People, Process, and Technology still matter
The People, Process, Technology framework remains useful because each part depends on the other two.
Technology fails when people cannot use it. A process without supporting systems creates more administration. Skilled people inside a fragmented process spend their time compensating for the gaps.
AI can act inside the workflow, so people, process, and technology have to support that action.
AI now adds operating capacity
Stanford's 2026 AI Index reports that 88% of surveyed organizations used AI in 2025. It also summarizes measured productivity gains of 14% to 15% in customer support, 26% in software development, and 50% in marketing output across cited studies.
In the World Economic Forum's Future of Jobs Report 2025, 86% of surveyed employers expected AI and information-processing technologies to transform their business by 2030. Microsoft's 2025 Work Trend Index found that 82% of leaders expected to use digital labor within 12 to 18 months.
GRC teams still scale research, evidence collection, questionnaires, control mapping, and change monitoring through human coordination. AI adds capacity to that work.
AI gives experts more capacity
PwC's 2026 Global AI Jobs Barometer, based on more than a billion job advertisements, associates the most AI-exposed companies with 40% higher productivity growth. It also reports faster headcount and wage growth among companies achieving the largest AI-related productivity gains.
Use that capacity to help experts cover more ground. An experienced reviewer should spend less time locating a policy, copying an obligation, formatting a response, or asking for status. Their time is better spent judging whether the evidence is sufficient, whether a risk is acceptable, and what the organization should do next.
AI should increase the amount of expert judgment an organization can apply while keeping decisions visible and accountable.
Extend the operating model with PPT+AI
PPT+AI is Sorena's extension of People, Process, Technology. It separates AI from technology to make its operating role visible.
- People own the outcome. They set intent, contribute expertise, approve consequential outputs and changes, and remain accountable.
- Process governs the path. It defines triggers, required evidence, review gates, escalation, completion, and the measures used to judge the result.
- Technology holds the truth. It supplies permissioned data, source systems, integrations, identity, event history, and audit records.
- AI observes and moves the work. It retrieves, compares, maps, drafts, monitors, routes, measures, and recommends within the boundaries set by the other three.
Traditional systems record and route work. AI can also prepare the work, detect patterns across many cases, and propose an improvement. Its proposal does not authorize the change.
People own decisions and direct the work
A human-led AI operating model changes where people spend their attention.
Microsoft describes emerging organizations as AI-operated but human-led. Employees direct specialized agents, review their work, and decide where automation belongs. In GRC, people should own applicability decisions, interpretations, risk acceptance, exceptions, and approvals.
They also remain accountable to customers, auditors, boards, and regulators. AI should bring them the relevant source material and complete the preparatory work before a decision reaches them.
Process turns intelligence into repeatable execution
A useful process specifies what starts the work, which sources AI may use, what the output must contain, who reviews it, what happens when evidence is missing, and how completion is recorded. It also defines the baseline, the success measures, and who may approve a process change.
BCG's 10-20-70 approach to AI transformation puts 70% of the effort into people and processes, 20% into technology and data, and 10% into algorithms. Organizations can create value before they have a perfect model. They need a workflow designed around what AI can already do well.
For GRC, assign each AI task to a named owner and a defined workflow. AI retrieves the source, prepares the work, flags uncertainty, routes the reviewer, records the decision, and preserves the evidence. When the same delay or correction keeps appearing, AI should open a review with the cases behind its recommendation.
Technology gives AI context, permission, and memory
Dependable AI needs governed context. The technology layer supplies it through a Single Source of Truth, current source material, identity, permissions, integrations, version history, event logs, and operational telemetry.
In an enterprise workflow, AI knows which material it may use. The reviewer can inspect the passage behind a claim. Event history shows the actual sequence, wait time, handoffs, rework, and exceptions. A later auditor can see what the system proposed, who approved it, and which source was current at the time.
The model can change. The governed context, measurement definitions, and accountability record should remain.
AI gives PPT an execution layer
In the PPT+AI model, AI works inside defined boundaries.
For a compliance workflow, AI can read a new requirement, locate the relevant policy and control, compare the obligation with existing evidence, draft the response, identify a gap, propose the next action, route it to the owner, and assemble the review package. The reviewer receives prepared work instead of a blank page.
IBM reports that 78% of executives believe maximum value from agentic AI requires a new operating model. Give AI a defined job inside a governed process.
AI can inspect the operating model
Execution produces data about how the operating model behaves. AI can examine that record and prepare a case for change across all four parts.
People: Find overloaded review queues, unclear ownership, repeated handoff failures, inconsistent interpretations, and correction patterns that point to a training or guidance gap. AI can recommend a clearer role, a job aid, or a different allocation of work. It should not make employment decisions or score people from opaque proxies.
Process: Reconstruct the path work actually took from event logs, compare it with the approved process, locate wait time and rework loops, group recurring exceptions, predict an SLA miss, and test whether a proposed routing or review rule would help. IBM describes how process mining uses timestamps and organizational data to expose bottlenecks and root causes, including discovery, conformance checking, and enhancement.
Technology: Detect stale or conflicting sources, broken integrations, permission failures, missing event data, configuration drift, duplicate records, rising latency or cost, and systems that no longer support the approved process. AI can identify the affected dependencies and prepare a remediation plan for the system owner.
Operating environment: Monitor authoritative regulatory publications, standards, threat information, vendor notices, customer commitments, incidents, and audit findings. AI can compare a change with policies, controls, contracts, evidence, and open work, then prepare the impact assessment and proposed updates.
Treat a pattern as evidence for review. Only authorized owners can change the organization.
Run a closed improvement loop
Use AI to analyze the operating record without letting it approve its own changes.
- Sense. Watch authoritative external sources and internal events for a new requirement, recurring delay, correction cluster, control failure, or change in demand.
- Diagnose. Compare the intended process with actual cases. Separate a one-off exception from a repeated pattern, show the affected people, systems, controls, and customers, and state what the data cannot prove.
- Recommend. Prepare the proposed process, policy, control, integration, staffing, or guidance change. Include supporting cases, expected effect, risk, confidence, dependencies, owner, and a rollback condition.
- Decide. The accountable human reviews the evidence, resolves tradeoffs, and approves, rejects, or narrows the proposal.
- Implement. AI can draft the updated procedure, control text, test cases, training note, work items, and monitoring rule. The approved change moves through normal change control.
- Verify. Compare the new results with the baseline. Keep, adjust, or roll back the change, and preserve the decision and evidence.
A plausible recommendation can still be wrong. Process data can be incomplete, the measured pattern can have another cause, and an improvement for one metric can damage another.
Measure the workflow, the AI, and the human control
NIST separates information-security measures into implementation, effectiveness and efficiency, and impact. That structure prevents a team from treating deployment as proof of value. The NIST AI RMF Measure playbook also calls for production monitoring, error and incident data, human feedback, overrides, drift checks, and documented performance changes.
Use a small set of measures tied to the purpose of one workflow:
| Question | Metric | Practical definition |
|---|---|---|
| Is work moving? | End-to-end cycle time | Median and 90th-percentile time from a valid trigger to approved completion. Keep wait time separate from active work time. |
| Is the queue under control? | Throughput, work in progress, and SLA attainment | Completed cases per period, open cases by age, and the share completed within the agreed service level. |
| Is quality improving? | First-pass acceptance and rework rate | Share accepted without material correction; share reopened or materially corrected after completion. Record correction reasons. |
| Is GRC coverage improving? | Coverage and freshness | Share of applicable obligations with an owner, mapped control, and current evidence; age of unmapped gaps and expired evidence. |
| Are changes handled sooner? | Change-to-control lead time | Time from an authoritative change being detected to an approved impact decision, then to a verified policy, process, or control update. |
| Is expert capacity returning? | Human review minutes per completed case | Reviewer time including escalations and corrections. Time saved before review does not count if review or rework grows. |
| Is AI dependable for this task? | Supported-claim, error, abstention, and escalation rates | Sampled claims backed by an allowed source; material false positives and false negatives; cases the system correctly declines or routes to a person. |
| Is the control working? | Override, exception, and incident rates | Human overrides by reason, policy exceptions, unauthorized actions prevented, incidents, and time to contain and recover. |
| Is the workflow worth running? | Cost per approved outcome and downstream impact | Model, platform, integration, and human cost per completed case, paired with a relevant outcome such as audit turnaround, past-due findings, or procurement delay. |
Define the numerator, denominator, owner, source, review frequency, target, and risk limit for each metric. Compare with a baseline and segment results by workflow, risk class, business unit, model version, and degree of human review. Raw counts belong beside percentages when volume is small.
Keep the measures separate. One composite AI score hides the tradeoff between speed, quality, risk, and review effort. A 40% cycle-time reduction is useful only if material-error, rework, exception, and oversight measures remain within their approved limits.
Governance lets AI do more useful work
Clear governance lets teams assign AI meaningful work. The NIST AI Risk Management Framework Core connects technical AI work to organizational policies, values, roles, and oversight. It calls for organizations to define responsibilities for human-AI configurations and document human-oversight processes. The GAO AI Accountability Framework organizes its practices around governance, data, performance, and monitoring.
Permissions control what AI can read. Workflow gates control what it can finalize. Evaluation shows where it performs well, monitoring catches drift and failure, and an accountable reviewer resolves consequential cases. Record overrides and appeals as operating data, but do not let the system treat every disagreement as proof that the human or the model was wrong.
AI may identify, draft, test, and recommend a change. Accountable people approve the decision, the risk, and the change to production.
See the model in one GRC workflow
Take a customer security questionnaire.
People: Legal, security, and compliance define the approved positions and assign the final reviewer.
Process: The workflow extracts each question, requires a source-backed answer, flags missing proof, and routes approval before anything is sent.
Technology: Policies, prior approved answers, controls, architecture records, evidence, and case events remain in permissioned systems connected to the workflow.
AI: Sorena Assessment reads the questionnaire, retrieves matching material, drafts answers, cites the evidence, identifies gaps, and sends the decisions to their owners.
After completion, AI can group material corrections, unanswered topics, evidence gaps, long waits, and repeated escalations. It may find that encryption answers are repeatedly corrected because the approved position is stale, or that most of the cycle time sits in one ownership queue. It prepares the cases, likely cause, proposed source or routing change, and expected measure. The policy owner or process owner decides whether to change it.
Track questionnaire cycle time, 90th-percentile queue age, first-pass acceptance, material corrections by reason, evidence freshness, reviewer minutes, and cost per approved response. AI takes on the searching, copying, formatting, chasing, and analysis. The team keeps the decisions.
Sorena makes PPT+AI operational
Sorena brings the four parts into one governed workbench.
- Sorena SSOT gives the technology and AI layers permissioned, current context.
- Sorena Integrations connect the systems where organizational truth already lives.
- Sorena AI Assistant and Research Copilot retrieve, compare, explain, and cite.
- Assessment, Risk Management, Contract Ops, and Law Tracker put that intelligence into owned workflows.
The workbench should preserve the source, recommendation, reviewer action, exception, completion time, and outcome needed to examine the workflow later. Sorena keeps judgment with people, guardrails in the process, organizational truth in governed systems, and bounded execution with AI.
Start with one workflow that should already be faster
Skip the company-wide AI slogan. Choose one recurring workflow where experts lose time to retrieval, reconciliation, drafting, or follow-up.
Before adding AI, record a usable baseline: volume, median and 90th-percentile cycle time, wait time, first-pass acceptance, rework, evidence coverage, reviewer minutes, exceptions, and cost per approved outcome. Define the accountable person, the review path, the approved sources, the work AI may perform, and the conditions that force escalation.
Run a limited set of cases. Compare like with like, review a sample for material errors and missed issues, and inspect who gained or lost work. Keep the change only when it returns expert time or improves coverage without pushing quality, risk, or oversight outside the approved limit.
Then ask the system to watch the workflow for the next repeated delay, correction, gap, or external change and prepare the evidence for its owner.
Frequently asked questions
Isn't AI already part of technology in the PPT framework?+
Yes. PPT+AI separates AI to make its operating role clear. Traditional technology mainly stored, connected, and routed information. AI can analyze context and perform bounded workflow steps such as retrieval, mapping, drafting, monitoring, and routing. That execution role needs explicit ownership and governance.
Does PPT+AI mean replacing people with AI agents?+
No. People own intent, judgment, approval, and risk. AI supplies additional capacity around those decisions. Research from Stanford, PwC, Microsoft, and BCG points toward productivity and human-AI collaboration when organizations redesign work, train people, and introduce clear oversight.
Why does GRC need AI now?+
GRC teams repeatedly retrieve evidence, compare requirements, map controls, draft responses, monitor change, and chase owners. AI can do much of that preparatory work across a larger volume of cases. Organizations that leave those workflows entirely manual must continue adding human coordination as the volume grows.
Where should an organization start?+
Choose one high-volume, reviewable workflow such as a security questionnaire, control review, regulatory-impact assessment, vendor review, or recurring audit. Record the baseline, then define the sources, owner, approval gate, success measures, risk limits, and escalation conditions before adding AI execution.
Can AI decide how a process should change?+
AI can detect a pattern, analyze affected cases, simulate or estimate an alternative, and draft the process, control, guidance, tests, and work items. The process owner and other accountable people decide whether the evidence is sufficient, resolve tradeoffs, and approve, reject, narrow, or roll back the change.
Which PPT+AI metrics matter most?+
Start with end-to-end cycle time, queue age, first-pass acceptance, rework, coverage and evidence freshness, human review minutes, supported-claim and material-error rates, overrides by reason, and cost per approved outcome. Set a baseline and risk limit for each workflow. Do not combine them into one score that can hide a quality or oversight failure.
Sources
- Stanford Institute for Human-Centered Artificial Intelligence, 2026 AI Index Report: Economyhttps://hai.stanford.edu/ai-index/2026-ai-index-report/economy?ref=sorena.io
- World Economic Forum, Future of Jobs Report 2025: Drivers of Labour-Market Transformationhttps://www.weforum.org/publications/the-future-of-jobs-report-2025/in-full/1-drivers-of-labour-market-transformation/?ref=sorena.io
- Microsoft, 2025 Work Trend Index: The Year the Frontier Firm Is Bornhttps://www.microsoft.com/en-us/worklab/work-trend-index/2025-the-year-the-frontier-firm-is-born?ref=sorena.io
- PwC, 2026 Global AI Jobs Barometerhttps://www.pwc.com/gx/en/issues/artificial-intelligence/publications/artificial-intelligence-study.html?ref=sorena.io
- Boston Consulting Group, AI Transformation Is a Workforce Transformationhttps://www.bcg.com/publications/2026/ai-transformation-is-a-workforce-transformation?ref=sorena.io
- IBM Institute for Business Value, Agentic AI's Strategic Ascenthttps://www.ibm.com/thought-leadership/institute-business-value/en-us/report/agentic-ai-operating-model?ref=sorena.io
- NIST, AI Risk Management Framework Corehttps://airc.nist.gov/airmf-resources/airmf/5-sec-core/?ref=sorena.io
- NIST, AI Risk Management Framework Playbook: Measurehttps://airc.nist.gov/airmf-resources/playbook/measure/?ref=sorena.io
- NIST Special Publication 800-55 Volume 1, Measurement Guide for Information Securityhttps://csrc.nist.gov/pubs/sp/800/55/v1/final?ref=sorena.io
- IBM, What Is Process Mining?https://www.ibm.com/think/topics/process-mining?ref=sorena.io
- U.S. Government Accountability Office, An Accountability Framework for Federal Agencies and Other Entitieshttps://www.gao.gov/products/gao-21-519sp?ref=sorena.io


