Skip to content
AI Enablement pmo

The Governance Bar Just Moved From Policy to Proof

Clearline Advisors
Clearline Advisors

A new industry survey finds most organizations have AI policies in place and almost none have the evidence controls behind them. The PMOs that generate that evidence as a byproduct of delivery work already have the answer.

The argument

A PMO Director defending an AI deployment plan is starting to face a different question than the one asked a year ago. The old question was whether a policy existed. The new one is whether the organization can produce the evidence the policy promises — what the AI produced, who reviewed it, and where the record lives. Arctera's State of AI Governance 2026 report puts a number on the distance between those two questions: "while more than half (55%) have the core AI policies, training and review steps in place, fewer than one in five (19%) have the logging, retention, detection and scoring controls needed to prove what happened." Policy adoption is not the bottleneck anymore. Proof is. A PMO whose delivery practices generate that proof as a normal byproduct of the work — not as a retrofit project after an auditor asks — answers the harder question by default.

The gap, in the report's own words

Arctera is a business unit of Cloud Software Group, and the report is vendor survey data — Arctera sells the logging, retention, and compliance controls it recommends. That does not make the finding wrong, but it means the number should be read as a vendor's measurement of a market it serves, not as neutral third-party research. Read that way, the finding still holds up: a Hanover Research survey of compliance decision-makers and influencers across the Americas and EMEA, fielded in May 2026, found a wide gap between organizations that have adopted AI policy and organizations that can demonstrate what their policy requires.

The same report finds the risk case moving in the opposite direction. Arctera reports "more than three-quarters (78%) of respondents at organizations using AI tools expecting risk to increase over the next 12 to 24 months." Policy adoption is treated as settled. Evidence infrastructure is not. Risk expectations are rising anyway.

A third finding names the failure mode precisely: confidence has outrun capability. Arctera reports that "while 71% of organizations using AI say they are very or extremely prepared to produce a defensible audit trail, the report indicates confidence alone is not enough." Self-reported readiness and the actual presence of evidence controls are two different measurements, and the report is explicit that they diverge. An organization can believe it is prepared and still belong to the 55-percent-but-not-19-percent population — policy in place, nothing behind it that would survive a request for the record.

Why this is a delivery problem, not a compliance problem

The report's own framing points at the fix, even though it is describing enterprise compliance infrastructure rather than PMO delivery practice. Arctera's SVP and GM, Soniya Bopache, put it this way: "Moving from policy to proof means organizations must treat evidence as part of the AI workflow itself, not something to be recreated after the fact." That is Brief 03's argument — citation discipline as an AI-readiness signal — stated independently, in a compliance vendor's words, about a different object. Arctera is describing logging and retention controls for AI-assisted communications inside regulated industries. Brief 03 is describing citation and retrieval discipline inside PMO delivery artifacts: status reports, decision records, standards documents. The objects differ. The principle converges: evidence has to be generated as work happens, or it does not exist when someone asks for it.

This is also the same gap Brief 02 names between policy and practice. A policy document describes what should happen. A PMO's delivery artifacts — intake records, tiering decisions, status reports — are what actually happened, and they are only useful as evidence if they were built to be traceable in the first place. The 55-to-19 gap is the policy-to-practice gap, measured at the evidence layer instead of the adoption layer.

A composite pattern: the audit request nobody could answer

Consider a composite, drawn from a pattern observed across PMOs rather than any single engagement. A PMO has an AI usage policy, reviewed and signed off eighteen months ago. An internal audit team asks a straightforward question: for the last quarter, which AI-assisted decisions were reviewed, by whom, and where is the record. The PMO has the policy. It does not have the record, because nothing in its delivery process was built to produce one — status reports summarize outcomes without tracing them to the standard that governed the decision, and no field in the tiering matrix captures whether an AI output was reviewed before it moved forward. Reconstructing three months of decisions after the fact takes longer than the original work did, and the reconstruction is thinner than a live record would have been.

A PMO with citation discipline built into its delivery artifacts does not run this reconstruction. Its status reports already trace claims to the standards that govern them. Its tiering matrix already records review steps by exposure level. The audit request gets answered from documents that already exist, because the evidence was a byproduct of the work rather than a project undertaken in response to the question.

What to do about it

Three moves for a PMO Director reading this gap as a warning rather than someone else's compliance problem.

First, treat the finding as a vendor measurement worth taking seriously, not as neutral research. Arctera has a commercial interest in the answer. The gap it measured is still real and still worth acting on — the two things are not in tension.

Second, do not wait for an audit request to test whether delivery artifacts can answer it. Pick one recent AI-assisted decision and try to reconstruct, from existing status reports and standards documents alone, who reviewed it and against what standard. If that reconstruction takes more than a few minutes, the evidence is not built into the workflow yet.

Third, close the gap at the delivery layer, not the policy layer. A new policy document does not move an organization from the 55 percent to the 19 percent. Citation discipline inside status reports, tiering decisions, and standards documents does — because it generates the record while the work happens, instead of asking someone to recreate it later.

Sources

1. Arctera (Cloud Software Group). *State of AI Governance 2026*. Via GlobeNewswire. July 21, 2026. https://www.globenewswire.com/news-release/2026/07/21/3330375/0/en/arctera-state-of-ai-governance-2026-finds-more-than-three-quarters-78-of-organizations-using-ai-expect-communications-risk-to-rise-but-fewer-than-one-in-five-can-prove-ai-governanc.html

Share this post