
The chair will ask the question every chair is asking right now.
“Where are we on AI?”
The CEO will answer in aggregate. Copilots in marketing. A forecasting model in sales. A customer success agent in pilot. The board will nod. The answer will be wrong, and the chair will not know it.
AI is not adopted by a company. It is adopted inside workflows. Each workflow carries its own risk. Each workflow is open to AI in its own way. The aggregate hides exactly the picture the chair needs.
The right frame is the Target Operating Model. The TOM is a one-page map of the end-to-end processes that run the business. Each box on the map is a full workflow. Click into any box and you see the actual swim lane (who does what, in what order, with which handoff) and the risk register beneath it (causes, controls, initial score, mitigation, post-mitigation residual). The colour on the box is a rollup of the residual scores below.

Live tool: ortent.co/tools/operating-model/. Click a card to drill into the workflow and the risk register beneath it.
In regulated industries the risk score is what the board returns to first. The diagram shows it as a colour and a label. Green for healthy. Amber for watch. Red for acute. Each label rolls up from a consequence-times-likelihood score on every workflow underneath. A cluster of amber boxes inside one operating area gets flagged separately, because three watch boxes in one place is a different conversation from three spread across the map.

The AI overlay is a different layer. It is not a colour score. It is a classification of each workflow into one of three states.
Agent-ready workflows can be run end-to-end by an AI agent, under audit and replay, with a human in the loop only on the exceptions. The handoffs are codified. The inputs are clean. The outputs are inspectable.
Augment workflows are where AI can speed or improve the human work inside the workflow, but cannot run the workflow autonomously. The human is in the loop on every decision. AI is the co-pilot, not the pilot.
Human-only workflows must stay with humans. Judgement, accountability, regulation, or context that does not codify mean AI is the wrong tool. Deploying AI here adds risk, not value.
AI is not adopted by a company. It is adopted inside workflows.
To know where you actually are on AI, you need three things at once. The TOM, mapped. The risk score, current. The AI overlay, applied. Without all three, you are guessing.
You also need a fourth thing the overlay does not give you on its own. A view of which workflows would benefit most from AI if implemented. An agent-ready workflow with a high cost of friction is the best place to invest. An agent-ready workflow with already-good throughput is a waste of the next quarter's budget. The board's job is to argue about that priority on a single page, not in slideware about copilots.
Without the TOM, the picture defaults to something else entirely. Departmental leads play with tools in their own areas. Marketing experiments with copilots because the team is curious. Sales runs a forecasting model because a vendor pitched it. Customer success buys a summariser because the head of success went to a conference. None of them see the broader picture. None of them see the risks the company is taking. Two quarters later the business has spent serious money, has no audit trail across workflows, and the first regulator question becomes a board crisis.
Consider a healthtech company. Three workflows on the same TOM.
The “acquire customer” workflow is amber on the risk score and agent-ready on the AI overlay. The workflow could be automated end-to-end. The risk score says fix the controls first. Invest in the audit trail. Then deploy the agent.
The “patient pathway” workflow is red on the risk score and human-only on the AI overlay. AI is the wrong tool. The workflow needs the operating model fixed before any model is called. The board’s instinct will be to throw an agent at it. The board’s instinct is wrong.
The “regulatory filing” workflow is green on the risk score and augment on the AI overlay. AI can speed the analyst’s work. A human still owns the signature. The gain is in cycle time, not headcount.

Three workflows. Three different answers. None of them visible if the CEO answers the chair in aggregate.
The chair’s question should not be “where are we on AI”. It should be: show me the TOM, show me the risk score, show me the AI overlay, show me which workflow you are moving this quarter.
Without the TOM, AI is a series of departmental experiments. With it, AI is a strategy.
Worked example with both overlays live on the TOM tool: /tools/operating-model/