Start with the real path of work

A useful audit follows the actual path of a task: who starts it, what information they need, where they get stuck, who checks it, and what happens after it is finished.

The map often reveals that the first win is not a new tool. It is a clearer handoff, a better template, or a shorter review loop.

This is slower than opening a tool's feature list and asking what it could automate, but it is the only way to find the handoff nobody mentioned in the kickoff meeting — the spreadsheet someone keeps privately because the shared one is always out of date, or the approval that happens over a phone call with no record.

Check the risk before the excitement

Data sensitivity, customer promises, regulated advice, and reputational risk all affect how much automation is appropriate. Responsible AI work keeps the riskiest judgement points visible.

Two examples make this concrete. A workflow that drafts responses to customer complaints touches both data sensitivity and customer promises at once — a drafted reply that overstates a refund or a timeline can cost more than the time it saved. A workflow that summarises technical specifications for a regulated product touches accuracy risk directly, since a dropped caveat in a summary can travel into a decision no one meant to make lightly.

None of this is a reason to avoid automation in sensitive areas. It is a reason to keep the riskiest step — the one where a wrong answer reaches a customer or a regulator — reviewed by a person for longer than the rest of the workflow.

The categories are not exhaustive, and they overlap in practice — a workflow that touches customer promises will often touch reputational risk too, since a public complaint about a broken promise costs more than the promise itself would have.

Who should be in the room

An audit that only interviews the manager who owns the budget misses the workflow. The people who do the work daily know where the template does not fit, where the policy gets bent for a good reason, and where the "process" is actually three different people doing three different things under the same name.

Thirty minutes with the two or three people closest to the task usually surfaces more than an hour reviewing whatever documentation already exists, because documentation tends to describe the process as it was designed, not as it currently runs.

This does not mean skipping the manager. It means treating their view as one input among several, since they often see the workflow's intended design rather than its lived reality.

A common surprise

Audits regularly turn up a step nobody remembered existed — a manual check someone added after a specific incident years ago, still running for every case even though the incident that caused it happens once a decade. Removing that step is sometimes the single highest-value outcome of the whole exercise, and it has nothing to do with AI.

What the audit actually produces

A completed audit is not a slide about AI's potential. It is a short written account of the workflow as it actually runs today, the two or three points where it breaks down, and a plain recommendation for what to do about each one.

That recommendation is deliberately narrow — one workflow, one next move — rather than a roadmap for the whole business. Teams that ask for a full AI strategy before touching a single workflow usually end up with a document instead of a change.

Handing that document to the team is itself useful, independent of whether anything gets built afterwards. Several audits end with the team fixing the handoff or the template themselves, once someone has written down clearly what was actually happening.

It should also name what the audit did not look at. A workflow review scoped to one team's process is not a verdict on the rest of the business, and pretending otherwise oversells a narrow piece of work.

Choose the first move

The audit should end with a practical recommendation: leave it alone, tidy the workflow, run a workshop, or scope a sprint. The point is not to find AI everywhere. It is to find the next useful step.

"Leave it alone" is a legitimate outcome, not a failure of the audit. A workflow that is already fast, low-risk, and rarely used does not need automation — it needs to stay exactly as unremarkable as it is.