# AI Governance Consulting RFP and Build-vs-Buy Templates

Deciding whether to hire an AI governance consultant or build in-house, and running the engagement so the program survives the handoff. A build-vs-buy matrix, an RFP template, a scope-of-work with handoff milestones, and reference-check questions focused on what happens after the consultant leaves.

**Who this is for:** The leader weighing external help against internal build for an AI governance program.

Source playbook: https://aigovernance.com/playbook/ai-governance-consulting

---

## Build-vs-buy decision matrix

_Score the decision on capability, urgency, and budget rather than instinct._

### Template

| Factor | Points to building in-house | Points to hiring a consultant |
|---|---|---|
| Internal capability | someone can lead this credibly today | no one with the mix of legal, technical, and risk knowledge |
| Urgency | months of runway before an obligation bites | a deadline in weeks or a live regulator interaction |
| Budget | headcount budget available | project budget easier to get than a hire |
| Scope clarity | you know what program you need | you need help defining the program |
| Longevity need | must be run forever internally | need a jump-start, then internalise |
| **Decision:** | | |
| **If hiring: what stays in-house regardless:** | | |

### Worked example

| Factor | Assessment |
|---|---|
| Internal capability | one strong lead, thin on EU AI Act specifics |
| Urgency | EU high-risk deadline ~15 months; a US state deadline in 6 |
| Budget | project budget available; a senior hire would take 4+ months |
| Scope clarity | program shape is clear; execution capacity is the gap |
| Longevity | must run internally long-term |
| **Decision** | Hire a consultant for a time-boxed build (inventory, classification, EU AI Act gap analysis), with the internal lead owning the program throughout |
| **Stays in-house** | program ownership, board reporting, all decisions and risk acceptance |

### Acceptance criteria

- The decision is scored against the factors, with the reasoning recorded.
- If hiring, the matrix names what stays in-house no matter what (ownership, decisions, board reporting).
- The decision has a review point.

---

## AI governance consulting RFP template

_What to ask for, so proposals are comparable and handoff is built in from the start._

### Template

> Send to 3-4 firms. Weight the handoff criteria heavily.

- **Context:** the company, its AI footprint, and what triggered this
- **Scope of work:** the specific deliverables (not "advise on AI governance")
- **Explicitly out of scope:** decisions, risk acceptance, board representation stay with us
- **Deliverables:** each as an artifact we will own and maintain (templates, register, gap analysis, roadmap)
- **Handoff criteria:** what "done" means; a knowledge-transfer plan; our team demonstrably able to run each deliverable
- **Timeline and milestones**
- **Team:** named individuals and their relevant experience, not just the firm
- **References:** clients 12+ months post-engagement who still run the program
- **Pricing:** fixed-fee by deliverable preferred
- **Conflicts:** disclose any AI tools, audit, or assurance services the firm would later sell us

### Worked example

**Scope of work excerpt:**
1. AI system inventory: run discovery, deliver a populated register and the method doc; our team completes the last 20% with you.
2. Risk classification: deliver the method and worksheet; classify all systems jointly.
3. EU AI Act gap analysis for the 3 High-tier systems: deliver the gap analysis and a dated remediation roadmap.
4. Policy set: deliver drafts of the 6 priority policies; we own final approval.
**Handoff:** by the end, our lead can independently run classification and update the roadmap, demonstrated in a working session. All artifacts in our systems, in editable form.

### Acceptance criteria

- Deliverables are concrete artifacts the company will own, not advice.
- Handoff criteria and a knowledge-transfer plan are part of the scope, not an afterthought.
- The RFP asks for conflicts (downstream tool or assurance sales) to be disclosed.

---

## Engagement scope-of-work with handoff milestones

_The engagement broken into milestones, each with a deliverable and a handoff test._

### Template

| Milestone | Deliverable (we own) | Handoff test (our team can...) | Due | Payment |
|---|---|---|---|---|
| <milestone> | | | YYYY-MM-DD | % |

### Worked example

| Milestone | Deliverable | Handoff test | Due | Payment |
|---|---|---|---|---|
| M1 Inventory | populated register + method doc | run a discovery cycle unaided | 2026-10-31 | 25% |
| M2 Classification | method, worksheet, all systems tiered | classify a new system correctly in a session | 2026-11-30 | 25% |
| M3 EU gap analysis | gap analysis + remediation roadmap | update the roadmap after a scope change | 2026-12-20 | 25% |
| M4 Policy drafts + transfer | 6 policy drafts; KT sessions complete | maintain and update each policy | 2027-01-31 | 25% |

### Acceptance criteria

- Every milestone has a deliverable the company owns and a concrete handoff test.
- Payment is tied to milestones, with a meaningful portion at the final transfer.
- The final milestone is knowledge transfer, not a document drop.

---

## Vendor reference-check question set

_Questions for past clients, aimed at whether the program survived after the consultant left._

### Template

> Call references who are 12+ months past the engagement.

- What exactly did they deliver, and do you still use it?
- After they left, could your team run the program without calling them back?
- What did they build that has since fallen into disuse, and why?
- Did they push decisions and risk acceptance to you, or take them on?
- How did the knowledge transfer actually work?
- Did they later try to sell you tools, audits, or ongoing retainer work?
- Anything you would insist on in the contract if you did it again?
- Would you hire them again for a defined-scope build?

### Worked example

**Reference call summary (Firm B, client 14 months post-engagement):**
- Delivered inventory, classification method, EU gap analysis, 5 policies. Still using all of it.
- Team runs it independently; called the firm once, for a paid half-day on a new regulation.
- Nothing has fallen into disuse; the register is maintained.
- Decisions stayed with the client throughout.
- KT was 4 working sessions plus a recorded walkthrough of each artifact.
- No upsell pressure; offered a retainer, took no for an answer.
- Would insist on fixed-fee-by-milestone again. Would rehire.

### Acceptance criteria

- References are 12+ months post-engagement, not current clients.
- Questions focus on post-handoff program survival, not satisfaction during the project.
- The reference is asked directly about downstream sales pressure.

---

## Governance controls this kit produces evidence for

- **MGV-003**: The SOW milestones map to the governance program milestone framework.
- **PRC-001**: The RFP and reference-check set are due diligence on the consulting vendor.
- **PRC-005**: The build-vs-buy matrix is a procurement-stage risk assessment for the engagement.
- **MGV-004**: Keeping assurance and decisions in-house preserves an independent assurance function.
