GovTech & Regulated AI

GovTech & Regulated AI

4 min read · Jul 8, 2026

Security review, without the six-week wait

Procurement security review is where good AI projects go to stall. Here's what we changed about how we package evidence, so reviewers can say yes in days, not quarters.

PROJECX Security & Governance Team

Published Jul 8, 2026

Illustration — PROJECX

{ 01 }

Why review takes six weeks

It's rarely the technology that's slow — it's the evidence. A reviewer asks for a data flow diagram, waits a week, then asks for the subprocessor list, waits another week, then asks for access logs. Each request goes to a different person on a different team, and each round trip costs the calendar far more than it costs anyone's actual working hours.

{ 02 }

What we send before anyone asks

So we stopped waiting to be asked. Every regulated engagement now ships with a standing evidence package — data residency, subprocessors, access controls, audit log export — handed over before the first review call, not extracted from us one email at a time.

REVIEW TIMELINE — STATE IT SECURITY OFFICE

A regulator's security office received the full evidence package ahead of kickoff. Review closed in 9 days instead of the six to eight weeks they'd budgeted for.

{ Nobody's holding up your project to be difficult. They're holding it up because the evidence they need is scattered across six people who don't reply to the same email thread. }

{ 03 }

The part that actually took work

None of this required a new technical capability — it required deciding, in advance, what a reviewer would eventually ask for and writing it down in language a non-engineer could act on. That's a documentation problem wearing a security problem's clothes, and it's exactly why it kept getting deprioritized until we made it standard.

Written by

PROJECX Security & Governance Team

The team that packages the evidence procurement and security offices actually need — so technical review stops being the bottleneck.

Topics

  • GovTech & Regulated AI
  • Security & Trust
  • Procurement
  • Compliance

Continue reading

More from the team.

How we think about the paperwork that decides whether a project ships.