Case study
AI enablement for three departments in a regulated business
The same workshop delivered three times, to Operations, Regulatory Affairs and Software Quality Assurance, rebuilt each time around that department’s own work process and the compliance constraints it works under.
- Departments
- Operations, Regulatory Affairs, Software Quality Assurance
- Format
- One workshop design, delivered three times
- Preparation
- Discovery per department
- Frameworks
- Three paths to AI value, RIGHT prompting
- Hands-on
- The client's own approved AI tools
The situation
Three departments in a medical device business, each doing work that looks nothing like the others: Operations running project management for new components, Regulatory Affairs preparing submissions, and Software Quality Assurance producing test documentation. All three had heard what generative AI can do in general. None of them had seen what it does inside a process where every output is subject to audit, traceability and regulatory review.
What we did
One workshop design, delivered three times, adjusted for each department. Discovery ran per department first, so each delivery used that department’s real work rather than a generic example set.
- Business value opportunities with generative AI: the three paths, applied by participants to their own function before any tool was opened.
- Frameworks, tools and key concepts: what the technology does across text, visual, audio and data, where the current limits are, and what the EU AI Act means for a regulated manufacturer.
- Using generative AI in the work: the department’s own process, mapped and then re-mapped with AI applied stage by stage.
- AI agents and what to do about them: the difference between a copilot, a tool and an agent, and which of the three a given task actually needs.
The method: map the process, then map it again
The core of each session was a pair of views of the same work. First, how we do things: the department’s process laid out stage by stage, with the inputs, outputs, roles and data sources at each one. Then, how we do things with generative AI: the same stages with a specific application named at each. Not a list of tools looking for a use, but a process the participants already owned, with the intervention points identified.
What the regulated setting changed
Almost every application the departments identified was shaped by compliance rather than by speed. Software Quality Assurance surfaced regulation alignment for test protocols, traceability matrix generation, duplicate defect detection, and formatting to regulatory standard. Operations surfaced supplier matchmaking, submission drafting, and root cause summarization after launch. The pattern held across all three: in a regulated business the highest-value AI work is usually documentation, traceability and review, because that is where the effort sits and where the standard is unambiguous.
Hands-on, in their own tools
Prompting practice ran on the RIGHT framework and the zero-shot to few-shot ladder, and it ran inside the company’s own approved AI chatbot rather than a public tool. Capability that only works in software the organization has not sanctioned is capability nobody can use on Monday. The later sessions added live application building, so participants saw a working thing appear rather than hearing that it could.
What participants left with
A workshop companion guide, a set of AI use cases identified for their own department during the session, hands-on experience in the tools they are permitted to use, and a standing resource page with the materials, prompts and links from both sessions.
Related: Inspiration & Activation · The RIGHT Prompting Framework · The AI Value Framework