imagine the daily cost of that gap if workers lose roughly 2.5 hours a day looking for information they already have. Neither point is about the technology failing. Both are about firms pointing AI at content nobody has secured or governed.
A firm can’t put AI to work on content it hasn’t secured, and it can’t secure content that isn’t organized in the first place. Consolidate, then secure, then comply, then activate AI. That order of operations is what this series calls compliant collaboration: the sequence a firm must work through before AI deployment can be trusted with real client engagements.
Compliant collaboration is a four-stage AI governance maturity model for getting professional firms ready for AI: consolidate engagement content, secure access to it, enforce ethical walls, then activate AI within appropriate boundaries. The stages are designed to be worked in order.
Why compliant collaboration is a sequence, not a single project
Firms tend to treat AI governance as a policy question: write the rules, turn on AI, and move on. That approach fails because governance isn’t something you bolt onto content after the fact. Firms have to build it into how they create, store, and access engagement content in the first place, and that only works if it happens in order.
We’ve distilled the patterns we see across client engagements into a four-stage maturity model. It’s a working framework built from what actually gets firms to safe AI deployment. Each stage builds on the one before it, and firms can reach stage three by more than one route. A firm on Microsoft 365 gets to stage three by consolidating content first, and then securing what it has built. A firm that runs content across multiple repositories, with no plan to consolidate them into one environment, can secure and wall off those repositories directly with Intapp Walls instead. Either way, a firm cannot enforce ethical walls over information it hasn’t secured, and it cannot put AI to work on information whose access and boundaries aren’t already under control.
| Stage | Focus | Description |
| One | Consolidate | AI needs grounded information. Disparate sources across email, drives, and devices hurt the journey before it starts. |
| Two | Secure | Ensure only the people working on an engagement can access its information. |
| Three | Comply | Enforce ethical walls consistently across service lines, engagements, and applications. |
| Four | Activate AI | Reuse and exploit information assets from prior and ongoing engagements within appropriate boundaries. |
Not every firm has the same goal
The model works whether or not AI is the reason a firm picks it up. A firm with no active AI program can treat stage one and stage two, consolidate and secure, as the destination. Cleaning up fragmented content and locking down access to it solves a real productivity and risk problem on its own, whatever the firm does or doesn’t do with AI afterward.
A larger firm building toward AI at scale will look at the same two stages differently: as the foundation the rest of the model, and any serious AI deployment, sits on. The work in stage one and stage two doesn’t change depending on which firm is doing it. What changes is what a firm chooses to build on top of it.
The governance gaps firms still need to close
In our experience, firms often already run Microsoft Purview and assume it covers governance. It wasn’t built for the engagement lifecycle, and the gap between what Purview does and what a regulated engagement actually needs shows up quickly once a firm goes looking for it.
AI governance itself isn’t a policy a firm signs off once and files away — it’s an operational condition that has to hold every time a new engagement opens, a new person joins it, or someone’s access needs to change, which is often where AI projects stall once the pilot ends and production begins.
A firm should expect to be asked a more specific question than whether a policy exists: who accessed what, when, and under whose authorization, and whether that record was captured automatically rather than reconstructed after the fact.
And the information barriers a firm already enforces across email and document systems don’t stop applying just because the system in front of a fee earner is now an AI assistant instead of a folder.
Consolidation is where all of this starts.
Stage one: Consolidate
Consolidation is the least glamorous stage of the model and the one firms are most tempted to skip. The effort of getting control of where your information is stored and secured is also the area that nothing else in the model works without. If engagement content is scattered across inconsistent folder structures, personal OneDrive accounts, and inboxes, there is no single, governed body of information for a firm to secure, apply ethical walls to, or point AI at with any confidence in the result.
The productivity case for consolidation
The cost of fragmentation is measurable well before AI enters the picture. Research from a recent Boomer Consulting webinar found that professionals spend 12 to 15 hours a week hunting for information, reconciling versions, and working across disconnected systems, nearly two billable days per person, every week, lost to friction rather than client work. In our view, fragmented systems, scattered documents, and collaboration tools that don’t talk to each other can do as much damage to an engagement as a gap in talent.
Microsoft 365 gets part of the way there. Firms often already run on it, but on its own it’s a set of building blocks (Teams, SharePoint, Outlook, OneDrive), not a finished engagement environment. Some firms migrated file shares into SharePoint years ago and assumed the fragmentation problem was solved. It often wasn’t: without a consistent permissions model, retention policy, and filing discipline built into how workspaces are created, Microsoft 365 becomes just one more place content can go missing, rather than the fix for fragmentation.
The AI case for consolidation
Consolidation matters even more once AI is in the room. Governed AI generates value from an engagement’s actual context: prior work, firm-specific precedent, decades of institutional knowledge. When that knowledge is scattered across practice management systems, email threads, and shared drives with no consistent structure, AI has nothing coherent to draw from. It produces generic output, and no amount of prompt tuning fixes that when the model has nothing firm-specific to work with.
If a senior partner left the firm tomorrow, would the firm retain the knowledge that partner carried, or would it walk out the door with them?
That risk is becoming a due-diligence question as well as an operational one. Private equity acquirers can look closely at the quality of a target firm’s document environment during diligence. A fragmented knowledge base can slow the firm down day to day, signal key-person dependency, and depress valuation.
What consolidation looks like in practice
For a firm on Microsoft 365, consolidation means every engagement starts from a governed, standard structure rather than whatever the engagement lead happens to set up: a workspace created automatically the day an engagement is won, folders and permissions applied consistently, and correspondence filed to the right place without relying on someone remembering to do it. Content stays inside Microsoft 365 rather than moving to a separate system the firm has to maintain and reconcile. IT isn’t running two governance models in parallel, and nothing falls through the gap between them.
This is the path for firms on Microsoft 365, but it isn’t the only one. A firm running content across multiple repositories, with no intention of consolidating them into one environment, can still reach stage three: Intapp Walls secures and enforces ethical-wall boundaries directly across those repositories, without requiring the content to move first.
That single change, a structure instead of ad hoc folders and inboxes, is what the next three stages of the model build on. Security controls, ethical walls, and activated AI all depend on there being one governed body of information to apply them to, rather than dozens of inconsistent ones.
This is not a knowledge-management initiative that depends on people changing habits and sustaining new discipline over time. Firms often have already tried something like that and watched it decay. Consolidation here is built into how a workspace gets created in the first place, so filing correctly is the default, not an ask.
Structure isn’t the same as security
Stage one gets a firm to a single, governed structure, or a securable one. Getting the structure right doesn’t answer who can get into it. Stage two asks a harder question: whether access reflects who is meant to be in an engagement right now, or still traces back to a distribution list someone was added to two years ago and never removed from. In our experience, firms often don’t find out the answer until an audit or a regulator asks, at which point it’s a live incident rather than a housekeeping task. For a firm whose ambitions stop at getting organized, stage two can be a finish line. For a firm building toward stage three and stage four, it’s the access layer everything else has to trust.