Chapter 6: The Buyer and the Engagement
What the buyer is buying
What the buyer purchases is not a working agent. A working agent is easy to show, and getting easier every month, and a demonstration of one proves almost nothing about whether the work it does can be stood behind. What the buyer purchases is defensibility: the ability to produce, when someone with authority asks, a record showing that the work was controlled, attributed, and checked. The demonstration is what gets the meeting. Defensibility is what gets bought. The two are different purchases, and a buyer who confuses them pays for the wrong one, because the first is cheap and abundant and the second is the whole of the work.
The buyer is whoever's name is on the risk
A business does not sign anything, lose a licence, or answer a regulator's letter. A person does. The buyer of agent assurance is whoever's name is on the risk when the work fails. The founder inventing the company as they go, the chief executive, the compliance officer, the company secretary, the key individual whose licence is the thing that lets the firm trade at all.1 Identify that person exactly, because the engagement is addressed to them and to no one else, and the generic stakeholder in an org chart is not the one who lies awake.
The founder is the archetype the earlier chapters kept circling. Someone inventing the business as they go has placed enterprise-grade capability in their own hands before any tradition arrived to tell them what it costs to run it safely. They carry a risk they were never handed the concepts to see, and they carry it personally, because at the size where one person is still the company there is no committee to spread it across. The chief executive of a larger firm carries the same exposure with more insulation and more distance from the actual system. In both cases the assurance is bought by the individual who will be asked to answer for the work, and the first task of the engagement is to find out who that individual is.
The compliance officer of a broker-dealer was assigned to review the firm's electronic communications, and for roughly two years reviewed none of the messages that made up about eighty-five percent of them.2 When the failure surfaced, the sanction did not stop at the firm. The regulator suspended him personally, in every supervisory capacity, and fined him, and the appeals affirmed it up the chain.3 The name on the risk was his, and the consequence found it.
The regulator set out when a compliance officer's personal liability attaches and when it does not. It attaches when the officer engages in wrongdoing, covers it up, crosses a clearly established line, or fails meaningfully to implement a compliance program. It does not attach where the officer, in good faith and after reasonable inquiry, made a judgment that only looks wrong in hindsight.4 That line is the one the accountable buyer wants to stand on the right side of, and standing on the right side of it is a matter of having meaningfully implemented, in good faith, and being able to show it. The evidence that the buyer implemented and inquired is exactly what an assurance practice produces. The person is protected not by the system never failing, which no system promises, but by the record of how they ran it.
The former compliance officer of a money transfer business was pursued personally by two federal agencies for failing to implement an effective anti-money-laundering program. The penalty was a civil assessment of a million dollars and, in a separate settlement, a further fine and a three-year bar from compliance work at money transfer firms.5
It does not always reach the person. Knight Capital's forty-five minutes, the change-control incident of chapter 3, reads here for where the penalty landed: the regulator charged the entity and only the entity, twelve million dollars, and named no individual officer at all.6 When a large bank was found to have left roughly eighty percent of its transaction volume unscreened by an automated monitoring system it had failed to update for a decade, the regulator attributed the failure to the institution's under-resourcing and inadequate training of its own staff. It attached the penalty and the monitorship to the bank rather than to any named compliance officer.7 In both, the name on the risk was the firm's.
So the buyer is whoever's name is on the risk. Where that name falls, on a person or on the institution, is a structural fact about the firm. It is fixed before any failure by how responsibility was assigned, not decided afterward by who happens to be standing nearby. Part of the assurance work is making that assignment deliberate rather than accidental: making sure the person who will be asked to answer is the person who actually decided, and that the record can show the connection between the two. An engagement that leaves the accountable person unidentified has not started.
The demonstration and the product
The clearest public window onto the demonstration-and-product distinction is the vendor security questionnaire, because it is the closest thing to a standardized version of what the buyer must eventually produce. A widely used one asks a cloud provider a long list of yes-or-no questions about its security controls, so that a customer or an auditor can check the provider against a published control matrix.8 It is a useful instrument, and it is explicitly a first-level screen: completing it takes a few hours, and the guidance that accompanies it advises more intensive review beyond it.9 A questionnaire full of "Yes" is a demonstration. What makes any single "Yes" defensible is the record sitting behind it, and the questionnaire itself is candid about the gap.
The published questionnaire for Amazon Web Services is a document AWS completed itself, with its own answers, not an independent assessment of the provider by anyone else.10 On at least one line, the answer to "is cloud data periodically backed up" is "Yes," while the same row records that backup and retention are actually the customer's responsibility, not the provider's.11 Read quickly, the "Yes" looks like an assurance. Read properly, it is a pointer to where the obligation really sits, which is with the reader. And where the provider's own answers are meant to carry weight, the document does not rest on the answers. It points past them, to a formal program of independent internal and external audits whose reports the customer can go and read.12 Even for a vendor of that size, the defensible thing is not the "Yes." It is the independent report the "Yes" refers to.
A capability demonstration shows that the agent can do the thing. Defensibility is the record that lets the accountable person show, to a bank, an insurer, a regulator, or an acquirer, that the thing was done under control. The buyer who mistakes the first for the second has bought entertainment.
At the far end of the same spectrum, the gap between demonstration and substance has been prosecuted. The founder of a shopping-app company was criminally charged with securities and wire fraud. The allegation was that he raised more than forty million dollars on the representation that the app used proprietary AI to complete purchases automatically, when the actual rate of automation was, by the charge, effectively zero.13 This is the market condition the honest firm works inside, where "we use AI" can mean anything from a controlled and monitored system to a person typing the answers a model only appeared to produce. The buyer usually cannot tell those apart from a demonstration, because a demonstration is designed to be indistinguishable. Making the difference legible, so the accountable person can see what they actually have, is a large part of what the engagement is for.
What the buyer feels, read from the record
The intuitive account says buyers are hesitant, holding back from AI until it is safe. The surveys say the opposite. A large executive study on agentic AI describes the pattern as a tidal wave of adoption and a trickle of strategy. The technology is already at thirty-five percent adoption, with another forty-four percent of organizations planning to deploy it. The study locates the adoption as occurring well before the organizations have a strategy in place.14 A survey of more than a thousand senior leaders found that seventy-eight percent say they are implementing AI faster than they can effectively measure its impact, and half admit they lack clear visibility into the skills and roles their organizations will need.15 The buyer is not standing at the edge deciding whether to enter the water. The buyer is already in, deeper than they can measure, and the unease is retrospective. It is about what they cannot yet show.
The value gap runs the same way. A large survey of AI use covered nearly two thousand organizations. Only about five and a half percent could report that AI contributed more than a small fraction of their earnings. It identified the redesign of workflows, not the model, as the single attribute most associated with getting measurable value, and found that only about a fifth of companies using the technology had actually redesigned any workflows.1617 The capability is everywhere and the return is thin and concentrated, and the difference between the firms getting value and the firms not is organizational work the buyer has mostly not done. That gap, felt by a named person as the distance between how fast they have moved and how little they can yet stand behind, is the demand for assurance. It is not a demand the buyer always knows how to phrase, which is why the engagement often begins before the buyer can say what they want.
The engagement shapes
There are five shapes: a way in, the three engagements it resolves into, and the tenure the three end in.
The way in is the undirected engagement, and it is the most common first contact. The buyer says some version of "I want to use AI, but I do not know what I want." That sentence is an accurate description of the condition the surveys documented: someone who has adopted ahead of strategy and knows it. The undirected engagement is a master key. It does not presume the answer. It runs a short, structured assessment of what the firm is already doing, what it is exposed to, and what it is trying to protect. It resolves into one of the three shapes below, depending on what that assessment finds. The skill is in the resolution, not in having a fixed product to sell.
The first shape it resolves into is the readiness assessment: small, fixed in price, and built to produce an artifact rather than a transformation. The method runs in a fixed order: scope what is being assessed, gather what the firm actually runs, record the current state, set it against a target state, and turn the gap between the two into an ordered plan. The assessment records presence, whether a control exists and can be shown, not a subjective grade of how well it is run, because presence is the thing a third party can check. And it states where the firm stands in terms plain enough to be disagreed with, so the next assessment has something to measure against. The output is a defensible current-state picture, what the firm has, what it is missing, and what to do about it, in a form the accountable person can show and act on, with a date on it. The shape is not invented here; its ancestry is the assessment method the security frameworks have documented for years.18192021
The second shape is the governance programme, a staged engagement that moves the buyer from a current-state assessment to standing governance to a first controlled deployment. Assess, govern, pilot. The stages are not padding: each produces the record the next one governs by, and the programme is built to recur, because an assessment run once and filed is a photograph of a firm that no longer exists. The governance programme takes an improvised adoption and gives it a spine that keeps standing after the engagement ends: a place where decisions about tools, data, and deployment are made deliberately and recorded, so the next assessment has something to check against. The staged, recurring shape is old security practice, not an invention of this book.22
The third shape is the hardening engagement, and it connects directly to the previous chapter. The shadow artifact, the improvised system the business already depends on, is that chapter's requirements document, and it is also unsafe. The hardening engagement takes that system and re-founds it on controlled substrate, preserving the workflow the client actually relies on while replacing the improvised parts underneath it with components that can be inspected and stood behind. It does not start from a blank page or a written brief. It starts from the thing that works, and makes it defensible without making it unfamiliar. The controls it installs are the subject of Part III; what belongs here is only the shape of the engagement that installs them.
The last shape is the custodial engagement, and the other three end in it whenever the client keeps operating. Any sign-off attests to the system as it stood on a date. The client's world then moves, a new product, a changed data feed, a regulation, and the attestation decays without anyone acting wrongly. The assurance regimes that watch operating systems all resolve this the same way: they expire the certificate and renew it by re-examination. A public company must appoint its auditor for each financial year.23 A boiler's certificate of operation is valid for twelve months from the date of the inspection, and the statute requires a fresh inspection within thirty days of its expiry.24 When a structure changes engineers, the successor signs and seals the original documents as their own work, so that a named engineer always holds the whole responsibility.25 The certificate that never expires is the anomaly. The custodial engagement is that cadence sold as a shape: a named practitioner of record, change events answered under a stated obligation in the engagement letter, and a re-verification on a cadence whose artifact renews the attestation. The hardening engagement is its natural onboarding, and chapter 10's continuity controls are what keep the tenure survivable. The client is buying a signature that stays current, not a system that was defensible once.
None of these needs to be sold as a demonstration, and part of the discipline is refusing to. The readiness assessment does not open with an impressive agent doing something clever. It opens with a question about who signs, what breaks, and what the firm would have to show if asked tomorrow.
The commercial doctrine
The doctrine that holds the commercial half together is that advisory scope leaves implementation and liability with the client, and that the engagement letter is the control that keeps the line where it belongs. It is the work's central commercial instrument, and the assurance professions treat it as one.
The scope of what a practitioner is responsible for is set by the purpose the engagement was hired to serve. A supreme court, reframing how professional liability is measured, moved away from older distinctions and toward a purpose test. One looks at the risk the practitioner's duty was engaged to guard against, and then at whether the loss the client suffered was the realization of that particular risk.26 A loss that falls outside the purpose the practitioner was engaged for is not the practitioner's to carry, however real it is. A trial court put the same principle more bluntly for a law firm. The contract between adviser and client sets the limits of the representation, and so long as the adviser performs the scoped work with competence and loyalty, nothing more is required.27 The scope is not a disclaimer bolted onto the relationship. It is the definition of the relationship.
Which is why the engagement letter is treated, in the assurance professions, as a live control rather than paperwork. Professional guidance holds that any task performed for a client that is not named in the signed engagement letter is an expansion of the service that requires the contract to be modified first.28 The letter is the boundary, and stepping across it is a decision made on purpose, not a drift that happens by accident. Guidance from another professional body goes further and calls the letter evidence. The lack of a properly scoped engagement letter has been identified as a key element in successful negligence claims. The letter itself is the record of what was actually agreed when a dispute later turns on scope.29 That is the same instrument the whole discipline runs on. A record made in advance, so that the question "what were you responsible for" has a documented answer and not a memory.
The boundary is a boundary, not an escape hatch, and the doctrine has a floor. A practitioner who told a client to go and get specialist advice was still found liable for failing to give competent general advice that was within his own ordinary competence. Suggesting someone else handle it did not absolve him of the part that was his.30 Scoping work out keeps liability where it belongs. It does not let a practitioner shed a duty they were plainly competent to meet. The engagement letter draws the line honestly or it does not draw it at all.
Liability caps sit inside the same doctrine and are less universal than they look. In one jurisdiction an accounting firm's standard clause limited its liability to the amount of its fee, fifteen thousand dollars. It was upheld against a client who alleged the error cost her more than half a million. The court noted that accountants there were free to cap their liability where lawyers, barred by their own governing statute, were not.31 Against that, bank regulators in another jurisdiction advised that boards should not accept external-auditor engagement terms that cap liability in ways the regulators consider unsafe and unsound. The work is relied on by others, and the liability is meant to sit somewhere real.32 The lesson for agent assurance is that the liability has to land somewhere accountable, and the engagement is where that is decided, in the open, at the start.
The practitioner advises, scopes, and records. The client implements and owns the result. The engagement letter draws the line between the two and is itself part of the evidence the accountable person can later produce. The liability is not made to disappear. It is placed, deliberately, where it belongs.33
The price the buyer is anchored on
The buyer arrives anchored on a very low number. The AI capability itself is sold like software, by the seat, for something in the region of twenty dollars per person per month.34 That is the mental reference the buyer carries into the conversation: AI is a cheap subscription. Assurance-grade advisory work is priced nothing like that, and it is priced opaquely, because advisory pricing has largely moved off the visible hourly rate. A benchmark survey of advisory practices found only about a tenth still using hourly billing as their main method. The rest have moved to fixed-fee or value-based pricing that does not present the buyer with a rate they can multiply out.35 So the buyer meets a quote that is an order of magnitude above their anchor, arrives without an hourly rate to sanity-check it against, and reads it as expensive.
Naming that gap is part of the engagement rather than something to work around. The subscription buys the capability. The assurance buys the defensibility, and the second is priced like advice because it is advice, the kind that carries a named person's judgment and a liability that has been deliberately placed. The buyer who understands that they are buying two different things at two different prices stops comparing the second to the first. The buyer who does not will keep measuring the cost of being able to answer the regulator against the cost of the tool that created the exposure, and will get the comparison wrong.
The defensible no
The defensible answer is sometimes no. There is work that cannot be assured as specified, and automation that should not be built at all, and a practice that cannot decline either is a vendor selling hours, not a discipline holding a line.
A national court ordered an immediate halt to a government system that used an algorithm to detect welfare fraud, finding that the system as deployed violated a basic right and could not stand.36 Some automation should not be built or run in the form proposed, and the right professional response, when the thing cannot be made defensible, is to say so and decline, not to assure it anyway and hope. Declining unassurable work, and scoping out what should not be automated in the first place, is an act the engagement must leave space for, and it protects the client as much as the practitioner.
The book meets the same reflex twice more, as a runtime control in chapter 9 and as a professional obligation in chapter 12.
The commercial half
The engagement takes documented shapes, places implementation and liability with the client through the engagement letter, prices the work like advice rather than like software, and keeps room for the refusal, because a practice that cannot decline cannot assure.
The engagement sells defensibility; the controls that manufacture it are Part III.
Notes
- The named accountable roles vary by jurisdiction and sector: in South African financial services the "key individual" is a licensed, personally accountable role under the Financial Advisory and Intermediary Services Act (Act 37 of 2002), whose section 1 defines it as "any natural person responsible for managing or overseeing...the activities of the...provider...relating to the rendering of any financial service," with every licensed provider required to appoint at least one approved key individual under the Act and the Financial Sector Conduct Authority's fit-and-proper requirements; elsewhere the equivalent is the compliance officer, the company secretary, the chief executive, or, in the smallest firms, the founder. The book uses the roles generically; the point is that a named person, not the entity, carries the exposure. Primary (statute); SAFLII returns 403 to automated retrieval, so the definition is carried from the statutory text. Ledger: ch06-e32. ↩
- SEC opinion affirming FINRA disciplinary findings against a broker-dealer's chief compliance officer, 2018: "For approximately two years, North completely failed to review any Bloomberg messages/chats... which comprised 85% of the firm's electronic communications." A named compliance role held to account for a monitoring duty that was not performed. Cited from the SEC opinion; sec.gov returns 403 to automated retrieval, so the quote is carried from the evidence extraction. Ledger: ch06-e06. ↩
- Same opinion: FINRA imposed consecutive suspensions "in all principal and supervisory capacities" and a forty-thousand-dollar fine; the SEC affirmed, and the D.C. Circuit affirmed the SEC in 2020. The consequence reached the person, not only the firm. Ledger: ch06-e07. ↩
- Same opinion, stating the standard: liability attaches when a compliance officer "engages in wrongdoing, attempts to cover up wrongdoing, crosses a clearly established line, or fails meaningfully to implement compliance programs," and not in "an isolated circumstance where a CCO, using good faith judgment makes a decision, after reasonable inquiry, that with hindsight, proves problematic." Ledger: ch06-e08. ↩
- Bar-association report compiling the enforcement record against the former chief compliance officer of a money transfer business: a one-million-dollar civil penalty assessed by the financial-crimes regulator for willfully violating the Bank Secrecy Act, and a separate Department of Justice settlement of a $250,000 fine and a three-year injunction from compliance work at money transfer businesses. Secondary source. Ledger: ch06-e09. ↩
- SEC press release, 2013: for a 2012 trading malfunction that generated "over 4 million orders in 45 minutes... resulting in 397 million shares traded and $460+ million in losses," the SEC charged and penalized only the entity, twelve million dollars for violating the Market Access Rule, naming no individual officer. Cited from the SEC release; sec.gov returns 403 to automated retrieval, quote carried from the evidence extraction. Ledger: ch06-e10. ↩
- FinCEN consent order against a large bank, 2024, finding roughly eighty percent of transaction volume left unscreened by an unmaintained automated monitoring system over a decade: "the bank did not invest sufficient time, money, or managerial resources to adequately maintain its AML program... TD Bank failed to adequately train its employees who served as a first line of defense." The penalty and monitorship attach to the institution; no individual compliance officer is named. Ledger: ch06-e11. ↩
- The Consensus Assessments Initiative Questionnaire, published by the Cloud Security Alliance: "a set of Yes/No questions a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM)." The published questionnaire standard behind cloud vendor-risk review. Ledger: ch06-e01. ↩
- Trade reference on the same questionnaire: "Completing the CAIQ questionnaire usually takes a few hours and is considered only a first-level screening process; more intensive provider review processes are advised." Secondary source. Ledger: ch06-e02. ↩
- AWS's published questionnaire response states that the provider "has completed this questionnaire with the answers below," using the current questionnaire standard version. The document is a self-completed set of answers, not an independent third-party assessment. Ledger: ch06-e03. ↩
- Same document: "AWS has established a formal audit program that includes continual, independent internal and external assessments... Compliance reports from these assessments are made available to customers." What backs the answers is the independent report, retrievable by the customer, not the answers themselves. Ledger: ch06-e05. ↩
- Law-firm client alert on a 2026 enforcement action: the founder of a shopping-app company was charged with "one count of securities fraud and one count of wire fraud" for representing that "the app used proprietary AI to complete purchases autonomously," when the actual automation rate was "effectively zero," having raised over forty million dollars. Secondary source. Ledger: ch06-e12. ↩
- MIT Sloan Management Review and Boston Consulting Group global executive study on agentic AI, 2025: "A Tidal Wave of Adoption, a Trickle of Strategy... organizations are rapidly adopting agentic AI, well before they have a strategy in place... agentic AI has already reached 35% adoption, with another 44% of organizations planning to deploy it soon." Confirmed against the source directly, 2026. Ledger: ch06-e13. ↩
- Survey of 1,252 senior leaders across the US, UK, and India, reported 2026: "78% say they are implementing AI faster than they can effectively measure its impact," and "50% acknowledge they lack clear visibility into the skills and roles their organizations will need as AI matures." Secondary reporting of the survey. Ledger: ch06-e14. ↩
- McKinsey Global Survey on AI, 2025: "Out of nearly 2,000 respondents, only 109, roughly 5.5%, reported that more than 5% of their organization's EBIT is attributable to AI." Disclosed-methodology survey. Ledger: ch06-e15. ↩
- Same survey: "The redesign of workflows has the biggest effect on an organization's ability to see EBIT impact from its use of gen AI, out of 25 attributes tested," while "only 21% of companies using gen AI report having redesigned workflows to date." The value sits in organizational change the buyer has largely not done. Ledger: ch06-e16. ↩
- The NIST Cybersecurity Framework version 2.0, published 2024: its six Core Functions are "GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER," with Govern defined as the organization's cybersecurity risk management strategy, expectations, and policy being "established, communicated, and monitored." Confirmed from the primary publication, 2026. Ledger: ch06-e26. ↩
- Same framework: the five-step process for a CSF Organizational Profile, "1. Scope the Organizational Profile... 2. Gather the information... 3. Create the Organizational Profile... 4. Analyze the gaps between the Current and Target Profiles, and create an action plan... 5. Implement the action plan, and update the Organizational Profile." The public shape a readiness assessment borrows. Ledger: ch06-e27. ↩
- Same framework: four Tiers reflecting how rigorously an organization manages cybersecurity risk, "Partial (Tier 1), Risk Informed (Tier 2), Repeatable (Tier 3), and Adaptive (Tier 4)." A defensible way to state current state. Ledger: ch06-e28. ↩
- The CIS Controls Assessment Specification: it "focuses on determining whether or not a Safeguard has been measured," that is, whether a control is present rather than a subjective grade of how well it is run. The readiness artifact records presence, which is the checkable, showable thing. Ledger: ch06-e29. ↩
- NIST Special Publication 800-115 (2008): a three-phase security assessment methodology, "Planning... Execution... Post-Execution," on a recurring cadence, the underlying statute requiring testing "with a frequency depending on risk, but no less than annually." The staged, recurring shape a governance programme borrows. Ledger: ch06-e30. ↩
- Companies Act 2006, section 489(1): "An auditor or auditors of a public company must be appointed for each financial year of the company, unless the directors reasonably resolve otherwise on the ground that audited accounts are unlikely to be required." The audit's attestation is renewed annually, by statute, through fresh appointment. Primary (statute). Ledger: ch06-e34. ↩
- Florida Administrative Code 69A-51.025: "The certificate of operation for a power boiler or a high pressure, high temperature water boiler is valid for a period of 12 months from the date of the certificate inspection." The statute behind it requires each boiler to be "inspected within 30 days after expiration of the boiler's certificate of operation" (s. 554.108, Florida Statutes). Primary (regulation and statute); the legislature's own host refuses automated retrieval, so the rule text is carried via the Legal Information Institute's mirror, block noted. Ledger: ch06-e35. ↩
- The Florida engineering board, describing section 471.025, Florida Statutes: successor engineers must "assume full professional and legal responsibility of engineering documents when assuming an existing project from another engineer," treating the originals "as if they were the successor engineer's original product, which includes signing and sealing those documents." Custody of an engineered system transfers whole or not at all. The licensing board's own guidance describing the statute. Ledger: ch06-e36. ↩
- UK Supreme Court, 2021, reframing the test for a professional adviser's scope of duty: "one looks to see what risk the duty was supposed to guard against and then looks to see whether the loss suffered represented the fruition of that risk." Cited from a legal commentary reporting the judgment; the commentary page returns no article text to automated retrieval, so the quote is carried from the evidence extraction. Secondary source. Ledger: ch06-e20. ↩
- US federal district court, 2023, on a law firm's engagement letter: "The legal contract between the attorney and client sets out the limits of representation, and so long as an attorney executes these duties with competence, loyalty, and fidelity, nothing more is required." Reported in a law-firm risk alert. Secondary source. Ledger: ch06-e19. ↩
- Professional-body guidance on engagement letters: "any additional task not cited in the engagement letter is an expansion of service and will require contract modifications." The letter is the operative boundary. Ledger: ch06-e21. ↩
- Professional-body indemnity guidance: "The engagement letter provides important evidence of what was agreed in the event of a dispute as to the scope of a practitioner's engagement... The lack of a properly scoped letter of engagement has been identified as a key element in successful claims against accountancy professionals." Ledger: ch06-e22. ↩
- Court of Appeal decision reported in professional-body guidance: a practitioner who "had suggested to the client that specialist tax advice be sought" was "not... absolve[d]... from their obligation to give the client competent advice," and the failure "amounted to a breach of their retainer and/or negligence." Scoping out has a floor. Ledger: ch06-e23. ↩
- Provincial court of appeal decision reported in a professional-body risk-management note: an accounting firm "uphold[ing] its standard term limiting its liability to the amount of its fees ($15,000) for the specific tax advice negligently given," against a client who alleged a loss above half a million dollars, the court noting accountants there could cap liability where lawyers could not. Secondary source. Ledger: ch06-e24. ↩
- US interagency advisory, 2006: bank boards "should not enter into agreements that incorporate unsafe and unsound external auditor limitation of liability provisions" for audit engagements and related attestations. Where the work is relied-on assurance, the cap is not freely available. Ledger: ch06-e25. ↩
- The nearest existing legal frame for this placement is the law of agency: a principal is answerable for work performed by an agent it directs but does not supervise act by act, and a legal literature now applies that doctrine to AI, treating AI programs as agents acting on behalf of human principals and locating the resulting liability with the principal. The book's "name on the risk" is that principal in a lawyer's vocabulary. The book frames the work as assurance rather than doctrine because the two do different jobs: agency doctrine allocates the liability after a failure, while assurance manufactures, in advance, the evidence of good-faith implementation that the allocation turns on. Ian Ayres and Jack Balkin, "The Law of AI is the Law of Risky Agents Without Intentions" (University of Chicago Law Review, 2024); the book-length treatment is Samir Chopra and Laurence White, A Legal Theory for Autonomous Artificial Agents (2011). Ledger: ch06-e33. ↩
- A major vendor's AI add-on for its business productivity suite is listed at $25.20 per user per month on a monthly commitment (discounted to $18.00 on annual billing during a mid-2026 promotional window). The cheap per-seat anchor the buyer arrives with; fast-layer product detail. Ledger: ch06-e17. ↩
- Benchmark survey of client advisory services practices, 2024: "only 10% of respondents still employing hourly billing as the primary pricing method," the rest having moved to fixed-fee or value-based models. Why assurance-grade advisory reads as opaque next to a per-seat subscription: it is not priced by a published hour. Ledger: ch06-e18. ↩
- Press release on a 2020 district-court judgment: the court "ordered an immediate halt to the government's use of a digital welfare fraud detection system, System Risk Indication (SyRI), for violating human rights," on the basis that the deployed system breached a basic right. Ledger: ch06-e31. ↩