To content
goeke.digitalSMART DIGITAL CREATIVE

COLLABORATION

Depending on the task, the starting point can vary.

Four formats. No mandatory steps.

View collaboration
AI and automation

What companies need to clarify before AI automation

A technically functioning prototype is not yet a robust business process. Six prerequisites must be clarified before AI automation.

In this post

A prototype is not yet a robust business process

Task, data, roles, release, risk, and success criterion belong before technical implementation.

Those who clarify these six fields only after the setup adapt the process to the tool. Those who clarify them beforehand can decide whether AI is necessary at all, what level of control applies, and how the process fits into the organization.

Starting point

By October 2023, generative AI had long since arrived in many companies.

Texts were prepared, documents summarized, requests classified, and initial processes connected via interfaces. At the same time, a typical transition emerged:

A helpful individual attempt should become a repeatable process.

Example:

An employee uses a language model to analyze incoming requests and prepare a response. The result saves time. Now the process should start automatically after every form submission.

This changes the risk situation.

The individual test was visible and controllable. In the future, automation will process every suitable process, possibly with personal data, different cases, and immediate follow-up actions.

Before this handover, the question "Does the prompt work?" is no longer sufficient.

The six audit fields

1. Task

The task must be described more narrowly than the entire process.

Not sufficient:

AI should process customer inquiries.

More precisely:

The system should recognize the affected service and missing mandatory information from a complete request, prepare an internal response draft, and flag uncertain cases.

The description must include:

  • expected result,
  • permissible inputs,
  • impermissible tasks,
  • Termination conditions,
  • Further processing.

The broader the task, the more difficult testing and responsibility become.

2. Data

It must be clarified which data are used, where they come from, and where they are transferred.

Test questions:

  • Does it contain personal or confidential information?
  • Is the use necessary for the purpose?
  • Which data can be minimized or removed?
  • Which provider processes the data?
  • Where are inputs and outputs stored?
  • What permissions apply?
  • Which sources are binding and current?

The data protection audit is based on the specific application. This contribution does not replace legal advice. For personal data, special categories, employee data, or significant impacts, a specialized law firm or a data protection officer should be involved.

3. Roles

The process requires named roles.

At least:

  • subject matter process owner,
  • Responsible for knowledge and data,
  • technical responsibility,
  • auditing or approving role,
  • Contact person for errors and escalation.

One person can take on multiple roles. The functions must still be described separately.

Without this clarity, an error remains between the business unit, IT, and the provider.

4. Approval

It must be determined what can be automatically processed further and what requires human confirmation.

Possible stages:

  • internal draft without external effect,
  • automatic processing with random checks,
  • Mandatory check before dispatch,
  • Four-eyes approval,
  • no automation in case of insecure or sensitive cases.

Approval is not a uniform switch. It depends on impact, reversibility, and error consequences.

5. Risk

Risk is assessed in the specific context.

Relevant categories:

  • factually incorrect output,
  • impermissible data processing,
  • discriminatory or inappropriate treatment,
  • security or access problem,
  • Reputational damage,
  • incorrect system action,
  • lack of traceability,
  • Dependency on provider or model,
  • unexpected process termination.

The NIST AI RMF already classified risk in 2023 as an ongoing task from governance, context, measurement, and treatment. A one-time release does not replace operational observation.

6. Success criterion

Before implementation, it is determined what constitutes success and quality.

Possible criteria:

  • Proportion of correctly identified cases,
  • Proportion of necessary rework,
  • Processing time,
  • Number and type of escalations,
  • Error handling,
  • User acceptance,
  • Process costs,
  • Data and security incidents.

A success criterion must not only state that the automation was technically executed.

Strategic Classification

The six fields do not form an additional management layer. They translate technical possibilities into a responsible corporate decision.

NIST classifies this task as a connection of governance, context, measurement, and risk management. ISO/IEC 23894 also addresses risk throughout the entire lifecycle. For an individual use case, this means: The review does not end with the pilot. Changes to the model, data, process, or provider can trigger a new assessment.

The model thus creates a common handover point between the specialist department, technology, data protection, and management.

The audit model

Perspective from practice

The six test fields do not have to be processed in a months-long program.

For a limited use case, a compact working document may suffice:

  • one page of task description,
  • Data and source list,
  • Role overview,
  • Release rule,
  • Risk list,
  • Measurement plan.

The value lies in the joint decision.

Business unit, technology, and responsibility see the same use case. This makes unclear assumptions visible before they are incorporated into interfaces and automation rules.

What companies should not do

Companies should not start with the most technically spectacular use case.

A process with the following is more suitable:

  • clear task,
  • limited scope of data,
  • correctable result,
  • existing expert review,
  • measurable benefit.

You should also not enter personal or confidential data into a system before the legal basis, purpose, provider, storage, and access have been clarified.

And they should not directly extend a working test to all cases. The pilot must also make exceptions, errors, and maintenance needs visible.

Consequences for companies

The six audit fields do not unnecessarily slow down the introduction. They prevent unclear decisions from becoming technically expensive later.

A company can arrive at three meaningful results after the review:

  1. The process is suitable and is being controlled and piloted.
  2. Only individual steps are automated.
  3. The prerequisites are not yet sufficient and will be improved first.

Even the decision against immediate automation can be a good result.

Subject-matter connection

Check AI automation before implementation

AI orchestration and process consulting connect business tasks, data, roles, release, risk, and measurement. SDC Discovery creates the basis for decisions for a controlled pilot instead of premature system integration.

Sources and technical foundations (5)
  1. National Institute of Standards and Technology, „Artificial Intelligence Risk Management Framework (AI RMF 1.0)“, 2023. Open source
  2. ISO, „ISO/IEC 23894:2023. Artificial intelligence. Guidance on risk management“, 2023. Open source
  3. Information Commissioner’s Office, “Guidance on AI and data protection”, updated March 15, 2023. Open source
  4. Information Commissioner’s Office, „AI and data protection risk toolkit“. Open source
  5. OECD, "OECD AI Principles". Open source
Göke Frerichs, digital strategist and Smart Digital Creative
Author

About Göke Frerichs

Göke Frerichs has been combining digital strategy, communication, technology, and implementation since 1999. As a digital strategist and Smart Digital Creative, he supports owner-managed B2B companies in developing clear and reliable digital systems from individual measures. His perspective is based on many years of consulting and implementation experience in the DACH region and North America.

More about Göke Frerichs
AI orchestration and process consulting

Clarifying the digital starting point

The right collaboration begins with a clear categorization.

Categorize collaboration