Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Thought leadership & research. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

Key Findings

IBM and OpenAI's enterprise partnership gives consulting firms a route to advise regulated clients on governed AI deployment.

IBM and OpenAI, A Secure AI Path for Consultants
Insight ai

IBM and OpenAI, A Secure AI Path for Consultants

Sam McKay

IBM and OpenAI create a different conversation

The reported IBM and OpenAI enterprise partnership matters to consulting and advisory firms for a practical reason.

Your regulated-industry clients don’t just want access to a capable AI model. They want to know where data goes, who can access it, how prompts and outputs are governed, what support looks like when something fails, and who is accountable for the deployment.

Direct API access can be the right route for a product company with a mature engineering, security, and legal function. For many banks, insurers, health businesses, government-adjacent organisations, and large industrial firms, it often isn’t enough on its own. The technology may be capable, but the operating model around it isn’t ready.

That is where IBM’s enterprise delivery footprint and OpenAI’s models create an implementation path worth evaluating. It gives advisory firms a more grounded option when a client says, “We want AI, but our security team won’t approve an ungoverned experiment.”

The point isn’t to recommend one vendor before the discovery work is done. It is to recognise that enterprise AI decisions are shifting away from a simple model comparison. Clients need help assessing architecture, controls, data boundaries, workflow design, vendor support, and the commercial case.

For a consulting firm between $1 million and $25 million in annual revenue, this creates two opportunities:

  1. Advise clients on a credible path to secure AI deployment.
  2. Build your own internal agents using the same disciplined approach you recommend.

The second point matters more than many partners realise. If your firm is still recreating proposals, research, and project knowledge manually, you’re paying a hidden tax before you ever advise a client on AI.

Across consulting firms of this size, we usually see $80,000 to $300,000 a year in avoidable leakage. It shows up as senior delivery time spent finding old slides, repeated secondary research, late-stage proposal rewrites, and knowledge that disappears into folders after a project closes.

Why regulated clients need more than an API key

An API is a technical connection. It is not an enterprise deployment plan.

A direct model API can be useful for prototyping. A developer can send a prompt, receive a response, and connect that response to a workflow in a few days. That speed is attractive. It can also conceal the questions that come later when the pilot needs to move into production.

A regulated client will usually ask questions like these:

  • What data is permitted to enter the system?
  • Is client information separated from other data?
  • How is access controlled across teams, roles, and regions?
  • Are prompts, outputs, and decisions logged?
  • Can the organisation retain records for audit purposes?
  • What is the escalation route if a model response is inaccurate or harmful?
  • Which workflows require a human approval step?
  • Who owns the vendor relationship and support process?
  • How will the model, retrieval layer, and workflow be tested after changes?

These aren’t reasons to avoid AI. They are the work required to make AI useful at scale.

The IBM and OpenAI partnership should be treated as a potential answer to part of this problem, particularly for clients that value enterprise integration, security controls, implementation support, and a known operating partner. Your job as an adviser is to test the fit against the client’s existing stack and risk posture.

That means asking harder questions than, “Which model is best?”

Ask where the client needs the agent to work. Ask what information the agent can retrieve. Ask what decisions it can prepare versus make. Ask where a person must remain in control. Ask what evidence the client needs to show its risk committee, regulator, board, or external auditor.

This is the kind of work that sits naturally inside Omni Advisory. The technology choice follows the operating design, not the other way around.

The consulting work clients will actually pay for

There is a temptation to frame AI advisory as strategy workshops and a future-state roadmap. Some clients need that. Most also need a team that can turn vague concerns into a working process.

A strong secure-AI engagement usually has five practical stages.

1. Pick a workflow that has value and boundaries

Start with work that is frequent, expensive, document-heavy, and easy to review. Examples include:

  • Reviewing policy documents against a control framework
  • Preparing first drafts of client due diligence responses
  • Creating research briefs for investment or strategy teams
  • Classifying and routing customer correspondence
  • Summarising technical incident records for operations teams
  • Drafting compliance evidence packs for human approval

Avoid starting with a workflow where an AI output creates an irreversible decision. If an agent recommends a credit outcome, clinical action, legal conclusion, or payment instruction, the controls need to be much stronger.

The first use case should have a clear owner, a defined input, a useful output, and a person who can validate the result.

2. Map the data and risk path

This is where many AI projects slow down. A team can build a demo before it has identified the documents, systems, personal data, confidential information, retention rules, and permissions involved.

Your client needs a data map that answers:

  • Which system is the source of truth?
  • Is the information structured, unstructured, or both?
  • Is retrieval restricted by user permission?
  • Is data minimised before it reaches the model?
  • What information cannot be included in prompts?
  • What must be retained as an audit record?
  • What is the process for correcting bad source material?

A good consulting team doesn’t try to answer these from memory. It creates a repeatable intake process that brings security, legal, data, operations, and the workflow owner into the room early.

3. Select an enterprise deployment route

This is where IBM’s relationship with OpenAI becomes relevant. For a client already invested in IBM services, infrastructure, or enterprise governance processes, the partnership may reduce implementation friction. For another client, a different cloud, model provider, or deployment architecture may be a better fit.

Don’t sell the partnership as a blanket security guarantee. Security and compliance remain specific to the environment, configuration, contracts, data flows, and controls the client approves.

Instead, evaluate it against a vendor scorecard:

  • Supported models and their capabilities for the required task
  • Identity and access controls
  • Data residency and contractual terms
  • Logging, monitoring, and audit evidence
  • Integration with the client’s existing data and security tools
  • Support model and escalation commitments
  • Cost at expected usage volumes
  • Portability if the client later changes model providers
  • Testing and change-management requirements

This turns a vendor conversation into a commercial decision the client can defend.

4. Build the agent around a controlled workflow

An enterprise agent is not a chatbot sitting beside a pile of documents. It is a workflow with inputs, instructions, retrieval rules, tools, guardrails, outputs, and review steps.

For example, a policy-review agent might work like this:

  1. A user submits a new policy document through an approved workspace.
  2. The system confirms their role and access permissions.
  3. The agent retrieves only the relevant internal controls and prior approved policies.
  4. It identifies gaps against a defined checklist.
  5. It drafts a findings report with citations to source material.
  6. A compliance analyst reviews, edits, and approves the report.
  7. The final version and decision trail are stored in the client’s records system.

The model is one component. The retrieval process, permissions, approval gates, and recordkeeping are what make the workflow deployable.

5. Measure what changes

Clients need evidence beyond “people like it.” Agree on a baseline before deployment.

For a research agent, measure time to a usable brief, source quality, rework rate, and analyst review time. For a document-review agent, measure turnaround time, exception rate, and the percentage of outputs accepted with minor edits.

That same discipline improves your own firm. It also makes your AI advice more credible because you’ve lived through the practical work of deploying and governing agents.

Your own firm has the same problems

Consulting firms often advise clients on knowledge transformation while running on a fragmented collection of shared drives, proposal folders, PowerPoint archives, CRM notes, and inboxes.

The result is a quiet form of leakage.

A major proposal can consume 20 to 40 hours of senior time. Someone finds an old deck. Another person rewrites the case studies. Pricing is pulled from a spreadsheet that may not be current. The delivery lead spends a Saturday turning generic language into something that sounds like the client.

The win rate may be acceptable. The cost of sale is still brutal.

Then the engagement begins. A team spends days or weeks collecting market reports, competitor information, annual reports, analyst commentary, and previous internal work. Much of that research was completed for another client six months earlier. Nobody can find it, trust it, or adapt it quickly enough.

At project close, valuable insights land in a final deck, meeting recording, or consultant’s local files. The firm has paid to develop the knowledge, but it has not built a reliable way to reuse it.

This is exactly where Omni Ops is designed to help.

What AI agents look like inside a consulting firm

Start with an agent that removes repeatable preparation work while leaving senior judgment where it belongs.

The Proposal Generation Agent pulls approved past proposals, relevant case studies, service descriptions, team credentials, and current pricing guidance into a tailored first draft. It can produce a structured response based on a prospect brief, highlight missing information, and point the proposal lead to the original source material.

It should not set a final price, make legal commitments, or submit a proposal without review. A partner still decides the commercial positioning. The agent removes the blank-page work.

The Research Agent creates a structured starting point for every engagement. It gathers public company and industry information, records sources, produces summaries, flags uncertainty, and prepares a one-page brief for the project team. Consultants can then spend their time forming a point of view rather than repeating basic fact-finding.

The Knowledge Agent is the longer-term asset. It reads and indexes approved decks, documents, project deliverables, and meeting transcripts. A consultant can ask, “What have we previously found about claims operations in mid-market insurers?” and receive an answer linked to the firm’s source material.

That answer needs controls. The agent must respect client confidentiality, engagement permissions, retention rules, and the separation between reusable intellectual property and restricted client content. This is why consulting firms can’t treat knowledge management as a simple file-upload exercise.

A well-built Knowledge Agent uses permissions as part of retrieval. It only retrieves material the user is allowed to see. It cites the documents used. It gives people a way to correct bad metadata or outdated content. It records useful feedback so the system improves over time.

The economics are not abstract

Consider a 15-person advisory firm that pursues 25 substantial opportunities a year. If each proposal uses 28 hours of blended senior and manager time, that is 700 hours annually before accounting for follow-up revisions.

At a blended internal cost that is typical for experienced consulting staff, the proposal process alone can carry a meaningful six-figure annual burden. Recovering even a portion of that time changes margin capacity.

Research has the same effect. If a four-person project team spends 30 hours each rebuilding a market brief that already exists somewhere in the firm, 120 hours disappear before the real engagement work begins.

The goal isn’t to remove consultants from consulting. It is to stop highly paid people doing work that can be prepared, retrieved, structured, and checked faster.

That is how firms begin to close the $80,000 to $300,000 leakage band. They don’t need to automate everything. They need to identify the few workflows where senior time is repeatedly consumed without creating new client value.

If you want a practical way to identify those workflows, see Omni for consulting firms. It is built around the operational reality of advisory businesses, not a generic AI maturity score.

How to assess IBM and OpenAI for a client engagement

When a client asks about the partnership, don’t begin with a vendor presentation. Begin with an assessment brief.

Document the workflow, stakeholders, data classifications, integration requirements, expected volume, review requirements, and risk thresholds. Then identify the available deployment options, including the IBM and OpenAI path where appropriate.

Your recommendation should make clear:

  • Why this workflow is suitable for AI assistance
  • Which tasks remain human-owned
  • What data the system can access
  • What control evidence the client will retain
  • What the pilot must prove before wider deployment
  • What commercial and technical dependencies exist
  • How the client avoids becoming locked into a poorly defined architecture

This is valuable advisory work because it gives the client an implementation decision, not another AI trend report.

It also gives your firm a repeatable offer. Rather than selling broad AI strategy, you can sell a controlled workflow assessment, a pilot design, a governance pack, and an implementation roadmap. Each stage has tangible outputs.

For more examples of how firms are turning operational work into deployable agent workflows, browse the EDNA insights library. The useful ideas are usually grounded in a single process, not a sweeping transformation claim.

Start with an audit, not a software purchase

Before choosing a model provider, platform, or systems integrator, get clear on where your own firm is losing time and what a client-ready delivery method should look like.

An Omni Audit takes 60 minutes and produces three useful outputs: a map of the highest-value manual workflows, a view of the likely leakage tied to them, and a practical recommendation for the first agent to build. There is no deck for the sake of a deck. You leave with a decision framework.

If proposal preparation, repeated research, or lost intellectual property is holding back your margin, Book a 60-min Omni Audit.

You can also use our Deploy Your First Business Agent resource as a working checklist for selecting a workflow, defining inputs and approvals, and setting a first success measure. If you want the printable version to use with your leadership team, access it directly here.

The IBM and OpenAI partnership may be a useful implementation route for regulated clients. It won’t replace the need for sound workflow design, governance, and adoption. Those are the areas where a good consulting firm earns its fee.

Start by applying the same standard to your own operation. The AI audit for consulting firms will show you where to begin, then Book my Omni Audit when you’re ready to turn that map into an agent plan.