Productize the AI governance question your clients keep asking
Every MSP has fielded this question for free, on a discovery call, more than once: is a client ready to roll out Copilot? The advice is good. Giving it away for free every time is not a business model. Here is how to turn that question into a scoped, billable assessment instead.
The AI governance risk your clients don't see, and the opening it creates for you
Copilot does not create new risk out of nothing. It surfaces risk that has been sitting quietly in a client's Microsoft 365 tenant for years. Copilot answers questions using whatever a user already has permission to see, every shared drive, every mailbox, every SharePoint site nobody remembered to lock down properly. Turn it on for a client's team and you have not added a new risk to their business. You have added a very fast, very thorough way of finding every place their access controls were already loose.
That is the uncomfortable part for most of the SMB clients on an MSP's books. Permissions get set once, during onboarding, and almost never get audited again. A person who left a client's finance team two years ago might still technically have read access to a folder they should never have seen in the first place. Copilot will find it, and when it does, the client is going to ask their MSP about it, whether or not that MSP has an answer ready.
The same pattern shows up in a handful of predictable places on nearly every client tenant. Old project folders shared with "everyone in the organisation" because it was faster than working out who actually needed access at the time. Guest accounts from a contractor engagement that finished a year ago and were never revoked. Shared mailboxes with a dozen people able to read everything sent to them, most of whom only ever needed one folder inside it. None of this was a problem when finding the relevant document meant physically opening the right folder. It becomes a problem the moment a tool can search all of it in a second and hand back a confident-sounding answer to whoever asked.
Why "just check your permissions" is not a business
AI governance sounds like a big-business problem, a compliance department and a stack of policy documents, but not for a typical MSP client under 200 people. AI governance simply means a clear answer to three things: who can see what, where the data lives, and whether the business is ready for AI tools touching it. That is genuinely useful advice. It is also advice most MSPs are already giving away for free, one anxious phone call at a time.
The instinct to help is the right one. The problem is scale. Answering "are we ready for this" informally, from memory, on a call that was booked for something else, does not compound. It does not show up as a line item, it does not get scheduled, and it does not get better the tenth time you do it, because there is no structure capturing what you learned the first nine times.
Turning the same advice into a structured, repeatable assessment fixes all three. It becomes a scoped engagement instead of a favour. It produces a document the client can act on, not a verbal reassurance they will half-remember by Friday. And every assessment run makes the next one faster, because the questions and the scoring logic are doing the thinking a senior engineer used to do from scratch every time. This is the same pattern behind turning any advisory expertise into a client-facing tool, covered in full on how to productize advisory expertise into a client tool.
What the AI governance assessment itself should actually check
Whatever you call the offer, a governance assessment worth charging for needs to cover three things properly.
- Access control. Audit who can actually see what across the client's tenant. Stale permissions from people who changed roles or left the business are the single most common gap, and they stay invisible until something like Copilot starts surfacing what they can reach. Build this as a recurring check, not a one-time report, because every new hire, role change and offboarding on the client's side creates the next stale permission.
- Data governance. Map where a client's sensitive data actually lives, which drives, which mailboxes, which shared sites, and whether it is labelled and protected the way it should be. AI tools are only as careful as the permission structure they are running inside of. A folder full of client financials sitting in a general shared drive because nobody moved it after a reorganisation is exactly the kind of thing an assessment should surface.
- A tiered maturity assessment. Not every part of a client's business is ready for the same level of AI access at the same time. A structured assessment that produces a maturity verdict and a recommended pathway gives the client, and you, a defensible answer to "are we ready for this" instead of a guess, and it is the part that turns a checklist into something that reads like an actual deliverable.
What it costs you to keep giving this advice away
The failure mode of not productizing this is rarely dramatic. Nobody notices a breach alert or gets a call from a regulator on the day it happens. What actually happens is quieter. A client's staff member asks an AI assistant a completely reasonable work question, and it answers using a document it should never have had permission to see. That document could be a salary list, a client's financial position, or a legal matter that was supposed to stay contained to two people. The AI did exactly what it was built to do. The access control did not, and the MSP who never formalised an answer to "are we ready for this" is the one fielding the call afterwards.
There is a second, quieter cost too. Every hour spent giving this advice informally is an hour that never shows up as revenue, never gets scoped, and never turns into the kind of recurring, defensible offer that makes a client relationship stickier. The advice was good. The business model around it was missing.
What the assessment looks like once productized
We built exactly this for a Melbourne-based Microsoft 365 MSP. It is a 3-tier AI governance assessment (foundational, managed, ready) that produces a maturity verdict and a recommended pathway, run inside a browser so no client data is stored server-side, and every result is reviewed and approved by the MSP's own consultant before it reaches a client. The first client run through it, an accounting firm, came out at the top governance tier, which opened the door to a strategic AI governance engagement, proof that a proper assessment surfaces upside for the MSP as well as risk for the client. See the full build on the Melbourne MSP case study, or what the pattern looks like more broadly on the AI agents for MSPs page.
Where to start this week
Start with the questions you already ask informally. Every MSP has a version of this conversation memorised, the things you actually check when a client asks if they are ready for Copilot. Write that list down in order. That is your questionnaire, and it is most of the work already done.
Then decide what the deliverable looks like: a scored report, a maturity tier, a recommended pathway, something with enough structure that a client can see what they are paying for. You do not need to build the finished tool before you sell the first one, you need the questionnaire and a clear enough picture of the output to scope it properly. See how we build the self-drafting, review-gated side of this on the human in the loop pattern, or get in touch and we will map out what productizing this looks like for your business.