Consulting 12 min read

The consulting firm's real product is memory: institutional knowledge, procedures, and the advantage the big firms already built.

McKinsey built a private AI on a century of firm knowledge and made it the only place consultants can use client data. That is not a technology story. It is a revealed preference about what a consulting firm actually is.

The Short Answer

A consulting firm's product is not the deliverable. It is the accumulated judgment behind it: engagement archives, methodologies, procedures, and trained people. That asset leaks constantly through attrition, and it compounds only when captured. The largest firms have already built private AI on top of their institutional knowledge. Firms that keep renting generic AI while their knowledge sits unmanaged are competing against firms that own theirs.

Ask a client why they hired your firm and they will not say "for the PowerPoint." They hired you because your team has seen this problem before. Fifty times before, across different industries, failure modes, and personalities. The deliverable is an artifact. The product is memory.

That is worth sitting with, because it means a consulting firm is one of the purest knowledge businesses that exists. There is no factory, no inventory, no patent portfolio. The entire enterprise value is people plus what the firm collectively knows, and only one of those two stays when someone resigns.

Most firms manage the people side obsessively: recruiting, utilization, reviews, comp. The knowledge side gets a shared drive, a wiki nobody updates, and a prayer. This article is about closing that gap. It covers what institutional knowledge actually consists of in a consultancy, why the industry's own operating model is engineered to destroy it, what the largest firms have already done about it, and how procedures, training, and AI application across the full engagement lifecycle turn legacy knowledge from a liability into the most defensible asset a firm can own.

What institutional knowledge actually is in a consultancy

Institutional knowledge in consulting is broader than most partners assume when they hear the term. It is not just "old decks." A working taxonomy:

Engagement archives. Final deliverables, yes, but also the working materials behind them: analysis models, interview notes, data room findings, the three approaches that were tried and discarded before the one that worked.

Methodologies and frameworks. The firm's actual way of doing things. How you structure a diagnostic, run a workshop, size a market, stand up a PMO. Often this exists at full fidelity only in the heads of the people who built it.

Procedures and quality standards. Review protocols, citation and sourcing standards, engagement setup checklists, risk escalation paths. The unglamorous layer that keeps the glamorous layer from blowing up. More on this below, because 2025 gave the industry a very public lesson in what happens without it.

Commercial memory. Proposal libraries, win-loss history, pricing decisions and their outcomes, scoping assumptions that held and ones that did not. The difference between a firm that prices from data and one that prices from vibes.

People and network knowledge. Who inside the firm has actually done this work. Which subcontractors deliver. Which client stakeholders move decisions.

Lessons learned. The most valuable and least captured category. What went wrong, why, and what the team would do differently. Almost always discussed at the bar after the engagement and recorded nowhere.

The research on how badly this asset is managed is blunt. One widely cited study found that 42 percent of institutional knowledge is held solely by individual employees, unshared with coworkers, and that knowledge workers spend an average of 5.3 hours per week waiting for information from colleagues or recreating knowledge that already exists somewhere in the organization. The same research pegged the productivity cost of inefficient knowledge sharing at an average of $47 million per year for large U.S. companies. In a business that bills by the hour, 5.3 hours per consultant per week of searching and recreating is not an abstraction. It is margin, walking.

The consulting model is engineered to lose knowledge

Every industry loses knowledge to turnover. Consulting is unusual in that its core operating model is designed around departure.

Up-or-out promotion systems, the alumni-network business development strategy, and the two-to-three-year analyst tour are all features, not bugs. But they guarantee a structural knowledge exodus. Professional services attrition averaged roughly 12 percent in 2024 against a five-year average near 13 percent, and attrition at the largest firms has historically run higher, in the 15 to 20 percent range. Run a 15 percent rate against a ten-year horizon and the math is stark: the majority of the people who built your current methodology will not be at the firm to explain it.

The cost side is equally well documented. Replacing an employee typically costs 50 to 200 percent of their annual salary, and for senior knowledge workers the true figure skews to the top of that range because the visible replacement costs are the smallest component. Analyses of knowledge-worker attrition decompose the real cost into five parts: direct replacement, productivity loss, team disruption, erosion of institutional knowledge and innovation capacity, and risk cost. Most firms measure only the first. McKinsey's own research estimates that mid-size S&P 500 companies lose between $228 million and $355 million per year to attrition and disengagement combined.

For a boutique or mid-market consultancy there is a second clock running: founder and senior partner retirement. In firms built around two or three rainmakers, the institutional knowledge concentration is extreme. The firm's pricing judgment, client relationships, and methodology may live 80 percent inside two skulls. Without deliberate capture, a retirement is not a transition. It is a partial liquidation that never shows up on a closing statement.

A firm that captures engagement knowledge converts every project into two deliverables: one the client pays for, and one the firm keeps forever. A firm that does not is doing the work, getting paid once, and letting the asset evaporate.

What McKinsey figured out, and what it tells everyone else

If you want to know what the smartest money in consulting believes about institutional knowledge, do not read their thought leadership. Look at what they built for themselves.

In July 2023, McKinsey launched Lilli, a proprietary internal AI platform named for Lillian Dombrowski, the firm's first professional woman, hired in 1945, who organized its archives. Lilli sits on top of the firm's knowledge base: more than 40 curated knowledge sources and over 100,000 documents, interview transcripts, and sector playbooks representing roughly a century of accumulated intellectual property. Ask it a question and it retrieves the most relevant internal artifacts with citations and points you to the partners with the deepest expertise on the topic.

The adoption numbers are the proof of value. More than 75 percent of McKinsey's roughly 43,000 employees use Lilli monthly, averaging about 17 interactions per week and generating over 500,000 prompts per month. The firm reports it saves consultants roughly 30 percent of the time previously spent gathering and synthesizing information. McKinsey has since deployed thousands of specialized internal AI agents on the same foundation for tasks like document summarization, deck creation, and writing in the firm's house style.

But the most instructive detail is a policy detail. McKinsey permits employees to use public tools like ChatGPT internally, yet Lilli is the only platform on which consultants are allowed to input confidential client data.

Read that as a revealed preference from the most sophisticated knowledge business on earth: general-purpose cloud AI is fine for generic work, and the crown jewels only touch infrastructure the firm controls.

Honesty requires the next chapter too, because your best-informed colleagues will know it. In March 2026, a red-team security startup published findings that its autonomous AI agent had exploited a vulnerability in Lilli's infrastructure and reached its production database in roughly two hours. McKinsey reported that it patched the issues within hours of disclosure and that its forensic investigation found no evidence of unauthorized access to client data. Two lessons come out of that episode, not one. Owning the vault does not exempt anyone from securing it: private infrastructure concentrates value, value attracts attack, and security discipline belongs to the procedures layer this article keeps returning to. And when the incident came, the party answering for it was the firm itself: its own patch, its own forensics, its own client conversations, with no third-party vendor's terms of service or breach timeline standing in the middle. That is what control looks like on a bad day, and bad days belong in the analysis.

McKinsey is not alone. PwC piloted an internal assistant, and BCG, Deloitte, and KPMG have all built comparable internal platforms on their own knowledge bases. Industry surveys show generative AI implementation in consulting and legal services jumped from 33 percent in 2023 to 71 percent in 2024, the fastest uptake of any sector.

So the frontier of the industry has converged on a model: private AI, on proprietary knowledge, under firm control, as the default work surface. The open question is not whether that model wins. It is whether mid-market and boutique firms adopt it while it is still a differentiator, or after it becomes table stakes. Because right now, the typical mid-market firm's version of "AI strategy" is forty consultants with personal chatbot subscriptions, no shared knowledge layer, and client-confidential material moving through consumer tools the firm has never vetted.

Procedures: the layer that failed in public

In October 2025, the consulting industry got its cautionary tale. Deloitte Australia agreed to refund the final installment of a A$440,000 contract with the Australian government after a 237-page assurance report was found to contain fabricated academic citations, references to nonexistent research, and a fabricated quote attributed to a federal court judgment. A university researcher flagged the errors publicly, and the revised report disclosed that a generative AI model had been used in drafting. The department kept the report's substantive recommendations, but the reputational damage was global news, and commentators across the profession called it a wake-up call on AI governance.

The instinctive reading is "AI is risky." The correct reading is "procedures are load-bearing." The model did what ungoverned models do: it generated plausible text, some of it false. What failed was everything around it: sourcing standards, citation verification, review protocols, disclosure practice. Those are procedures, which is to say, codified institutional knowledge about how the firm protects its name.

This is why procedures deserve equal billing with engagement archives in any knowledge strategy. A firm's QA checklist is the compressed memory of every past near-miss. When it lives in a partner's habits instead of a system, it scales exactly as far as that partner's calendar. When it is codified, embedded in workflow, and enforced by the same knowledge platform consultants already use, quality becomes a property of the firm rather than a property of whoever happens to staff the review. In an AI-accelerated delivery model, that distinction is existential: AI raises output volume, and only procedure keeps error rates from rising with it.

A practical standard worth adopting now, ahead of client demand: document which AI systems touch each deliverable, require human verification of every citation and factual claim, and disclose material AI use in the engagement letter or the deliverable itself. Firms that institutionalize this early will be selling trust while competitors are drafting apology letters.

Training: the apprenticeship model meets its successor

Consulting has always trained people the expensive way: apprenticeship. Juniors learn by doing low-leverage work next to seniors who correct them. It works, and it takes years, and it is now under real pressure, because AI is absorbing exactly the tasks juniors used to learn on. When internal AI platforms draft slides, summarize documents, and assemble research, the traditional bottom rung of the ladder gets thinner. The firms deploying these tools say junior roles shift toward client-facing and strategic work earlier, which raises an uncomfortable question: earlier, with what judgment, learned from what reps?

The answer has to be deliberate knowledge infrastructure. A structured, searchable, AI-accessible knowledge base changes training economics in three ways:

Ramp time collapses. A new hire who can interrogate the firm's entire engagement history conversationally ("show me how we have approached carve-out separations for clients under $500M, and what went wrong") compresses months of hallway learning into days. McKinsey's reported 30 percent reduction in information-gathering time is, functionally, a training subsidy applied to every consultant every week.

Tacit knowledge gets a capture path. Exit interviews, engagement close-outs, and post-mortems become asset transfers instead of rituals when there is a system that ingests them and serves them back in future work. The 42 percent of knowledge trapped in individual heads only moves when there is somewhere for it to go and a workflow that routes it there.

Training becomes a product, not an event. Onboarding curricula, methodology guides, and QA standards maintained in the knowledge base stay current because they live where the work happens. The alternative, the annual offsite and the aging LMS module, trains people on how the firm worked three years ago.

There is a retention effect, too. Consultants leave firms where growth stalls. A firm whose collective intelligence is genuinely accessible makes every consultant better, faster, and that is a stay-reason money struggles to buy.

Depth and breadth: where knowledge AI applies across the firm

The scope of application is wider than most partners assume. Knowledge infrastructure is not a research tool bolted onto delivery. Applied properly, it touches the entire engagement lifecycle:

Lifecycle stage Institutional knowledge applied What it looks like in practice
Business development Proposal library, win-loss history, relationship map Draft proposals grounded in past wins; instantly surface relevant credentials and case studies
Scoping and pricing Historical effort actuals, scope-creep patterns Price from what comparable engagements actually took, not from optimism
Staffing Expertise graph of who has done what Match the team to the problem in minutes; find the one person who did this exact work in 2019
Delivery Engagement archives, frameworks, sector playbooks Start every workstream from the firm's best prior thinking instead of a blank page
Quality assurance Codified review standards, error and near-miss history Enforced citation checks, consistent house standards, AI-use verification protocols
Engagement close Lessons-learned capture, updated playbooks Every project ends by making the next one easier; the second deliverable the firm keeps
Training and onboarding All of the above, made queryable New hires learn from the firm's full history, not just their first two staffing assignments
Alumni and succession Captured judgment of departing seniors Retirement becomes a transition instead of an amputation

Depth matters as much as breadth. A generic chatbot can draft an email. Only a system grounded in your engagement history can tell a manager that the last four times the firm modeled synergies in this sector, realized savings came in 30 percent under deck, and here are the workpapers. That answer is unavailable at any price from a public model, because the public model has never seen your firm work. Depth of application is a direct function of how much of your own knowledge the system can reach, which is precisely why the knowledge has to be captured, structured, and owned.

The confidentiality constraint that decides the architecture

Everything above collides with one hard wall: consulting knowledge is saturated with client-confidential material. Engagement archives are, in large part, other people's secrets, held under NDAs and master service agreements that restrict disclosure to third parties. That constraint decides what infrastructure is acceptable.

Consumer-tier AI tools fail the test outright. Standard consumer plans of the major platforms may use inputs for model training, and legal analysts reviewing those terms, along with a 2026 federal court decision, have concluded there is no enforceable expectation of confidentiality on consumer plans. Meanwhile, security telemetry shows roughly 17 percent of enterprise sensitive-data exposures flow through personal free-tier AI accounts invisible to firm IT, and IBM's breach research found unapproved "shadow AI" tools added an average of $670,000 to breach costs. For a firm whose entire commercial promise is discretion, a single demonstrated leak of client material through an ungoverned chatbot is a franchise-level event.

Enterprise cloud tiers, with no-training commitments and data processing agreements, are the defensible floor. Private AI, running on infrastructure the firm owns and controls, is the ceiling, and it is the only architecture that fully resolves the tension between depth of application and confidentiality obligations. It is not a coincidence that the firm with the most valuable knowledge base on the planet allows client-confidential data only on the platform it built and controls. The deeper you want AI to reach into your best knowledge, the more completely you need to own the place where that knowledge lives.

The mid-market playbook

The encouraging news for firms without a nine-figure technology budget: the McKinsey model is now reproducible at boutique scale. The sequence matters more than the spend.

  1. Audit the asset. Inventory where the firm's knowledge actually lives: archives, drives, inboxes, and heads. Identify the concentration risk by name. If two departures would take 60 percent of your methodology out the door, you now have a number for the board.
  2. Codify procedures first. QA standards, sourcing rules, AI-use policy, engagement close-out protocol. This is the cheapest, fastest-payback knowledge to capture, and it is the layer that prevents your own Deloitte moment.
  3. Build the capture habit into the workflow. A mandatory lessons-learned artifact at every engagement close, structured so a system can use it. Ten disciplined minutes per project, compounding forever.
  4. Stand up a private knowledge base with AI on top. On-premises or dedicated infrastructure the firm owns, ingesting the archive, the procedures, and the ongoing capture stream, with access controls that respect client confidentiality walls. This is the vault. Everything else in the stack can be rented; this cannot.
  5. Govern the boundary. A one-page AI policy every consultant signs: what may enter third-party tools (approved, business-tier, no-training terms), what may only enter the firm's own system (anything client-confidential), and what the verification standard is for AI-assisted deliverables.
  6. Point it at training. Onboard every new hire through the knowledge base from day one. The system that stores the firm's memory should be the same system that transfers it.

The framing for the partnership discussion is an ownership question, not a technology question. Subscription AI is an operating expense that makes everyone incrementally faster, including your competitors, since they rent the same intelligence. A captured, structured, firm-owned knowledge asset is equity: it compounds with every engagement, survives every resignation, differentiates every proposal, and shows up in valuation if the firm ever sells or merges. Consulting firms have spent a century telling clients to invest in durable competitive advantage. The advice was correct. It is time to take it.

The same ownership logic runs through every knowledge profession. For the parallel analysis in law, wealth management, tax, and real estate, see our posts on Rule 1.6(c) and law firm confidentiality, the RIA books-and-records rule, IRC §7216 for CPA firms, and brokerage client confidentiality.

Primary Sources

Additional references cited in this article include AP, Guardian, and CFO Dive coverage of the Deloitte Australia report refund (October 2025), Panopto's workplace knowledge and productivity research, IBM's Cost of a Data Breach Report 2025, Deltek/SPI professional services benchmarks, Gad Allon's analysis of knowledge-worker attrition costs, and Fasken's review of consumer AI terms and the 2026 federal privilege decision.

Frequently asked questions

What is institutional knowledge in a consulting firm?
It is the firm's accumulated, reusable judgment: engagement archives and working materials, methodologies and frameworks, procedures and quality standards, commercial memory like proposal and pricing history, expertise maps of who has done what, and lessons learned. Research suggests around 42 percent of it typically exists only in individual employees' heads, which is why unmanaged firms lose it continuously to attrition.
How much does losing a senior consultant really cost?
Direct replacement typically runs 50 to 200 percent of annual salary, but analyses of knowledge-worker attrition show the larger costs are indirect: lost productivity, team disruption, and the erosion of institutional knowledge and client relationships that were never written down. For senior people in knowledge-concentrated firms, the true cost is best understood as a partial loss of the firm's product itself.
What is McKinsey's Lilli and why does it matter to smaller firms?
Lilli is McKinsey's proprietary internal AI platform, launched in 2023 on more than 100,000 documents across 40-plus knowledge sources spanning about a century of firm IP. Over 75 percent of employees use it monthly, and the firm reports roughly 30 percent time savings on information gathering. It matters to smaller firms as proof of the model: the industry leader treats its knowledge as an owned asset, runs AI privately on top of it, and restricts confidential client data to that platform alone.
Can't we just use ChatGPT or Claude for consulting work?
General-purpose tools on business-tier plans with no-training commitments are reasonable for generic tasks. They fail for anything client-confidential on consumer tiers, where terms permit training on inputs and courts have found no enforceable expectation of confidentiality. They also cannot deliver depth: a public model has never seen your engagement history, so it cannot answer the questions your firm's own archive can. The pattern the major firms converged on is public tools for public work, private infrastructure for the crown jewels.
Where should a small or mid-size firm start?
Start with procedures and capture, not technology. Codify QA and AI-use standards, make lessons-learned capture mandatory at engagement close, and inventory where knowledge concentration risk sits. Then stand up a private AI knowledge base on infrastructure the firm controls and route onboarding and training through it. The sequence converts existing work product into a compounding asset before adding any new tooling complexity.
Does AI eliminate the need for junior consultants and training?
No, but it changes what training must accomplish. As AI absorbs traditional junior tasks like research synthesis and deck production, juniors reach client-facing judgment work earlier. That makes structured knowledge transfer more important, not less: the apprenticeship reps that once taught judgment implicitly now have to be delivered deliberately, through a knowledge base that gives every new consultant access to the firm's full history from day one.

Mitch Boraski

Co-Founder of Deepvine AI. Deepvine installs private AI knowledge systems for consultancies, law firms, RIAs, CPA firms, brokerages, and other knowledge-driven businesses: connected to your systems, backfilled with your history, deployed in your environment, and owned by you.

This article is for general information and does not constitute legal advice on confidentiality obligations, client contracts, or AI governance requirements.

Private AI for Consultancies

Your firm's memory, working on every engagement.

Deepvine deploys a private AI knowledge system in your firm's environment: engagement archives, methodologies, procedures, and decades of accumulated judgment, answerable in Slack with source-backed citations. Client-confidential material never leaves your control.

Bring us one real question about a past engagement. We will show you where the answer comes from.