Redesigning for AI: What the Board, the CEO and the HR Director Must Decide Before AI Agents Arrive
Most organisations are buying AI tools. Very few are redesigning the work.
An interesting article, based on recent comments by Sonar and McKinsey, popped up over coffee this morning. It was so fascinating I then spent the next hour researching and digging deeper.
Just a week ago, I was in conversation with a coaching client about the difficulties they were having with people just going out and grabbing AI tools to use. The thing that came up for me was not just what bits of stuff that people currently do could be solved by slapping AI tools or agents on it, but: Is this the opportunity to redesign the organization?
The other reason this hit with me is because just last week I was running a workshop with a client who is quite literally starting an AI-first organization (minimum number of people, and everything being designed around workflows where the humans do what the humans only can do, and AI does the rest). Now, that's great when you're building a fresh organization from the ground up, but the world's kind of full of a lot of existing, well-established organizations. Maybe the opportunity is to figure out how to redesign the organisation to optimise the path into the AI future.
The most important question about generative AI is no longer simply:
Which tools should employees use?
It is becoming:
How should the organisation redesign work when AI agents can perform substantial parts of a workflow?
That distinction separates ordinary technology adoption from organisational transformation. A company can give employees copilots and still leave its processes, reporting lines, approvals, job descriptions, incentives, and accountability unchanged. It may obtain local productivity gains, but it is unlikely to capture the larger value available from redesigning the system of work.
Recent work from McKinsey and Sonar makes this point through software development. Their argument is that organisations should not merely insert AI into existing workflows; they should redesign the product-development lifecycle around the capabilities of both people and agents. The reported gains included significantly higher pull-request throughput and shorter development cycle times, demonstrating that the value came from workflow and operating-model redesign, not tool adoption alone.[1, 2]
This has direct implications for three groups that must see the issue differently but act together:
- The Board, which must oversee strategy, risk, accountability, and workforce consequences.
- The CEO, who must redesign how value is created and how work flows across the organisation.
- The HR director, who must translate the redesigned work into roles, skills, career paths, training, performance management, and employee transition.
The central proposition is:
AI agents should not be treated merely as tools attached to existing jobs. They should be treated as participants in redesigned human-agent operating models.
That does not mean every organisation should invent a collection of fashionable new titles. It means the organisation must examine what work is actually performed, decide what should be done by humans and agents, and then deliberately redesign roles around the resulting division of labour.
From automation to work redesign
There are three increasingly ambitious levels of AI adoption.
| Level | Description | Typical result |
|---|---|---|
| Tool adoption | AI assists an existing task | A developer uses code completion |
| Workflow automation | AI performs several connected steps | An agent turns a request into a tested draft |
| Role and operating-model redesign | Work is reallocated across people, agents, systems, and controls | Humans focus on intent, judgement, exceptions, relationships, and accountability |
Most organisations are still operating at the first level. They purchase a model or application, encourage employees to use it, and then hope that productivity will improve. The more consequential opportunity lies at the third level.
McKinsey’s work on agentic organisations describes a future in which people and virtual or physical agents work together in hybrid systems. Some existing roles will shrink, others will expand or change, and new responsibilities will emerge around orchestration, governance, evaluation, and exception handling.[3]
This is not necessarily a prediction that organisations will create a separate “AI department” for every new responsibility. In many cases, the new work will initially be added to existing roles. A product manager may become responsible for supervising product agents. A finance manager may oversee automated controls and exceptions. A subject-matter expert may become a workflow designer and evaluator.
The relevant question is not whether a new job title sounds modern. It is whether the organisation needs a continuing human capability that did not previously exist, or that previously existed only in a much smaller form.
The organisational evidence base
The Sonar example is useful because it illustrates the difference between embedding AI in a task and reconstructing a system of work. McKinsey describes Sonar’s transformation as a redesign of the product-development lifecycle, including workflows, governance, and operating practices.[1]
The sequence is important. An agent may initially review code, then identify issues, then propose fixes, then eventually participate in approval and merge processes. Each step transfers more execution and decision-making responsibility to the agent. The organisation must therefore define new quality gates, escalation rules, permissions, and human responsibilities.
McKinsey’s CEO guidance makes a similar point: capturing value from agents requires redesigning workflows around business outcomes, either within a function or across an end-to-end process such as lead-to-order. Agents need explicit access rights, decision rights, governance rules, and quality gates so that supervising humans are not overwhelmed.[4]
The Conference Board’s 2026 framework expresses the sequence in practical terms:
- Identify the business outcome that matters.
- Identify the work that most affects that outcome.
- Redesign and allocate the work task by task.
- Decide what AI should do, what people should do, and where they should work together.
- Assign a person accountable for the workflow’s result and the use of agents within it.
- Build the required data, permissions, controls, skills, and monitoring.
- Measure the value of the combined work of people and agents rather than focusing only on headcount or cost per employee.[5, 6]
That sequence is more useful than beginning with a technology catalogue.
The organisational map required
To redesign work intelligently, an organisation needs more than a collection of job descriptions. It needs an integrated map connecting business outcomes, processes, roles, tasks, systems, decisions, and risks.
Job descriptions
Job descriptions explain the formal organisation:
- Why the role exists.
- What responsibilities it is expected to carry.
- Where it sits in the hierarchy.
- What qualifications and competencies are expected.
- Who the role reports to.
They are necessary, but insufficient. They describe intended work rather than necessarily describing the work that employees actually perform.
A role described as “manage key client relationships” may involve account analysis, meeting preparation, opportunity detection, proposal drafting, coordination, negotiation, escalation, and relationship maintenance. Those activities have different automation potential and different risk profiles.
Task inventories
The task is the more useful unit for AI analysis.
For each task, the organisation should record:
- The outcome sought.
- The trigger.
- Inputs and data sources.
- Activities performed.
- Systems used.
- Output produced.
- Frequency and volume.
- Time consumed.
- Skills and knowledge required.
- Degree of judgement.
- Consequence of error.
- Current owner.
- Possible human-agent allocation.
- Required review or approval.
For example:
| Task | Possible agent contribution | Human responsibility |
|---|---|---|
| Prepare quarterly client review | Retrieve data, detect patterns, draft agenda and briefing | Interpret implications, manage relationship, decide what to discuss |
| Draft proposal | Assemble relevant material and create first draft | Set commercial position, validate promises, approve final proposal |
| Monitor industry developments | Search, summarise, classify, and alert | Decide strategic significance and response |
| Handle sensitive client concern | Retrieve history and suggest options | Conduct conversation, exercise judgement, preserve trust |
This task-level view prevents the organisation from asking the overly broad question, “Will AI replace this role?” Most roles are bundles of tasks. Some tasks may be delegated; others may become more important for the human.
Process maps
Process maps show how work travels across the organisation. They link:
- Business outcomes.
- End-to-end value streams.
- Departments and teams.
- Roles and tasks.
- Systems and data.
- Handoffs and approvals.
- Decisions and exceptions.
- Outputs and accountability.
The organisation should not necessarily begin by drawing one enormous map of every activity. A better approach is to map priority value streams such as:
- Lead generation to signed contract.
- Order to cash.
- Product idea to launch.
- Customer complaint to resolution.
- Recruitment to onboarding.
- Client intake to coaching engagement.
- Board appointment preparation to ongoing board support.
The maps should distinguish between the process as designed and the process as executed.
Process mining can use event logs from systems such as CRM, ERP, finance, service management, and HR platforms to reconstruct how work actually happens. It can expose bottlenecks, rework, skipped steps, delays, and unexpected process variants.[7, 8]
But process mining cannot see everything. It may not capture phone calls, informal conversations, personal spreadsheets, tacit knowledge, or expert workarounds. Therefore, the strongest approach combines system evidence with employee interviews, workshops, documentation, and AI-assisted analysis.
Decision maps
A decision map goes beyond showing where work travels. It identifies where judgement and authority are exercised.
For each significant decision, the organisation should record:
- The decision itself.
- The person or role currently responsible.
- The data and evidence used.
- Relevant rules or thresholds.
- Permitted discretion.
- Exceptions.
- Consequences of error.
- Required approval.
- Escalation route.
- Whether an agent may recommend, decide, or execute.
- The evidence and audit trail that must be retained.
A useful example is an expense process. An agent might check whether a receipt is attached and whether a low-value expense matches policy. It might recommend approval of a routine claim. It should not necessarily authorise an unusual high-value expense or decide whether an ambiguous client expense is commercially justified.
The process map tells us where the expense claim goes. The decision map tells us who has authority to make each decision and what the agent may do.
Risk and control maps
The risk map identifies what could go wrong and what controls are required.
It should include:
- Data and privacy risk.
- Security and access risk.
- Bias and fairness risk.
- Accuracy and hallucination risk.
- Operational failure.
- Customer or employee harm.
- Regulatory and legal exposure.
- Reputational risk.
- Loss of accountability.
- Agent drift or performance deterioration.
- Escalation failure.
NIST’s AI Risk Management Framework is intended to help organisations incorporate trustworthiness into the design, development, use, and evaluation of AI systems. Its generative-AI profile identifies risks and risk-management actions specific to generative AI.[9, 10]
ISO/IEC 42001 provides a management-system approach for organisations that develop or use AI. It covers leadership, policy, risk management, data governance, transparency, performance monitoring, and continual improvement.[11, 12]
These frameworks do not eliminate the need for organisational judgement. They provide structures through which judgement can be made repeatable, auditable, and governable.
What AI can do, and what it cannot own
AI can assist with much of the mapping work.
It can:
- Extract responsibilities from job descriptions.
- Cluster similar tasks across departments.
- Identify duplicated work.
- Detect likely handoffs and bottlenecks.
- Analyse process logs.
- Infer candidate decision points from policies and procedures.
- Compare documented workflows with actual execution.
- Suggest automation opportunities.
- Classify tasks by judgement, risk, frequency, and value.
- Draft future-state role descriptions.
- Identify missing capabilities.
- Suggest new roles and reporting relationships.
- Generate questions for employee interviews.
- Maintain a living organisational knowledge graph.
However, AI should not be allowed to silently determine:
- What the organisation’s purpose is.
- Which outcomes matter most.
- Who is accountable for a decision.
- What risk the organisation is willing to accept.
- Whether a sensitive exception is legitimate.
- Whether an activity creates trust or strategic value despite appearing inefficient.
- Whether a role should be removed.
- Whether a human capability is ethically or commercially important to preserve.
- Whether the organisation has the cultural capacity to implement the proposed change.
The correct model is therefore:
AI discovers, drafts, compares, simulates, and monitors. Humans interpret, validate, authorise, and remain accountable.
This is especially important because introducing an agent is not merely a technology decision. It is often a transfer of decision rights. McKinsey’s governance guidance emphasises the need to define the scope, ownership, and auditability of agents and their actions.[13]
What this means for the board
The board should not treat AI as solely an operational or IT matter. It should ask whether management has understood how AI changes the company’s operating model, risk profile, workforce, and competitive position.
Strategic questions
The board should ask:
- Which strategic outcomes could be materially improved through agentic workflows?
- Where could agents enable a new product, service, or customer experience?
- Is management merely purchasing tools, or redesigning the business?
- Which processes are strategically differentiating?
- Where could competitors create a structural advantage through agent-enabled work?
- What should remain a distinctive human capability?
The board should be cautious about accepting productivity claims that are not tied to outcomes. More generated content, more automated actions, or more software commits do not necessarily mean more value.
Governance questions
The board should ask:
- What agents are currently deployed?
- What systems and data can they access?
- Which decisions can they make or execute?
- Who owns each agent?
- Where is human approval required?
- How are failures, exceptions, and unauthorised actions handled?
- Can the organisation reconstruct what an agent did and why?
- What happens if an agent must be suspended or rolled back?
- Are material AI risks included in the enterprise risk framework?
PwC’s guidance for boards argues that boards should challenge management to redesign roles, decision rights, skills, and accountability rather than simply automate existing processes. It also identifies workforce readiness, employee trust, and the shift toward a workforce of people and agents as board-level concerns.[14]
Workforce questions
The board should ask:
- Which roles are likely to expand, shrink, or be redesigned?
- How will the company treat productivity gains?
- Will gains be used for growth, reduced workload, redeployment, or headcount reduction?
- Which human skills will become more valuable?
- Is there a credible reskilling and transition plan?
- Are senior leaders being held accountable for responsible adoption?
The board does not need to design every future job description. It does need assurance that management is addressing the consequences systematically.
What this means for the CEO
The CEO’s task is to connect AI adoption to the organisation’s value-creation model.
The CEO should resist two common errors:
- Allowing each function to purchase AI tools independently.
- Treating AI as a cost-reduction project measured mainly through headcount.
The more important CEO responsibility is to identify where agent-enabled redesign can improve the company’s strategic outcomes.
Begin with value streams
The CEO should select a limited number of high-value workflows and ask:
- What customer or business outcome does this workflow produce?
- Where is time lost?
- Where does work wait for approval?
- Where is information repeatedly reassembled?
- Where do employees spend time coordinating rather than exercising judgement?
- Which tasks are expensive because they require scarce expertise?
- What could agents make possible that was previously uneconomic?
The CEO should then appoint one accountable owner for each priority workflow. The owner should be responsible not only for the process outcome but also for how agents are used inside it.
Redesign before deployment
The organisation should not simply insert an agent into a broken process. It should first challenge the process itself:
- Should this step exist?
- Does the handoff add value?
- Is the approval required?
- Can the decision be made earlier?
- Is the same information being entered multiple times?
- Could the process be personalised or monitored continuously?
- What would the process look like if designed from scratch around agents?
McKinsey’s change-management guidance recommends mapping what a key role’s week looks like today and what it should look like tomorrow, including the decisions at which an agent enters the workflow and the moments when a person accepts, rejects, or overrides the agent’s input.[15]
Design agent autonomy deliberately
A useful autonomy ladder might be:
| Level | Agent role | Human role |
|---|---|---|
| 1 | Retrieve and summarise | Review information |
| 2 | Recommend | Accept, reject, or edit |
| 3 | Execute low-risk actions | Monitor |
| 4 | Execute within defined thresholds | Handle exceptions |
| 5 | Coordinate multiple agents | Govern the system and intervene when needed |
The organisation should not move up the ladder merely because the technology appears capable. It should do so only when evidence, controls, and accountability are adequate.
What this means for the HR director
HR is not merely responsible for retraining employees after technology has been selected. In an agentic organisation, HR must help design the work itself.
The Conference Board explicitly argues that IT may own the technology, but HR should help shape roles, skills, staffing, training, and change management wherever AI alters how work gets done.[6]
Build a work and skills inventory
HR should move beyond static job descriptions toward a structured inventory of:
- Roles.
- Tasks.
- Skills.
- Knowledge.
- Decisions.
- Relationships.
- Systems.
- Workload.
- Accountability.
- Risk.
- Learning requirements.
This inventory should be dynamic. As workflows change, role profiles and skill requirements should change with them.
McKinsey’s technology-workforce research recommends a skills-based view rather than relying exclusively on static role definitions. It also argues that people will need support to move into roles where they manage agents alongside colleagues.[16]
Redesign the human role
HR should ask what remains for the human after the agent takes on execution.
The answer may include:
- Setting objectives.
- Providing context.
- Exercising judgement.
- Handling ambiguity.
- Managing relationships.
- Resolving exceptions.
- Validating quality.
- Taking accountability.
- Learning from outcomes.
- Improving the workflow.
- Maintaining trust.
These responsibilities may require greater skill, not less. The World Economic Forum’s Future of Jobs research identifies AI and big-data skills as increasingly important while also emphasising leadership, social influence, creative thinking, resilience, and other human capabilities.[17]
Create new capabilities where necessary
Possible AI-native responsibilities include:
- AI workflow architect: Redesigns end-to-end work around human and agent capabilities.
- Agent operations lead: Monitors deployed agents, permissions, failures, and performance.
- AI quality and evaluation lead: Creates tests, benchmarks, red-team scenarios, and acceptance criteria.
- Knowledge architect: Structures organisational knowledge so agents can retrieve and use it reliably.
- Human-in-the-loop designer: Defines where human review is required and what evidence the reviewer must examine.
- AI governance and risk specialist: Establishes policies, controls, documentation, and monitoring.
- Workforce planning architect: Connects AI strategy to organisational design, staffing, capability development, and workforce transition.
KPMG’s research specifically discusses new roles spanning strategy, operations, governance, workforce planning, AI security, and ethics. It also suggests that organisations may need to give agents formal identities and defined places within HR and organisational systems.[18]
These roles should not automatically become new permanent departments. HR should first determine whether the responsibility is:
- A temporary transformation assignment.
- A responsibility added to an existing role.
- A shared service.
- A full-time specialist role.
- A capability that can be supplied externally.
Change performance management
Traditional performance systems may become misleading when employees work with agents.
For example, an employee may produce more output because an agent performs much of the initial execution. The relevant performance questions become:
- Did the employee choose the right tasks to delegate?
- Did they provide adequate context?
- Did they detect errors?
- Did they handle exceptions effectively?
- Did they improve the workflow?
- Did the combined human-agent system create better outcomes?
- Did the employee preserve trust and accountability?
Performance management should therefore assess the quality of orchestration and judgement, not merely visible activity.
New roles versus redesigned roles
It is useful to distinguish three categories.
Existing role, unchanged
Some roles may be affected very little, especially where work depends heavily on physical presence, deep interpersonal trust, or unusual expert judgement.
Existing role, substantially redesigned
This will probably be the most common category. Examples include:
- Product manager becoming product-and-agent orchestrator.
- Finance manager becoming controller of automated decisions and exceptions.
- Recruiter becoming a talent adviser supervising sourcing and screening agents.
- Executive coach becoming a coach supported by a governed knowledge and analysis system.
- Developer becoming an architect, evaluator, and supervisor of coding agents.
Genuinely new role
A new role is justified where the organisation has a continuing responsibility that no existing role can reasonably absorb. Examples include enterprise agent operations, AI governance, evaluation, workflow architecture, and knowledge architecture.
The goal should not be to create new titles. The goal should be to ensure that important responsibilities have clear owners.
Can a general-purpose AI model do the analysis?
Yes, but only if it is given sufficiently rich and reliable organisational evidence.
A model could analyse:
- Job descriptions.
- Organisation charts.
- Process documentation.
- Policies and controls.
- Meeting transcripts.
- CRM and ERP event logs.
- Service tickets.
- Project records.
- Performance data.
- Employee interviews.
- Skills inventories.
- Customer feedback.
- Risk and audit findings.
It could then produce draft outputs such as:
- Task taxonomies.
- Process maps.
- Role-to-process matrices.
- Decision inventories.
- Risk registers.
- Human-agent allocation proposals.
- Future-state job descriptions.
- Skills-gap analyses.
- Candidate AI-first roles.
- Questions for validation workshops.
- Simulations of proposed workflows.
But a model cannot safely make the final design decisions on its own. It will not automatically know whether an apparent inefficiency is actually a valuable control, whether an exception reflects customer trust, or whether a decision carries political, ethical, legal, or reputational significance.
The best formulation is:
Use AI to accelerate organisational diagnosis and design, but use accountable humans to validate meaning, set boundaries, allocate decision rights, and approve changes.
A practical implementation model
From reading all these articles and papers, the question that came to my mind was: How could this be turned into an implementation model that can be scaled from simple in the smaller organization up to the needs of a large, complex organization.
And what emerged from that thinking was that an organisation could approach this in five stages.
Stage 1: Establish the governance frame
The board and CEO define:
- Strategic outcomes to pursue.
- Acceptable risk boundaries.
- Accountability principles.
- Reporting expectations.
- Workforce commitments.
- Priority business areas.
HR, risk, legal, operations, and technology should be involved from the beginning.
Stage 2: Select priority value streams
Choose a small number of processes with:
- High strategic value.
- Significant volume or cost.
- Visible customer impact.
- Excessive delay or rework.
- Clear data availability.
- A willing accountable owner.
Do not begin by mapping the entire organisation at equal depth.
Stage 3: Build the evidence base
Gather:
- Formal job descriptions.
- Actual task inventories.
- Process documentation.
- System event logs.
- Policies and procedures.
- Interviews and workshops.
- Existing risk and audit information.
- Employee and customer experience data.
Use AI to consolidate and draft the maps, but ask employees and managers to validate them.
Stage 4: Design the human-agent operating model
For each task and decision, specify:
- Human owner.
- Agent contribution.
- Required context.
- Permitted actions.
- Approval threshold.
- Escalation route.
- Evidence and audit trail.
- Quality measure.
- Failure response.
- Skills required of the human role.
Stage 5: Pilot, measure, and institutionalise
Measure:
- Cycle time.
- Quality.
- Error rates.
- Customer outcomes.
- Employee workload.
- Exception volume.
- Agent reliability.
- Human override rates.
- Cost of the combined system.
- New revenue or service possibilities.
Then update the process map, role profiles, skills framework, controls, and training based on actual evidence.
The leadership conclusion
The realization I came to is not that every company should create a large collection of new AI job titles. It is that organisations must stop treating AI as an add-on to a static organisation.
The required transformation is a movement:
From jobs to tasks.
From departments to value streams.
From tools to workflows.
From approvals to explicit decision rights.
From headcount planning to human-agent capacity planning.
From informal experimentation to governed operating models.
The board should ask whether the company is managing the strategic and accountability implications. The CEO should redesign work around outcomes and value streams. The HR director should translate the redesign into roles, skills, career pathways, training, performance systems, and fair workforce transitions.
The most important practical principle is this:
AI can help discover how an organisation works and propose how it might work better. But the organisation’s leaders must decide what work should be done, who should be accountable, what authority may be delegated, and which human capabilities must remain central.
References
Numbers in square brackets in the text link directly to the sources below.
[1] McKinsey
Rethinking software development: An AI-native approach
Sonar case on redesigning product development around AI agents.
[2] McKinsey
Beyond the copilot: Scaling the agentic product development life cycle
Workflow redesign, role change, and agentic product development.
[3] McKinsey
The agentic organization: A new operating model for AI
Human-agent operating models and emerging work patterns.
[4] McKinsey
CEO strategies for leading in the age of agentic AI
CEO priorities, workflow redesign, access rights, and quality gates.
[5] The Conference Board
A Framework for Agentic AI and Work Redesign
Five-stage framework for CHROs and work redesign.
[6] The Conference Board
Report: Companies Need a New Playbook to Unlock the Value of AI Agents
[7] UMSIDA Repository (PDF)
AI-Enhanced Process Mining in Business Analysis
[8] ARIS
What is process mining? Why it matters and how to get started
[9] NIST
AI Risk Management Framework
Trustworthiness and risk management for AI systems.
[10] NIST
Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile
Generative-AI-specific risk guidance.
[11] ISO
ISO/IEC 42001:2023, AI management systems
International standard for organisation-wide AI management systems.
[12] ISO
ISO 42001 explained
[13] McKinsey
Trust in the age of agents: Agentic AI governance for autonomous systems
Decision rights, ownership, and agent governance.
[14] PwC
Board oversight of AI transformation
Board responsibilities for AI, workforce, roles, and accountability.
[15] McKinsey
Agentic AI change management: Closing the adoption gap
Persona-based change journeys and redesigning the role’s week.
[16] McKinsey
Designing an end-to-end technology workforce for the AI-first era
Skills-based workforce design and new technology roles.
[17] World Economic Forum
Future of Jobs Report 2025
Workforce transformation, AI skills, leadership, creativity, and reskilling.
[18] KPMG
Agents of change: New organizational roles in the age of AI
Emerging roles in workforce planning, governance, security, ethics, and agent operations.
[19] McKinsey
Unlocking AI and agentic for your organization
Redesigning workforce roles, skills, and talent profiles.
Further reading
[20] Deloitte
Rethinking operating models for humans with agents
[21] NIST
Generative AI
[22] NIST
AI RMF Resources
[23] ISO
AI management systems: What businesses need to know
[24] ISO
Responsible AI governance and impact standards package
[25] NIST
NIST AI 600-1: Generative Artificial Intelligence Profile (PDF)
[26] ANSI Webstore
ISO/IEC 42001:2023 preview (PDF)
[27] Deloitte
ISO 42001 Standard for AI Governance and Risk Management
[28] BSI
ISO 42001: AI Management System
[29] World Economic Forum
New Economy Skills: Unlocking the Human Advantage (PDF)
[30] World Economic Forum
Four Futures for Jobs in the New Economy: AI and Talent in 2030 (PDF)
[31] McKinsey
Case study: AI in the product development life cycle
[32] McKinsey
HR’s dual mandate in the AI era
[33] McKinsey
Software development: Leading the AI revolution
[34] McKinsey
Agentic AI operating model for enterprise value
Accelerate your career development
Put a C-suite executive coach in your inbox!
Sign up for regular Insights & Tips on leadership and coaching
We hate SPAM. We will never sell your information, for any reason.