Solutions AYJIS EU AI Act Industries Vision Pricing Company Request Assessment
Case Studies

Governance that has been deployed, not just designed.

Selected OneCompliant™ engagements across regulated enterprises — from an AI governance programme deployed within a tier-one European telecommunications environment to assessment, framework, and awareness work. Client identities are anonymised to respect confidentiality.

Delivered Enterprise Outcomes

OneCompliant methodologies and governance capabilities — including OASAT, OASF and OASAP — have been deployed within a tier-one European telecommunications environment. AYJIS extends this operating model into runtime enforcement. Client identities are anonymised to respect confidentiality.

Delivered Engagement — Tier-One European Telecom

Enterprise AI Governance Programme for a Tier-One European Telecommunications Operator

Client profile

Tier-one European telecommunications operator with a workforce of more than 7,000 employees across multiple countries and languages, operating under NIS2 and GDPR.

Challenge

Approved and shadow AI use was spreading across business units with no governance framework, no runtime control, and no audit trail. The operator faced regulatory exposure under NIS2 and GDPR and needed a consistent operating model, control guidance, and workforce awareness across a large, multilingual environment.

Scope

OneCompliant was asked to assess enterprise AI risk, design a governance and control architecture, provide policy and operational control guidance, and deliver organisation-wide AI security awareness supported by executive and technical briefings.

Delivered

1AI risk assessment — AI risk posture evaluated across business units; approved and shadow AI mapped; regulatory gaps identified against NIS2 and GDPR. (OASAT)
2Governance framework — AI governance and control architecture defining policy domains, authorisation boundaries, and accountability. (OASF)
3Policies and control guidance — operational policies and control guidance mapped to major regulatory and security frameworks.
4Multilingual awareness content — AI security awareness produced in five or more languages for the organisation's official learning platform. (OASAP)
5Executive and technical briefings — emerging-risk briefings, including agentic AI, delivered to enterprise stakeholders.

Result

7,000+
Employees reached through a live enterprise AI governance and awareness programme
5+
Languages of awareness content produced
4
Major regulatory and security frameworks mapped
Adopted
Governance architecture adopted by enterprise stakeholders

✓ 7,000+ employees reached through a live enterprise AI governance and awareness programme
✓ Awareness content produced in five or more languages
✓ Controls mapped to EU AI Act, NIS2, GDPR, and NIST AI RMF
✓ Governance architecture adopted by enterprise stakeholders

Current status

Delivered and adopted. The governance architecture is in use as an operational reference, and the multilingual awareness content is published internally on the operator's official learning platform. Runtime enforcement via AYJIS extends this operating model and is offered separately as an available / pilot capability.

Delivered capabilities

Each capability below was delivered within the engagement above. Details are anonymised; metrics reflect real programme outcomes.

AI Risk Assessment · OASAT

Mapping approved and shadow AI against regulatory gaps

A structured assessment of AI usage across a regulated enterprise — identifying where AI was being used, what data was at risk, and where the organisation was exposed under the EU AI Act, NIS2, and GDPR.

Result: approved and shadow AI mapped across business units; prioritised governance roadmap delivered.
Status: delivered.
AI Governance Architecture · OASF

A control architecture adopted by enterprise stakeholders

An AI governance and control architecture defining policy domains, authorisation boundaries, and accountability — aligned to the EU AI Act and NIST AI RMF.

Result: adopted by enterprise stakeholders at a tier-one operator.
Status: delivered and adopted; in use as an operational reference.
AI Awareness Programme · OASAP

Awareness across a multinational workforce

An AI security awareness programme delivered across a large, multilingual workforce — produced for the organisation's official learning platform.

Result: 7,000+ employees reached; five or more languages.
Status: delivered and in use; published internally on the official LMS.

Representative Use Cases and Emerging Capabilities

The scenarios below are illustrative product capabilities, not completed named client engagements. They show how OneCompliant's operating model extends into runtime enforcement and risk quantification.

Runtime Governance and Enforcement · AYJIS

Enforcing AI policy at runtime Available / Pilot

Runtime policy enforcement with prompt and response inspection, data protection controls, model routing, and audit evidence — extending the deployed governance model into live enforcement. Shown here as a representative capability.

Capability: available / pilot; not represented as deployed in production.
AI Risk Quantification · OCiF™

From governance maturity to an insurability score Illustrative

Translating AI governance maturity and AI attack surface into an underwriting-grade risk score that insurers and boards can act on. An emerging OneCompliant capability shown here as a representative scenario.

Outcome model: structured AI risk scoring to support cyber-insurance underwriting.

Engagement details are anonymised to respect client confidentiality. Items marked Illustrative or Available / Pilot represent emerging or pilot capabilities rather than completed named engagements. References can be discussed under NDA.

Work With Us

Ready to see what this looks like for your organisation?

Start with an OASAT assessment — a structured evaluation of your AI risk posture, regulatory gaps, and governance readiness. References available under NDA.

Request Assessment Explore Our Solutions