Standfirst. The best first workflow is rarely the most impressive demonstration. It is a recurring, bounded task where administrative effort is visible, source material is available, errors can be detected and a named owner can decide whether the result is useful.
Start with lost capacity, not a model
Most organisations begin by listing AI capabilities. A better starting point is to locate capacity leaks: repeated searching, rekeying, reconciling, summarising, routing and drafting that consume specialist time without themselves requiring specialist judgement.
The distinction matters. “Use a chatbot in client service” is a technology idea. “Prepare a meeting brief from five approved internal sources, for review by the relationship manager” is a workflow. The second formulation has a trigger, inputs, transformation, output, reviewer and boundary.
Map a week of work
Ask a representative group to record recurring tasks for five working days. For each task, note frequency, handling time, waiting time, systems touched, information class, rework and decision owner. Do not ask only where people “want AI”; that tends to favour visible annoyances and confident respondents.
Look for queues and hand-offs. A ten-minute task performed 300 times can matter more than a three-hour task performed quarterly. Waiting for a missing field may be more costly than producing the document itself.
Separate work from judgement
Break each candidate into stages:
- select inputs;
- retrieve authorised sources;
- transform, extract or draft;
- verify facts;
- exercise professional judgement;
- communicate or execute.
AI may support stage three without owning stages five or six. This decomposition also reveals whether a deterministic rule, template, search improvement or integration would solve the problem more reliably.
Score candidates
| Factor | Useful first-workflow signal | Warning signal |
|---|---|---|
| Frequency | Weekly or daily | Rare exception |
| Boundaries | Clear start and finish | Open-ended advice |
| Sources | Approved and retrievable | Uncontrolled folders |
| Error detection | Reviewer can compare evidence | Output cannot be verified |
| Consequence | Internal and reversible | Immediate external action |
| Ownership | Named process owner | Shared but unowned |
| Baseline | Time and quality measurable | Benefit based on impression |
Do not collapse the score into a false precision. Use it to compare candidates and expose assumptions.
Define a testable outcome
Choose two or three measures: minutes of specialist effort, cycle time, missing-field rate, correction rate or proportion completed without escalation. Establish the baseline before the pilot. Include the time spent reviewing AI output and resolving exceptions. Faster drafting with slower verification is not a capacity gain.
Minimum authorisation evidence
Before testing, document purpose, data classes, approved service, sources, access, retention, failure modes, human checkpoint and suspension trigger. NIST’s AI Risk Management Framework recommends defining business context, targeted scope, benefits, costs and oversight. FINMA’s AI guidance similarly emphasises inventory, classification, responsibilities, testing and monitoring for supervised financial institutions. These sources support a lifecycle approach; they do not certify a particular workflow.
Cytria’s operational interpretation
Cytria favours a first workflow that is boring enough to control and important enough to measure. A successful pilot should yield more than an output: it should leave a reusable control pattern, an evidence trail and a clearer view of the underlying process.
Limitations and next step
This is general operational information, not legal advice. Select three capacity leaks, score them with the table, and run a two-week baseline measurement before choosing technology.
Sources
- NIST, AI Risk Management Framework Core, current framework; reviewed 14 July 2026.
- FINMA, Governance and risk management when using AI, 18 December 2024; reviewed 14 July 2026.