Operational Diagnostic Report
Evaluated Organisation (Fictional)
Geneva Fiduciary SA
35 employees · 3 partners
Evaluation Date
July 13, 2026
Cytria Scan Methodology v1.2
1. Overall Maturity Score
Evaluated Level
Level 2 of 4
Emergent usage,
no framework
This profile characterises organisations where the use of AI tools is initiated individually by employees (e.g. Copilot, public ChatGPT) to speed up drafting and synthesis tasks.
Key finding: No usage policy or governance framework has been formalised. Client data is processed on external third-party servers without access controls or data isolation, posing major risks of nLPD non-compliance and violation of fiduciary professional secrecy.
The 4 Cytria Maturity Levels:
2. Analysis of the 4 Dimensions
Client and billing files are stored on a shared local network drive. Employees occasionally copy segments of client declarations or financial analyses into public AI tools, exposing confidential client data to routing outside of Switzerland.
No policy or usage guideline for AI is distributed. There is no central register of AI tools in use, and no protocol defines responsibility for integrating AI outputs into advisory or tax audit reports.
Out of 35 employees, 3 use AI tools daily to accelerate administrative writing. This usage is purely individual and informal, with no shared prompts, best practices, or awareness of technical limitations like model hallucinations.
Several software vendors (accounting packages, HR software) have activated AI capabilities by default without opt-out options or strict legal guarantees to isolate client data from their model training loops.
3. Critical Risks Identified
Fiduciary Impact: Sourcing financial reports or specific tax situations into public web-based LLMs.
Required Control: Deploy a private internal assistant running on local GPU servers or secure Swiss VPC hosting, contractually ensuring that no data is retained or used for training.
Fiduciary Impact: Automated processing of sensitive personal data (payroll data, tax statements) without logging access or formal documentation.
Required Control: Formal document mapping, strict access logs stored locally, and an active usage framework.
Fiduciary Impact: Erroneous summaries of tax regulations or cantonal tax directives generated by generic public engines.
Required Control: Private semantic search algorithms mapping documents with exact citation tags, coupled with strict human validation requirements before any client output is sent.
4. Primary Action Recommended
To move out of critical risk without blocking staff productivity, the fiduciary must prioritize establishing basic governance and isolating internal data flows.
Key Step 1: Draft an AI usage framework & deploy sovereign access
- Distribute an AI Policy banning copy-pasting of nominative client data into public tools.
- Set up a secure private interface (an open-weight model hosted in Switzerland) with strict non-retention agreements.
Key Step 2: Focused Review
To analyze specific operational workflows, Cytria recommends a Focused Review of your key processes.
Sovereignty Scan Methodology
What the diagnostic assesses:
The Sovereignty & AI Maturity Scan is a preliminary evaluation based on a 30-minute online questionnaire. It assesses organizational maturity, data exposure, internal governance, and team awareness.
What the diagnostic does not assess:
This report is a preliminary guidelines overview. It does not constitute a formal legal compliance audit or a technical security validation (penetration testing).
Privacy note on data handling:
All answers collected during the online scan remain anonymous and confidential. If a founder review or briefing is scheduled, the data is used solely to prepare the session and is protected in compliance with the Swiss nLPD.
If you have any questions regarding this sample report or wish to schedule your own scan:
Cytria Sàrl · Chemin de la Florence 10 · 1208 Geneva
contact@cytria.com