Insights

Why the Big 4 AI Governance Offering Won't Reach Mid-Market Firms

No Big 4 firm will publish a mid-market AI governance offering this year. Not because the capability is missing. All four have built it, staffed it and taken it to market over the past eighteen months. The obstacle is arithmetic, and arithmetic does not respond to demand.

Meanwhile a £500 million wealth manager carries precisely the same EU AI Act obligations as a £50 billion universal bank. The same FCA systems-and-controls expectations. The same DORA ICT risk management requirements. Both firms can ring their relationship partner on the same Monday morning. Only one gets back a proposal it can fund.

Research and drafting for this article were AI-assisted. Every figure is linked inline to the source that published it. Editorial responsibility is mine.

Four tall glass corporate towers lit in blue on the left, linked by a gold line to a much smaller office building and a glowing cyan governance shield on the right, on a dark navy field.
Produced by Gemini-Nano-Banana

That asymmetry is the most consequential thing happening in the AI advisory market right now, and almost nobody selling into it will say so out loud.

The Capability Exists. It Is Priced for Someone Else.

Four illuminated corporate towers rising above a row of small dark low-rise buildings, with glowing orange circuitry threaded between the towers and a fractured chasm in the foreground.
Produced by Gemini-Nano-Banana

Consider what has actually been built. PwC launched Assurance for AI in June 2025, putting AI engineering, risk management and attest services into single multidisciplinary teams, then followed it with Agent OS, an enterprise orchestration platform that took a 2026 CIO 100 Award. KPMG built its Trusted AI Framework around ISO 42001, the EU AI Act and DORA. Deloitte UK is moving audit staff into a fast-growing AI assurance practice. EY reports that 90% of financial services CEOs now claim board-level accountability for AI outcomes.

The research behind all of it is genuinely good. KPMG’s 2026 Global AI in Finance report contains the single most useful finding I have read on this subject: organisations with strong AI audit evidence capability achieve error reduction improvements at five times the rate of those without, 33% against 6%. That is not a marketing number. It is an operational one, and it tells you exactly where to spend.

Then you ask what it costs to act on it.

The Arithmetic

Bar chart contrasting three tall grey bars labelled Big 4 pricing with a single short glowing cyan bar labelled productised alternative, identical document icons strung between them at equal height.
Produced by Gemini-Nano-Banana

Big 4 AI governance engagements run $500,000 to $2 million for initial implementation across 18 to 24 months, with ongoing advisory of $300,000 to $500,000 a year. Strategy only, no implementation, no tooling, rarely lands under £250,000. Those figures come from Rovers Strategic Advisory, which brokers these engagements rather than critiques them.

Read that source the way you would read any number published by a competitor. It has an interest in the spread looking wide. Nobody who has sat on either side of one of these proposals disputes the direction of it, and the firms’ own published engagement structures point the same way, but treat the bands as indicative rather than audited.

The staffing model explains the spread. Big 4 engagements deploy analysts and associates at $200 to $400 per hour while selling the expertise of partners who appear quarterly. The mid-market client pays enterprise day rates for junior delivery. None of that is a criticism of the individuals involved, who are frequently excellent. It is a structural feature of a business built for FTSE 100 work, and structures do not apologise.

For contrast, BASG’s 2026 mid-market framework puts a workable governance baseline at $25,000 to $60,000 initially with $10,000 to $25,000 annually. Set that against a seven-figure implementation proposal and you are not looking at a discount. You are looking at two different industries pretending to sell the same thing.

There is a question worth putting to any proposal in this range, and it tends to end the meeting early. Ask what proportion of the fee covers work that will be done again, in almost the same form, for the next client in the same sector. Nobody answers it directly. The answer, for a governance mapping exercise across published frameworks, is most of it, and the reason the question is uncomfortable is that everybody in the room already knows.

Where the Mid-Market Actually Sits

A stepped pyramid of grey blocks topped by a single gold block, split down the middle by a jagged bolt of cyan light, standing on a glowing grid beside three slim icon pillars.
Produced by Gemini-Nano-Banana

Grant Thornton’s 2026 analysis puts numbers on the damage. Among firms in the $100 million to $1 billion revenue band:

  • 14% have a formal AI enterprise strategy, against 30% of emerging enterprise firms in the $1.1 to $5 billion band. Less than half the rate one tier up.
  • 70% have at least half their core applications not AI-ready, against 39% at the next tier.
  • 29% describe themselves as extremely well-prepared for AI-related privacy and security challenges. Among emerging enterprise firms it is 63%, and self-assessment tends to flatter, which makes the true gap wider than the survey shows.
  • 12% hold an AI incident response playbook.

Two to three times less prepared on every dimension that matters, and deploying at broadly the same pace. The Cambridge Centre for Alternative Finance found in its 2026 Global AI in Financial Services Report that 81% of financial services firms are using AI at some level, and firm size is not the variable that predicts it.

Adoption is size-blind. Preparedness is not. That is the whole problem in two sentences.

Regulation Does Not Read Your Revenue Line

The EU AI Act contains no revenue tiering. A high-risk AI system at a mid-market asset manager triggers the same Article 9 risk management duties, the same Article 11 technical documentation obligations and the same Article 14 human oversight expectations as an identical system inside a global systemically important bank. The obligation attaches to the system and its use, not to the balance sheet behind it.

The FCA’s practical guidance on AI, expected by the end of 2026, will apply SYSC 13 and SYSC 14 operational risk requirements to any regulated firm using AI in decision-making. Senior manager accountability already bites, and the FCA’s published approach is explicit that it does not intend to write AI-specific rules because the existing regime already reaches AI in use. There is no revenue threshold in that position, because there is no revenue threshold in the rules it points at.

DORA’s ICT risk management framework applies to every EU-regulated financial entity.

So the demand side is fixed. The question is capability, and here the McKinsey 2026 work on AI trust is bleak reading for firms of any size: governance and agentic controls are the two lowest-scoring dimensions in every region measured, and only one enterprise in three has reached adequate governance maturity for the autonomous agents it has already put into production.

One in three. Those are the firms that can afford the help.

Which leaves the mid-market in a genuine bind. Identical obligations to Tier 1, with an advisory market that has priced its answer exclusively for Tier 1. Forbes has called this a gap that could break financial markets, and the argument is not hysterical: systemic risk does not care whether the ungoverned model sits inside a bank with a compliance floor or a wealth manager with a compliance officer.

Why This Will Not Correct on Its Own

A glowing cyan shield at the centre of a ring, connected by gold spokes to eight icons covering cost, security, law, cloud, AI, partnership and connectivity.
Produced by Gemini-Nano-Banana

The staffing pyramid. A typical Big 4 engagement fields six to twelve consultants across a hierarchy: partner, director, senior manager, managers, senior associates, associates. Internal quality review, methodology alignment and risk sign-off sit on top of that. The combined overhead creates a cost floor that cannot be compressed much below £200,000 without the engagement losing money. Mid-market AI governance can be delivered for a fraction of £200,000, but not by a pyramid.

Bespoke by default. Each engagement opens on a blank canvas: custom framework, custom risk taxonomy, custom control catalogue. It maximises billable hours and it ignores something obvious, which is that the governance questions a £500 million wealth manager must answer overlap heavily with those facing a £5 billion bank. Same regulatory instruments. Same control objectives. What differs is the scale and messiness of the AI estate, not the architecture of the governance around it.

The managed services pivot stopped short. KPMG has moved hard into outcome-based managed services for financial crimes, packaging AI-driven AML monitoring as a multi-year subscription. That model could reach the mid-market. It has not, and the reason is instructive: it works because transaction monitoring is one well-bounded function with a repeatable output. Governance across an entire AI estate is not one function, so the same commercial wrapper does not fit without rebuilding what sits inside it.

Notice what the pivot concedes. A firm that starts subscription-pricing part of its work has accepted that bespoke advisory does not scale down. It simply has not applied the lesson to governance yet.

The Objections Worth Taking Seriously

Three push back at me regularly, and one of them is nearly right.

“Just hire a governance lead.” A good hire helps enormously. It does not solve the problem, because the person you hire spends their first year discovering what the firm owns, and the talent pool that could shorten that year is being absorbed by exactly the Big 4 practices described above. Ask any mid-market COO how the last governance hire went. The role is real, the market for it is thin, and one person cannot both build the mapping and chair the committee that reviews it.

“The frameworks are free.” They are. NIST’s AI Risk Management Framework, ISO 42001 and the AI Act’s risk tiers are published, and a competent risk officer can read all three inside a fortnight at no cost. Free to download is not the same as mapped to your systems, and the mapping is the work. This is the objection that comes closest to right, and it is also the one that most reliably produces a beautiful policy document sitting above an AI estate nobody has inventoried.

“The Big 4 will get to it eventually.” They have had two years and a visible market. Not one has published a mid-market AI governance offering with transparent pricing.

There is a harder version of all this in the Cambridge data, which found that 62% of the heaviest AI spenders reach advanced maturity. Money buys governance maturity. That is precisely why a pricing gap becomes a governance gap rather than merely a commercial inconvenience.

The Gap Is Operational, Not Intellectual

Nobody is short of frameworks. What is missing is the translation: mapping published requirements onto a named list of the firm’s own AI systems, finding where controls are absent or performative, and producing a record a supervisor can actually read.

A mid-market firm running AI in credit decisioning, client servicing or portfolio analytics does not need eighteen months and twelve consultants. It needs the same questions asked, across the same regulatory instruments, through a delivery model that does not rebuild the whole thing from scratch for every client. Build the mapping once. Run it many times.

KPMG’s own data says why that matters. The firms that pull ahead are the ones that can produce AI audit evidence efficiently, and the differentiator is not framework sophistication. It is whether a firm can demonstrate rather than assert that its controls exist and work.

The Advantage Nobody Is Pricing

The Grant Thornton table measures one direction only. Mid-market firms are behind on every measure in it, and they also hold something no Tier 1 institution can buy.

Fewer legacy AI systems. A model inventory small enough for one person to hold in their head. A decision chain short enough that a COO can change a control on Tuesday and see it applied on Wednesday. The £50 billion bank will spend the better part of a year simply establishing what it owns, across how many business units, under which committee. A £500 million manager can know by Friday.

That is a real edge, and it is perishable. It lasts exactly as long as the AI estate stays small, which is not long at current adoption rates.

So the pricing gap is worth being annoyed about. It is not withholding a luxury from smaller firms. It is withholding the one thing that would let them convert a genuine structural advantage into a defensible position, in the narrow window before the estate grows past the point where anyone can hold it in their head.

The obligations arrived on the same date for everybody. The help did not.

Regulatory position as at April 2026. Timetables and supervisory expectations described here were current at that date and are moving quickly.

Sources

AI GovernanceMid-MarketFinancial Services