For many small and medium-sized enterprises, process improvement still follows a familiar sequence: document the current processes, identify risks and inefficiencies, redesign them, implement the changes and periodically review the results.

This methodology remains valuable. What is changing is the ability to combine it with data, process mining, automation and Artificial Intelligence from the very beginning.

The opportunity is not simply to “add AI” to traditional process consulting. It is to rethink how process reengineering itself is approached.

From process mapping to continuous process intelligence

Traditional process-management platforms are excellent at documenting, modeling and analyzing processes. However, many of them are built around proprietary ecosystems, including proprietary AI capabilities.

An alternative approach is to build a more open architecture in which processes, business rules, operational data and AI can interact through standard interfaces.

An ecosystem based on technologies such as Apache KIE/Kogito, PostgreSQL, PM4Py and Dashbuilder, for example, can provide the foundations for this approach:

  • BPMN and DMN can represent processes and business rules in structured, standardized formats.
  • Process Mining can reconstruct how processes actually operate from historical event data.
  • AI agents can analyze information, identify patterns, assist professionals and accelerate the redesign of processes.
  • APIs and open standards make it possible to connect different AI models and services rather than depending on a single provider.
  • Dashboards and continuous monitoring can turn process performance into an ongoing management activity rather than an occasional review.

The important point is that these technologies have different responsibilities. Process Mining does not “audit” an organization by itself. AI does not determine that a transaction is fraudulent. A process engine does not replace professional judgment.

Instead, each component contributes to a larger methodology in which data provides evidence, technology provides execution and automation, and professionals provide judgment and accountability.

A practical example: Procure-to-Pay

Consider a typical purchasing and payment process:

Purchase Request → Quotation → Purchase Order → Goods Receipt → Invoice → Approval → Payment

A traditional review might examine the documented procedure, interview employees, select samples and evaluate the associated controls.

A process-mining approach can add another dimension: analyzing the historical records of the ERP to reconstruct what actually happened.

It may reveal, for example:

  • invoices paid without a recorded goods receipt;
  • approval steps occurring after payment;
  • unusually long waiting times;
  • duplicated transactions;
  • frequent deviations from the expected process.

The objective is not for AI to declare that fraud has occurred. The objective is to identify exceptions, anomalies and patterns that deserve professional attention.

This changes the role of the auditor or process specialist. Instead of spending most of the effort discovering where to look, the professional can increasingly focus on why an exception occurred, what risk it represents and how the process should be redesigned.

From controls documented in spreadsheets to executable controls

The same principle can be applied to risk and internal controls.

A risk matrix traditionally lives in a spreadsheet or document. With DMN, business rules can be represented in a structured and executable form.

For example:

Transaction amount + customer credit history + credit score → risk level

The AI can help transform existing policies, procedures or historical risk matrices into structured rules. The professional validates those rules and determines whether they accurately represent the organization’s policies and risk appetite.

Once validated, however, the rule can become part of the operational process itself.

The same applies to segregation of duties. A principle such as “the person who creates a purchase request should not subsequently approve the associated payment” can move from being merely a documented control to becoming an actual condition within the workflow.

This is an important conceptual shift:

A control does not have to exist only as a recommendation or a periodic audit test. When appropriate, it can become part of the process itself.

Reengineering means deciding where humans add value

AI-driven reengineering should not be about eliminating human intervention indiscriminately.

Suppose process data shows that a particular approval stage takes four days on average. The relevant question is not simply how to automate it. The better question is:

Does every transaction really require this human intervention?

Perhaps transactions within predefined risk and tolerance thresholds can proceed automatically, while exceptions are routed to a specialist.

In this model, automation does not eliminate control. It concentrates human control where it creates the greatest value.

The same principle can be applied to invoice processing, three-way matching, inventory reconciliation, credit assessment, cash-flow forecasting and many other processes.

From static documentation to a living management system

There is another significant benefit.

Once processes are represented structurally and implemented in a controlled environment, AI can use those process definitions and business rules to assist in generating procedures, operating manuals and training material.

This creates a stronger connection between:

Process → Controls → Rules → Execution → Documentation

When the process changes, the documentation can be regenerated or reviewed against the new process definition.

The objective is to reduce a common problem in management systems: procedures that describe how an organization should operate while the actual operation has gradually evolved in another direction.

Data sovereignty as a strategic principle

For SMEs, this approach can also introduce an important strategic consideration: data sovereignty.

Financial information, customer and supplier data, contracts, operational records and internal controls are among an organization’s most valuable assets.

An open architecture can allow these data and processes to remain within infrastructure controlled by the organization, while still providing access to the AI models and services that make sense for each particular use case.

This is not only about reducing software licensing costs.

It is also about governance, traceability, security, technological independence and avoiding unnecessary dependence on a single technology provider.

Open-source technologies and locally deployable AI models can therefore become strategic components of the architecture, rather than simply cheaper alternatives to proprietary software.

A progressive and adaptive transformation

Perhaps the most important advantage for an SME is that this does not require a “big bang” transformation.

The organization can start with one critical process, such as Procure-to-Pay, Order-to-Cash or Inventory Management.

First, analyze the existing process and its risks.

Then use historical data to understand how it actually operates.

Next, redesign the highest-impact bottlenecks and controls.

Then automate selected activities.

Finally, monitor the results continuously and use the evidence to determine what should be improved next.

This creates a progressive cycle:

Data → Diagnosis → Risk & Controls → Reengineering → Automation → Continuous Monitoring → Professional Intervention on Exceptions

Rather than implementing an enormous technological platform before knowing what the organization actually needs, the technology evolves together with the process.

The real product is not the technology

For SMEs, the most important message is perhaps the simplest one.

The objective is not to introduce Apache KIE, Process Mining, AI agents or any other technology for its own sake.

The objective is to improve the way the organization operates, controls risk and makes decisions.

Technology becomes the enabling infrastructure. Open standards provide flexibility. AI accelerates analysis and implementation. Automation executes validated rules. Data provides continuous evidence.

But professional expertise remains essential.

The result is a different model of process reengineering: more data-driven, more continuous, more adaptive and potentially more sovereign, while preserving the human responsibility for decisions, controls and accountability.

For an SME, this means that process transformation no longer necessarily has to begin with a large software investment. It can begin with a critical process, its data, its risks—and a methodology capable of progressively turning that knowledge into a better way of operating.