The deliverable is fuzzy
"AI policy" means different things to different clients — one PDF to some, a full program (discovery, approved-tool list, training, review cadence) to others. Undefined deliverables get expanded after you've already quoted.
MSP guide
A client asks “can you help us with AI policy?” and you have no idea what to charge. This guide walks through why the work is hard to scope, three packaging models that actually hold up, what drives cost, and how to write a statement of work that doesn't drift into free consulting.
Why this is hard
Most MSPs price this badly the first time. There are three reasons, and none of them are about your skill.
"AI policy" means different things to different clients — one PDF to some, a full program (discovery, approved-tool list, training, review cadence) to others. Undefined deliverables get expanded after you've already quoted.
Once you're reviewing AI tools you surface adjacent questions — data classification, vendor contracts, HR concerns, incidents. Each feels like "part of the same conversation," and each is technically a different deliverable.
A client can find a free policy template in five minutes. If your engagement looks like handing over a document, you're competing with free. If it looks like a decision process with an owner and a review date, you're not.
The fix for all three is the same: define the deliverable set before you quote a number, not while you're doing the work.
Packaging
There isn't one right answer. Each model fits a different client relationship and a different stage of your own practice.
A defined assessment-and-rollout engagement with a start and an end date: discovery, policy set, tool decisions, employee rollout, handoff. You quote one number for the whole thing.
Same fixed-fee first project, but you build in a quarterly review from day one — priced separately, ongoing. The project pays for the build; the retainer pays for keeping it current as tools and staff change.
If you already bill a vCIO or security retainer, AI governance becomes a line item inside it — an initial catch-up project, then folded into the recurring scope you already manage.
| Model | Best fit | Upside | Risk |
|---|---|---|---|
| Fixed-fee project | New client, no existing retainer, wants a clear budget number | Easy to sell; client sees exactly what they're paying for | No recurring revenue unless you sell a follow-on separately |
| Project → retainer | Client likely to keep adding AI tools over time | Converts a one-off into recurring revenue with a natural reason | Retainer has to earn its keep — a review that's just a check-in email is a hard renewal |
| Bundled into vCIO/security retainer | Existing retainer clients where AI is a new risk category, not a new relationship | Lowest friction to sell; feels like an extension of trust you already have | Easy to under-scope — "we'll just add it to the retainer" can mean unpaid extra work if you don't size it |
Illustrative comparison only — not pricing data, survey results, or benchmarks. Fit depends on your client base and existing service lines.
Cost drivers
Before you quote anything, get answers to these five questions. They matter far more than client headcount.
One department using ChatGPT is a short conversation. Copilot, a meeting bot, a coding assistant, and department-level tools nobody told IT about is a different job — each tool needs its own use-case, data-type, and risk review.
Sales, HR, finance, and engineering each use AI differently and touch different data. More departments means more stakeholder interviews and more places policy language has to stay consistent.
If the client already knows what's in use, you skip to review and decisions. If nobody knows — the common case — you need a discovery pass first: a survey, a few interviews, maybe expense reports or SSO logs. Scope and price that as its own step.
Healthcare, finance, legal, and similar clients need the language reviewed against their existing obligations. You're not providing that compliance judgment yourself — that's their counsel's job — but coordinating around it adds cycles.
A policy one IT director signs off on is a one-cycle job. One that passes through IT, HR, legal, and an executive committee is multi-cycle, and each round usually means edits, not just approval. Cap review rounds in the SOW, or fixed-fee projects quietly become unprofitable.
None of these drivers is expensive alone. Stack several — many tools, many departments, unknown shadow AI, regulatory exposure, uncapped reviews — and the job gets materially bigger. Size the engagement to which of these are actually true, not to a flat rate card.
Scoping
An open-ended "help us with AI governance" engagement never closes. A first engagement with a named, finite deliverable set does — and that's what makes it sellable at a fixed fee.
A workable first engagement typically follows Discover → Decide → Operate:
A short survey or set of interviews to identify AI tools currently in use across departments, including tools nobody officially approved. Output: a list, not a report.
Score each tool for risk and decide its status. Prefer Conditionally approved for first-pass reviews and pilots — including low-risk tools — rather than jumping straight to standing Approved. Approved ≠ unrestricted, and Low ≠ auto-Approve. Output: a decision register.
Publish the acceptable-use policy and employee guidance, brief managers, and set a first quarterly review date. Output: a live policy and a named owner.
That's the whole first engagement: a start, three phases, and a defined output at the end of each — a tool list, a decision register, and a published policy with an owner and a review date. When all three exist, the project is done.
The quarterly review is what turns this into recurring work without inventing a retainer pitch. You already told the client, in the deliverable itself, that decisions get revisited every quarter as tools and staff change. Selling the next quarter is following through on what you scoped — not a new sales conversation.
Statement of work
Most scope creep on this type of engagement isn't malicious — it's a client reasonably assuming something is included because the SOW didn't say it wasn't. Be explicit.
Margin
The expensive part of this work is not scoping, interviewing, or reviewing — it's the hours a senior person spends drafting policy language, an employee FAQ, and a tool-decision framework from a blank page. That's slow, easy to get subtly wrong, and largely the same starting work for every client, because the underlying structure of an AI acceptable-use policy doesn't vary much from one SMB to the next.
Two engagements with identical scope can have very different margins depending on whether the drafting starts from nothing or from an edited baseline. A template kit doesn't change what you charge for judgment, discovery, or review cycles. It changes how many senior hours go into producing a first draft that didn't need to be reinvented per client.
If you find yourself rewriting the same acceptable-use policy structure for every new client, that's not expertise being applied — it's time being spent on something that should already be solved.
FAQ
Fixed-fee is easier to sell for a first engagement because the client knows the number up front, and it forces you to define the deliverable set before you start — which is the real fix for scope creep. Hourly can work if the client is uncomfortable committing to scope yet, but be clear that hourly without a cap can feel risky to a client who's never bought this kind of engagement before.
Clarify what they mean. Most clients asking for "ongoing AI compliance" actually want a periodic review of tools and decisions, not continuous monitoring — which maps to a quarterly review retainer on top of the initial project, not a new open-ended commitment.
No — and you shouldn't imply you are one. This is operational work: defining who decides what, documenting decisions, and rolling out guidance. Regulated clients still need their own legal and compliance review; scope your engagement to stay clear of giving that advice yourself.
Be upfront that a template kit is the drafting layer, not the engagement. The client pays for discovery on their environment, decisions on their tools, stakeholder alignment, and an owner who keeps it current — not for a document.
Where a template kit fits
Everything above still has to happen: discovery, tool decisions, stakeholder alignment, and a scoped SOW that keeps the engagement from sprawling. A kit doesn't replace that judgment. What it removes is the blank-page drafting time — the acceptable-use policy, the tool-decision structure, the employee FAQ, and the rollout materials that would otherwise eat a senior person's hours before the client-specific work starts.
The AI Guardrails Kit ships an editable policy set, tool playbooks, and trackers, plus — in the MSP / Consultant Pack — a client pitch, discovery agenda, scope language, and a QBR outline built around this same Discover → Decide → Operate structure. See how it's packaged for delivery across client accounts on the for MSPs page.
The kit is available now on the product page. To see the style first, start with the free AI tool checklist, or email hello@railstead.com.
Operational templates only — not legal, compliance, privacy, security, HR, or professional advice. Seller: CurioHausCo LLC.