Choose one bounded workflow
Start with a recurring task whose inputs and outputs can be described. Drafting a support response is easier to evaluate than a broad instruction to improve customer experience. Record the current handling time, common exceptions and cost of an incorrect result. Decide whether the system is advising a person or taking an action; the latter needs more stringent authorization and recovery controls.
Check whether the information is usable
Inventory the sources the workflow relies on, including outdated documents and information held only by experienced employees. Identify a source owner and an update process. A retrieval system cannot resolve conflicting policies without a rule about which source takes precedence. Build a small, representative set of questions and acceptable answers before choosing a model or automation tool.
Carry permissions into retrieval and actions
A user should not gain access to a restricted document through an AI answer. Apply authorization to retrieved information and to every downstream action. Test cross-team and cross-customer access explicitly. Limit connected tools to the operations required by the workflow, and distinguish an answer generated from a source from an instruction contained in that source.
Plan evaluation and escalation
Evaluate ordinary requests, incomplete inputs, ambiguous instructions and malicious content. Record when the system should decline, request clarification or route work to a person. A model confidence score alone is not evidence that an answer is correct. Review outcomes using actual task criteria and maintain a repeatable evaluation set when prompts, tools or models change.
Pilot with a named owner
Keep the initial audience small and preserve the original workflow as a fallback. Track correction rate, completed tasks and review effort alongside speed. The NIST AI Risk Management Framework provides a broader framework for identifying and managing risks; this checklist is a practical starting point, not certification. Expand only when the pilot shows useful outcomes and the business owner accepts the residual risks.
Run a small readiness workshop
Bring together the workflow owner, a person who performs the task and the team responsible for data access. Walk through a real example from intake to completion. Identify where an AI system could assist and where a person must retain approval authority. This often exposes missing information before any model integration begins.
- List the sources the assistant may use and who maintains them.
- Include examples with missing, conflicting and restricted information.
- Define actions that always need human approval.
- Agree how users report an incorrect result.
- Record a baseline for time, quality and review effort.
End the workshop with a bounded pilot brief. It should name the owner, the allowed data, the evaluation examples and the conditions for stopping. Readiness is specific to a workflow; one promising use case does not mean every business process is ready for automation.
Further reading
Start with a recurring task whose inputs and outputs can be described. Drafting a support response is easier to evaluate than a broad instruction to improve customer experience.
