There's a conversation I have on first calls more often than almost any other.
Somewhere in the organization there's one person who holds the whole compliance program together. Their title might say information security, or risk, or operations, or IT. In practice they own a lot more than that: policies, vendor reviews, business continuity, incident response, the audit request list, and increasingly AI governance. They've been doing it for years. They built most of it themselves. And the audits go well, because they know exactly what the auditors will ask.
Then something changes. They're planning to step back. Or they're promoted into a bigger role. Or leadership finally asks the question out loud: what happens if this person isn't here?
The worry isn't the tasks
You'd expect the concern to be workload. Who writes the policies, runs the tabletop exercise, chases the vendor reports, pulls everything together when the auditors show up. Those things matter. But when I talk to the person who built the program, that's rarely what worries them.
What worries them is the reasoning. Anyone can be shown which buttons to push. The hard part is knowing why a control exists, which requirement it answers, and what an examiner will look for next year. That part lives in their head.
Most of them have already seen what happens when it doesn't transfer. A responsibility gets reassigned, the tasks keep getting done, and a year or two later an old finding comes back. Nobody made a mistake. They just didn't know why things had been done the way they were.
That's the real risk in a lot of compliance programs. It isn't a missing control. It's a program that lives in one person's head, calendar, and spreadsheets. It works beautifully until that person leaves.
We see this in community banks, law firms, accounting firms, asset managers, and growing companies of every kind. InfoSec, privacy, vendor risk, and AI governance matter a great deal to them, but none of it is the core business. So one capable person ends up owning all of it.
The two options everyone gets offered
When an organization realizes it has this problem, it usually hears two answers.
Buy a platform. Software tracks the controls, sends the reminders, and holds the evidence. That's useful, and we've built one. But a platform tracks what to do. It doesn't know why. It hands the work back to whoever is left, who now has a better system and the same gap in expertise.
Hire people or bring in consultants. Replacing someone who covers five or six functions usually takes more than one hire, if you can find them. Hourly consultants know their material, but you pay for every question. The first time someone forwards a customer questionnaire and asks "are we okay here?", the answer arrives with an invoice.
Neither option protects the thing that's actually at risk. One gives you tools without judgment. The other gives you judgment you have to ration.
What AI changed, and what it didn't
This is where most conversations about the future of professional services go wrong.
AI has made the assembly side of compliance cheap: mapping one policy across three frameworks, drafting the 200th questionnaire answer, organizing evidence, flagging a vendor report that's about to expire. That's real, and firms that don't use it will be priced out.
But assembly was never the scarce part. The scarce part is judgment. Which regulation applies. Whether a finding is worth fixing or worth accepting and documenting as a risk. What an examiner is going to ask next. When a clean-looking answer is wrong.
AI doesn't remove the need for that person. It makes that person the whole product.
What an expert-led, AI-native firm looks like
That's the model we're building at Greenplaces.
An expert owns the program, not a ticket queue. A senior practitioner learns your program the way your internal owner knows it: the audits you face each year, your board reporting rhythm, the reasons behind past decisions. They work alongside your team as part of it.
Machines do the assembly. Controls, policies, evidence, and the risk register live in one place that auditors can work from, not in spreadsheets and one person's memory. That keeps the expert focused on judgment instead of formatting.
The knowledge stays with the organization. When the person who built the program steps back, the reasons behind it are written down, kept current, and owned by someone accountable for them.
It's priced like a team, not a meter. A flat rate means finance can budget for it, and nobody hesitates to ask a question because of what it'll cost.
The best transitions we see aren't a switch flipped on someone's last day. They're a period of working side by side. You start with one area, build trust, and let the internal person who takes over grow into the role with an expert behind them. The organization doesn't need to hire a replacement for its most experienced person. It needs that person's reasons to stay in the building.
If you have one of these people
Most organizations do. If the answer to "who knows how our program works?" is one name, a few questions are worth asking now:
- If that person left tomorrow, which deadlines would someone else know about?
- Is the reasoning behind your accepted risks written down anywhere?
- Is your plan a tool, a hire, or an expert who can carry the judgment forward?
The next era of professional services will be built by firms that treat expertise as the product and use AI to deliver it. The tools get cheaper every month. The person who knows why doesn't.
If your program lives in one person's head, let's talk about continuity before it becomes a vacancy.