Case Study

FTI Technology Provides Assessment, Testing and Governance Framework for Copilot Implementation at Large Financial Services Institution

A financial services institution was seeking to deploy Copilot across its Microsoft 365 environment as part of a broader objective to leverage artificial intelligence to improve employee efficiency and work experience. With a robust risk management program in place, the company understood the importance of testing and evaluating the legal and regulatory risks associated with the new generative AI tool. FTI Technology is a longstanding trusted advisor to the company across information governance, e-discovery and digital risk, and was engaged to conduct a robust governance assessment during a contained project pilot.

Our Role

Working with the organization’s IT, legal, compliance and outside counsel teams, FTI Technology initiated a Copilot evaluation as part of its larger, ongoing program for testing new technology. With deep expertise in Microsoft 365 governance and e-discovery, the team developed a workflow and customized testing plan to deliver a thorough examination of Copilot within an accelerated timeline, and ensured ongoing AI governance could be incorporated into the broader information risk management framework.

The assessment spanned every aspect of Copilot within the organization’s environment, from end-user impacts to administrative considerations and functionality, providing the client with a way to clearly understand the tool’s business value, legal and regulatory risks, and settings needed to mitigate potential issues. The team methodically went through each product within Microsoft 365 to identify specific risk issues within certain applications, so they could be escalated with Microsoft customer support. Throughout the review, FTI Technology identified the following:

  • Issues with certain Copilot activity and interactions that were not captured by Microsoft Purview Compliance tools.
  • Permissions and access controls for OneDrive and SharePoint content that could help avoid inadvertent or inappropriate user access to sensitive information.
  • Copilot artifacts that were unavailable to access or extract for potential e-discovery needs. This finding helped inform steps to establish litigation and investigative readiness for Copilot data.
  • Variances in risk between different tools within Microsoft 365, including the types and extent of data Copilot could access within each application, allowing the team to establish customized governance controls to prevent sensitive or protected information from access by unauthorized users.

As issues were identified, FTI Technology worked closely with the client to lead discussions with Microsoft around adjusting functionality and controls to resolve risks and improve capabilities. The team also provided the client with detailed reports of testing results, so they could socialize potential concerns across stakeholders and determine the settings and configurations needed to address them.

Related topics: