You bought AI licences. Your people use them. Then the board asks what changed, and nobody has a number. An AI audit answers that question. In four weeks it finds the use cases in your company that pay off, puts a euro figure on each one, and builds one of them as a working prototype on your real systems.
This guide explains what an AI audit is, what happens in the four weeks, what it costs and what you hold in your hands at the end. It is written for the people who decide: the CEO who signs, the CFO who checks the number, and the IT and Legal teams who approve.
Key takeaways
- “AI audit” means three different things. This one is about where AI pays off in your business. It does not certify an AI system, and it does not check your accounts.
- It takes four weeks. It ends with a readout: a scored list of use cases, a euro figure for each, and a working prototype.
- It has a fixed price, from €15,000, set by company size. It is its own contract, and you can stop after it.
What is an AI audit?
Search for “AI audit” and you find three different jobs under one name.

- Auditing an AI system. Someone checks that a model is fair, safe and compliant. This is work for risk teams and certified auditors, and ISACA offers a credential for it.[1] It answers the question “is this AI safe to run?”
- AI inside a financial audit. Audit firms use AI to test transactions and read contracts. This is about how your accounts are checked.
- An audit of where AI pays off. It looks at the work your teams do by hand and asks three questions. Which parts can AI take over? What is each one worth? In what order should you do them?
This guide is about the third meaning. One honest point first: it is not an audit in the accounting sense, and nobody signs an assurance opinion at the end. It is a documented method with named assumptions. The maths is visible, so your CFO can argue with any line of it.
Why do companies need it? McKinsey found that nearly eight in ten companies say they use generative AI, and that just as many report no significant impact on the bottom line.[2] Often the licences are not the problem. The tools stop at the edge of the real work, where security, identity and your actual systems begin. An AI audit starts on the other side of that line. See how our method works from audit to rollout.
What happens in the four weeks
The audit runs twenty working days, from kickoff to the readout. The readout date is set at the start.

Week 1: kickoff and access
We agree the scope and name one person in your team who owns system access. We usually start with go-to-market: sales, marketing and customer success. The access request goes out on day one. The first talks with your leaders start in the same week.
Week 2: discovery
We sit with your leaders and with the teams that do the work. What do they do by hand, step by step? A head of renewals exports a list every Monday and pastes it into three systems. A sales leader builds a customer deck from scratch for every deal. We write it down in their words. At the end of week two we rank the first list and choose which use case becomes the prototype.
Week 3: scoring and the prototype
Every use case is scored on seven impact factors and seven difficulty factors. Each score has an owner in your team, so the ranking is yours, not ours. Each use case gets a euro figure, with the arithmetic and the assumptions visible. At the same time we build the prototype on your real systems, with read-only data.
Week 4: the readout
The prototype is finished. Your sponsor sees the numbers two days before the readout, so there are no surprises in the room. At the end of week four we present to your leadership team, and you decide what happens next.
One honest limit: access is the part that does not get faster. Security reviews in large companies often take longer than a week. That is why the request goes out on day one. If access arrives late, we build the prototype by another route, so the readout can keep its date.
What you get: six deliverables
At the readout you have six things in your hands.
- Discovery notes. What each team does by hand, step by step, in their own words.
- A scored list of use cases. Every use case placed on impact and difficulty. Quick wins first.
- A working prototype. It runs on your real systems. You see it working before you decide anything.
- An ROI model. A euro figure for every use case, with the maths visible. Your CFO can check every line.
- A roadmap. Quick wins first, then the rest, in order.
- A board case. Built on your numbers, including what waiting costs you each month.

The matrix is where the arguments end. High impact and low difficulty goes live first. High impact and high difficulty comes in phase two. The box that people underrate is “skip”: the ideas you can stop discussing, with a reason your team agrees with.
What you do not get is a thick strategy report. One buyer described a consulting study to us in one line: “750 slides, and we used nothing.” The audit is built the other way round: fewer pages, and one thing that works.
What does an AI audit cost?
Our four-week AI audit has a fixed price, from €15,000. The price is set by one thing: the size of your company, measured by annual recurring revenue. It is never billed by the hour.
A larger company has more teams and more people in each role, so there are more discovery talks. The calendar stays the same: four weeks.
What is fixed, whatever the size: the price, the scope, four weeks, and us in the room for the readout.
The audit is its own signature and its own invoice. If the readout does not convince you, that is where it ends, and you owe nothing further. The rollout is a separate decision that you make with the numbers in your hand.
We do not guarantee a result, because half of the result is what your organisation does with it, and we do not control that half. We also do not publish an ROI multiple. After the audit you have your own figure, computed from your own numbers.
If you compare offers, ask every provider three questions. Is the price fixed? Do you build something that works on our systems? Can we stop after the audit?
What it looks like in practice
A recent example: a European software company above €100 million ARR. The audit ran end to end, with eleven discovery sessions and thirty-six opportunities scored. That audit took six weeks; today it runs in four. Then the work went live: the Claude Enterprise rollout, the go-to-market use cases, the rules for data and security, and training for the teams.
After the full rollout, not the audit alone, the value created runs from a conservative floor of €2.07 million a year to about €3.0 million all-in. One of the tools turns a week of work on customer collateral into minutes: a rep asks for on-brand material for a deal, and it is ready. Read the case studies.
One company’s numbers are not a benchmark. Yours will be different, and the audit’s job is to calculate them from your own data.
How to tell a good AI audit from a slide deck
Before PromptPartner I spent more than twenty years in software go-to-market, and helped grow WebPros (cPanel, Plesk, WHMCS) to a €1.5 billion exit to CVC. As an operator, the test I use on any consulting work is simple: does anything work on Monday after the final presentation?
Four checks cover it:
- The maths is visible. Every euro figure shows its inputs and its assumptions.
- Something works at the end. A prototype on your systems, not a mock-up on a slide.
- Your people own the scores. Each score has a named owner in your team.
- You can stop. The audit is a separate contract from anything that follows.
If an offer fails two of these, you are buying a report, not an audit. See what AI agents do once the audit is done.
Frequently asked questions
What is AI auditing?
AI auditing has two common meanings. The first is checking an AI system for risk, fairness and compliance. The second is checking a business for where AI pays off, and putting a euro figure on each use case. This guide covers the second.
How long does an AI audit take?
Ours takes four weeks, from kickoff to the readout. The main thing that can slow it down is access to your systems, so that request goes out on day one.
How much does an AI audit cost?
Our four-week AI audit has a fixed price, from €15,000, set by company size. It is its own contract, and you can stop after it.
Is an AI audit the same as an AI governance audit?
No. A governance audit checks the rules for AI you already run. An AI audit finds the use cases worth running. In our method, the rules for security and data come next, set once with your IT and Legal teams, so every later use case goes live on the same rules. That is how we build it.
What is the best AI audit tool?
No tool does the job alone. A tool can list your software and your licences. It cannot sit with your head of renewals and see the manual steps that nobody wrote down. The talks with your teams are where the value is found. The scoring model then keeps it honest.
Is AI going to replace auditors?
We don’t think so. AI takes over the checking work that nobody should do by hand, and people keep the judgement. We give people superpowers, not replacements.
Next step
If you want to know what an AI audit would find in your company, book a 30-minute call. No pitch. You’ll leave with at least one recommendation you can use, whether or not we ever work together.
Sources
- [1]ISACA, Advanced in AI Audit (AAIA) credential— retrieved 1 October 2026
[2] McKinsey & Company, “Seizing the agentic AI advantage,” June 2025 — the “gen AI paradox”


