First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Fractional Chief AI Officer (vCAIO) Advisory Retainer
Managed ServicesConsulting

Fractional Chief AI Officer (vCAIO) Advisory Retainer

Fractional Chief AI Officer (vCAIO) Advisory Retainer gives an organization of roughly 50 to 1,000 seats a named IT Partner AI executive on a flat monthly retainer: an AI inventory and current-state summary in the first month, a 12-to-24-month AI roadmap tied to business goals and re-baselined quarterly, an AI budget and licensing posture (Microsoft 365 Copilot seats versus pay-as-you-go Copilot Credits versus Azure consumption), ownership of your acceptable-use and AI governance policy set, vendor and tool evaluation, a standing watch on the EU AI Act, ISO/IEC 42001 and the AI questions in insurer and customer questionnaires, change-management guidance, a monthly strategy call (up to 60 minutes), and a quarterly executive review with a board-ready deck. It costs $1,950 per month with no long-term contract. It is an advisory cadence, not an embedded executive — the advisor is not in your office several days a week — and hands-on implementation, security-program leadership, IT strategy and budget, and the ISO/IEC 42001 readiness project are separate services this page names explicitly.

Timeline 30 daysService owner Mike MackeyMicrosoft 365 CopilotMicrosoft Copilot StudioMicrosoft Foundry

What this engagement is

Somewhere between 50 and 1,000 seats, most organizations are already using AI without anyone being accountable for it. Microsoft 365 Copilot seats were bought for a pilot that never formally ended; a department built an agent in Copilot Studio; sales runs a third-party AI tool nobody in IT has reviewed; a customer's security questionnaire has grown an AI section; the cyber-insurance renewal asks whether there is an AI acceptable-use policy; and the board has asked for "the AI plan". The person answering is whoever has the strongest opinion — an enthusiastic manager, the IT lead between tickets, or a vendor. The result is rarely a disaster; it is spend without a plan, tools that overlap, policies that exist on paper or not at all, and a leadership team that cannot say what AI costs, what it has delivered, or what it exposes them to. A fractional Chief AI Officer exists to own that thinking on a schedule, at a fraction of the cost of the seat. This retainer gives you a named AI executive from IT Partner's senior bench — a practice that has run Microsoft 365 and Azure estates as a Microsoft partner since 2006, led by a founder whose Microsoft certification transcript is published on Microsoft Learn rather than asserted on a slide. In the first month the advisor builds an AI inventory — Microsoft 365 Copilot seats and their usage, Copilot Chat, agents in Copilot Studio and on Microsoft Foundry, Azure AI resources, AI features switched on inside business applications, the shadow AI your people use with a personal login, and whatever policies exist — and turns it into a current-state summary leadership can read. From then on the rhythm is fixed: a 12-to-24-month AI roadmap that ties every initiative to a business goal and is sequenced by dependency, data readiness and licensing; an AI budget and licensing posture that decides, per group of people, whether a Copilot seat, pay-as-you-go Copilot Credits, Copilot Studio capacity or Azure consumption is the right shape and what it will cost you from Microsoft; an acceptable-use policy and AI governance charter the advisor owns and keeps current; vendor and tool evaluation with written criteria; a standing watch on the EU AI Act calendar, ISO/IEC 42001 and the AI questions in your customers' and insurers' questionnaires; a monthly strategy call; and a quarterly executive review with a deck written for the board, not for IT. Two things separate an IT Partner vCAIO from a vendor's "AI strategist". First, nobody here earns a commission — the advisor's pay does not move when your Copilot seat count does, so a recommendation to buy fewer seats, to meter a group on credits instead, or to pick a non-Microsoft tool costs them nothing. Second, the advisor sits next to the engineers who would do the work: when the roadmap spins off a project — a Copilot rollout, an agent, a Purview data-governance pass — you get a fixed-price quote in writing before it starts and pay after you approve delivery, and you are always free to take that scope elsewhere. The shape is stated plainly: this is a standing advisor on a fixed cadence, not a fractional executive embedded in your office two days a week; where that is what you need, the higher tiers are quoted separately. Security-program leadership is the vCISO; IT strategy and the IT budget are the vCIO; hands-on implementation is quoted per project; the formal ISO/IEC 42001 gap assessment is its own engagement. A vCAIO who profits from selling you the implementation is a conflict of interest; one who refuses to help you scope it is useless. We do the second without the first.

Success criteria

01An AI inventory and current-state summary exist within the first monthly cycle — every Microsoft 365 Copilot seat, agent, Azure AI resource, embedded AI feature and known shadow-AI tool with an owner, a purpose and a data-exposure note — and are updated on every monthly call.
02A written AI roadmap and AI budget exist within the first two cycles, tie each initiative to a business goal, and are re-baselined at each quarterly review — living documents, not annual artifacts.
03Every significant AI decision in the period — seats bought or released, a tool adopted or declined, an agent approved for production, a use case funded or parked — has a recorded recommendation, the options considered and the reason, in a decision log you own.
04An acceptable-use policy and an AI governance charter are approved by leadership, published to staff, and reviewed on a stated cycle, with an exception process that is used rather than bypassed.
05Leadership can answer, at any quarterly review and from the deck alone, what AI costs the organization, what it has delivered against the roadmap, and what it exposes them to.
06Regulatory, standards and questionnaire changes that affect you — EU AI Act application dates, ISO/IEC 42001 expectations in customer RFPs, insurer AI questions — are surfaced by the advisor before they land on your desk, with a recommended action.
07Projects spun off the roadmap arrive as scoped, fixed-price quotes in writing — and the roadmap records equally when the recommendation is to do nothing, or to do it with someone else.

What you receive

Onboarding and AI inventory (first monthly cycle): interviews with leadership, IT and the business owners who already use AI; an inventory of Microsoft 365 Copilot seats and usage, Copilot Chat, Copilot Studio and Microsoft Foundry agents, Azure AI resources, AI features enabled inside business applications, third-party and shadow AI, and existing policies; and a short written current-state summary — what is sound, what is at risk, what is undecided.
AI roadmap: a 12-to-24-month plan tying each initiative to a business goal, sequenced by dependency, data readiness, licensing and change capacity, with a use-case pipeline that records what was proposed, prioritized, funded and parked — maintained as a living document and re-baselined at each quarterly review. Where you want candidate use cases costed and ranked as a project before the roadmap commits to them, the Microsoft 365 Copilot and AI Use-Case ROI Sprint feeds the pipeline.
AI budget and licensing posture: per group of people, the recommended shape — Microsoft 365 Copilot seats, pay-as-you-go Copilot Credits, Copilot Studio capacity, Azure consumption for Foundry workloads, or a non-Microsoft tool — built from Microsoft's published prices and your actual usage, with planning assumptions stated and variance tracked quarter over quarter. Microsoft's charges remain Microsoft's; the posture tells you what to buy, what to meter and what to stop paying for.
AI policy set, owned: an acceptable-use policy for staff, an AI governance charter (decision rights, the approval path for new tools and agents, human-oversight expectations, an exception process), and a register of approved and declined tools — drafted where nothing exists, aligned to what does, published, and reviewed on a stated cycle.
Vendor and tool evaluation: written criteria (data handling, tenancy, identity integration, retention and training-use terms, model and hosting terms, exit), a recommendation per request, and the advisor on the call when you meet a vendor, on request.
Risk and regulatory watch: the EU AI Act calendar as amended, ISO/IEC 42001 expectations, and the AI sections now appearing in cyber-insurance renewals and customer security questionnaires — tracked continuously, translated into what it means for you and what to do, with draft answers to questionnaire AI sections prepared from the inventory and policy set.
Change-management guidance: a rollout and communication approach per initiative, champion and training recommendations, and the adoption signals to watch — delivered as guidance the initiative owners execute, or scoped as a training or adoption engagement when you want us to run it.
Monthly strategy call (up to 60 minutes) with the named advisor: decisions pending, risks, changes since last month, roadmap, budget and policy updates, and an action register with owners.
Quarterly executive review (up to 90 minutes) with a board-ready deck: progress against the roadmap, spend against budget, an AI scorecard (adoption, usage, spend, incidents and policy exceptions against your own baseline), risks and decisions required, the regulatory and Microsoft changes that matter, and the next quarter's priorities.
Priority access to IT Partner's engineering teams for scoping: roadmap initiatives turned into fixed-price written quotes, with the advisor reviewing scope on your side of the table. The decision log, action register, inventory, policies and every deck are yours to keep if the retainer ends.

How the work unfolds

1. Onboarding and AI inventory (first monthly cycle)

The named advisor is introduced, interviews leadership, IT and the business owners already using AI, and gathers licensing, invoices, Copilot usage reporting, Azure cost reports, AI-tool contracts, existing policies, and the questionnaires and renewals that ask about AI. Where technical evidence helps — Microsoft's Copilot usage report and Copilot Dashboard, the agent inventory in Microsoft Agent 365 or the Copilot Studio admin views, Defender for Cloud Apps discovery for shadow AI where you are licensed for it — we use IT Partner's free read-only assessments and least-privilege access rather than asking you to pay for discovery. The cycle closes with the AI inventory, the current-state summary, and first drafts of the acceptable-use policy where none exists.

2. Monthly strategy cycle

Each month the advisor prepares from the action register, the use-case pipeline, the licensing and usage data, and the regulatory watch, then runs the strategy call: decisions pending, risks, what changed, and roadmap, budget and policy updates. The roadmap and AI budget are in first draft by the end of the second cycle. Between calls, questions go through IT Partner's intake with first response inside our published one-business-hour SLA; substantive analysis is scheduled rather than improvised.

3. Budget, licensing and regulatory watch (continuous)

The licensing posture is checked against actual usage each month — idle Copilot seats, groups better served by metered credits, Azure AI consumption drifting from plan — and a recommendation is made ahead of every renewal date. Vendor requests get written criteria and, on request, the advisor in the room. EU AI Act dates, ISO/IEC 42001 developments, Microsoft licensing and product changes for Copilot, Copilot Studio, Foundry and Agent 365, and new AI questions in your customers' and insurers' questionnaires are filtered continuously and surfaced on the monthly call — or immediately, when a date or a questionnaire deadline needs action before then.

4. Quarterly executive review

Every third cycle the advisor delivers the board-ready deck and runs the review with your leadership: progress, spend, the AI scorecard against your baseline, risks, decisions, and next priorities. The roadmap, budget and policy set are re-baselined against what the business now knows. Attending your board meeting in person or presenting to the board directly is a quoted higher tier; the deck is written so the sponsor can present it unaided.

5. Scoping and hand-off

When the roadmap says an initiative is next — a Copilot readiness or deployment project, a Purview data-governance pass, an agent build, AI security hardening, a training program — the advisor scopes it with IT Partner's engineering teams and brings you a fixed-price quote in writing: reviewed by the advisor on your behalf, executed only if you approve, paid after you approve delivery, and always yours to take elsewhere.

Prerequisites

An executive sponsor — owner, CEO, COO or CFO — who will attend the quarterly executive review and can make or carry decisions on AI spend and policy.
A named day-to-day contact (whoever runs IT today: internal staff, an office manager, or your MSP's account lead) for the monthly call and the action register, plus a business-side owner for each area where AI use is concentrated.
Access to Microsoft licensing and invoices, Copilot usage reporting, Azure cost reports, contracts and terms for third-party AI tools, existing policies, and the customer questionnaires, RFPs and insurance renewals that ask about AI.
Read-only or least-privilege technical access where the advisor needs evidence — granted through GDAP that you approve and consistent with our published access policy; the retainer needs no standing admin rights and no change rights at all.
Agreement at onboarding on cadence, attendees, confidentiality, how decisions are recorded, and who inside your organization approves new AI tools and agents once the governance charter is in place.
An organization of roughly 50 to 1,000 seats without a Chief AI Officer or an equivalent accountable executive; larger, regulated or multi-entity organizations are scoped individually before we quote.

Who does what

IT Partner

  • Provide a named senior AI advisor and keep the same advisor across the engagement, with a planned handover if that ever changes.
  • Maintain the AI inventory, roadmap and use-case pipeline, AI budget and licensing posture, policy set and tool register, decision log, and action register as living documents.
  • Run the monthly strategy call and deliver the quarterly executive review with its board-ready deck and AI scorecard.
  • Watch the EU AI Act calendar, ISO/IEC 42001, Microsoft's Copilot, Copilot Studio, Foundry and Agent 365 licensing and product changes, and the AI questions in questionnaires and renewals, and surface what affects you with a recommended action.
  • Provide vendor and tool evaluation criteria and a recommendation ahead of every AI-tool purchase or renewal, Microsoft or not.
  • Scope roadmap initiatives with IT Partner's engineering teams into fixed-price written quotes, and say plainly when the right answer is to do nothing, to buy less, or to use someone else.

Your team

  • Attend the monthly call and the quarterly review with the people who can decide.
  • Share licensing, usage and cost data, contracts, budgets, business plans, questionnaires and organizational changes early enough to plan for them.
  • Own the decisions — the advisor recommends and records; leadership decides, approves the policies, and enforces them internally.
  • Work the action register between calls — initiative owners execute rollouts, communications and champion programs — or tell the advisor what is blocked.
  • Route incidents, day-to-day administration and end-user AI questions through the appropriate support, administration or managed service rather than holding them for the monthly call.

What's not included

Hands-on implementation — the advisor decides what should be done and scopes it; the doing is a separately quoted project: the Microsoft 365 Copilot Readiness Assessment, Microsoft Purview Data Governance for Copilot, Copilot Deployment and Adoption, agent builds in Copilot Studio or on Microsoft Foundry, AI Security for Microsoft 365 Copilot and Agents, standing up agent governance as a working system in the tenant (AI Agent Inventory and Lifecycle Governance Implementation), and Power Platform governance.
Security-program leadership — security policies, the risk register, compliance coordination, incident-readiness planning and security metrics are the Virtual CISO (vCISO) — Security Program as a Service. The vCAIO owns the AI policy set and carries its security requirements to the security program; the vCISO owns the program and the controls. Where you need both, the two advisors coordinate, but this retainer does not substitute for security leadership.
IT strategy and the IT budget — the IT roadmap, the renewal calendar for the wider estate, and the Microsoft 365 and Azure platform direction are the Virtual CIO (vCIO) Advisory and IT Roadmap Retainer. Where both advisors are engaged, the AI roadmap becomes a chapter of the IT roadmap and the two are re-baselined together; this retainer does not fund the IT seat.
The formal ISO/IEC 42001 gap assessment, Annex A control mapping, Statement of Applicability and certification-readiness roadmap — that is the AI Governance and ISO/IEC 42001 Readiness Assessment, a scoped project. The retainer maintains a baseline policy set and carries the assessment's roadmap forward; it does not replace the assessment, and IT Partner is not a certification body.
Training — full training days, role-based prompt workshops and champion enablement are Microsoft 365 Copilot Training and Prompt Workshops, priced per trainer-day. The retainer recommends the program; it does not deliver it.
Managed operations — monthly seat optimization and champion programs are Managed Microsoft 365 Copilot Adoption and Optimization; telemetry, prompt and knowledge refresh and cost review for production agents are Managed AI Agent Operations and Optimization. The retainer reads their reports; it does not run them.
Formal assessments beyond the current-state summary (a costed, ranked use-case portfolio is the Use-Case ROI Sprint), model evaluation or red-teaming, data-readiness audits, and custom Power BI or executive dashboards beyond the quarterly scorecard — separate engagements the roadmap may call for; the free tenant health check and tenant optimizer scan are used freely where they help.
Vendor contract negotiation as your agent, procurement execution, and responsibility for third-party AI vendor performance — the advisor sets criteria, reviews terms and joins calls on request; you sign.
Legal advice of any kind — EU AI Act classification or applicability opinions, contractual AI clauses, privacy determinations or regulatory representations. The watch reports what has been published and frames the question; your counsel answers it. The advisor is not an officer of the company and carries no binding corporate authority.
Emergency response, AI incident handling, 24/7 availability and end-user helpdesk for Copilot questions — incidents go through your security arrangement and users through your support arrangement; the advisor's role is to make sure both exist and know what an AI incident looks like.
Microsoft licensing, Copilot Credits, Copilot Studio capacity, Azure consumption, Agent 365 licensing and third-party AI subscriptions — billed by their vendors and never part of this fee; where you buy Microsoft subscriptions through IT Partner they are at Microsoft's published list price, never marked up into the retainer.
More advisor time than the cadence provides — board meeting attendance, workshop facilitation, a formal RFP for an AI platform, or an embedded number of days per week — quoted separately as a higher tier or through CIO on Demand by the hour, agreed in writing before it starts.

Limitations & technical notes

!This is advisory work. Recommendations are made on the evidence and access you provide; the roadmap, budget and licensing posture are planning documents, not fixed-price quotes or guaranteed cost commitments, and the service promises no specific business, financial, adoption, security or compliance outcome. We publish no return-on-investment figures of our own — the scorecard measures against your baseline, and the numbers that come out are yours.
!The retainer is defined by its cadence and artifacts — the monthly call (up to 60 minutes), the quarterly review (up to 90 minutes), the preparation behind both, and the living inventory, roadmap, budget, policy set, tool register and logs — rather than by an hour bank or days on site. It is not a fractional executive embedded in your office one to three days a week; organizations that need that shape are quoted a higher tier. Work that needs substantial standalone analysis — a platform selection with a formal RFP, a due-diligence review of an AI vendor, a full data-readiness assessment — is scoped separately, often through CIO on Demand by the hour, and agreed in writing before it starts.
!Microsoft's licensing, credit rates, product names and admin surfaces for Microsoft 365 Copilot, Copilot Studio, Microsoft Foundry and Agent 365 are Microsoft's and change without notice; the licensing posture reflects Microsoft's published terms at the time it is written and is re-checked each cycle. Microsoft's metered charges — Copilot Credits, Copilot Studio capacity, Azure consumption — are billed by Microsoft to you and are not resold, discounted, capped or absorbed by this retainer.
!The regulatory watch is not legal advice. At the time of writing (September 2026) the EU AI Act, Regulation (EU) 2024/1689, applies in stages: prohibited practices since 2 February 2025, general-purpose AI model obligations since 2 August 2025, and transparency obligations under Article 50 from 2 August 2026; the Digital Omnibus on AI (Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026) deferred the high-risk obligations to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I products. The Act's scope clause reaches organizations outside the EU where an AI system's output is used in the Union; whether that describes you is a question for your counsel. ISO/IEC 42001:2023, published in December 2023, is the current edition of the AI management-system standard at the time of writing. Dates and editions are re-verified each review cycle.
!Where the vCAIO runs alongside the vCIO or the vCISO, decision rights are explicit: the IT budget and platform direction belong to the IT engagement, the security program and its controls to the security engagement; the vCAIO carries AI requirements into both and does not override either. Where only the vCAIO is engaged, the AI budget is written as a standalone line your finance lead can fold into whatever IT budget exists.
!Projects spun off the roadmap are quoted separately, fixed-price and in writing, and paid after you approve delivery. You are never obliged to give that work to IT Partner, and the advisor's compensation is unaffected either way — nobody at IT Partner earns a commission.
!Between calls, questions go through IT Partner's intake, with first response within our published SLA of 1 business hour and monthly support statistics published openly since December 2023; substantive analysis is scheduled, not answered in the first hour. Organizations that buy their Microsoft licensing through IT Partner already have unlimited break-fix support during business hours under our published policy; this retainer is not a support plan and does not change that.

Frequently asked questions

What is the Fractional Chief AI Officer (vCAIO) Advisory Retainer?

A flat-fee monthly retainer that gives your organization a named senior IT Partner AI executive: an AI inventory and current-state summary, a living 12-to-24-month AI roadmap and AI budget, a licensing posture that decides seats versus credits versus Azure consumption per group of people, an acceptable-use policy and AI governance charter the advisor owns, vendor and tool evaluation, a standing watch on the EU AI Act, ISO/IEC 42001 and questionnaire AI sections, change-management guidance, a monthly strategy call, and a quarterly executive review with a board-ready deck. It costs $1,950 per month with no long-term commitment.

Who is it for?

CEOs, COOs and CFOs of organizations of roughly 50 to 1,000 seats where AI is already in use but nobody is accountable for it — Copilot seats bought for a pilot, agents built by a department, third-party tools nobody reviewed, a board asking for the AI plan, and a customer or insurer asking for the AI policy. If leadership cannot say what AI costs, what it has delivered and what it exposes them to, this is the missing seat.

How much of the advisor's time do we get? Is this a fractional executive two days a week?

No, and the page says so plainly. The retainer is defined by cadence and artifacts rather than by days on site: the monthly strategy call (up to 60 minutes), the quarterly executive review (up to 90 minutes), the preparation behind both, the maintained inventory, roadmap, budget, policy set, tool register, decision log and action register, the continuous licensing and regulatory watch, and scoping conversations with our engineers. Questions between calls go through the intake. Fractional AI executives who embed in your office one to three days a week are a different shape at a different price; if that is what you need, we quote a higher tier in writing rather than stretching this one silently.

How is this different from the vCIO retainer?

Same shape, different seat. The vCIO owns IT strategy: the IT roadmap, the IT budget, vendors and renewals across the whole estate, and the Microsoft 365 and Azure platform direction. The vCAIO owns AI: what to use it for, what to buy and in what shape, the policies that govern it, the tools you let in, the regulatory calendar, and the board's view of it. Many organizations have neither seat; some have a capable IT director and lack only the AI one. When you run both retainers, the AI roadmap becomes a chapter of the IT roadmap, the two advisors re-baseline together, and the IT budget stays with the vCIO.

Where is the line between vCAIO and vCISO?

The vCAIO owns the AI policy set — acceptable use, the governance charter, the approval path for tools and agents, human-oversight expectations — and the business case for every AI initiative. The vCISO owns the security program: security policies, the risk register, compliance coordination, incident readiness and the controls in Purview, Defender and Entra. They overlap where an AI policy needs a control behind it — sensitivity labels before Copilot, data-loss prevention for a third-party tool — and there the vCAIO carries the requirement and the security engagement owns the control. A vCAIO retainer is not a security program, and we will not let it be mistaken for one.

How is this different from the ISO/IEC 42001 readiness assessment?

The readiness assessment is a scoped project: a formal gap assessment against ISO/IEC 42001, an Annex A control mapping, a drafted policy set, a Statement of Applicability starter and a certification-readiness roadmap. The retainer is the standing seat that comes before, after or instead of it: it maintains a baseline acceptable-use policy and governance charter, keeps the inventory current, and carries the assessment's roadmap forward month by month. If certification is the goal, start with the assessment and bring its roadmap into the retainer; if you need someone accountable for AI and are not yet sure certification matters, start here and the advisor will tell you when the assessment is worth buying.

Do we need Microsoft 365 Copilot licenses to start?

No. Deciding whether, for whom and in what shape you should license Copilot is one of the first things the retainer does. Some groups justify a per-user seat; some are better served by pay-as-you-go Copilot Credits for agent use; some need Copilot Studio capacity or Azure consumption for a Foundry workload; some are best left on Copilot Chat that your Microsoft 365 subscription already includes; and some should be using a non-Microsoft tool. The licensing posture records the shape per group and revisits it against usage each quarter.

What does the "AI budget and licensing posture" actually decide?

Per group of people, the recommended shape and what it will cost you from Microsoft or the vendor: Microsoft 365 Copilot seats, pay-as-you-go Copilot Credits, Copilot Studio capacity, Azure consumption for Foundry workloads, Agent 365 licensing where agents warrant it, or a third-party subscription — built from Microsoft's published prices and your actual usage, with idle seats and drifting consumption flagged each month and a recommendation ahead of every renewal. Two things it does not do: it does not change Microsoft's prices, and it does not absorb Microsoft's metered charges. Credits, capacity and Azure consumption are billed by Microsoft to you; the posture tells you what to buy, what to meter and what to stop paying for.

Does the EU AI Act apply to a US organization?

Possibly, and that is exactly the kind of question the watch exists to frame rather than guess at. The Act's scope clause reaches providers and deployers outside the EU where an AI system's output is used in the Union, and most mid-market organizations are deployers of other people's models rather than providers. At the time of writing the prohibited-practice and general-purpose-model obligations already apply, transparency obligations apply from 2 August 2026, and the Digital Omnibus on AI moved the high-risk obligations to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I products. The advisor keeps that calendar against your inventory and tells you which use cases would need a legal opinion; your counsel gives the opinion.

Do you write our AI policies?

Yes, within the retainer's shape. Where nothing exists the advisor drafts a baseline acceptable-use policy for staff and an AI governance charter — decision rights, the approval path for new tools and agents, human-oversight expectations, an exception process — in the first cycles, aligned to whatever security and HR policies you already have. Leadership approves them, you publish them, and the advisor owns them from then on: reviews on a stated cycle, exceptions recorded, tool register kept current. A full policy program mapped to ISO/IEC 42001 or written to a certification standard is the readiness assessment, and the security controls behind a policy belong to the security engagement.

What about shadow AI — tools people use with a personal login?

It goes in the inventory first, not in a disciplinary memo. The advisor asks the business owners what is actually being used and why, uses the discovery evidence your licensing already provides — Defender for Cloud Apps where you have it, sign-in and consent data in Entra, browser and expense signals — and records each tool with an owner, a purpose and what data reaches it. Then the governance charter gives people a sanctioned path: an approval route that answers in days, an approved-tools register, and a policy that says what may never go into an unapproved tool. Most shadow AI exists because there was no way to ask. Where the agent estate is large enough to need a registry, lifecycle rules and offboarding as a working system rather than a list the advisor maintains, that is the AI Agent Inventory and Lifecycle Governance Implementation, scoped as a project.

Does the vCAIO do hands-on work in our tenant?

No. The advisor decides what should be done and reviews what was done; the doing is a scoped project, a managed service or your own team. That separation is deliberate — the person recommending a change should not be the person marking their own homework. The advisor also holds no standing admin rights: where evidence is needed we use IT Partner's free read-only assessments or request least-privilege, time-bound GDAP access that you approve for a specific purpose, against a published access policy you can compare any request with.

Is the vCAIO going to sell us Copilot seats or projects?

The advisor will tell you what to buy and scope the projects the roadmap calls for, with fixed-price quotes in writing — that is part of the value. What the advisor will not do is benefit from it: nobody at IT Partner earns a sales bonus or commission, so a recommendation to release seats, to meter a group on credits instead, to defer, or to pick a non-Microsoft tool costs them nothing. Where you buy Microsoft subscriptions through IT Partner they are at Microsoft's list price, never marked up into this fee. You are never obliged to give spun-off work to IT Partner, and when you do, you pay after you approve delivery.

Can the advisor evaluate non-Microsoft AI tools?

Yes — the inventory, the tool register and the evaluation criteria cover your whole AI estate, not just Microsoft's. The criteria are written down (data handling, tenancy, identity integration, retention and training-use terms, model and hosting terms, exit), the recommendation is recorded in the decision log, and the advisor joins vendor calls on request. What the advisor does not do is negotiate as your agent or sign on your behalf; you hold the pen.

What happens in the first month?

Onboarding: the advisor is introduced, interviews leadership, IT and the business owners already using AI, gathers licensing, usage, cost and contract data and existing policies, runs the free read-only assessments where they help, and delivers the AI inventory and current-state summary plus a first draft of the acceptable-use policy where none exists. The roadmap and AI budget are in first draft by the end of the second cycle, the monthly rhythm is in place from then on, and the first quarterly executive review falls at the end of the third.

Can the advisor attend our board meeting?

The base retainer delivers a board-ready deck each quarter, written so the sponsor can present it unaided, and runs the quarterly review with your leadership team. Attending or presenting at the board itself, facilitating an executive workshop, or adding advisor hours beyond the cadence is a higher tier quoted in writing — we would rather price it plainly than promise availability the base fee cannot honour.

How does billing work, and can we stop?

A flat $1,950 per month, invoiced monthly, with no long-term contract: stop any month, and all we ask is payment of previously approved invoices. The inventory, roadmap, budget, policy set, tool register, decision log and every deck are yours to keep — they were built to be read by your leadership, not to make you dependent on ours.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$1,950 per month
30 days
Start the vCAIO retainer