How to choose an AI consultancy in the UK: seven questions to ask before you sign

Ask any AI consultancy seven questions before you sign, and ask for the answers in writing. A firm that has delivered AI systems answers each one directly, with names, figures and documents. A firm that has not will generalise, deflect, or promise to cover it later. The seven questions are:
- Which system you have built is running for a client today, and can we speak to that client?
- Is the price fixed once the scope is agreed, and what exactly would change it?
- What will you examine in our data before you recommend any architecture?
- Does any vendor pay you, in any form, when we buy what you recommend?
- Who will do the work, by name, and are they employees or subcontractors?
- Where will our personal data go during the project, and what will you sign to cover it?
- What would make you stop or walk away, and what do we keep if you do?
If you only have time for one list, use that one. The rest of this guide explains why each question matters and what good and weak answers sound like, adds the UK checks that generic buyer guides leave out, and sets out how to match the size of the firm to the size of the job. At the end we answer the seven questions ourselves, so you can hold us to the same standard.
Why choosing an AI consultancy is harder than it looks
The label "AI consultancy" now covers global systems integrators, accountancy and management firms with AI practices, software houses that have added AI services, specialist AI firms, and single practitioners. The label tells you nothing about which of these you are talking to, how many of their people will work on your project, or whether they have taken a system into production before. Demand has pulled supply in quickly: Anthropic reported in June 2026 that more than 40,000 firms had applied to join its Claude Partner Network within three months of launch.
The vendor side has changed too. The model vendors now run partner programmes with certifications, public directories and, in some cases, rewards for firms that bring them new customers. Anthropic's Services Track, for example, measures a partner's practice on one ladder and rewards sending Anthropic new business on a separate track, through referral credit and deal protection. None of that is improper, and a consultancy that is honest about it is no worse for it. But it means the question of who pays your consultant is now a practical one, not a formality, and it belongs in writing before you sign.
The seven questions, and what a good answer sounds like
1. Which system you have built is running for a client today?
A proof of concept in a sandbox shows that a model can do a task. It does not show that the firm can integrate it with your systems, secure it, hand it over and support it once staff depend on it, which is where most of the cost and risk of an AI project sits. You are buying the second capability, so ask for evidence of it.
A good answer names a client, or a sector where the client has not agreed to be named, and describes the system: what it does, what it connects to, which platform it runs on, how long it has been in use, and what changed after launch. It separates production systems from pilots and strategy work rather than blending them, and offers a conversation with the client where the client agrees.
A weak answer is a demonstration, a wall of logos with no description of the work, or an outcome figure with nothing said about what was built. "We cannot share anything because of confidentiality" with no anonymised detail at all is also weak: a firm can describe a system without naming the client.
2. Is the price fixed once the scope is agreed?
A fixed price for a defined deliverable moves scope risk onto the firm, and a firm can only offer it if it has done similar work often enough to estimate it. Open-ended day-rate billing on a project that could have been scoped leaves the risk with you.
A good answer is a fixed fee per phase, each phase ending in a written deliverable, with milestone payments and a stated change mechanism: what counts as a change, how it is priced, and who approves it. Time and materials can be reasonable where an integration surface is genuinely unknown at the outset, but the firm should say why, cap it or set review points, and convert to a fixed price once the unknowns are resolved.
A weak answer is a monthly retainer with a vague mandate before any scoped first phase, or a fixed price with no definition of done.
3. What will you examine in our data before you recommend any architecture?
The quality, accessibility and legal status of your data decides what can be built far more than the choice of model does. A firm that proposes a model, a platform or an architecture diagram before it has looked at your data is either guessing or selling something it already had in mind.
A good answer describes what the firm will look at (completeness, accuracy, accessibility, format, who owns the data and the lawful basis for using it), how long that takes, and what you receive at the end. It makes clear that the architecture follows from the audit rather than preceding it.
A weak answer is a model recommendation in the first meeting, or an assurance that "the data will be fine" before anyone has seen it.
4. Does any vendor pay you when we buy what you recommend?
Referral fees, reseller margins, affiliate commission, marketing funds and partner-programme credits are common across software. They are legitimate when disclosed and they create an incentive when not. Specialisation is not the problem: a firm that specialises in one vendor's tools can still advise honestly, provided it tells you what it is paid and will say when a different product fits your case better.
A good answer is a direct yes or no, in writing, covering referral fees, commission, reseller margin, affiliate income and deployment payments from every vendor the firm recommends, together with an example of a project where it recommended a different vendor from the one it is best known for.
A weak answer is "we are vendor-agnostic" with no answer to the payment question, or an answer that covers one vendor and is silent on the rest.
5. Who will do the work, by name?
The person who runs the sales conversation is often not the person who builds the system. At a large firm the delivery team may be assembled after signature and may sit in another country. At a small firm there may be nobody to cover if a named person is unavailable. Both are manageable if you know about them before you sign.
A good answer gives names, roles and credentials, says whether each person is an employee or a subcontractor and where they are based, and names the one person accountable for delivery. Vendor certifications belong to individuals rather than firms (Anthropic's Claude Certified Architect credential, for example, is earned by a person through an exam), so the useful question is which named people on your project hold which credentials.
A weak answer is "our team" with no names until the statement of work arrives, or credentials quoted at firm level with nobody attached to them.
6. Where will our personal data go, and what will you sign?
You remain the controller for personal data used in an AI project, and UK GDPR sets out what has to be in place. Where the consultancy processes personal data on your behalf, Article 28 requires a written contract with processor terms. Article 35 requires a data protection impact assessment where processing, in particular using new technologies, is likely to result in a high risk to individuals. If data leaves the UK for a country not covered by UK adequacy regulations, a transfer mechanism such as the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses is needed. Our guide to DPIA screening for an AI assistant rollout covers the screening decision in detail.
A good answer raises these points unprompted in discovery, offers processor terms where the firm will handle personal data, provides the technical input to your DPIA while leaving sign-off with your DPO or solicitor, and can say which regions the chosen services process data in.
A weak answer is "the vendor is GDPR compliant, so you are covered". A vendor's compliance does not discharge your duties as controller, and it says nothing about what the consultancy will do with the data in its own hands.
7. What would make you walk away, and what do we keep?
Every engagement has conditions under which continuing would waste the client's money or put people at risk. A firm that has delivered AI work knows its own conditions and can state them before it starts. The second half of the question matters as much: when an engagement ends, early or on time, you need to know what you keep.
A good answer lists specific conditions and says what you retain: reports, documentation, code, and accounts, licences and cloud resources held in your company's name rather than the consultancy's.
A weak answer is "we never walk away from a client", which in practice means the firm will keep billing whatever happens, or vagueness about who owns the accounts and the code.
UK checks to add for regulated and public-sector buyers
Automated decisions about people. The Data (Use and Access) Act 2025 replaced Article 22 of the UK GDPR with new Articles 22A to 22D, and its automated decision-making provisions came fully into force on 5 February 2026. If the system will make significant decisions about individuals without meaningful human involvement, ask how the design provides the required safeguards. Our briefing on what the Act changes for AI and automated decisions sets out the detail.
Financial services. If you are regulated by the FCA, ask how the firm has worked within the Consumer Duty and your firm's senior manager accountabilities, and who will evidence customer outcomes once the system is live. See our guide to FCA Consumer Duty and AI.
Public sector. Most public-sector AI buying runs through Crown Commercial Service frameworks such as G-Cloud and Digital Outcomes and Specialists, with one-off competitions run under the Procurement Act 2023, in force since 24 February 2025. Cyber Essentials is the usual floor for central government suppliers. Our guide to UK public sector AI tenders covers the routes.
If the firm also supplies a product. Where the consultancy will sell or host software as well as advise, run the product through vendor due diligence as a separate exercise, using a checklist such as our AI vendor selection checklist for UK businesses.
Match the firm to the job, not the logo
AI consultancies fall into three broad shapes, and each suits a different job.
- Global integrators and professional services firms with AI practices. They bring bench depth, multi-country delivery and procurement familiarity for programmes that run for years across many business units. That capacity is priced in whether your project needs it or not, and the team you meet in the pitch may not be the team that delivers.
- Mid-size specialist firms. A standing delivery team, usually some sector depth, and room to staff several workstreams at once. Check whether the headcount quoted is for the UK entity or a wider group, and how long the AI practice itself, rather than the parent company, has existed.
- Small specialist firms and independent practitioners. The people in the room are the people who deliver, decisions are quick, and scoped work such as a readiness assessment, a pilot or an assistant rollout is priced accordingly. The risk is continuity, so ask who covers if a named person is unavailable, and whether the firm uses a vetted network for extra capacity.
None of the three is better by default. A multi-country data platform needs a large bench; a fixed-fee readiness assessment does not, and paying for one you will not use is poor value. The same logic applies to specialism. A firm that concentrates on one vendor's tools brings depth in that platform, which is valuable once you have chosen it and a risk if you have not. Our guide to choosing a Claude AI consultancy covers that decision for the Claude platform specifically.
Red flags to walk away from
- A model or platform recommended before anyone has looked at your data.
- Case studies that give outcome figures but do not say what was built, or logos with no work described.
- No written answer on vendor payments, or an answer that covers only one vendor.
- Named people in the pitch and unnamed people in the statement of work.
- A timeline with no milestones, or milestones with no deliverables attached.
- Nothing said about personal data until you raise it.
- Licences, cloud accounts or code repositories to be held in the consultancy's name rather than yours.
- Pressure to sign a retainer before a scoped first phase has been agreed.
How The AI Consultancy answers the seven questions
We publish our answers so that you can check them against what we say on a call. Each one links to the page where the detail is set out.
1. Systems running for clients. Our case studies describe what we built, on which platform and what changed. They include MoverAI, a video survey platform for the removals industry built on Google's Gemini models for Master Removers Group, and AWS infrastructure in the London region for a multi-chain group of dental surgeries. Some of our case studies are production systems and some are pilots or strategy and architecture work; ask us which is closest to your project and we will walk you through it.
2. Fixed price. Yes, by default. Our published fees are a two-week Readiness Sprint from GBP 3,500, Claude Enablement from GBP 4,500, a four-to-eight-week Discovery and Pilot from GBP 15,000, and an eight-to-sixteen-week Build and Embed from GBP 40,000, all ex VAT and invoiced against milestones, typically 30 per cent at kick-off, 40 per cent at mid-point and 30 per cent on delivery. A change of scope is quoted in a change-control note before any out-of-scope work begins, no additional cost is incurred without your written sign-off, and if the scope shrinks the fee comes down by the same process. Build and Embed moves to time and materials only where the integration surface is genuinely uncertain at the outset, and our GBP 950 to GBP 1,500 day rate is used only where the scope is too open-ended for an honest fixed quote; day-rate work is billed monthly in arrears against a written timesheet, and no additional cost is incurred without your written sign-off.
3. The data audit. Our AI readiness assessment includes a data quality audit covering completeness, accuracy, accessibility and format suitability, alongside a review of infrastructure, skills and processes. It ends in a written report with prioritised recommendations, and the report is yours whatever you decide next. We recommend starting there before any build.
4. Vendor payments. No. We take no referral fees, commission, reseller margin, affiliate income or deployment payments from Anthropic, OpenAI or any other vendor we recommend. We are a member of Anthropic's Claude Partner Network, which we joined for access to the Claude Certified Architect certification our clients ask for, and we specialise in Claude, but we recommend other tools where they fit better. The detail, including when we recommend something other than Claude, is on our independence and vendor relationships page.
5. Who does the work. Our core team is named on our About page, with each person's role and credentials. Dee Khabra, Jay Matharu and Dave Jenkins hold the Claude Certified Architect credential. The core team are in-house specialists. A vetted network of Claude Certified Architects, who are subcontractors, joins engagements as scope requires, and a named core consultant stays accountable for the work. We work from Hoxton in London and from Chelmsford in Essex.
6. Personal data. Where personal data is involved we put a data processing agreement in place, draft Article 30 record entries where they are required, and support the DPIA where the use case triggers one. We provide the technical input; the legal sign-off stays with your DPO or solicitor.
7. When we would walk away. We will stop, or decline to continue, if the work stops producing a result you can measure and a change of scope cannot fix that; if the data protection steps that personal data requires, such as a data processing agreement, a DPIA or proper access controls, are refused; or if we are asked to build something that would breach UK GDPR or sector rules or put people at risk. If discovery shows that a non-AI fix or a cheaper tool meets the need, we say so rather than bill for a build. On what you keep: a readiness report is yours whatever you decide next; when we install Claude, the licences sit on your company-owned tenancy and are paid by you to Anthropic; a Private AI Concierge device is yours; and a Build and Embed engagement ends with the documentation, training and operational runbook needed to keep the system running without dependency on us.
Where to start
If you are shortlisting now, send the seven questions to each firm before the first call and compare the written answers side by side. If you are earlier than that, our guides to what AI implementation costs in the UK and to building versus buying AI cover the decisions that usually come first, and a readiness assessment is the lowest-cost way to find out whether a larger engagement is worth commissioning at all.
Sources
- Anthropic, "Anthropic invests $100 million into the Claude Partner Network", 12 March 2026.
- Anthropic, "Introducing the Services Track and Partner Hub of the Claude Partner Network", 3 June 2026.
- UK GDPR, Articles 28 (processors) and 35 (data protection impact assessment).
- Information Commissioner's Office, guidance on data protection impact assessments, on controllers and processors, and on international transfers (International Data Transfer Agreement and UK Addendum).
- Data (Use and Access) Act 2025.
- Procurement Act 2023.
- The AI Consultancy, pricing, AI readiness assessment and independence and vendor relationships pages, as published on 30 September 2026.
This article is general information for UK businesses, not legal or procurement advice. Programme terms, legislation and prices change; confirm the current position before relying on it.
Frequently asked questions
- What should I ask an AI consultancy before hiring them?
- Ask seven questions and ask for the answers in writing: which system you have built is running for a client today, and can we speak to them; is the price fixed once scope is agreed, and what would change it; what will you examine in our data before recommending architecture; does any vendor pay you when we buy what you recommend; who will do the work, by name; where will our personal data go and what will you sign to cover it; and what would make you walk away, and what do we keep if you do. A firm with delivery experience answers each one directly.
- How do I know whether an AI consultancy is independent?
- Ask in writing whether the firm receives referral fees, commission, reseller margin, affiliate income or deployment payments from any vendor it recommends, and ask for an example of a project where it recommended a different vendor from the one it is best known for. Specialising in one vendor's tools is not a conflict in itself; an undisclosed payment for recommending them is.
- Should I choose a large firm or a small AI consultancy?
- Match the firm to the job. Large integrators and professional services firms bring bench depth for multi-country programmes but price that capacity in whether you need it or not. Small specialist firms suit scoped work such as a readiness assessment, a pilot or a rollout, where the people you meet are the people who deliver. With a small firm, ask who covers if a named person is unavailable.
- Is a fixed price realistic for an AI project?
- Yes, for a defined deliverable. Readiness assessments, pilots and most builds can be fixed once the scope is written down. Where an integration surface is genuinely unknown at the start, time and materials can be reasonable, but the firm should explain why, cap it, and convert to a fixed price once the unknowns are resolved.
- What data protection documents should be in place before an AI consultancy starts work?
- If the consultancy will process personal data on your behalf, a contract with processor terms under UK GDPR Article 28. A DPIA screening decision for the use case, and a full DPIA where the processing is likely to be high risk. An Article 30 record entry for any new processing, and a transfer mechanism, such as the International Data Transfer Agreement or the UK Addendum, if data will leave the UK for a destination not covered by UK adequacy regulations. Your DPO or solicitor signs these off; the consultancy should supply the technical input.
Get new briefings by email
The AI Consultancy newsletter delivers briefings and analysis for UK businesses. We use your address only to send it, and you can unsubscribe at any time.