← All insights
2 August 2026
Case StudyGuide

Case Study: The Audit That Turned “Not Sure” Into a Plan

A division head answered “not sure” to seven of twelve readiness indicators. Four weeks of asking — not surveying — turned the blind spots into the year's adoption roadmap.

The most honest readiness result we see is also the most uncomfortable one: “not sure”, seven times out of twelve1. It is uncomfortable because of what it actually means: decisions about AI in your area are being made every day — just not within your sight.1A composite case, anonymised from several Fellow engagements. Numbers are representative of the pattern, not one client's audited results.

The situation

A division head at a large Thai enterprise took our readiness assessment and answered “not sure” on seven of twelve indicators — tool visibility, data policy, verification, measurement, ownership among them. Her first reaction was to apologise for the result. Our reading was the opposite: she was the only leader in the cohort whose answers could be fully trusted, because everyone else had guessed.By the numbers7 จาก 12indicators answered “not sure” — the score wasn't low, it was invisible

An unscored assessment is not a failed assessment. It is a map of exactly where your line of sight ends — and hers ended, as it does for most senior leaders, precisely where the real work happens.

Why guessing is worse than not knowing

A leader who guesses “we're probably fine” converts a visibility problem into a false confidence problem. Budgets get set, policies get written, and risk gets accepted on a picture that is part data, part folklore. “Not sure”, said out loud, is the first governance act — it makes the gap workable.DefinitionBlind-spot risk Usage, spend and exposure running in the unobserved parts of a scope — unmanageable not because it is hidden deliberately, but because nobody is looking

The four-week audit

We designed the lightest audit that would close her specific blind spots — asking, not surveying:

  1. Week 1 — access and tools. With IT: which AI tools have licences, who activated them, what browser tools appear in network logs. Desk research, no interviews.
  2. Weeks 2–3 — fifteen conversations. Thirty minutes each with the people doing the work, selected across levels, with one script: show me where AI touches your week. No judgement, no forms.FigureFifteen conversations produced what two years of dashboards had not: an accurate pictureFifteen conversations produced what two years of dashboards had not: an accurate picture
  3. Week 4 — the one-page map. Tools in real use (thirteen, against four officially known), the five workflows that mattered, where data was actually flowing, and — for every practice found — a name: who runs this, who should own it.

Each of her original “not sure” answers became a line on that page with a finding and an owner attached.

What changed

The map became the division's adoption roadmap for the year: two shadow workflows promoted into supported ones, one genuine data exposure closed within a fortnight of being seen, and an adoption owner named — the first structural fix, because permanent visibility needs a person, not an annual audit. On re-assessment a quarter later, eleven of twelve indicators were answerable, and the score that emerged was lower than her peers' guesses had been — and, unlike theirs, true.By the numbers13 กับ 4AI tools actually in use versus officially known — found in four weeks of asking

What to steal

  1. This week: list your own “not sure” answers — from a readiness report or honest reflection. Each one is a question someone in your organisation can answer.
  2. Weeks 1–2: do the desk half — licences, activations, network-visible tools. It is faster than it sounds.
  3. Weeks 2–4: hold fifteen show-me conversations across levels. Conversations, not surveys — forms collect what people think you want to hear.
  4. Then: write the one-page map with a name against every finding, and appoint the owner who keeps it current.

If your readiness result was mostly unknowns, do not retake the assessment hoping for a better guess — run the audit, then measure what you can finally see.RelatedWhat the asking usually surfaces: the shadow-AI map

Keep reading

Want this in your organisation?

Talk to our team