Audit the workflow and customer impact
Choose one journey and follow real work through it. Record entry points, wait times, rework, approvals, exceptions, customer updates, abandoned cases and informal fixes. Distinguish a painful inconvenience from a constraint that materially affects customers, revenue, cost, risk or management capacity.
Document the baseline with available operational evidence. If the data is weak, say so and include better measurement as the first step. A precise invented number is more dangerous than an honest evidence gap.
Audit people, ownership and adoption capacity
Identify the executive sponsor, process owner, daily users, approvers, administrators and support route. Estimate the time needed for configuration, data cleanup, testing, training and transition. A team that is already overloaded may need a smaller change or dedicated capacity before a new system can succeed.
The World Bank case study of ERP adoption in Viet Nam found that initial use fell over time and highlighted the importance of an internal point person with management support. Treat that result as context from one study, not a universal forecast, but use it to ask who will own adoption after the consultant leaves.
Audit data and integration readiness
List the records the workflow depends on, their owners, required fields, duplicates, retention rules, export formats and systems of record. Sample the data rather than assuming it is clean. Clarify which integrations are required for the pilot and which are merely desirable later.
Avoid using a new platform to hide unresolved ownership. If no one can decide which customer status is correct or which system is authoritative, synchronising the ambiguity will make the problem faster, not smaller.
- Systems of record and authoritative fields.
- Data quality, duplication and reconciliation rules.
- Import/export and exit options.
- Permissions, privileged roles and offboarding.
- Third-party APIs, rate limits and failure handling.
- Retention, deletion, backup and recovery requirements.
Audit security, privacy and recovery
Record what customer, employee, financial or operational information will be accessed and where it will move. Identify least-privilege access, authentication, logging, breach or error response, vendor dependencies and a tested recovery route.
NIST’s small-business quick-start guide is designed for organisations with modest or no cybersecurity plans. Its outcome structure can help an audit ask who governs the risk, what must be identified and protected, how failures will be detected, and how the business will respond and recover.
Turn the audit into a decision
End with a decision, not a maturity score: do nothing yet, improve the existing process, run a small pilot, procure a product, commission implementation or seek specialist advice. State the evidence, assumptions, dependencies and unresolved risks behind that recommendation.
If a pilot is justified, define the user group, workflow boundary, baseline, acceptance threshold, stop conditions, rollback method, owner and review date before purchase. The audit has succeeded when the business can make a smaller and better-informed commitment.