← Case Studies
Case Study 02 · AI Governance Advisory · 2026

Setting governance. Getting it right before scaling.

A 15-year testing services company took their AI compliance product into enterprise pilots. The governance questions stopped the room. Orquestra AI was called in. Two weeks later the product was enterprise-class.

SectorTesting services · SaaS
EngagementAI Governance Advisory
Duration2 weeks
DeliverableAI Policy Framework
Navigator Framework™ use case Navigator Capability Model · Assurance Capability · Advisory mode
Case Study 02 · 2026
Visual summary
Case Study 02 visual summary — the pilot moment with five enterprise governance questions, five governance gaps identified, two-week advisory engagement (discovery + framework design), and the before/after outcome from 'no answers' to 'documented answers'. Closing principle: AI governance cannot be an afterthought for scaling. It is the condition for it.
Full narrative & findings below Download infographic →
I. The situation

Fifteen years of testing expertise. One pilot that changed everything.

The company had earned its credibility over 15 years — deep testing services delivery, a team that understood quality assurance at an engineering level, and a reputation built on rigorous work. The new product was a natural evolution: an AI-powered test automation platform with the capability to check compliance frameworks including SOX. The AI generates findings. The customer validates and acts on them.

The team built the product the way they knew how to build things — capable engineers, coding agents, fast iteration. The product worked. The compliance checks ran. The outputs looked right. They were confident going into the pilots.

The pilots delivered the shock.

What happened in the pilot room

The product demonstration went well. The AI ran the compliance checks cleanly. The output was clear. Then the enterprise security and risk team leaned in with their questions — and the room changed.

  • ?What is your AI governance framework? What documented policy governs how this AI operates?
  • ?Our compliance team will be reviewing these findings. What documentation do they get to validate against?
  • ?What controls define the scope and criteria of what your AI checks? Where is that documented?
  • ?You have traceability controls — but what policy do they enforce? What standard are they measuring against?
  • ?How was this built? What's your responsible AI development process?
The team had no answers. Not because the product did not work. Because no enterprise will deploy an AI product in their compliance environment without a documented governance framework — and that framework did not exist.

The pilots stalled. Not on capability — on governance. The product had been built to pass technical validation. It had not been built to pass enterprise procurement. Those are two different bars, and in 2026, every AI product faces both.

AI governance cannot be an afterthought for scaling. It is the condition for it.
Orquestra AI · Advisory finding · 2026
II. The engagement

Two weeks to answer every question the pilot room asked.

The brief was specific: produce the documented AI governance framework that enterprise procurement required. Not policy for policy's sake — a framework that directly answered every question the pilots had exposed and made the product enterprise-deployable.

The instinct in most product teams is to ship first and add governance when someone asks for it. What the pilot room revealed is that enterprise clients ask for it before they deploy — not after. Governance that arrives after the failed pilot is damage control. Governance that arrives before the pilot is a commercial advantage.

Week 1 · Discovery

Understanding the product — and what was missing.

  • ·Mapped every AI feature: what it generates, how findings are produced, what the customer reviewer receives today.
  • ·Assessed the development process — how coding agents were used, what specifications existed, why the traceability controls in place were not effective.
  • ·Mapped every pilot question to a specific governance gap — making the remediation list concrete and auditable.
  • ·Risk-classified each AI feature against Navigator Framework categories to determine oversight requirements per output type.
  • ·Assessed what the customer reviewer needed to exercise meaningful validation — not just receive a finding, but evaluate it.
Week 2 · Framework design

Building the answers enterprise clients need.

  • ·Documented the AI governance policy: what the AI is permitted to generate, how it is supervised, who is accountable for its outputs.
  • ·Defined AI generation controls and scope: documented criteria for every compliance check, within defined scope boundaries.
  • ·Built the customer review documentation package: what reviewers receive alongside findings to validate meaningfully, not just sign off.
  • ·Established the policy benchmark for existing traceability controls — transforming a log into governance evidence.
  • ·Drafted the responsible AI development policy: spec requirements and review gates for all AI-built features going forward.
III. Governance gaps

Five questions. Five gaps. One framework.

Each question the pilot room asked mapped directly to a governance gap. The advisory identified all five, and the framework addressed all five — giving the team documented answers before the next enterprise conversation.

01

No documented AI governance framework.

The AI operated under no documented policy. No defined rules for what it could generate, how it was supervised, or who was accountable for its outputs. This is the first question every enterprise security and risk team asks — and it had no answer. Without it, the product could not be considered for onboarding by any enterprise with its own AI risk governance requirements.

Critical
02

Customer reviewer had nothing to review against.

The product design put the customer in the HITL role — the human who validates AI findings before acting on them. Sound design. But the customer received findings with no documentation of the criteria, scope, or logic that produced them. Human oversight without documented criteria is not oversight — it is a signature on something the reviewer cannot evaluate. The responsibility transfers. The tools to exercise it do not.

Critical
03

No documented controls on AI generation scope.

No specification defined what the AI checks, how it checks, or what constitutes a finding. The AI operated as a capable but undocumented agentic engine. Enterprise clients deploying an AI product inside their compliance environment need to know exactly what that AI does and within what boundaries. Without documented controls, the product created ungoverned AI exposure in the client environment.

Critical
04

Traceability controls present — but no policy to enforce.

The product had traceability controls. They were not effective because there was no documented policy to trace against. The controls recorded what happened. There was no defined standard for what should happen. A trail without a policy benchmark is a log, not governance evidence. Enterprise procurement specifically asked what policy the controls enforced. The answer did not exist yet.

High
05

No responsible AI policy for the development process.

The product was built using coding agents without a spec-driven development process — no documented requirements before the agent started, no defined acceptance criteria, no formal review gates. Enterprise due diligence now covers not just how a product operates but how it was built. The "how was this built?" question in the pilot room had no structured answer.

High
"The product passed every technical test. It failed the governance questions. In enterprise AI procurement, those are the questions that matter."
Orquestra AI · Advisory finding · 2026
IV. What was delivered

An AI Policy Framework built around the questions the pilot exposed.

Each component of the framework was designed to answer a specific question enterprise procurement had asked. Not generic governance documentation — direct, demonstrable answers that the team could walk into the next pilot conversation with.

01

AI Governance Policy

Documents how AI operates in the product: what it generates, how it is supervised, who is accountable for its outputs, and how the policy is maintained. Answers “What is your AI governance framework?” directly. The foundation enterprise procurement needs before any AI product enters their environment.

02

Customer Review Documentation Package

Accompanies every AI finding to the customer reviewer — criteria applied, scope of the check, basis of the finding, and what the reviewer needs to assess. Transforms customer HITL from a liability transfer into a meaningful governance layer. The reviewer now has what they need to validate, not just approve.

03

AI Generation Controls and Scope Definition

Documented criteria for every compliance check — what it checks, how, on what basis, within what defined scope. Establishes the boundaries of autonomous AI generation. Enterprise clients can see exactly what AI does in their compliance environment, and what it cannot do without human specification.

04

Policy Benchmark for Traceability Controls

The documented policy that the existing traceability controls now enforce. Transforms a process log into governance evidence. The controls now measure compliance against a defined standard — and the answer to “what do your traceability controls enforce?” is documented and demonstrable.

05

Responsible AI Development Policy

Defines how AI is used in the development process going forward — what requires human specification before coding agents begin, what requires review before shipping, what traceability is required from requirement to code. Answers the “how was this built?” question for the current product and covers all future AI-built features.

V. The outcome

Back into pilot. Different room.

Two weeks after the engagement, every question the first pilot room had asked had a documented, demonstrable answer. The product had not changed. The governance framework around it had — and that was exactly what had been missing.

Pilot one — no answers
“What is your AI governance framework?” — no answer
“What does our reviewer validate against?” — no answer
“What controls govern your AI's scope?” — no answer
“What do your traceability controls enforce?” — no answer
“What's your responsible AI development process?” — no answer
Pilot two — documented answers
AI governance policy — documented, demonstrable
Customer review package — delivered with every finding
Generation controls — criteria documented per check type
Traceability policy benchmark — controls now enforce a defined standard
Responsible AI development policy — spec requirements in place

This is the commercial reality of AI products in enterprise markets. Governance is a procurement gate, not a regulatory nicety. Enterprise customers with their own AI risk obligations cannot deploy a product that cannot demonstrate how its AI is governed. The pilot that fails on governance does not get a second chance through better demos. It gets a second chance through better documentation.

The broader principle runs deeper than one company's experience. Every AI product team building toward enterprise scale faces the same threshold. The question is not whether governance will be required — it will be. The question is whether it is in place before the pilot room, or being assembled in response to it.

The principle this case study illustrates: AI governance cannot be an afterthought for scaling. Governance built after the failed pilot is damage control. Governance built before the pilot is a commercial asset — the documented framework that takes an AI product across the enterprise onboarding threshold and keeps it there.
Downloads · Case Study 02

Take this off the page.

Both documents below are free to download and share — no email gate.

Don't let governance questions stop your next pilot.

A Navigator Governance Advisory produces the documented AI framework, controls, and policy that enterprise procurement requires — in two weeks. Before the pilot room asks questions you cannot answer.