Operational Diagnostic Report
Evaluated Organisation (Fictional)
Geneva Fiduciary SA
35 employees · 3 partners
Evaluation Date
July 13, 2026
Cytria Scan Methodology v1.2
1. Overall Maturity Score
Evaluated Level
Level 2 of 4
Emergent usage,
no framework
This profile characterises organisations where the use of AI tools is initiated individually by employees (e.g. Copilot, public ChatGPT) to speed up drafting and synthesis tasks.
Key finding: No usage policy or governance framework has been formalised. Client data is processed on external third-party servers without access controls or data isolation, posing major risks of nLPD non-compliance and violation of fiduciary professional secrecy.
The 4 Cytria Maturity Levels:
2. Analysis of the 4 Dimensions
Client and billing files are stored on a shared local network drive. Employees occasionally copy segments of client declarations or financial analyses into public AI tools, exposing confidential client data to routing outside of Switzerland.
No policy or usage guideline for AI is distributed. There is no central register of AI tools in use, and no protocol defines responsibility for integrating AI outputs into advisory or tax audit reports.
Out of 35 employees, 3 use AI tools daily to accelerate administrative writing. This usage is purely individual and informal, with no shared prompts, best practices, or awareness of technical limitations like model hallucinations.
Several software vendors (accounting packages, HR software) have activated AI capabilities by default without opt-out options or strict legal guarantees to isolate client data from their model training loops.
3. Critical Risks Identified
Fiduciary Impact: Sourcing financial reports or specific tax situations into public web-based LLMs.
Recommended control to evaluate: Deploy a private internal assistant running on local GPU servers or secure Swiss VPC hosting, contractually ensuring that no data is retained or used for training.
Fiduciary Impact: Automated processing of sensitive personal data (payroll data, tax statements) without logging access or formal documentation.
Recommended control to evaluate: Formal document mapping, strict access logs stored locally, and an active usage framework.
Fiduciary Impact: Erroneous summaries of tax regulations or cantonal tax directives generated by generic public engines.
Recommended control to evaluate: Private semantic search algorithms mapping documents with exact citation tags, coupled with strict human validation requirements before any client output is sent.
4. Primary Action Recommended
To move out of critical risk without blocking staff productivity, the fiduciary must prioritize establishing basic governance and isolating internal data flows.
Key Step 1: Draft an AI usage framework & deploy sovereign access
- Distribute an AI Policy banning copy-pasting of nominative client data into public tools.
- Set up a secure private interface (an open-weight model hosted in Switzerland) with strict non-retention agreements.
Key Step 2: AI Governance & Readiness Audit
To analyze specific operational workflows, data flows and control requirements, Cytria recommends a structured AI Governance & Readiness Audit.
Diagnostic Methodology
What the diagnostic assesses:
This illustrative diagnostic evaluates organisational readiness, data perimeters, internal governance rules, and team operational practices.
What the diagnostic does not assess:
This report is an illustrative overview. It does not constitute a formal legal compliance audit or a technical security validation (penetration testing).
Privacy note on data handling:
All information reviewed during diagnostic engagements is treated confidentially and protected in compliance with the Swiss FADP.
If you have any questions regarding this sample report or wish to discuss your situation:
Cytria Sàrl · Chemin de la Florence 10 · 1208 Geneva
contact@cytria.com