GovTech & Regulated AI
4 min read · Jul 8, 2026
Procurement security review is where good AI projects go to stall. Here's what we changed about how we package evidence, so reviewers can say yes in days, not quarters.
PROJECX Security & Governance Team
Published Jul 8, 2026

Illustration — PROJECX
{ 01 }
It's rarely the technology that's slow — it's the evidence. A reviewer asks for a data flow diagram, waits a week, then asks for the subprocessor list, waits another week, then asks for access logs. Each request goes to a different person on a different team, and each round trip costs the calendar far more than it costs anyone's actual working hours.
{ 02 }
So we stopped waiting to be asked. Every regulated engagement now ships with a standing evidence package — data residency, subprocessors, access controls, audit log export — handed over before the first review call, not extracted from us one email at a time.
REVIEW TIMELINE — STATE IT SECURITY OFFICE
A regulator's security office received the full evidence package ahead of kickoff. Review closed in 9 days instead of the six to eight weeks they'd budgeted for.
{ Nobody's holding up your project to be difficult. They're holding it up because the evidence they need is scattered across six people who don't reply to the same email thread. }
{ 03 }
None of this required a new technical capability — it required deciding, in advance, what a reviewer would eventually ask for and writing it down in language a non-engineer could act on. That's a documentation problem wearing a security problem's clothes, and it's exactly why it kept getting deprioritized until we made it standard.
Written by
PROJECX Security & Governance Team
The team that packages the evidence procurement and security offices actually need — so technical review stops being the bottleneck.
Topics
Continue reading
How we think about the paperwork that decides whether a project ships.