Skylar Moran, Director of Customer Success
Align Managed Services
Every investment firm I speak with is asking how to implement AI. Far fewer are asking whether they are ready for it.
That distinction matters.
AI will not automatically correct outdated information, excessive permissions, inconsistent processes, or weak governance. It can make those existing problems easier to find, faster to spread, and more difficult to control.
The firms best positioned to benefit from AI will not necessarily be the first to deploy it. They will be the firms that understand the business problem they are trying to solve, know and trust their data, define their risk tolerance, and establish governance before connecting AI to the organization.
This is also where a managed service provider can add significant value. Not by defining the firm’s AI strategy, but by helping the firm build the secure, governed foundation required to execute it.
Start With the Business Problem, Not the AI Tool
The biggest misconception I see is that an AI strategy begins with buying a tool and giving it access to as much data as possible.
It does not.
An AI strategy should begin with a business question:
What problem are we trying to solve?
Is the firm trying to accelerate due diligence, improve research, make institutional knowledge easier to access, streamline workflows, or reduce the time employees spend searching for information?
Once the objective is clear, the next questions should focus on the data:
Is it accurate and current?
Is it organized and appropriately classified?
Are multiple versions of the same information circulating?
Who owns the data?
Who should have access to it?
How will the firm keep it clean over time?
How will leadership measure whether the use case produces value?
More data is not always better.
If AI is working with outdated, duplicated, poorly classified, or irrelevant information, the firm may receive an answer quickly. That does not mean it will receive the right answer.These are not simply IT decisions. They are operating, compliance, security, and risk-management decisions.
Internal AI governance work already reflects this model through approved-platform inventories, human-review requirements, data-handling rules, training, vendor diligence, escalation processes, and ongoing policy review.
A strong MSP can help translate the firm's decisions into technical controls and operating processes. The firm, however, must make the decisions.
Investment firms routinely rely on MSPs to manage infrastructure, implement controls, administer access, monitor systems, and support users. That relationship can and should extend to AI.
But the firm cannot outsource accountability.
An MSP can help the firm understand what is technically possible, assess whether its environment is ready, identify security and governance gaps, implement approved tools, and monitor the resulting environment.
What the MSP cannot do is decide:
Clients own their data and understand what is important within their firms. We do not know their businesses better than they do. If we did, we would be investment firms, not technology and managed service providers.
The strongest AI initiatives are are partnerships.
The investment firm brings the business problem, subject-matter expertise, risk tolerance, and desired outcome. The MSP brings technology, security, governance, implementation and monitoring expertise.
An MSP should enable your AI strategy. It should not become your AI strategy.
If there is one issues that concerns me most, it is excessive permissions, especially when combined with an overshared SharePoint environment.
Historically, a person might have had access to information they should not have seen but never discovered it. They may not have known the information existed, where is was stored, or which sequence of shared folders and links would lead to it.
AI changes that dynamic.
When an AI assistant works as an extension of a user's access, it can search across substantial amounts of organizational information. That makes it much easier to surface content the user was technically permitted to access, even when that access was broader than the firm intended.
AI may not create the permissions problem. It can make an existing permissions problem far easier to discover.
Align's readiness material identified excessive permissions, external sharing, unauthorized applications, prompt-based data leakage and shadow AI as issues to review before connecting enterprise data. It also places identity, device trust, governance, education, and monitoring at the center of secure adoption.
this is why one of my first questions when a firm says it is ready to deploy AI is:
Are you confident every user has access only to the information that person should see?
If the answer is unclear, the organization is not ready to connect AI broadly to its data.
AI security is not only about the model or platform. It begins with verifying two things:
1. Is this the right user?
2. Is this a trusted device?
From there, firms should evaluate what that verified user can access, whether those permissions remain appropriate, how sensitive information is protected, and whether activity can be investigated if something goes wrong.
An internal AI readiness assessment specifically reviews identity and access management, data protection, information governance, collaboration controls, and security monitoring. It also evaluates controls such as multifactor authentication, trusted-device requirements, restrictive sharing, data-loss prevention, auditing, and SharePoint governance.
Assessment alone is not enough. Identified gaps must lead to remediation, and those improvements must be maintained as users, tools, integrations, and business requirements change.
Governance is not a document the firm completes once. It is an operating discipline.
Your MSP can provide value across the AI lifecycle:
Align's AI Governance and Readiness framework follows this same sequence: assess current-state usage, establish firmwide governance, implement appropriate controls, and securely configure the enterprise AI platforms employees will use.
Engaging the MSP after a deployment makes troubleshooting and remediation considerably more difficult. The team must reconstruct what the firm was trying to accomplish, determine which data the tool can access, review permission after the fact, and determine how the implementation aligns with the organization's governance and security requirements.
Those questions are easier to address at the beginning.
AI presents a meaningful opportunity for investment firms to improve productivity, strengthen knowledge management, and reduce operational friction.
But deployment is not the same as readiness.
Before purchasing another AI tool, Ask:
Is our firm prepared to use AI securely, responsibility, and effectively?
You do not need to have every element of your long-term AI strategy finalized today. You should, however, understand whether your organization is ready and where the gaps remain.
Before turning on another AI tool, ask your MSP to help assess your readiness. Build the governance, remediate the access issues, and agree on the operating model together.
AI can accelerate the work.
Your data, governance, and security foundation will determine whether it accelerates the right outcomes.
If you're evaluating AI initiatives and aren't sure whether your firm is ready, Align can help assess your current environment, identify governance and access-control gaps, and develop a roadmap for secure, responsible adoption.
The goal isn't simply to deploy AI. It's to ensure your organization has the foundation needed to use it effectively.