The CEO of a PE-backed marketing agency should, before a sale process opens, list every AI tool used on client work with the contract term that governs it, what the client was told and who reviewed the output, then check that list against one published framework.
Morgan Lewis, a law firm with corporate and technology transactions practices, whose site says some of its content is considered attorney advertising, wrote for dealmakers on March 31, 2026, that AI diligence is now a baseline requirement and that evaluating AI means examining in detail systems, training data, governance models, regulatory exposure, and risk controls.
At an agency, the list should start from the client contracts. An ANA piece dated June 26, 2025 says the Association of National Advertisers, along with Venable LLP, created an AI Rider template to help its members draft and negotiate the use of AI Tools in their ad creative service arrangements. That piece is open to members only, so the terms here are AdExchanger's account of July 17, 2025: as written, agencies are required to tell their clients when they use AI tools for any work output and cannot pass off AI-generated work as being done by humans, with some degree of human oversight on any AI-generated work. Those duties bind an agency only where a client adds the rider to its service agreement, and AdExchanger reported that the ANA couldn’t share any details about adoption.
Each line of the list names the tool, the client, the contract clause on AI, the date and form of the client's disclosure, and the person who reviewed the output. Where a contract says nothing about AI, the line records that, along with what the client was told in writing. Where a clause required disclosure and none was given, the line records that too, and the agency's lawyers review it before the sale process opens.
The check needs a named standard to run against. ISO/IEC 42001, a standard ISO sells, published in December 2023, specifies requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS) within organizations, for organizations involved in developing, providing, or using AI-based products or services. ISO says it does not perform certification or issue certificates; external certification bodies do, and for some industries, ISO notes, certification is a legal or contractual requirement. The NIST AI Risk Management Framework, released January 26, 2023, is intended for voluntary use, and NIST added a generative AI profile on July 26, 2024.
In month one the chief operating officer gathers every AI tool that staff and freelancers use on client work, from software licences, expense claims and a written question to every team and freelancer. Account directors then fill in the contract clause, the disclosure and the reviewer for each of their clients during month two. By the month three review, the COO checks the list against the NIST framework and notes which version was used, and the CEO takes the gaps to the board.
The work can stop at the list and that one self-assessment, with certification to ISO/IEC 42001 left until a client contract asks for it. NIST's own page for the framework says The AI RMF 1.0 is being revised as part of the White House AI Action Plan.