Repetition
How often does the task recur?
Volume
How much time and transfers is she asking for?
Sensitivity to error
What errors occur and what do they cost?
Exceptions
How many cases do not follow the normal route?
Dates
Is the necessary information usable and lawfully available?
Human control
Where should an employee assess or decide?
Start with the process, not the tool
A tool can demonstrate impressive capabilities, but process selection starts with work that is demonstrably causing friction today. Observe the inputs, steps, exceptions, transfers and outcome. Only then do you decide whether fixed rules, classic workflow automation or AI are appropriate.
Make the process small enough to measure unambiguously. 'Automate administration' is too broad. 'Checking data from one type of supplier invoice and preparing it for booking' is better defined.
Six criteria for a good first automation
Repetition and volume determine the potential reach. Stability and available data determine how much variation the system must accommodate. Error-proneness can make automation attractive, but at the same time increases the need for validation.
Exceptions deserve special attention. A process with many implicit decisions or changeable rules may appear technically automatable, but remain operationally unpredictable. Therefore, identify normal cases and exceptions separately.
- Is the input recognizable and sufficiently standardized?
- Can a process owner assess the desired outcome?
- Are errors quickly detectable and correctable?
- Can the system safely stop or pass on when in doubt?
- Is it clear which data is used and stored?
Sources for this section: NIST · Data Protection Authority
Fixed rule, AI assistant or agent?
Use fixed rules when the logic is stable and fully writable. An AI assistant is appropriate when interpretation is needed, but an employee assesses the result and carries out the action. An agent is given more room to act and therefore requires stronger rights control, logging, boundaries and fallback.
Choose the least complex form that solves the problem. More autonomy is not a goal in itself. As impact and uncertainty increase, supervision must also become proportionately stronger.
Sources for this section: European Union · NIST
Illustrative example: invoice processing
A fictitious company wants to process incoming invoices. The assumptions are that invoices are received via one channel, suppliers are known and employees today lose a lot of time taking over fields.
The first phase is limited to data extraction and validation. Deviating suppliers, illegible documents and missing order references are sent to an employee. Booking and payment remain out of scope until data quality, error handling and access rights have been validated.
When should you not automate yet?
Wait when the process is constantly changing, employees explain the desired method differently or necessary data is incomplete and unreliable. Automation usually makes an unclear process unclear more quickly.
A realistic first step is a process observation with baseline measurement. Then select one route with sufficient volume, limited exceptions and a clear owner. Determine in advance what success, doubt and stop mean.
Frequently asked questions
How quickly do you see results?
That depends on process maturity, integrations and risk. First agree on a short validation period and measure against the baseline measurement, not against a general expectation.
Do you need to clean all the data first?
Not necessary. You must know which data is critical for the chosen scope and whether it is sufficiently correct, complete and accessible.
What is the difference between an assistant and an agent?
An assistant supports an employee with substantive work. An agent can carry out steps himself within agreed limits. This extra room for action requires stronger control.
How do you ensure compliance and safety?
By recording the purpose, data, rights, logging, exceptions, retention periods and human control from the design onwards and periodically testing them.
Sources
The sources below support the indicated factual and regulatory passages. The practical decision frameworks are professional recommendations from DSC Solution.
- NIST — Artificial Intelligence Risk Management Framework (AI RMF 1.0)January 26, 2023Gebruikt voor: risk management, governance and the cyclical measurement and management of AI risks.
- NIST — AI RMF Playbookaccessed August 29, 2026Gebruikt voor: practical actions around Govern, Map, Measure and Manage.
- European Union — Regulation (EU) 2024/1689 — AI ActJune 13, 2024Gebruikt voor: risk-based obligations, documentation, monitoring and AI literacy.
- Data Protection Authority — Information brochure about artificial intelligence systems and the GDPRDecember 2024Gebruikt voor: Belgian points of interest for AI and personal data.




