Evaluation 11 min read

An AI audit that starts with your business

How an operations-first AI audit works: what it looks for, how the evidence is collected, what the report contains, and what it tells you to skip.

If you run a small business, you have probably had the AI conversation by now. A supplier has pitched you something, a competitor claims to be using it, and somewhere in your week there is a job that feels like a machine should already be doing it. The question is no longer whether AI is relevant to your business. The question is where to start, and you cannot answer it from inside a product demo.

There are two ways to look for AI in a business. You can start with the technology: what the model can do, where a chatbot could fit, which platform to deploy, and then hunt for somewhere to use it. Or you can start with the operations: how the business actually runs, where the time goes, where customers drop off, where money leaks, and only then ask whether AI is the right intervention. Sometimes it is. Sometimes it is not. The method should not have a preferred answer.

We work the second way. Across the audits and analyses we have now written, spanning bookkeeping, family law, property valuation, trades, and professional services, that distinction, technology-first versus operations-first, has been the single biggest predictor of whether an AI project delivers value or becomes another tool nobody uses. That is our own experience talking, and most of this post is built on it.

This is the full shape of how we run an audit: what it looks for, how the evidence gets collected, what the report has to contain to be worth paying for, and what happens after you have read it.


Why do technology-first AI projects fail?

They fail because the technology gets chosen before the problem gets diagnosed. Every industry has a version of the same story. A business invests in a new system: a CRM, a reporting dashboard, a customer management platform. It gets built to spec. It works. It launches. Six months later, nobody uses it. Nobody asked who would actually enter the data, what would happen with the output, or whether the people responsible for acting on it had any reason to. The technology was sound. The evaluation was missing.

AI has the same failure mode, with a twist that makes it worse. Garbage in, garbage out is an old rule, and AI updates it cruelly: garbage in now gives you plausible garbage out. Output that reads almost right and is quietly wrong. A business that bolts a model onto messy data and an undiagnosed process does not get an obvious failure it can catch. It gets slop it might act on. In everything we have built and reviewed, when an AI project disappoints, the model is rarely the reason; the foundation it was bolted to usually is, and the published evidence we track in our State of AI review keeps pointing the same way.

Here is how the failure plays out. A business asks for a chatbot, because chatbots are the visible technology. Built technology-first, the chatbot gets delivered, and it even works. But the problem actually costing the business money was never identified. Maybe it is the quotes that never get followed up. Maybe it is the two hours a day someone spends copying data between systems. Maybe it is the complete absence of any contact with a customer after their first purchase. These are not technology problems. They are operational problems that technology can solve, but only if someone diagnoses them first.


What does an operations-first audit look for?

It looks for three things a technology-first lens misses: revenue that is leaking, time that is invisible, and the adoption barriers that will kill the project.

Revenue that is leaking, not missing. Most owners think of AI as a way to do new things. In our experience the highest-value findings are usually about stopping existing losses: quotes that go unfollowed, customers never contacted again after their first job, enquiries that arrive outside business hours and are answered the next afternoon or not at all. These are measurable, recurring losses that compound every month, and they are invisible to a technology-shaped review because they are not technology-shaped problems.

Time that is invisible. Ask any business owner how they spend their day and they will describe the work they value. Record the actual day and a different picture emerges: hours spent on repetitive sequences that follow identical patterns. Data copied between systems. Emails drafted from the same template. Follow-ups sent manually that could be triggered automatically. These tasks are the highest-leverage automation targets precisely because they happen every day without anyone noticing them. We have written up the method for surfacing them in the personal workflow audit.

Adoption barriers that will kill the project. The most common reason we see AI projects fail is not that the technology does not work. It is that the people who need to use it will not. An operations-first audit identifies those barriers before anything gets built: who will use this tool, what changes about their day, and what the rollout has to do about their resistance.

The highest-impact opportunity is rarely the most technically impressive one. It is usually the one that removes the most friction from the process that drives revenue. The evidence should decide, not the toolkit.


Which question are you actually asking?

Nearly every audit request we receive is one of two questions, and it pays to know which one is yours. The first is strategic: where should we invest in AI? The second is personal: where is my time going, and what can I get back?

The first question is top-down. Answering it means looking at the whole business from the outside in: your digital presence, your market position, your customer journey, your operations, and mapping each opportunity against cost, effort, and expected return. This is the right question for an owner who knows AI is relevant but does not know where it fits, or a business that wants the full picture on paper before committing budget to anything.

The second question is bottom-up. Answering it means a day-in-the-life analysis of one person’s work: not how they describe their day, but what a recording of a typical workday actually reveals. Some owners run it on themselves, to strip out the repetitive grind and reclaim hours for the work that grows the business. Others point it at a specific role, so one person’s workflow becomes a proven model for the rest of the team. This is the right question for someone who feels busy but cannot pinpoint where the hours go.

The two answers feed each other. The business-level view might find that lead follow-up is the highest-return thing to automate. The desk-level view might reveal that the owner spends two hours a day on admin, and that those two hours are exactly why the follow-up never happens manually. One finds the opportunity. The other removes the obstacle.

We deliver both under one product, the Workflow audit, scoped to whichever question you are asking. Part of the audit’s job is to find the best place to start: the first pain point might sit with one person, one role, one team, or the whole organisation, and choosing that starting point well matters more than choosing the most impressive one. There is no wrong entry: each scope produces recommendations that stand on their own, and one often uncovers the other’s territory. A business-wide audit tends to expose workflow problems worth measuring; a single desk tends to expose strategic opportunities nobody could see from the top.


How is the evidence collected?

We automate the collection and keep the judgement personal. Data collection is what makes an audit expensive and disruptive, so it is the part we automate as far as we can. The reading of the evidence, and the strategy that comes out of it, is the part a person does.

The groundwork starts before we take up any of your time. We use AI to compile what is already public about your business, your market, and how AI is actually being applied in your industry, so the engagement does not open with a blank page and a long questionnaire. Where staff input matters, we sometimes use AI-conducted, always-disclosed interviews to collect and confirm information. Done well, that is thorough and even-handed in a way a round of meetings rarely is: the awkward question a person softens or skips gets asked plainly and answered, without the politics, the defensiveness, or the fortnight of diary coordination.

For the desk-level question, the method is observation. The person records a representative workday using the screen recording built into their operating system, and the recording is analysed for repetitive task sequences, context-switching patterns, and work that follows the same structure every time it occurs. These are the tasks you stop noticing, because they feel like just doing the work.

One more thing the collection produces, worth naming because it is easy to undervalue: the compiled picture is a deliverable in itself. Before anything is recommended, you get a clear view of how AI is actually affecting your industry and where it touches your particular business. For some owners, being brought genuinely up to speed is the most valuable thing the whole engagement produces, and it leaves the decision where it belongs: with you, made from a clear view, including the decision that the timing is not right yet.


What does a good audit report contain?

Specific findings ranked by effort to impact, grounded in your numbers, with the answer on the first page and an honest list of what to skip. We write the report as the whole product: there is no live demo to distract from a weak recommendation and no prototype bundled in to carry the argument. The report has to earn a decision sitting on your desk with nobody there to talk it up, and that constraint changes what goes in it.

Findings, not categories. “AI could help with your follow-up” is a category. It gives you nothing to act on, cost, or measure. A finding written to standard reads more like: “AI-assisted follow-up on 340 dormant leads is projected to reactivate 8 to 12% within 90 days, adding $28,000 to $42,000 in revenue.” (Those numbers are illustrative; in a real report they are calculated from your own records.) Every recommendation has to survive five questions: what exactly should we do, how much will it cost, how long will it take, what will the return be, and what happens if it does not work. A recommendation that cannot answer all five comes out of the report. Three specific findings beat thirty pages of vague possibility, because vagueness wastes an owner’s most limited resource, which is the energy to make a decision.

The answer on the first page. The report opens with the top three opportunities, not the methodology. From there, recommendations are ranked by effort to impact: quick wins that land in days, medium-term opportunities, and the larger strategic plays, with the sequence made explicit. The ordering matters as much as the findings, because the fastest way to stall a project is to begin with the hardest item on the list.

Your numbers, not industry averages. A projection built on your own conversion rates and margins is one you can check against what you already know. A projection built on an industry benchmark is one you have to take on faith. The numbers in the report come from the business being audited, which is the whole point of starting with the operations.

What to skip. A report that only ever says yes is a sales document. The most useful line in an audit is often “you do not need this yet,” when it is true. The same discipline applies to tools that do not work as sold: capabilities a vendor shows on a slide but cannot run at your volume, autonomous systems that are still demos, and the pilot that will fail for adoption reasons rather than technical ones. We keep a running, sourced view of which capability claims actually hold in our State of AI review, and the report draws on it. Naming what to avoid, before it costs you money, is worth as much as naming what to pursue.


What happens after the report?

A clear next step, which is sometimes nothing. The Workflow audit delivers a written report with specific, prioritised recommendations. It is not a slide deck, and it is deliberately not a proposal for more work: the report has to be worth its fee if you never speak to us again, and “act on this internally” or “wait” are legitimate next steps for it to name.

If a recommendation is worth building and you want us involved, the build that follows starts with a working prototype of the priority opportunity, so nothing larger is committed on faith. That is the shape of how we work overall: workflow mapping to learn how your business actually runs, AI design to identify what is worth automating, then build. We build it, or coach your team to. Either way, you own the result.

The sequencing principle is first win first. The opening move is chosen because its benefit clearly exceeds its cost, it is delivered before anything larger is attempted, and it funds the search for the next opportunity. One pattern from our own client work shows how this compounds. A business hitting a ceiling often reaches for a new admin hire, and the cost and lead time of that hire is itself the bottleneck to scaling. Instead, we help the admin person you already have put AI through their workflow, and the business absorbs the extra load without adding a salary. When you do eventually hire, the new person steps into a system that works instead of inheriting chaos, and your original person moves up to improving the next part of the business on the same model.

There is a quieter payoff underneath the time saved. The first win forces the data behind it to be tidied, structured, and owned, and that foundation is what every later win gets cheaper by. It is also what keeps you model-agnostic: the models will keep changing, and something benchmarks higher every few months, but swapping to a better one stays cheap when the value lives in your own systems rather than in whichever model is current. That foundation, not the model, is what makes the result a system rather than a tool, and there is no lock-in to us or to a vendor.

If you want to see the whole arc on a real engagement, one client, one finding, one build, we have written it up: what a good AI audit actually delivers follows a coaching practice from a paper form to a working system, including the recommendation the report argued against.

Recommendations are easy to write and easy to ignore. An audit specific enough to act on, honest enough to tell you what to skip, and grounded enough that you can check the numbers yourself: that is where the value sits, and we can show you a real sample written for a business like yours before you commit to anything.


Perth AI Consulting delivers the Workflow audit as part of AI strategy and governance for small and medium businesses in Perth. A written report with specific, prioritised recommendations and a clear next step. Start with a conversation.

Published 2 February 2026

Perth AI Consulting delivers AI opportunity analysis for small and medium businesses. Start with a conversation.

Prepared by Claude, directed and approved by PAC.

More from Thinking

Evaluation 11 min read

AI in property valuation: the evidence, the design rules, and what it could become

The best Australian evidence on vision AI in valuation measures a different task than the one vendors demo. The findings, and the design rules that follow.

Evaluation 7 min read

Eleven cells moved. Here is what they mean for your business.

Reading the September 2026 State of AI verdict table: what improved, what declined, and what to do differently this quarter.

Evaluation 7 min read

Competitor intelligence for small business: what AI can and cannot see

What AI-assisted competitor intelligence really is for a small business: the public sources worth watching, what they cannot tell you, and the legal line.

Evaluation 10 min read

AI in regulated professional work, Mid-2026

One structure links family law, valuation, and building inspections: a signed document others rely on. How each field's regulator answered the AI question.

Technical 9 min read

The business knowledge base: evidence, risks, and how to build one

What a business knowledge base actually is, what the evidence says it delivers, the security and privacy realities, and how we build one that holds up.

Evaluation 8 min read

What AI can see in your customer data (and what it cannot)

What AI can genuinely find in the customer records an SME already holds, what it cannot, and when a spreadsheet honestly beats a model.

Building 7 min read

What an AI quoting engine actually does

What an AI quoting engine takes in, what it drafts, what the evidence says about accuracy and speed, and why the final price stays with a human.

Adoption 6 min read

Australia's AI adoption gap is bigger than the 12% headline suggests

ABS says 12% of Australian businesses use AI. The real story is 35% of large businesses against 11% of small ones, and the barrier isn't the technology.

Building 7 min read

Why we let AI run the interviews (and why we never let it pretend to be human)

AI-conducted interviews compress weeks of stakeholder discovery into days, standardise what gets asked, and lower the guard that distorts honest answers.

Adoption 14 min read

How AI capability actually moves through a business

The decisive variable in SME AI adoption is the human absorption sequence, not the tooling. A working framework from observation across WA businesses.

Evaluation 7 min read

AHPRA advertising rules for psychologist websites

Recovery stories, 'specialist', 'clinical psychologist', and endorsement titles are where psychology sites breach the National Law. A practical read-through.

Adoption 4 min read

Customer service AI has finally grown up

Chatbots and AI receptionists earned their bad reputation. What changed, and how the mature version answers every call without replacing anyone.

Evaluation 6 min read

Who can use the titles 'Dr', 'Specialist', and 'Surgeon'?

AHPRA restricts 'specialist' and 'surgeon' to specific registrations, and 'Dr' has its own rule. What health practice websites can and cannot claim.

Adoption 5 min read

Your best people hate writing reports

The operators you promote are brilliant at the work and allergic to reporting. A scheduled AI call interviews them, drafts the briefing, they approve it.

Building 6 min read

Your website isn't just for humans anymore

How to build a chatbot that keeps itself up to date, can't leak client information, and won't answer beyond what you've published.

Evaluation 7 min read

Can you show Google reviews on your health practice website?

AHPRA bans clinical testimonials, even true ones, but service reviews are fine. What that means for the Google reviews widget on your practice site.

Evaluation 7 min read

What AHPRA's advertising rules mean for your website

Your practice website is advertising under the National Law. What AHPRA's rules prohibit, who is responsible, and how to check your own site.

Evaluation 8 min read

Is it safe to paste client data into ChatGPT?

Short answer: it depends on one setting, and most people have it wrong. What ChatGPT, Claude and Copilot do with your data, and what the Privacy Act expects.

Evaluation 4 min read

What a good AI audit actually delivers

The audit report named one recommendation specific enough to check, and what the Build that followed looked like: one real engagement, generalised.

Evaluation 7 min read

AI and video, Mid-2026: the models can watch now, not just listen

AI could always transcribe video. It can now read the frames as well, and every hour of footage a business owns becomes something it can question.

Building 7 min read

Case study: a 119-page AML/CTF program in three days

How we built a seven-document AML/CTF compliance pack for a small accounting practice in three days, working from 31 confirmed assumptions.

Building 11 min read

From evidence base to delivery: a production AI methodology

How we delivered 34 evidence-anchored AI briefings to a WA peer-advisory chapter: fact-checked literature review, multi-agent verification, one method.

Technical 9 min read

The six functions of a working AI system

A working AI system is six functions doing six jobs. When all six connect, hallucinations get caught, outputs hold steady, and models become swappable.

Technical 7 min read

Supervised autonomy: the middle path for AI architecture

Between drafts you approve and agents you hope about sits the middle path: an envelope of authorised routine work, supervised, audited, and yours to widen.

Evaluation 5 min read

The state of applied AI in Mid-2026

Our literature review of applied AI in mid-2026: ten capability categories, three fact-check passes, written for operational leaders.

Technical 9 min read

How to design a PHI redaction system for clinical AI

PHI redaction is part of a clinical AI tool's architecture, not a feature you add. What the literature says it should look like, and how we built it.

Building 9 min read

How we built on-device de-identification so AI never sees real names

Most AI privacy is a policy. Ours is architecture: an NER model runs in the browser and strips names before anything leaves the device.

Technical 7 min read

Your agency's clients are about to ask why this costs so much

A solo consultant built in three weeks what your agency quoted twelve for. The client doesn't know why yet. The agencies that survive change what they sell.

Adoption 6 min read

What do you love doing? What do you hate doing?

Ask people what they love doing and what they hate doing, then show them AI is coming for the second list. Why the reframe works, and how it fails.

Technical 7 min read

Why I don't use n8n (and what I do instead)

n8n demos well. But a compelling demo and a reliable production system are different things, and the distance between them is where businesses get hurt.

Technical 10 min read

Your codebase was not built for AI. That's the actual problem.

Amazon's mandatory meeting about AI breaking production is an architecture story: codebases built for human maintainers only, now maintained by AI.

Adoption 4 min read

Your team has AI licences. You don't have an AI system.

Fifteen people, fifteen separate AI accounts, no shared context. The problem isn't the tool; it's the architecture around it. Here's the fix.

Building 7 min read

Your $2,000 day starts the night before: our system keeps you on the tools, not on the phone

Optimised routes overnight, automatic customer notifications, and promises the system keeps or corrects. A scheduling system that protects your daily rate.

Evaluation 4 min read

The fastest way for an executive to get across AI

AI moves faster than any executive can track. One focused conversation, one written report, and a decision you can act on: your time stays on the business.

Building 6 min read

Your IT department will take 18 months. You need this working by next quarter.

Senior leaders know what they need built; the gap is time. A prototype gets the tool working now and hands IT a validated blueprint for later.

Building 8 min read

We built an AI invoice verifier. Here's where it hits a wall.

We built an AI invoice verifier and watched a fake beat a real invoice. Why document analysis alone cannot stop fraud, and the five layers that can.

Building 5 min read

How to build an AI chatbot that doesn't lie to your customers

Woolworths scripted its AI to talk about its mother. The business fix is honesty; the technical fix is architecture that prevents fabrication by design.

Technical 9 min read

Why AI safety features are load-bearing architecture, not political decoration

The 'woke AI' label came from real failures, but they were engineering failures, not safety failures. The difference matters wherever errors have consequences.

Adoption 3 min read

Woolworths' AI told a customer it had a mother. That's a problem.

Woolworths' AI assistant Olive was scripted to talk about its mother and uncle. When callers realised, trust broke instantly. The fix is honesty.

Evaluation 5 min read

Google is no longer the only way your customers find you

Customers now find businesses through ChatGPT, Perplexity, and Gemini. The sites AI cites are structured differently to the sites Google ranks.

Evaluation 6 min read

The personal workflow analysis: what watching a real workday reveals about automation

People describe the work they value, not the work that eats their time. Recording a real workday reveals the automation opportunities interviews miss.

Building 6 min read

What production AI teaches you that demos never will

The gap between a demo and a working system is where the useful lessons live. Architecture, framing, privacy, adoption: the patterns repeat every time.

Adoption 6 min read

The psychology of why your team won't use AI

You buy the tool, run the demo, and three months later nobody is using it. Five predictable psychological barriers, each with a strategy that works.

Technical 4 min read

Stop telling AI what NOT to do (and what to say instead)

Instructions built on prohibitions make AI cautious and generic. Describing what you want instead transforms the output, and the reason comes from psychology.

Building 5 min read

How we turned generic AI into a specialist: and what that means for your business

Mediocre AI output is rarely the model's fault. Three structural changes that turn the same model from generic to specialist-grade.

Evaluation 6 min read

Your business has 9 customer touchpoints. AI can fix the 6 you're dropping.

You pay to get customers to your door, then lose them to missed follow-up. AI can handle the six touchpoints most businesses drop.

Technical 6 min read

What happens to your data when you press 'Send' on an AI tool

Businesses send customer data to AI tools without knowing what happens during processing. The spectrum of AI privacy is wider than you think.