A practical scorecard for choosing a high-value, low-risk first workflow
A small business should usually automate one frequent, repeatable workflow that consumes meaningful time, follows reasonably stable rules, has a named owner and is easy to check or reverse. Good first candidates often include enquiry routing, appointment confirmations, routine reminders and structured handoffs. Keep sensitive decisions, unusual cases and important customer conversations with people.
The best first automation is not necessarily the most impressive or the task that somebody dislikes most. It is the workflow where useful value can be proved without exposing customers, staff or the business to avoidable risk. This guide gives you a practical way to compare candidates before choosing software.
Begin with the workflow, not the AI tool
Write down what happens today from the trigger to the finished outcome. Include who receives the work, which systems they open, what information they need, where they make a judgement, what exceptions occur and how somebody knows the task is complete. If the real process cannot be explained, automation will hide confusion rather than remove it.
Microsoft's process analysis guidance recommends examining inefficient or repetitive processes, recording the work, looking for frequent patterns and involving the employees and supervisors who understand it. That is a useful starting principle for any platform: observe the actual work before designing the future version.
The Ostina first-automation scorecard
Score each candidate from zero to three on all eight criteria. Use evidence from recent work rather than a general impression. The scorecard is a prioritisation aid, not a compliance assessment or guarantee of return.
| Criterion | 0 points | 1 point | 2 points | 3 points |
|---|---|---|---|---|
| Frequency and time | Rare or trivial | Monthly or a few minutes | Weekly with visible effort | Daily or consumes hours |
| Rules and stability | Different every time | Mostly judgement | Common path is clear | Repeatable rules and outputs |
| Business impact | Little effect | Minor convenience | Reduces delay or rework | Protects service, revenue or capacity |
| Data and knowledge | Unknown or unreliable | Scattered and incomplete | Usable with preparation | Trusted, necessary and accessible |
| Exceptions | Most cases are unusual | Many exceptions | Exceptions can be identified | Few, clear escalation routes |
| Review and reversibility | Errors are hard to detect or undo | Limited review | Human check is practical | Easy to verify, stop and reverse |
| Ownership | Nobody owns it | Shared informally | Likely owner identified | Named owner and backup |
| Measurement | No useful baseline | Only anecdotal feedback | One or two measures available | Time, quality and outcome can be compared |
- 18 to 24: a credible pilot candidate, subject to the safety checks below.
- 12 to 17: simplify the process, improve data or clarify ownership before building.
- 0 to 11: leave it manual for now or redesign the underlying workflow first.


Apply the hard-stop checks before trusting the score
A high score does not make every workflow suitable. Pause and seek the right specialist input when a process uses sensitive personal data, makes or strongly influences a decision with a significant effect on somebody, creates financial or contractual commitments, involves safeguarding, or has no meaningful way for a person to intervene.
The UK government's Data and AI Ethics Framework says organisations should record how much control belongs to people, name those responsible for oversight and keep final human decisions in high-impact situations. The ICO's AI guidance and risk toolkit help organisations consider UK data-protection duties, including when a Data Protection Impact Assessment is required.
For customer-facing automation, responsibility cannot be handed to the software. The Competition and Markets Authority's 2026 guidance makes clear that a business remains responsible if an AI agent acts unlawfully. Keep approved boundaries, clear records, escalation and a route to a person.
A worked example: routing a new website enquiry
Imagine a growing service business receives website enquiries every day. Someone copies each enquiry into a CRM, decides which service it concerns, assigns it to a colleague, sends an acknowledgement and chases the next action. The business scores that workflow:
| Criterion | Score | Reason |
|---|---|---|
| Frequency and time | 3 | It happens daily and creates repeated copying and checking. |
| Rules and stability | 3 | Required fields, service categories and response promises are documented. |
| Business impact | 3 | Delay can affect customer confidence and sales follow-through. |
| Data and knowledge | 2 | Most inputs are usable, but duplicate records need attention. |
| Exceptions | 2 | Unclear and sensitive messages can be identified and escalated. |
| Review and reversibility | 3 | A person can check the record and draft before external follow-up. |
| Ownership | 3 | A sales owner and backup are named. |
| Measurement | 3 | Response time, ownership, corrections and next actions can be tracked. |
| Total | 22 | A strong assisted-mode pilot, with people handling ambiguity and customer judgement. |
The first version should not try to close the sale. It can capture the original message, check for duplicates, suggest a service category, assign an owner and prepare a relevant acknowledgement for approval. That small scope proves the handoff before adding more.
If you need candidates to score, compare our 18 practical AI automation examples by trigger, human boundary and proof measure.
Which common workflows tend to score well?
| Workflow | Useful first scope | Keep with people |
|---|---|---|
| New enquiries | Capture, duplicate check, routing, acknowledgement and owner reminder. | Discovery, promises, price, objections and unusual needs. |
| Appointments | Confirmation, approved information, reminders and rescheduling route. | Sensitive changes, complaints and judgement about priority. |
| Customer onboarding | Create tasks, request standard information and show what is outstanding. | Expectations, exceptions and relationship decisions. |
| Shared inbox | Suggest category, priority and owner; prepare drafts from approved knowledge. | Sensitive messages, disputes, commitments and final review. |
| Invoice reminders | Scheduled, accurate reminders with clear status and escalation. | Disputes, vulnerability, payment plans and relationship context. |
| Routine reporting | Collect agreed data, flag missing inputs and prepare a consistent summary. | Interpretation, decisions and explanation of unusual results. |
These are candidates, not automatic recommendations. The same label can describe very different risks in different businesses. Map your real data, decisions and exceptions before choosing.
Use the simplest dependable method
Not every automation needs AI. If the rule is fixed, use a fixed rule. A website form can create a CRM record, a booking can trigger a reminder and an approved status can create a task without asking a model to interpret anything. Use AI where language or context must be summarised, classified or drafted, and make uncertainty visible.
This proportional approach also makes the workflow easier to test. The UK government's introduction to AI assurance recommends combining suitable techniques such as risk assessment, impact assessment, performance testing and monitoring according to context. The NIST AI Risk Management Framework similarly organises work around governing, mapping, measuring and managing risk throughout the system lifecycle.
A four-week first pilot
- Week 1: map and baseline. Observe recent examples, record the real steps and exceptions, measure current time and quality, and agree the intended outcome.
- Week 2: assisted mode. Let the workflow prepare records, suggestions or drafts while a person checks every action. Record corrections and missing context.
- Week 3: limited live use. Allow only the stable, low-risk steps to run. Keep clear alerts, an owner, a backup and a manual route for exceptions.
- Week 4: review and decide. Compare the evidence, ask the team and affected customers what changed, fix weak points and choose whether to expand, hold or stop.
Measure value and control together
| Measure | Question it answers |
|---|---|
| Minutes per completed case | Did repetitive effort genuinely fall? |
| Time to the next useful action | Did work move faster for customers or colleagues? |
| Completion and overdue rate | Did consistency and follow-through improve? |
| Corrections and rework | Are rules, data and generated outputs dependable? |
| Exceptions and escalations | Are unusual or risky cases reaching the right person? |
| Staff experience | Did the change lower pressure or create new hidden work? |
| Customer outcome | Did service improve without losing clarity, choice or access to a person? |
Frequently asked questions
What should a small business automate first?
Start with one frequent, repeatable workflow that consumes meaningful time, follows reasonably stable rules, has a named owner and can be checked or reversed easily. Enquiry routing, appointment confirmations, routine reminders and structured handoffs are often stronger first candidates than sensitive decisions or complex exceptions.
Should we automate the task that takes the most time?
Not automatically. Time matters, but so do process stability, error consequences, data quality, human review and whether success can be measured. A high-volume task with unclear rules may need simplifying before it is safe to automate.
Do we need AI for our first automation?
No. Fixed rules may be enough for reliable steps such as copying approved form data, creating a task or sending a scheduled reminder. Add AI only where interpreting language, summarising or drafting creates useful value and the output can be checked.
What should not be automated first?
Avoid starting with decisions that can significantly affect people, sensitive or poorly understood data, unstable processes, high-value commitments, complaints, safeguarding matters or work where nobody can review and overturn a wrong result.
How long should a first automation pilot run?
Run it long enough to include normal work and meaningful exceptions. For a frequent workflow, four weeks can provide a useful first comparison: one week to map and baseline, one in assisted mode, one with limited live use and one to review evidence before expanding.
Sources and further reading
- Microsoft Learn: Prepare processes and recordings for analysis.
- UK government: Data and AI Ethics Framework.
- UK government: Introduction to AI assurance.
- Information Commissioner's Office: Artificial intelligence guidance and risk toolkit.
- Competition and Markets Authority: Using AI agents while complying with consumer law.
- NIST: AI Risk Management Framework Core.
The practical next step
List three workflows that create pressure, score them with the people who do the work and choose one small pilot. Ostina's AI readiness assessment and automation audit maps the real workflow and its priorities, our AI automation consultancy turns that evidence into a controlled roadmap, and our AI automation services support the build, testing and improvement.
