AI Addaiadd.org

Which parts of a process are better left unchanged?

Parts of a process involving human decisions and human oversight are better left unchanged. The cited approval guidance states that sign-off requests can be automated while remaining connected to human decision-making. The NIST AI RMF material likewise describes human-oversight processes as defined, assessed, and documented.

Where automation fits

The distinction between a request and a decision provides a practical boundary for workflow changes.

Process element Practical treatment
Sign-off requests Candidate for automation because the cited guidance explicitly covers automated sign-off requests
Human decisions Retain the human decision-maker rather than treating approval as part of the request automation
Human oversight Keep the process defined, assessed, and documented rather than allowing it to become implicit in the automated flow

This boundary does not mean that every surrounding activity must remain untouched. It means that automating the request should not quietly replace the decision or obscure how the resulting oversight is defined, assessed, and documented.

How to check a workflow’s fit

Before changing a process, separate its steps into request activity and decision activity. A request seeks sign-off; a decision determines whether that sign-off is given. The first category may fit the automation described in the cited guidance. The second should remain human when the objective is to preserve human judgment.

The next check is whether the proposed automation stops at the request. A flow may appear efficient while still altering the underlying control if it moves from requesting sign-off directly to recording an outcome without a human decision.

Readers should then examine the human-oversight process against the wording used in the NIST AI RMF material:

  • Is the process defined?
  • Has it been assessed?
  • Is it documented?

An unclear answer does not prove that a workflow is unsuitable, but it means that its oversight fit has not been established. The proposed change should also remain limited to the activity being automated rather than extending automatically to adjacent decisions, records, or responsibilities.

What still needs confirmation

The cited guidance does not provide a universal list of process steps that must always remain unchanged, nor does it establish the configuration of any particular workflow. Readers must still confirm the actual decision points, responsible roles, expected records, and any context-specific internal, contractual, legal, or regulatory requirements.

The two cited statements support a conservative workflow-fit principle: automate sign-off requests only where appropriate, while preserving human decisions and keeping human oversight defined, assessed, and documented. They do not by themselves establish a jurisdiction-specific legal duty or prove that a particular implementation conforms to the cited guidance.

Sources