Revenue playbook · Updated July 10, 2026

How MSPs Monetize AI Governance

AI governance is a real, near-term revenue line — not a someday play. The demand triggers are already live: enacted state AI laws, insurers adding AI questions to renewals, and clients ranking AI/automation as their #1 need. This is the opportunity-forward playbook: six service lines, pricing benchmarks presented as ranges, a land-and-expand ladder, and the talk tracks that turn a governance conversation into recurring revenue.

Current as of July 10, 2026 · Pricing figures are ranges; several are labeled estimates and vendor-sourced figures carry bias. Not legal advice.

The short version

Three things every MSP should take away

Demand is validated but under-monetized

Kaseya's 2026 State of the MSP Report (1,000+ MSPs) found 48% of clients now rank AI/automation as their #1 need — ahead of security (42%) and backup (36%) — yet only 13% of MSPs earn meaningful revenue from it. That gap is the opportunity, and it sits inside your existing base where new-customer acquisition is hardest.

The winning structure is a land-and-expand ladder

A paid shadow-AI assessment lands the account, a billable AI acceptable-use policy follows, managed governance turns it into MRR, and a vCISO retainer moves it up-market — with training running alongside as the recurring evidence layer. Each rung has a natural trigger to the next, so nothing has to be sold cold.

The premium is in regulated verticals and audit moments

Healthcare (HIPAA), finance (GLBA), and legal clients pay 20–40% more because the compliance work is genuine. And the sharpest openers tie AI governance to a specific event — an insurance renewal questionnaire, a new state law, or a breach headline — not to a vague future risk.

The offer set

The six service lines

Every line below applies existing MSP muscle — security policy, compliance navigation, software standardization, access management — to a new, fast-growing problem. Each card carries a representative price range, who buys it, and the sales motion that opens it.

1One-time · the "land" offer

Shadow-AI Assessment

$1,500–$7,500 one-time

A fixed-fee engagement that inventories the AI tools actually in use (browser ChatGPT/Claude/Gemini/Copilot, embedded SaaS AI, M365 OAuth grants), attributes usage to users, flags PII/PHI/source-code exposure, and delivers a written risk report with a remediation roadmap. Buyers: the owner/GM at a 20–200-seat SMB, or a compliance lead in a regulated firm. Regulated verticals price at the top; generic AI-readiness audits run $2,500–$25,000.

Sales motion

Lead with a free or low-cost discovery scan on a real tenant, then convert on specificity — "here are the 14 AI tools your staff used last month, and here is the client data that left your environment."

2One-time deliverable

AI Acceptable-Use Policy (AUP)

$1,000–$5,000 one-time (estimate)

A written policy defining sanctioned tools, data classes that may never be entered, required human-oversight steps, and an enforcement process — increasingly demanded by SOC 2 auditors, HIPAA assessors, and insurers, who now treat the absence of one as a governance failure. Buyers: any SMB, urgently those in healthcare, legal, and finance. Free templates exist, so the billable value is the customization, framework mapping, and enforcement design — not the boilerplate.

Sales motion

"You have a policy for passwords and remote access; you have none for the single fastest-spreading tool in your business." Always sell it with enforcement — a policy without a control is a wall with no gate.

3Recurring MRR

Managed AI Governance

~$2–$8 / seat / month

The recurring engine: ongoing monitoring and enforcement — policy cascade, prompt DLP/redaction, blocking unsanctioned tools, identity-gated access to approved AI, and monthly usage/risk reporting. Sold per-seat or per-endpoint, attached at renewal. Tool cost runs roughly $0.80–$4/device; client price applies the standard 2–3x resale markup (ShadowLock’s own playbook suggests 30–60% over device cost). Best folded into a Security+ / Premium tier, not sold as a standalone SKU.

Sales motion

"Your AUP is only a document until something enforces it. For $X per seat we monitor and enforce it, and you get a monthly report you can hand to your auditor or insurer." The report is the retention mechanism.

4Recurring retainer

vCISO / Compliance Advisory

$2,600–$15,000 / month

AI governance folded into a virtual-CISO retainer: AI risk register, framework alignment (NIST AI RMF / ISO 42001), board reporting, and audit point-of-contact duties. Buyers: 50–1,000-employee firms that need security leadership but can’t justify a full-time CISO ($250k–$350k+ loaded). Regulated/multi-framework engagements reach $10k–$20k/month. Per Cynomi, the share of MSPs offering vCISO more than tripled year-over-year (21% → 67%).

Sales motion

Assessment → conversion: Cynomi reports 50%+ of assessment clients convert to a vCISO engagement, higher when the assessment surfaces specific risks the client didn’t know about. Anchor against the full-time CISO cost; present outcomes, not activity lists.

5Hybrid (sprint + recurring)

Compliance & Insurance Readiness

Sprint $2,500–$10,000 + recurring

Helping clients answer the AI questions on security questionnaires and insurance renewals — assembling the evidence packet (written AI policy, training completion records, approved-tool inventory, attestations) and, at the top end, ISO 42001 readiness ($15k–$50k+ implementation if they pursue formal certification). Buyers: every client facing a renewal or enterprise questionnaire; urgency peaks 30–180 days out.

Sales motion

"Your carrier is asking whether you share data with AI systems. Right now the honest answer is ‘we don’t know.’ Here’s how we fix that before renewal — and it may lower your premium or restore a sublimit." Misrepresentation voids policies, so documented answers are both compliance and leverage.

6Recurring, runs alongside every rung

Client Training / Enablement

$2–$5 / user / month

AI acceptable-use training delivered as a service — short, role-based modules on what not to paste into public AI tools and why, with completion tracking for audit/insurance evidence. Buyers: every client; mandatory-feeling in regulated verticals. Tool wholesale runs ~$0.45–$3.25/user/mo (a security-awareness proxy). The behavior problem is documented: PagerDuty’s 2026 survey found 66% of AI-using workers used it despite believing it violated policy.

Sales motion

"Training completion records are exactly what your insurer and auditor ask for. We make the training a five-minute monthly habit and hand you the compliance report." Tie it to regulation and insurance, not to "another expense."

At a glance

Summary pricing table

Every range is presented with the context that drives it. Pricing varies widely by client size, scope, and vertical — read these as starting points, not quotes.

Service lineModelRepresentative price rangeWhat drives the range
Shadow-AI assessmentOne-time$1,500–$7,500 SMB (up to $15k+ regulated/mid-market); generic AI-readiness $2,500–$25,000Seat count, depth, vertical, whether bundled as a loss-leader
AI AUP developmentOne-time$1,000–$5,000 (estimate)Customization, vertical, framework mapping, enforcement design
Managed AI governanceRecurringTool cost $0.80–$4 / device or user / mo; client price ~$2–$8 / seat / mo (2–3x markup)Tool tier, seat volume, bundled vs. standalone
vCISO w/ AI governanceRecurring$2,600–$15,000 / mo (regulated $10k–$20k)Company size, # frameworks, audit clock, advisory vs. hands-on
Insurance / compliance readinessHybridSprint $2,500–$10,000; ISO 42001 implementation $15k–$50k+; CaaS +20–50% of IT MRRFramework, certification vs. compliance, existing controls
AI-use trainingRecurringClient price $2–$5 / user / mo (tool cost $0.45–$3.25)Platform tier, seat volume, bundling

One-time figures for the AUP and the SMB assessment low end are labeled estimates; MSP-specific published benchmarks for those exact deliverables are thin. All recurring client-facing figures assume standard MSP markup and vary by market. Vendor-sourced figures (e.g., markup guidance and waterfall claims) carry bias and should be validated against your own cost model.

The motion

The land-and-expand ladder

You don’t sell five products cold. You land one, and each rung creates the trigger that opens the next.

  1. 1

    Rung 1 — Paid shadow-AI assessment

    The low-risk land offer. Fixed-fee, productized, deliberately a loss-leader that scopes the follow-on work.

    Trigger to climb: The report surfaces specific, unmanaged AI usage and data exposure the client didn’t know about.

  2. 2

    Rung 2 — AI AUP development

    Sold immediately after the assessment — the assessment surfaces the exact risks the policy addresses.

    Trigger to climb: The client acknowledges the policy is only a document without enforcement.

  3. 3

    Rung 3 — Managed AI governance (MRR)

    The recurring destination. Enforcement + monthly reporting, folded into a premium security tier.

    Trigger to climb: The client faces an insurance renewal, a security questionnaire, or an audit requiring documented, ongoing evidence.

  4. 4

    Rung 4 — Insurance / compliance readiness

    A readiness sprint plus recurring evidence maintenance, folded into the governance or vCISO line.

    Trigger to climb: Regulatory exposure grows (new contract, new framework, new vertical) or leadership wants board-level assurance.

  5. 5

    Rung 5 — vCISO / compliance advisory retainer

    The highest-margin, stickiest rung: named security leadership and multi-framework management.

    Then: Templatize per vertical (HIPAA first) and repeat across the base.

Training runs alongside every rung

Client AI-use training is the evidence-generating recurring layer beneath the whole ladder — its completion records feed directly into the insurance and compliance evidence packet at every rung.

In the room

QBR & sales talk tracks

The sharpest openers tie AI governance to a specific event. Five that convert:

The insurance renewal (most reliable)

"Your cyber renewal is in Q[X]. Carriers are now asking whether employees share data with AI tools and whether you have a written AI policy and training records. If we can’t answer those, you risk a higher premium, an AI sublimit, or a denied claim later. Let’s run a two-week AI exposure assessment so the application is a paperwork step, not a scramble."

The new law

"Texas’s AI law has been enforceable since January, the EU AI Act’s high-risk rules phase in from August, and more states are following. The safe-harbor path is a documented program aligned to NIST AI RMF. We can build that starting with an inventory and a policy — before it’s a fire drill."

The breach headline

"You saw the story — an employee pasted confidential data into a public AI tool. We don’t actually know if that’s happening in your shop right now. A quick discovery scan will tell us, and we can show you exactly which tools and which data."

The Copilot / adoption angle (opportunity-forward)

"You’re rolling out Copilot. Before it inherits every oversharing permission you have, let’s audit access and set the guardrails — so AI accelerates your team instead of surfacing data it shouldn’t."

The "everyone’s already using it" opener

"Industry research shows two-thirds of companies that think they have AI under control are still finding unauthorized use. Let’s find out where you actually stand — it’s a fixed-fee assessment and you’ll get a report you can act on."

Where the premium is

Positioning by vertical

Each regime adds real tooling, audit work, and documentation overhead — which is why vertical-focused MSPs price 20–40% above generalist peers. The compliance scope is genuine work clients recognize.

Healthcare

HIPAA

Highest urgency. The modernized HIPAA Security Rule shifts to "show me the evidence," and PHI pasted into public AI is a textbook exposure. Business Associates (including MSPs) face more scrutiny; MSP-specific HIPAA credentials build credibility.

Finance

GLBA / FTC Safeguards / PCI

Documented risk assessments and data-handling controls are mandatory, and AI governance slots directly into existing Safeguards obligations. Strong willingness to pay for attestation and evidence.

Legal

Confidentiality & privilege

Uncontrolled AI use is an existential risk, and document-heavy workflows mean both high adoption and high exposure. Small firms rarely have internal expertise — ideal vCISO/advisory buyers.

Objection handling

The five you’ll hear, and how to answer them

"We don’t use AI."

Counter with evidence, not argument: run the discovery scan. Every environment shows ChatGPT/Copilot/Gemini traffic and embedded-AI SaaS. Employees adopt tools faster than policy — PagerDuty’s 2026 survey found 66% of AI-using workers used it despite believing it violated policy. The scan makes denial untenable and reframes the conversation around facts.

"It’s just a policy template."

The billable value is enforcement, framework mapping, and audit-ready evidence — not boilerplate. A policy without a control is a wall with no gate. Sell the recurring enforcement plus reporting, which templates can’t replicate.

"We don’t have the tooling or expertise."

The channel ecosystem closes this. Multi-tenant platforms built for MSPs (ShadowLock, DefensX, Longwave, CultureAI, Guardz) handle discovery and enforcement; enablement layers like Cynomi and Lemhi provide the advisory operating model. AI governance is an extension of existing security and compliance work, not a new discipline.

"We don’t know how to price it."

Start with the fixed-fee assessment as a low-risk land, use its findings to scope the recurring work, and bundle governance into a premium security tier rather than line-iteming a novel SKU. Mark up tooling 2–3x per the standard resale norm. (Note: MSP-specific benchmarks for the newest deliverables are thin — treat the AUP and SMB-assessment low-end figures as estimates, not surveyed prices.)

"Why would clients trust us on AI?"

Adopt AI governance internally first — run your own AUP, staff training, and shadow-AI tool on your own environment — so client rollouts are proven, not theory. That generates case-study proof points and de-risks delivery.

Frequently asked

Monetizing AI governance, answered

Can MSPs make money from AI governance?

Yes — it is a real near-term revenue line, not a someday play. Kaseya's 2026 State of the MSP Report found 48% of clients rank AI/automation as their top need, yet only 13% of MSPs earn meaningful revenue from it. The demand triggers are already live (enacted state AI laws, insurers adding AI questions to renewals, audit expectations), and every service line — assessment, policy, managed governance, vCISO, and training — maps onto existing MSP muscle in security, compliance, and access management.

How much should an MSP charge for a shadow-AI assessment?

For a 20–100-seat SMB, a productized shadow-AI assessment realistically prices $1,500–$7,500 one-time, with regulated verticals at the top and larger or mid-market scopes reaching $15,000+. (The SMB low end is an informed estimate — MSP-specific benchmarks for this exact deliverable are thin.) Generic AI-readiness audits in the broader market run $2,500–$25,000. Price it as a loss-leader that scopes the follow-on work, and avoid sub-$2,000 "audits," which are really sales calls.

What is the best way to package AI governance as a service?

Use a land-and-expand ladder rather than one big SKU. Land with a paid shadow-AI assessment, follow with a billable AI acceptable-use policy sold alongside enforcement, convert to managed AI governance as recurring MRR bundled inside a Security+ tier, then move regulated clients up to a vCISO retainer — with training running alongside as the recurring evidence layer. Each rung has a natural trigger (an unmanaged-usage finding, a policy that needs enforcement, an insurance renewal) that opens the next.

How do MSPs price managed AI governance per seat?

The common approach is cost-plus: tool cost runs roughly $0.80–$4 per device or user per month, and MSPs apply the standard 2–3x resale markup (ShadowLock’s own playbook suggests 30–60% over device cost), landing a client-facing price of roughly $2–$8 per seat per month. This is an estimate for a nascent category with no verified community price consensus yet — and it is usually folded invisibly into a security bundle rather than line-itemed, which reduces price sensitivity and churn.

Which verticals pay the most for AI governance?

Regulated verticals — healthcare (HIPAA), finance (GLBA / FTC Safeguards), and legal (confidentiality and privilege) — because the compliance work is genuine and audit- or insurance-driven. Vertical-focused MSPs price 20–40% above generalist peers, and regulated-vertical MSP pricing already runs $40–$100 per user per month above standard bands. Healthcare typically carries the highest urgency and premium, which makes it the natural first vertical playbook.

How do I start an AI governance practice?

Adopt AI governance internally first (your own AUP, staff training, and a shadow-AI tool on your own environment) to create proof points and de-risk delivery. Then pick one multi-tenant shadow-AI platform, productize a fixed-fee assessment ($1,500–$7,500 SMB), and close three to five paid assessments from your existing base. Convert those into AUP and managed-governance follow-ons, attach at renewals with the insurance and new-law talk tracks, and move regulated clients up to a vCISO retainer once the recurring base is established.

Turn AI governance into a service line

Every rung on the ladder — the assessment, the policy, the managed-governance MRR — needs an evidence layer underneath it. ShadowLock gives MSPs multi-tenant endpoint and browser visibility into unauthorized AI use across every client, so the discovery scan, the enforcement, and the monthly compliance report all run from one console.