Selected OneCompliant™ engagements across regulated enterprises — from an AI governance programme deployed within a tier-one European telecommunications environment to assessment, framework, and awareness work. Client identities are anonymised to respect confidentiality.
OneCompliant methodologies and governance capabilities — including OASAT, OASF and OASAP — have been deployed within a tier-one European telecommunications environment. AYJIS extends this operating model into runtime enforcement. Client identities are anonymised to respect confidentiality.
Tier-one European telecommunications operator with a workforce of more than 7,000 employees across multiple countries and languages, operating under NIS2 and GDPR.
Approved and shadow AI use was spreading across business units with no governance framework, no runtime control, and no audit trail. The operator faced regulatory exposure under NIS2 and GDPR and needed a consistent operating model, control guidance, and workforce awareness across a large, multilingual environment.
OneCompliant was asked to assess enterprise AI risk, design a governance and control architecture, provide policy and operational control guidance, and deliver organisation-wide AI security awareness supported by executive and technical briefings.
✓ 7,000+ employees reached through a live enterprise AI governance and awareness programme
✓ Awareness content produced in five or more languages
✓ Controls mapped to EU AI Act, NIS2, GDPR, and NIST AI RMF
✓ Governance architecture adopted by enterprise stakeholders
Delivered and adopted. The governance architecture is in use as an operational reference, and the multilingual awareness content is published internally on the operator's official learning platform. Runtime enforcement via AYJIS extends this operating model and is offered separately as an available / pilot capability.
Each capability below was delivered within the engagement above. Details are anonymised; metrics reflect real programme outcomes.
A structured assessment of AI usage across a regulated enterprise — identifying where AI was being used, what data was at risk, and where the organisation was exposed under the EU AI Act, NIS2, and GDPR.
Result: approved and shadow AI mapped across business units; prioritised governance roadmap delivered.An AI governance and control architecture defining policy domains, authorisation boundaries, and accountability — aligned to the EU AI Act and NIST AI RMF.
Result: adopted by enterprise stakeholders at a tier-one operator.An AI security awareness programme delivered across a large, multilingual workforce — produced for the organisation's official learning platform.
Result: 7,000+ employees reached; five or more languages.The scenarios below are illustrative product capabilities, not completed named client engagements. They show how OneCompliant's operating model extends into runtime enforcement and risk quantification.
Runtime policy enforcement with prompt and response inspection, data protection controls, model routing, and audit evidence — extending the deployed governance model into live enforcement. Shown here as a representative capability.
Capability: available / pilot; not represented as deployed in production.Translating AI governance maturity and AI attack surface into an underwriting-grade risk score that insurers and boards can act on. An emerging OneCompliant capability shown here as a representative scenario.
Outcome model: structured AI risk scoring to support cyber-insurance underwriting.Engagement details are anonymised to respect client confidentiality. Items marked Illustrative or Available / Pilot represent emerging or pilot capabilities rather than completed named engagements. References can be discussed under NDA.
Start with an OASAT assessment — a structured evaluation of your AI risk posture, regulatory gaps, and governance readiness. References available under NDA.