← Library
Case Study 01 · AI Governance Assessment · 2026

Two Teams. No AI Strategy. Zero Visibility.

A mid-size SaaS product and IT services company in Chennai was building AI agents into its platform. The AI R&D team and the Product team were working towards the same goal in complete isolation — and nobody had noticed.

SectorIT Services & SaaS
LocationChennai, India
EngagementAI Governance Assessment
Duration4 weeks · anonymous
StructureWk 1 Assess · Wk 2 Report · Wks 3–4 Implement
Navigator Framework™ use case Navigator Capability Model · Stage 1–2 · Moderate risk class
Case Study 01 · 2026
Visual summary
Two Teams. No AI Strategy. Zero Visibility. — visual summary of Case Study 01: the two-team silo, five governance gaps, six interventions, and the before/after state.
Full narrative & findings below Download infographic →
I. Context

A product company accelerating into AI.

The company is a mid-size SaaS product and IT services firm based in Chennai, India — serving over 200 enterprise and SME clients across India, the UK, Australia, and the United States, across verticals including e-commerce, education, and enterprise operations. A team of under 100, moving at pace, with a product footprint larger than its headcount would suggest.

In early 2026, leadership made a deliberate decision to embed AI agents into their existing SaaS platform and develop a standalone AI agent capability for their client base. They had an R&D team already working with on-premises models. They had a product roadmap. What they did not have was any governance structure connecting the AI work to the product, the delivery process, or their customers' regulatory expectations — including a growing number of EU and UK-based clients with explicit AI explainability requirements.

They came to Orquestra AI with a question: "We're building AI. Are we building it right?"

The assessment was conducted using the Navigator Framework™ — Orquestra AI's governance standard for Governable Autonomy. The framework scores five capabilities on a 0–4 scale: Human Responsibility, Decision Governance, Engineering Capability, Knowledge Capability, and Assurance Capability. Each finding and recommendation maps directly to one or more of these capabilities.

II. What we found

Two teams. No visibility.

Before the assessment began, the expectation was that the two primary functions — the R&D AI team and the Product/SDLC team — were working in close coordination. They were not. What the five-day assessment surfaced was a structural isolation that ran deeper than process gaps.

The structure we found on day one
R&D / AI Team

On-prem models. No product visibility.

  • On-premises model experimentation
  • AI agent development at pace
  • No view into product use cases
No handoff · No visibility
Product / SDLC Team

Live SaaS roadmap. Unaware of AI work.

  • Multi-client SaaS product roadmap
  • Unaware of AI capabilities being built
  • No process to integrate AI output
No audit No accountability No explainability for EU clients

The R&D team was technically proficient — experimenting with agents, fine-tuning on-premises models, and building capability at pace. The Product team was managing a live multi-client SaaS roadmap. But the two teams had no shared language, no integration process, and no mechanism to evaluate whether the AI being built corresponded to the use cases the product actually served.

No finding was a surprise in isolation. What made them significant was the combination: without audit, accountability, or shared context, an organisation cannot tell whether its AI is working correctly, whether it is governable, or whether a regulator would accept its explanation of what the AI did.

Navigator Framework™ · capability mapping
Human ResponsibilityStage 0

No named human owned any AI decision. No approval trail existed for any agent output — autonomy with no responsible human attached.

Assurance CapabilityStage 0

No audit record. No EU AI Act explainability documentation despite an active UK/EU client base — no evidence existed to assess.

Decision GovernanceStage 0

Each team was capable within its own domain but neither could evaluate the other's work. No escalation path, no shared vocabulary, no governance connecting the two.

Engineering CapabilityStage 1

AI output entering the product with no review gate, no test independence requirement, and no checkpoint enforcement before client delivery.

Knowledge CapabilityNot assessed

Both teams were operational independently on their own knowledge base. Cross-team knowledge governance was not the primary risk surface at this stage.

III. Approach

Four weeks. One structured engagement.

The engagement ran over four weeks with a clear phase structure — assessment first, recommendations second, implementation support third. The five-day assessment in Week 1 was intensive and structured around the Navigator Capability Model's five capabilities, applied across both the R&D AI team's development process and the Product/SDLC team's delivery workflow.

Week 1 · 5 days

Assessment

SDLC process review, AI development workflow mapping, audit gap identification, cross-team integration assessment, EU compliance gap review.

Week 2

Report & Workshop

Findings synthesis, risk classification per AI use case, recommendations report delivered, joint workshop with both teams.

Weeks 3–4

Implementation

Hand-holding during policy drafting, HITL framework setup, explainability template development, reskilling plan initiated.

The assessment used the Navigator Controls Catalogue as its reference standard — specifically the Human Responsibility, Decision Governance, and Engineering Capability controls at Stage 1 and 2. Where the catalogue identifies a control gap, the engagement produces a named remediation owner and a defined fix.

IV. Key findings

Five gaps. None of them technical.

Every gap identified in the assessment was a governance, process, or communication failure — not a capability failure. The teams were skilled. The problems were structural.

01
Critical

No audit trail of any kind.

No record of what AI agents had been built, what decisions they made, on what data, under what constraints, or who had approved them for any use. Zero audit infrastructure across both teams.

02
Critical

Complete silo between R&D and Product.

The R&D AI team had no visibility into product use cases. The Product team had no visibility into AI capabilities. There was no integration process, no shared roadmap, and no mechanism to connect AI output to product requirements.

03
High

No explainability for EU and UK customers.

The company serves clients in the UK and EU where AI Act transparency obligations apply to limited-risk AI systems — including disclosure requirements, accountability documentation, and explainability for automated outputs. No such documentation existed for any AI agent in development. A live compliance liability in active client relationships.

04
High

No HITL process for AI decisions.

AI agents were being developed without any defined human-in-the-loop approval points. No named person was accountable for AI outputs before they entered the product or were demonstrated to clients.

05
Medium

Capability mismatch in both directions.

Product team lacked the AI vocabulary to evaluate what the R&D team was building. R&D team lacked the product knowledge to prioritise the right use cases. Neither team could effectively brief the other.

"The AI team was building agents the product team didn't know existed, for use cases the product team hadn't defined, with no record that any of it had happened."
Orquestra AI · Assessment finding · 2026
V. Recommendations delivered

Six interventions. Delivered in week two.

The recommendations were delivered in a structured report and a one-week hand-holding session with both teams. Each recommendation addressed a specific gap and named the accountable owner for implementation.

01

Process bridge between R&D and Product.

A defined integration workflow connecting AI agent development to the product roadmap — including a shared backlog, a joint use-case review cadence, and a handoff checkpoint before any AI output enters the SDLC.

Governance
02

Risk classification per AI use case.

Each planned AI agent classified into a risk class — Low, Moderate, High, or Critical — using the Navigator Critical Controls Guide's five determinants. Higher-risk agents flagged for additional review before client-facing deployment.

Governance
03

Explainability framework for EU and UK clients.

A structured explainability template for each AI agent in the product: what it does, what data it acts on, what decisions it makes, and who is accountable for its outputs. Designed to meet EU AI Act transparency requirements for limited-risk systems.

Compliance
04

HITL approval framework for AI use cases.

Named human-in-the-loop approval points defined for each AI use case before production deployment. A named approver signs off that the AI output has been reviewed, meets the stated use case, and is fit for client use.

Governance
05

AI policy establishment.

A foundational AI use policy covering acceptable use cases, prohibited uses, data handling by AI agents, audit requirements, and the process for reviewing new AI use cases before development begins.

Compliance
06

Reskilling programme for both teams.

A structured capability exchange: Product team trained on AI agent capabilities, limitations, and evaluation criteria. R&D team trained on product use cases, client requirements, and the business context their agents need to serve. Designed so each team could brief the other effectively.

Capability
VI. Outcomes

From invisible to accountable.

At the end of the four-week engagement, the company had moved from a state of zero governance to a defined, operational governance posture — with named owners, documented policies, and an integration process both teams could use from day one.

Before → After

AI approvals: 0 → 100%

From zero documented approvals for any AI output to full HITL coverage — every AI use case requiring named human sign-off before client-facing deployment.

Before → After

Team integration: isolated → joint cadence

From two teams operating with no shared process to a defined integration workflow, a joint review cadence, and a shared backlog connecting AI capability to product requirements.

Before → After

EU compliance documentation: 0 → complete

From no explainability documentation to a structured template covering all EU and UK client-facing AI systems — aligned to AI Act transparency obligations for limited-risk systems.

Before → After

Risk-classified AI use cases: 0 → all catalogued

All planned AI use cases risk-classified for the first time — Low, Moderate, High, or Critical — with higher-risk agents identified before any client deployment.

Process

Defined R&D-to-Product integration workflow established for the first time.

Audit

HITL approval framework live — named sign-off required before AI reaches clients.

Compliance

Explainability framework covering EU and UK client-facing AI, aligned to AI Act obligations.

Policy

Foundational AI use policy established — acceptable use, data handling, and audit requirements.

Capability

Both teams reskilled to brief each other — shared vocabulary between R&D and Product for the first time.

Risk

All active AI use cases risk-classified — high-risk agents identified before deployment.

The most significant outcome was not a document or a policy. It was visibility. For the first time, both teams could see what the other was doing — and had a structure to work together without one team erasing the other's context.

VII. Navigator Framework™ in practice

How the framework surfaces what's invisible.

This engagement is a direct illustration of what the Navigator Capability Model was designed to find: AI development happening outside the governance structures that should contain it. The five capabilities — Human Responsibility, Decision Governance, Engineering Capability, Knowledge Capability, and Assurance Capability — are not abstract categories. In this case, three of the five scored at Stage 0 on day one of the assessment.

The framework works because it does not ask whether an organisation has good intentions about AI governance. It asks whether named humans can defend specific decisions, whether audit evidence exists for specific outputs, and whether the right checkpoints exist at the right points in the lifecycle. In this case, the answers to all three were no — and each no was fixable within the four-week engagement.

For this company, the exposure was compounded by active EU and UK client relationships where AI Act transparency obligations were not optional. The gap between what they had built and what they could account for was not a technical problem. It was a governance one — and it was solvable in four weeks because the framework gave both teams a common language and a clear set of named fixes.

That is what the Navigator Framework™ is for: not to slow AI development down, but to ensure that the humans responsible for it are actually in a position to defend it — at every gate, to any audience that asks.

Downloads · Case Study 01

Take this off the page.

Both documents below are free to download and share — no email gate.

Most AI governance failures aren't technical. They're visibility failures.

A Navigator Assessment identifies the governance gaps in your AI development — before a regulator, auditor, client, or investor does.