A practical worksheet for examining a real workflow before deciding whether AI belongs in it and where human control must remain.
IF useful → CHECK boundary → HUMAN decision
Begin with the work as it happens
Checkpoint detail
An AI workflow review is not a software demonstration. It follows one repeated job from trigger to finished output: for example, turning an incoming supplier document into an approved record. The reviewer asks who starts it, which systems and files are used, where people retype or interpret information, what counts as complete, and what happens when the input is unclear. Observing a few normal and awkward cases is more useful than documenting the ideal process from memory.
Inspect data before choosing a tool
Checkpoint detail
List every input and mark whether it contains personal data, special category data, confidential commercial material, credentials or information covered by a contractual restriction. Record where the tool sends data, how long it retains prompts and outputs, whether a provider uses them to improve models, and who can access the account. The ICO’s AI and data protection guidance stresses applying data protection principles to AI processing. A workflow should not be trialled with live customer records merely because the interface is convenient.
Finish with a bounded trial decision
Checkpoint detail
The review should end with one of four outcomes: do not use AI; improve the underlying process first; run a limited assisted trial; or proceed to a controlled implementation. A trial uses representative but appropriately protected inputs, a small scope and a manual baseline. Record corrections, failure types and time spent on checking rather than celebrating the first plausible output. The decision gate should ask whether the proposed assistance is safer and genuinely less burdensome after review effort, subscription costs, exceptions and staff training are included.
Split judgement from mechanical handling
Checkpoint detail
Each step should be classified. Copying approved fields, routing a request and applying a fixed naming convention are deterministic tasks. Summarising free text, extracting variable fields or drafting a response may suit assisted AI, but outputs can vary. Approving payment, deciding eligibility, giving regulated advice or resolving a disputed customer record carries consequences that usually require accountable human judgement. The aim is not to remove people indiscriminately; it is to place assistance where an error can be detected and corrected.
Design controls around plausible failure
Checkpoint detail
Define the mistakes that matter: invented facts in a reply, a missed exception in a contract, a document sent to the wrong person, or confident output based on an incomplete source. Then assign controls. These may include source citations, required fields, deterministic validation, restricted output formats, confidence-independent sampling, and human approval before an external action. A reviewer should also specify the fallback when the AI service is unavailable or the input is outside scope. ‘A person checks it’ is incomplete unless the checker, criteria and stopping rule are named.
Practical template
AI workflow review worksheet
Complete this for one named workflow, not for ‘the business’ in general.
Workflow and outcomeName the repeated job, its trigger, the person served, and the observable condition that means it is complete.
Current pathList each system, hand-off, copy-and-paste step, decision and waiting point in the order they occur.
Input variationAttach or describe normal, incomplete, ambiguous and exceptional examples; note which cases must leave the automated path.
Judgement boundaryMark steps as fixed-rule, interpretive assistance, or accountable decision. State which decisions a person must retain.
Data inventoryRecord personal, special category, confidential and contractual data; identify the lawful basis and minimisation question where personal data is involved.