The best first AI project is rarely the most futuristic one. It is usually an irritating, frequent workflow with visible inputs, a clear finish line, and enough human review to catch uncertainty. An audit replaces idea collecting with evidence.

Quick answer

Inventory recurring work, observe the actual steps, quantify volume and handling time, identify judgment and risk, score the opportunity, and select one pilot with measurable before-and-after data. Do not start by choosing a model or automation platform.

Inventory verbs, not departments

“Use AI in finance” is too broad. Capture work as a trigger and a sequence of verbs: receive invoice → verify vendor → match purchase order → code expense → request approval → post → archive. Verbs expose repeatable decisions and handoffs.

✓ Trigger✓ Inputs✓ Steps✓ Systems✓ Decisions✓ Exceptions✓ Output✓ Owner

Observe five real examples

Ask for recent examples: two normal, two messy, and one that failed. Record elapsed time, active handling time, wait time, rework, error causes, and where information leaves one system for another. People describe the official process; examples reveal the real one.

Score opportunity and exposure separately

Opportunity factorHigh score looks likeRisk factor
FrequencyDaily or weeklyRare cases are hard to learn from
Handling timeMeaningful human effortLong may indicate hidden complexity
Input consistencyKnown formats and sourcesUntrusted or unstructured inputs
Decision clarityDocumented policySubjective or regulated judgment
Outcome visibilityCorrectness can be checkedNo reliable feedback signal
ReversibilityDraft or internal updateMoney, deletion, access, external send
Pilot priority=value × feasibility−risk × change cost

A strong first workflow has these properties

  • One named ownerSomeone can define correct behavior and accept the result.
  • Stable triggerThe work starts from a recognizable event.
  • Available evidenceExamples and baseline data already exist.
  • Bounded outputA draft, classification, recommendation, or internal update.
  • Manageable exceptionsUncertainty can route to a real person.
  • Visible valueTime, delay, defects, capacity, or revenue movement can be measured.

Reject attractive bad ideas early

Too vague

“Company copilot”

No trigger, owner, or completion test.

Too risky

Autonomous finance

Money movement before controls and evidence.

Too rare

Executive edge case

Little volume, weak baseline, high judgment.

A rejected idea is an audit outcome, not a failure. It protects attention for a workflow that can prove value.

Turn the winner into a 30-day pilot brief

  1. Baseline.Volume, active minutes, wait time, error/rework, and current outcome.
  2. Boundary.One trigger, cohort, language, system set, and owner.
  3. Target.A measurable improvement with a safety constraint.
  4. Controls.Permissions, approval points, data rules, logs, and off switch.
  5. Shadow test.Run alongside people before changing production.
  6. Decision date.Scale, revise, or stop based on the agreed scorecard.

What the audit should leave behind

A useful audit produces a ranked opportunity map, current-state workflow diagrams, quantified baselines, data and integration inventory, risk register, shortlist rationale, and one pilot specification. A slide full of generic use cases is not an audit.

Choose the workflow that can teach you.

The first project should create reusable knowledge about permissions, data quality, approval design, evaluation, and adoption—even if it remains small.

Questions teams ask

How many workflows should an audit cover?

Capture broadly, then deeply inspect the top candidates. For a 10–50 person company, 15–30 workflow candidates and 3–5 detailed maps is usually enough to expose a strong first pilot.

Should ROI be calculated before building?

Estimate a range using real volume and handling-time data, then validate it in a pilot. Avoid false precision before you understand exception work and operating cost.

What if the process is not documented?

That is common. Reconstruct it from recent cases, system records, and observation; the audit should document the actual workflow, not an idealized version.

Primary references

  1. OpenAI: A practical guide to building AI agents
  2. NIST: AI Risk Management Framework